diff --git a/advisories/unreviewed/2023/11/GHSA-wv85-vm3v-v274/GHSA-wv85-vm3v-v274.json b/advisories/unreviewed/2023/11/GHSA-wv85-vm3v-v274/GHSA-wv85-vm3v-v274.json index 595acc83f7d..40f00dfc45a 100644 --- a/advisories/unreviewed/2023/11/GHSA-wv85-vm3v-v274/GHSA-wv85-vm3v-v274.json +++ b/advisories/unreviewed/2023/11/GHSA-wv85-vm3v-v274/GHSA-wv85-vm3v-v274.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv85-vm3v-v274", - "modified": "2023-11-09T18:34:55Z", + "modified": "2024-07-22T15:32:35Z", "published": "2023-11-09T18:34:55Z", "aliases": [ "CVE-2023-47610" diff --git a/advisories/unreviewed/2024/07/GHSA-54pm-mxvc-pw27/GHSA-54pm-mxvc-pw27.json b/advisories/unreviewed/2024/07/GHSA-54pm-mxvc-pw27/GHSA-54pm-mxvc-pw27.json new file mode 100644 index 00000000000..ccb761ce922 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-54pm-mxvc-pw27/GHSA-54pm-mxvc-pw27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54pm-mxvc-pw27", + "modified": "2024-07-22T15:32:42Z", + "published": "2024-07-22T15:32:42Z", + "aliases": [ + "CVE-2024-41828" + ], + "details": "In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41828" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json b/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json new file mode 100644 index 00000000000..303a05593d9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-634r-qhgm-h5w5/GHSA-634r-qhgm-h5w5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-634r-qhgm-h5w5", + "modified": "2024-07-22T15:32:40Z", + "published": "2024-07-22T15:32:40Z", + "aliases": [ + "CVE-2024-41315" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41315" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_4_apcli_do_enr_pin_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-63gw-9jw7-v975/GHSA-63gw-9jw7-v975.json b/advisories/unreviewed/2024/07/GHSA-63gw-9jw7-v975/GHSA-63gw-9jw7-v975.json new file mode 100644 index 00000000000..e881407e346 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-63gw-9jw7-v975/GHSA-63gw-9jw7-v975.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63gw-9jw7-v975", + "modified": "2024-07-22T15:32:42Z", + "published": "2024-07-22T15:32:42Z", + "aliases": [ + "CVE-2024-41827" + ], + "details": "In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41827" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6v56-9m73-2rm4/GHSA-6v56-9m73-2rm4.json b/advisories/unreviewed/2024/07/GHSA-6v56-9m73-2rm4/GHSA-6v56-9m73-2rm4.json new file mode 100644 index 00000000000..1bf079c0a09 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6v56-9m73-2rm4/GHSA-6v56-9m73-2rm4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v56-9m73-2rm4", + "modified": "2024-07-22T15:32:40Z", + "published": "2024-07-22T15:32:40Z", + "aliases": [ + "CVE-2024-39601" + ], + "details": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39601" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-071402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8582-mjhv-rmrr/GHSA-8582-mjhv-rmrr.json b/advisories/unreviewed/2024/07/GHSA-8582-mjhv-rmrr/GHSA-8582-mjhv-rmrr.json new file mode 100644 index 00000000000..18dfedd9e75 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8582-mjhv-rmrr/GHSA-8582-mjhv-rmrr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8582-mjhv-rmrr", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-21552" + ], + "details": "All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21552" + }, + { + "type": "WEB", + "url": "https://github.com/TransformerOptimus/SuperAGI/blob/9361f0491716e56bd0c0ae2f3b49da201a18c58c/superagi/agent/output_handler.py#L149" + }, + { + "type": "WEB", + "url": "https://github.com/TransformerOptimus/SuperAGI/blob/9361f0491716e56bd0c0ae2f3b49da201a18c58c/superagi/agent/output_handler.py#L180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json b/advisories/unreviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json index ee9a9252f08..0cf242ca46c 100644 --- a/advisories/unreviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json +++ b/advisories/unreviewed/2024/07/GHSA-8pxv-x6jq-5vw9/GHSA-8pxv-x6jq-5vw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pxv-x6jq-5vw9", - "modified": "2024-07-22T12:30:37Z", + "modified": "2024-07-22T15:32:39Z", "published": "2024-07-22T12:30:37Z", "aliases": [ "CVE-2024-38503" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/22/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json b/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json new file mode 100644 index 00000000000..2c6713f7146 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qw7-q76p-7f4h", + "modified": "2024-07-22T15:32:42Z", + "published": "2024-07-22T15:32:42Z", + "aliases": [ + "CVE-2024-41829" + ], + "details": "In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41829" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9gq7-p5w9-w899/GHSA-9gq7-p5w9-w899.json b/advisories/unreviewed/2024/07/GHSA-9gq7-p5w9-w899/GHSA-9gq7-p5w9-w899.json new file mode 100644 index 00000000000..33801cc262a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9gq7-p5w9-w899/GHSA-9gq7-p5w9-w899.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gq7-p5w9-w899", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-26020" + ], + "details": "An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26020" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-ccff-2f27-4w8g/GHSA-ccff-2f27-4w8g.json b/advisories/unreviewed/2024/07/GHSA-ccff-2f27-4w8g/GHSA-ccff-2f27-4w8g.json new file mode 100644 index 00000000000..471d12dddbb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-ccff-2f27-4w8g/GHSA-ccff-2f27-4w8g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccff-2f27-4w8g", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-41318" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41318" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_5_apcli_wps_gen_pincode/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cwqg-24rf-cjwq/GHSA-cwqg-24rf-cjwq.json b/advisories/unreviewed/2024/07/GHSA-cwqg-24rf-cjwq/GHSA-cwqg-24rf-cjwq.json new file mode 100644 index 00000000000..24bc30a45c6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cwqg-24rf-cjwq/GHSA-cwqg-24rf-cjwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwqg-24rf-cjwq", + "modified": "2024-07-22T15:32:42Z", + "published": "2024-07-22T15:32:42Z", + "aliases": [ + "CVE-2024-41826" + ], + "details": "In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41826" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fg59-j242-rcj9/GHSA-fg59-j242-rcj9.json b/advisories/unreviewed/2024/07/GHSA-fg59-j242-rcj9/GHSA-fg59-j242-rcj9.json index 21db8fd98d7..7c785578786 100644 --- a/advisories/unreviewed/2024/07/GHSA-fg59-j242-rcj9/GHSA-fg59-j242-rcj9.json +++ b/advisories/unreviewed/2024/07/GHSA-fg59-j242-rcj9/GHSA-fg59-j242-rcj9.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json b/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json new file mode 100644 index 00000000000..482d6a4771b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j6w5-3xwm-qv7j/GHSA-j6w5-3xwm-qv7j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6w5-3xwm-qv7j", + "modified": "2024-07-22T15:32:40Z", + "published": "2024-07-22T15:32:40Z", + "aliases": [ + "CVE-2024-41314" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41314" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_1_vif_disable/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json b/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json index 40ba695129e..27765c302c3 100644 --- a/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json +++ b/advisories/unreviewed/2024/07/GHSA-j73p-gc9r-3pf8/GHSA-j73p-gc9r-3pf8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j73p-gc9r-3pf8", - "modified": "2024-07-22T12:30:36Z", + "modified": "2024-07-22T15:32:39Z", "published": "2024-07-22T12:30:36Z", "aliases": [ "CVE-2024-34457" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/brlfrmvw9dcv38zoofmhxg7qookmwn7j" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/22/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-m88w-qcr5-cq82/GHSA-m88w-qcr5-cq82.json b/advisories/unreviewed/2024/07/GHSA-m88w-qcr5-cq82/GHSA-m88w-qcr5-cq82.json new file mode 100644 index 00000000000..ea40461a653 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-m88w-qcr5-cq82/GHSA-m88w-qcr5-cq82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m88w-qcr5-cq82", + "modified": "2024-07-22T15:32:42Z", + "published": "2024-07-22T15:32:42Z", + "aliases": [ + "CVE-2024-41824" + ], + "details": "In JetBrains TeamCity before 2024.07 parameters of the \"password\" type could leak into the build log in some specific cases", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41824" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json b/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json new file mode 100644 index 00000000000..b3c5d5bd5f4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p742-rf2c-hvf6/GHSA-p742-rf2c-hvf6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p742-rf2c-hvf6", + "modified": "2024-07-22T15:32:40Z", + "published": "2024-07-22T15:32:40Z", + "aliases": [ + "CVE-2024-41316" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41316" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_2_apcli_cancel_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q47p-v5rw-v574/GHSA-q47p-v5rw-v574.json b/advisories/unreviewed/2024/07/GHSA-q47p-v5rw-v574/GHSA-q47p-v5rw-v574.json new file mode 100644 index 00000000000..0fa0361d5dc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q47p-v5rw-v574/GHSA-q47p-v5rw-v574.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q47p-v5rw-v574", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-32152" + ], + "details": "A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32152" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1994" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-184" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-r6f4-5657-3fp7/GHSA-r6f4-5657-3fp7.json b/advisories/unreviewed/2024/07/GHSA-r6f4-5657-3fp7/GHSA-r6f4-5657-3fp7.json new file mode 100644 index 00000000000..60b1ee259e0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r6f4-5657-3fp7/GHSA-r6f4-5657-3fp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6f4-5657-3fp7", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-32484" + ], + "details": "An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32484" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1995" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rghf-m847-v399/GHSA-rghf-m847-v399.json b/advisories/unreviewed/2024/07/GHSA-rghf-m847-v399/GHSA-rghf-m847-v399.json new file mode 100644 index 00000000000..e4bc18a9a1c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rghf-m847-v399/GHSA-rghf-m847-v399.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rghf-m847-v399", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-41320" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41320" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_6_get_apcli_conn_info/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rp56-x26j-363p/GHSA-rp56-x26j-363p.json b/advisories/unreviewed/2024/07/GHSA-rp56-x26j-363p/GHSA-rp56-x26j-363p.json new file mode 100644 index 00000000000..c6b9526fafa --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rp56-x26j-363p/GHSA-rp56-x26j-363p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp56-x26j-363p", + "modified": "2024-07-22T15:32:40Z", + "published": "2024-07-22T15:32:40Z", + "aliases": [ + "CVE-2024-37998" + ], + "details": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled. This could allow an unauthorized attacker to obtain administrative access of the affected applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37998" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-071402.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json b/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json new file mode 100644 index 00000000000..ba2c40cd650 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vq4q-wfv6-qgq8/GHSA-vq4q-wfv6-qgq8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq4q-wfv6-qgq8", + "modified": "2024-07-22T15:32:40Z", + "published": "2024-07-22T15:32:40Z", + "aliases": [ + "CVE-2024-41317" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41317" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_3_apcli_do_enr_pbc_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x3r6-ccvq-cf5v/GHSA-x3r6-ccvq-cf5v.json b/advisories/unreviewed/2024/07/GHSA-x3r6-ccvq-cf5v/GHSA-x3r6-ccvq-cf5v.json new file mode 100644 index 00000000000..9472e1f5664 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x3r6-ccvq-cf5v/GHSA-x3r6-ccvq-cf5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3r6-ccvq-cf5v", + "modified": "2024-07-22T15:32:41Z", + "published": "2024-07-22T15:32:41Z", + "aliases": [ + "CVE-2024-29073" + ], + "details": "An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29073" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-xwcg-xmmg-hh8r/GHSA-xwcg-xmmg-hh8r.json b/advisories/unreviewed/2024/07/GHSA-xwcg-xmmg-hh8r/GHSA-xwcg-xmmg-hh8r.json new file mode 100644 index 00000000000..067d8cb66f7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-xwcg-xmmg-hh8r/GHSA-xwcg-xmmg-hh8r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwcg-xmmg-hh8r", + "modified": "2024-07-22T15:32:42Z", + "published": "2024-07-22T15:32:42Z", + "aliases": [ + "CVE-2024-41825" + ], + "details": "In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41825" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T15:15:04Z" + } +} \ No newline at end of file