diff --git a/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json b/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json index df3a9f8fb51..be2b1c3ad7a 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json +++ b/advisories/unreviewed/2024/03/GHSA-3q4w-x69r-v77m/GHSA-3q4w-x69r-v77m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q4w-x69r-v77m", - "modified": "2024-03-29T15:30:32Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-03-29T15:30:32Z", "aliases": [ "CVE-2024-30638" ], "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T14:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json b/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json index 73967174f91..6308005069c 100644 --- a/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json +++ b/advisories/unreviewed/2024/03/GHSA-7hr8-mwm4-3323/GHSA-7hr8-mwm4-3323.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hr8-mwm4-3323", - "modified": "2024-03-29T15:30:32Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-03-29T15:30:32Z", "aliases": [ "CVE-2024-28405" ], "details": "SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T15:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json b/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json index bda25099e2d..1bd424999ac 100644 --- a/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json +++ b/advisories/unreviewed/2024/03/GHSA-7rfv-m2fm-w83c/GHSA-7rfv-m2fm-w83c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rfv-m2fm-w83c", - "modified": "2024-03-28T15:30:34Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-03-28T15:30:34Z", "aliases": [ "CVE-2024-30612" ], "details": "Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T15:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json b/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json index d20fad939f9..072a462ca16 100644 --- a/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json +++ b/advisories/unreviewed/2024/03/GHSA-7w53-4qwf-wfw9/GHSA-7w53-4qwf-wfw9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7w53-4qwf-wfw9", - "modified": "2024-03-28T15:30:33Z", + "modified": "2024-08-01T18:32:48Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-30588" ], "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T14:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json b/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json index b72343236f3..52b7275dede 100644 --- a/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json +++ b/advisories/unreviewed/2024/03/GHSA-8j8v-w647-795g/GHSA-8j8v-w647-795g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j8v-w647-795g", - "modified": "2024-03-29T15:30:28Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30613" ], "details": "Tenda AC15 v15.03.05.18 has a stack overflow vulnerability in the time parameter from the setSmartPowerManagement function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json b/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json index e974fe86cf4..bbc623e0880 100644 --- a/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json +++ b/advisories/unreviewed/2024/03/GHSA-fh7f-4794-fgr3/GHSA-fh7f-4794-fgr3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json b/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json index 9f4a0c34c7d..4bcc2547f5a 100644 --- a/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json +++ b/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpm2-jf87-f6fp", - "modified": "2024-03-29T00:30:34Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-03-29T00:30:34Z", "aliases": [ "CVE-2024-24407" ], "details": "SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T23:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json b/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json index 662349ada45..73855b17873 100644 --- a/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json +++ b/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wrf8-rqf2-f8rc", - "modified": "2024-03-28T03:30:59Z", + "modified": "2024-08-01T18:32:48Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-28011" ], "details": "Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-912" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json b/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json index 79d2dc52f4b..e1f6b9d5355 100644 --- a/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json +++ b/advisories/unreviewed/2024/03/GHSA-xrjx-pr69-2frv/GHSA-xrjx-pr69-2frv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrjx-pr69-2frv", - "modified": "2024-03-29T15:30:31Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-03-29T15:30:31Z", "aliases": [ "CVE-2024-30631" ], "details": "Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T13:15:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jqcx-vw98-5q84/GHSA-jqcx-vw98-5q84.json b/advisories/unreviewed/2024/04/GHSA-jqcx-vw98-5q84/GHSA-jqcx-vw98-5q84.json index 4d0d7a1f600..1f9cdea3208 100644 --- a/advisories/unreviewed/2024/04/GHSA-jqcx-vw98-5q84/GHSA-jqcx-vw98-5q84.json +++ b/advisories/unreviewed/2024/04/GHSA-jqcx-vw98-5q84/GHSA-jqcx-vw98-5q84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqcx-vw98-5q84", - "modified": "2024-04-03T03:30:30Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-04-03T03:30:30Z", "aliases": [ "CVE-2024-30166" ], "details": "In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T03:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v67q-hfx9-pxhf/GHSA-v67q-hfx9-pxhf.json b/advisories/unreviewed/2024/04/GHSA-v67q-hfx9-pxhf/GHSA-v67q-hfx9-pxhf.json index 5e67917e8ef..2e228896497 100644 --- a/advisories/unreviewed/2024/04/GHSA-v67q-hfx9-pxhf/GHSA-v67q-hfx9-pxhf.json +++ b/advisories/unreviewed/2024/04/GHSA-v67q-hfx9-pxhf/GHSA-v67q-hfx9-pxhf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v67q-hfx9-pxhf", - "modified": "2024-04-01T03:30:39Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-04-01T03:30:39Z", "aliases": [ "CVE-2024-20039" ], "details": "In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01240012; Issue ID: MSV-1215.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8mqg-fwg4-6pjh/GHSA-8mqg-fwg4-6pjh.json b/advisories/unreviewed/2024/05/GHSA-8mqg-fwg4-6pjh/GHSA-8mqg-fwg4-6pjh.json index 74c0932455a..de3ad9f5cfa 100644 --- a/advisories/unreviewed/2024/05/GHSA-8mqg-fwg4-6pjh/GHSA-8mqg-fwg4-6pjh.json +++ b/advisories/unreviewed/2024/05/GHSA-8mqg-fwg4-6pjh/GHSA-8mqg-fwg4-6pjh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json b/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json index 5f38d932bd2..dbd2d5a0d90 100644 --- a/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json +++ b/advisories/unreviewed/2024/05/GHSA-hxv9-64g4-jhvj/GHSA-hxv9-64g4-jhvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hxv9-64g4-jhvj", - "modified": "2024-05-15T18:30:36Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-05-15T18:30:36Z", "aliases": [ "CVE-2024-3182" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9x7p-g38x-wwhv/GHSA-9x7p-g38x-wwhv.json b/advisories/unreviewed/2024/06/GHSA-9x7p-g38x-wwhv/GHSA-9x7p-g38x-wwhv.json index b7dce7a2bba..ca4d2db1bd7 100644 --- a/advisories/unreviewed/2024/06/GHSA-9x7p-g38x-wwhv/GHSA-9x7p-g38x-wwhv.json +++ b/advisories/unreviewed/2024/06/GHSA-9x7p-g38x-wwhv/GHSA-9x7p-g38x-wwhv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9x7p-g38x-wwhv", - "modified": "2024-06-29T06:31:41Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-06-29T06:31:41Z", "aliases": [ "CVE-2024-6265" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m59m-p56m-7mgm/GHSA-m59m-p56m-7mgm.json b/advisories/unreviewed/2024/06/GHSA-m59m-p56m-7mgm/GHSA-m59m-p56m-7mgm.json index 3655d411d9d..7124cd40ac2 100644 --- a/advisories/unreviewed/2024/06/GHSA-m59m-p56m-7mgm/GHSA-m59m-p56m-7mgm.json +++ b/advisories/unreviewed/2024/06/GHSA-m59m-p56m-7mgm/GHSA-m59m-p56m-7mgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m59m-p56m-7mgm", - "modified": "2024-06-29T06:31:41Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-06-29T06:31:41Z", "aliases": [ "CVE-2024-5889" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-m8p4-qc4v-39j2/GHSA-m8p4-qc4v-39j2.json b/advisories/unreviewed/2024/06/GHSA-m8p4-qc4v-39j2/GHSA-m8p4-qc4v-39j2.json index 841c68144f7..76d882d39d7 100644 --- a/advisories/unreviewed/2024/06/GHSA-m8p4-qc4v-39j2/GHSA-m8p4-qc4v-39j2.json +++ b/advisories/unreviewed/2024/06/GHSA-m8p4-qc4v-39j2/GHSA-m8p4-qc4v-39j2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8p4-qc4v-39j2", - "modified": "2024-06-29T06:31:41Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-06-29T06:31:41Z", "aliases": [ "CVE-2024-5192" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-p6r8-m6x2-9c74/GHSA-p6r8-m6x2-9c74.json b/advisories/unreviewed/2024/06/GHSA-p6r8-m6x2-9c74/GHSA-p6r8-m6x2-9c74.json index a7b6913f73e..7f8a1a4ac27 100644 --- a/advisories/unreviewed/2024/06/GHSA-p6r8-m6x2-9c74/GHSA-p6r8-m6x2-9c74.json +++ b/advisories/unreviewed/2024/06/GHSA-p6r8-m6x2-9c74/GHSA-p6r8-m6x2-9c74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p6r8-m6x2-9c74", - "modified": "2024-06-29T09:30:56Z", + "modified": "2024-08-01T18:32:49Z", "published": "2024-06-29T09:30:56Z", "aliases": [ "CVE-2024-5666" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rp9c-j467-r9xv/GHSA-rp9c-j467-r9xv.json b/advisories/unreviewed/2024/06/GHSA-rp9c-j467-r9xv/GHSA-rp9c-j467-r9xv.json index 91cd6beb784..93017ffb60a 100644 --- a/advisories/unreviewed/2024/06/GHSA-rp9c-j467-r9xv/GHSA-rp9c-j467-r9xv.json +++ b/advisories/unreviewed/2024/06/GHSA-rp9c-j467-r9xv/GHSA-rp9c-j467-r9xv.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-rv9m-cr53-rp67/GHSA-rv9m-cr53-rp67.json b/advisories/unreviewed/2024/06/GHSA-rv9m-cr53-rp67/GHSA-rv9m-cr53-rp67.json index a717f254049..cc7d5e493ff 100644 --- a/advisories/unreviewed/2024/06/GHSA-rv9m-cr53-rp67/GHSA-rv9m-cr53-rp67.json +++ b/advisories/unreviewed/2024/06/GHSA-rv9m-cr53-rp67/GHSA-rv9m-cr53-rp67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv9m-cr53-rp67", - "modified": "2024-06-29T09:30:56Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-06-29T09:30:56Z", "aliases": [ "CVE-2024-5790" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2r3p-m9qp-p35m/GHSA-2r3p-m9qp-p35m.json b/advisories/unreviewed/2024/07/GHSA-2r3p-m9qp-p35m/GHSA-2r3p-m9qp-p35m.json index a14521a9ad0..82924b87a85 100644 --- a/advisories/unreviewed/2024/07/GHSA-2r3p-m9qp-p35m/GHSA-2r3p-m9qp-p35m.json +++ b/advisories/unreviewed/2024/07/GHSA-2r3p-m9qp-p35m/GHSA-2r3p-m9qp-p35m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2r3p-m9qp-p35m", - "modified": "2024-07-26T18:30:37Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-07-26T18:30:37Z", "aliases": [ "CVE-2024-26520" ], "details": "An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-620" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-26T17:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json b/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json index 72c49d42da6..16a18d155e6 100644 --- a/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json +++ b/advisories/unreviewed/2024/07/GHSA-5vgq-r8m3-f582/GHSA-5vgq-r8m3-f582.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vgq-r8m3-f582", - "modified": "2024-07-31T06:30:35Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-07-31T06:30:35Z", "aliases": [ "CVE-2024-6272" ], "details": "The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-31T06:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-vrqh-v8jm-4v2m/GHSA-vrqh-v8jm-4v2m.json b/advisories/unreviewed/2024/07/GHSA-vrqh-v8jm-4v2m/GHSA-vrqh-v8jm-4v2m.json index bedcc63e900..7c04a880008 100644 --- a/advisories/unreviewed/2024/07/GHSA-vrqh-v8jm-4v2m/GHSA-vrqh-v8jm-4v2m.json +++ b/advisories/unreviewed/2024/07/GHSA-vrqh-v8jm-4v2m/GHSA-vrqh-v8jm-4v2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrqh-v8jm-4v2m", - "modified": "2024-07-09T09:30:56Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-07-09T09:30:55Z", "aliases": [ "CVE-2024-3604" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json b/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json index 13676c0cc73..5c095030992 100644 --- a/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json +++ b/advisories/unreviewed/2024/08/GHSA-4473-886f-f22q/GHSA-4473-886f-f22q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4473-886f-f22q", - "modified": "2024-08-01T03:30:46Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-08-01T03:30:46Z", "aliases": [ "CVE-2024-39607" ], "details": "OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-01T02:15:01Z" diff --git a/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json b/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json new file mode 100644 index 00000000000..617930b07b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gh-q5g8-jv59", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-7211" + ], + "details": "The Identity Server used by 1E Platform could enable URL redirection to untrusted sites.\nNote: The Identity Server on 1E Platform has been updated with the necessary patch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7211" + }, + { + "type": "WEB", + "url": "https://www.1e.com/trust-security-compliance/cve-info" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T17:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-67fw-w8f2-88wp/GHSA-67fw-w8f2-88wp.json b/advisories/unreviewed/2024/08/GHSA-67fw-w8f2-88wp/GHSA-67fw-w8f2-88wp.json new file mode 100644 index 00000000000..bd10c7bd823 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-67fw-w8f2-88wp/GHSA-67fw-w8f2-88wp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67fw-w8f2-88wp", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-41264" + ], + "details": "An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41264" + }, + { + "type": "WEB", + "url": "https://gist.github.com/nyxfqq/33ceaccbc9b05d439a944c2b55fa1c0f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6h2q-3m5q-wv4c/GHSA-6h2q-3m5q-wv4c.json b/advisories/unreviewed/2024/08/GHSA-6h2q-3m5q-wv4c/GHSA-6h2q-3m5q-wv4c.json new file mode 100644 index 00000000000..784324f6e14 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6h2q-3m5q-wv4c/GHSA-6h2q-3m5q-wv4c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h2q-3m5q-wv4c", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-6242" + ], + "details": "A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6242" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1682.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-420" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json b/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json new file mode 100644 index 00000000000..3dedeecc2eb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-756x-7gxj-qmpv/GHSA-756x-7gxj-qmpv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-756x-7gxj-qmpv", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-7360" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273339.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7360" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/ac97a335ed9fcf4eefe3c952928a6d0e" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273339" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273339" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383495" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7qmp-3hh8-g4vw/GHSA-7qmp-3hh8-g4vw.json b/advisories/unreviewed/2024/08/GHSA-7qmp-3hh8-g4vw/GHSA-7qmp-3hh8-g4vw.json new file mode 100644 index 00000000000..8f356e9cae1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7qmp-3hh8-g4vw/GHSA-7qmp-3hh8-g4vw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qmp-3hh8-g4vw", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-6040" + ], + "details": "In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding, /reinstall_binding, /unInstall_binding, /set_active_binding_settings, and /update_binding_settings are susceptible to CSRF attacks and local attacks. An attacker can exploit this vulnerability to perform unauthorized actions on the victim's machine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6040" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ac0bbb1d-89aa-42ba-bc48-1b59bd16acc7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json b/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json new file mode 100644 index 00000000000..e33e7a41ed2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9v35-4xcr-w9ph/GHSA-9v35-4xcr-w9ph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v35-4xcr-w9ph", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-41260" + ], + "details": "A static initialization vector (IV) in the encrypt function of netbird v0.28.4 allows attackers to obtain sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41260" + }, + { + "type": "WEB", + "url": "https://gist.github.com/nyxfqq/92232108ac153e95d538bb17fc5ad636" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9ww6-q6f9-p9jv/GHSA-9ww6-q6f9-p9jv.json b/advisories/unreviewed/2024/08/GHSA-9ww6-q6f9-p9jv/GHSA-9ww6-q6f9-p9jv.json new file mode 100644 index 00000000000..bec39300285 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9ww6-q6f9-p9jv/GHSA-9ww6-q6f9-p9jv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ww6-q6f9-p9jv", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-23600" + ], + "details": "Improper Input Validation of query search results for private field data in PingIDM OPENIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23600" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/docs/idcloud/latest/release-notes/regular-channel-changelog.html#changed_functionality" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/knowledge/kb/article/a95212747" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T17:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json b/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json new file mode 100644 index 00000000000..3ff0f85780a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7v9-gh22-gjq5/GHSA-c7v9-gh22-gjq5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7v9-gh22-gjq5", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-7359" + ], + "details": "A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_establishment. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273338 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7359" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/6fbd27f1942d76f0392d883dfd8fef10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273338" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273338" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383494" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T17:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json b/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json new file mode 100644 index 00000000000..3a67a09c0b9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gh9v-q4wx-5m5c/GHSA-gh9v-q4wx-5m5c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh9v-q4wx-5m5c", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-6990" + ], + "details": "Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6990" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/353034820" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json b/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json new file mode 100644 index 00000000000..97b1f86c25c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hj26-xxg9-8jhq/GHSA-hj26-xxg9-8jhq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj26-xxg9-8jhq", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-7361" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Tracking Monitoring Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_establishment. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273340.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7361" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/f01eca07fce854bf5de96588126cdd7e" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273340" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273340" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json b/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json new file mode 100644 index 00000000000..09bebabd78b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mcqx-pmh8-v9cr/GHSA-mcqx-pmh8-v9cr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcqx-pmh8-v9cr", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-7255" + ], + "details": "Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7255" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/352872238" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qwvh-x5gw-88v2/GHSA-qwvh-x5gw-88v2.json b/advisories/unreviewed/2024/08/GHSA-qwvh-x5gw-88v2/GHSA-qwvh-x5gw-88v2.json new file mode 100644 index 00000000000..828134c3fd5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qwvh-x5gw-88v2/GHSA-qwvh-x5gw-88v2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwvh-x5gw-88v2", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-7256" + ], + "details": "Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7256" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/354748060" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json b/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json index ee0910a9d9d..8c2a0905601 100644 --- a/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json +++ b/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqgx-gpv3-58p3", - "modified": "2024-08-01T06:30:34Z", + "modified": "2024-08-01T18:32:50Z", "published": "2024-08-01T06:30:34Z", "aliases": [ "CVE-2024-1747" ], "details": "The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-01T06:15:01Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vw7g-3cc7-7rmh/GHSA-vw7g-3cc7-7rmh.json b/advisories/unreviewed/2024/08/GHSA-vw7g-3cc7-7rmh/GHSA-vw7g-3cc7-7rmh.json new file mode 100644 index 00000000000..2c3e3939d6c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vw7g-3cc7-7rmh/GHSA-vw7g-3cc7-7rmh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw7g-3cc7-7rmh", + "modified": "2024-08-01T18:32:50Z", + "published": "2024-08-01T18:32:50Z", + "aliases": [ + "CVE-2024-41265" + ], + "details": "A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41265" + }, + { + "type": "WEB", + "url": "https://gist.github.com/nyxfqq/1a8237f3f9cf793c6433f08b17d1593c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T16:15:06Z" + } +} \ No newline at end of file