diff --git a/advisories/unreviewed/2022/05/GHSA-3686-jjcf-4w27/GHSA-3686-jjcf-4w27.json b/advisories/unreviewed/2022/05/GHSA-3686-jjcf-4w27/GHSA-3686-jjcf-4w27.json index 72b9e0aa8d8..6e78ee8da40 100644 --- a/advisories/unreviewed/2022/05/GHSA-3686-jjcf-4w27/GHSA-3686-jjcf-4w27.json +++ b/advisories/unreviewed/2022/05/GHSA-3686-jjcf-4w27/GHSA-3686-jjcf-4w27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3686-jjcf-4w27", - "modified": "2022-05-13T01:25:01Z", + "modified": "2024-08-28T18:31:52Z", "published": "2022-05-13T01:25:01Z", "aliases": [ "CVE-2016-9842" diff --git a/advisories/unreviewed/2022/05/GHSA-mrf4-89gh-pm62/GHSA-mrf4-89gh-pm62.json b/advisories/unreviewed/2022/05/GHSA-mrf4-89gh-pm62/GHSA-mrf4-89gh-pm62.json index 9f9541bcb3e..42dfe03fd63 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrf4-89gh-pm62/GHSA-mrf4-89gh-pm62.json +++ b/advisories/unreviewed/2022/05/GHSA-mrf4-89gh-pm62/GHSA-mrf4-89gh-pm62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrf4-89gh-pm62", - "modified": "2022-05-24T17:07:26Z", + "modified": "2024-08-28T18:31:52Z", "published": "2022-05-24T17:07:26Z", "aliases": [ "CVE-2019-19824" ], "details": "On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19824" }, + { + "type": "WEB", + "url": "https://github.com/yckuo-sdc/totolink-boa-api-vulnerabilities" + }, { "type": "WEB", "url": "https://sploit.tech" @@ -37,7 +44,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-6j48-hfg3-m4hg/GHSA-6j48-hfg3-m4hg.json b/advisories/unreviewed/2023/12/GHSA-6j48-hfg3-m4hg/GHSA-6j48-hfg3-m4hg.json index febe6685628..2b37594aed1 100644 --- a/advisories/unreviewed/2023/12/GHSA-6j48-hfg3-m4hg/GHSA-6j48-hfg3-m4hg.json +++ b/advisories/unreviewed/2023/12/GHSA-6j48-hfg3-m4hg/GHSA-6j48-hfg3-m4hg.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/12/GHSA-8c2m-63vf-p7p5/GHSA-8c2m-63vf-p7p5.json b/advisories/unreviewed/2023/12/GHSA-8c2m-63vf-p7p5/GHSA-8c2m-63vf-p7p5.json index fe65f7e8c4b..daab5d4c658 100644 --- a/advisories/unreviewed/2023/12/GHSA-8c2m-63vf-p7p5/GHSA-8c2m-63vf-p7p5.json +++ b/advisories/unreviewed/2023/12/GHSA-8c2m-63vf-p7p5/GHSA-8c2m-63vf-p7p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c2m-63vf-p7p5", - "modified": "2023-12-13T03:31:56Z", + "modified": "2024-08-28T18:31:52Z", "published": "2023-12-13T03:31:56Z", "aliases": [ "CVE-2023-47579" ], "details": "Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-13T02:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-ccr3-hvjj-q8xh/GHSA-ccr3-hvjj-q8xh.json b/advisories/unreviewed/2023/12/GHSA-ccr3-hvjj-q8xh/GHSA-ccr3-hvjj-q8xh.json index 559be8c247d..f1460835c07 100644 --- a/advisories/unreviewed/2023/12/GHSA-ccr3-hvjj-q8xh/GHSA-ccr3-hvjj-q8xh.json +++ b/advisories/unreviewed/2023/12/GHSA-ccr3-hvjj-q8xh/GHSA-ccr3-hvjj-q8xh.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json b/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json index 151d79701ed..7a20ac411cf 100644 --- a/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json +++ b/advisories/unreviewed/2023/12/GHSA-hrh7-rq69-242h/GHSA-hrh7-rq69-242h.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json b/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json index ab0055a2818..8b47fec36b8 100644 --- a/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json +++ b/advisories/unreviewed/2023/12/GHSA-mw7v-292c-8697/GHSA-mw7v-292c-8697.json @@ -76,7 +76,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json b/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json index 268a13f47f3..f77376f3bb0 100644 --- a/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json +++ b/advisories/unreviewed/2023/12/GHSA-vq7h-4q4f-453x/GHSA-vq7h-4q4f-453x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vq7h-4q4f-453x", - "modified": "2023-12-14T21:31:15Z", + "modified": "2024-08-28T18:31:52Z", "published": "2023-12-12T15:30:59Z", "aliases": [ "CVE-2023-46455" diff --git a/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json b/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json index e96383e089e..fca63b66a46 100644 --- a/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json +++ b/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28qc-v7xx-3vpf", - "modified": "2024-02-27T09:31:17Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-27T09:31:17Z", "aliases": [ "CVE-2023-7167" ], "details": "The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5wf4-qch9-828f/GHSA-5wf4-qch9-828f.json b/advisories/unreviewed/2024/02/GHSA-5wf4-qch9-828f/GHSA-5wf4-qch9-828f.json index 34cf33573ce..f117cb126ce 100644 --- a/advisories/unreviewed/2024/02/GHSA-5wf4-qch9-828f/GHSA-5wf4-qch9-828f.json +++ b/advisories/unreviewed/2024/02/GHSA-5wf4-qch9-828f/GHSA-5wf4-qch9-828f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wf4-qch9-828f", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-08-28T18:31:52Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-0015" ], "details": "In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T19:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6rrc-h5ph-44m6/GHSA-6rrc-h5ph-44m6.json b/advisories/unreviewed/2024/02/GHSA-6rrc-h5ph-44m6/GHSA-6rrc-h5ph-44m6.json index 0eee19226f0..b5ed3c7e230 100644 --- a/advisories/unreviewed/2024/02/GHSA-6rrc-h5ph-44m6/GHSA-6rrc-h5ph-44m6.json +++ b/advisories/unreviewed/2024/02/GHSA-6rrc-h5ph-44m6/GHSA-6rrc-h5ph-44m6.json @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-8hfg-rm42-2g24/GHSA-8hfg-rm42-2g24.json b/advisories/unreviewed/2024/02/GHSA-8hfg-rm42-2g24/GHSA-8hfg-rm42-2g24.json index a70d65903e1..b5a5e1eb79b 100644 --- a/advisories/unreviewed/2024/02/GHSA-8hfg-rm42-2g24/GHSA-8hfg-rm42-2g24.json +++ b/advisories/unreviewed/2024/02/GHSA-8hfg-rm42-2g24/GHSA-8hfg-rm42-2g24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hfg-rm42-2g24", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42860" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:49Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gr39-677j-2h8c/GHSA-gr39-677j-2h8c.json b/advisories/unreviewed/2024/02/GHSA-gr39-677j-2h8c/GHSA-gr39-677j-2h8c.json index c810c184547..2d6cbe19952 100644 --- a/advisories/unreviewed/2024/02/GHSA-gr39-677j-2h8c/GHSA-gr39-677j-2h8c.json +++ b/advisories/unreviewed/2024/02/GHSA-gr39-677j-2h8c/GHSA-gr39-677j-2h8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr39-677j-2h8c", - "modified": "2024-02-29T00:30:23Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-29T00:30:23Z", "aliases": [ "CVE-2024-25579" ], "details": "OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product. Affected products and versions are as follows: WRC-1167GS2-B v1.67 and earlier, WRC-1167GS2H-B v1.67 and earlier, WRC-2533GS2-B v1.62 and earlier, WRC-2533GS2-W v1.62 and earlier, and WRC-2533GS2V-B v1.62 and earlier.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T23:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hh87-73h8-gfwc/GHSA-hh87-73h8-gfwc.json b/advisories/unreviewed/2024/02/GHSA-hh87-73h8-gfwc/GHSA-hh87-73h8-gfwc.json index ef0d4455a1d..eea9e027fe5 100644 --- a/advisories/unreviewed/2024/02/GHSA-hh87-73h8-gfwc/GHSA-hh87-73h8-gfwc.json +++ b/advisories/unreviewed/2024/02/GHSA-hh87-73h8-gfwc/GHSA-hh87-73h8-gfwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hh87-73h8-gfwc", - "modified": "2024-02-29T00:30:22Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-29T00:30:22Z", "aliases": [ "CVE-2024-25866" ], "details": "A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T22:15:26Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hpw7-mvmj-35m8/GHSA-hpw7-mvmj-35m8.json b/advisories/unreviewed/2024/02/GHSA-hpw7-mvmj-35m8/GHSA-hpw7-mvmj-35m8.json index 328b03cbd60..00ef97c85c6 100644 --- a/advisories/unreviewed/2024/02/GHSA-hpw7-mvmj-35m8/GHSA-hpw7-mvmj-35m8.json +++ b/advisories/unreviewed/2024/02/GHSA-hpw7-mvmj-35m8/GHSA-hpw7-mvmj-35m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hpw7-mvmj-35m8", - "modified": "2024-02-27T18:31:02Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-27T18:31:02Z", "aliases": [ "CVE-2024-24323" ], "details": "SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T17:15:12Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hrxm-p844-p59w/GHSA-hrxm-p844-p59w.json b/advisories/unreviewed/2024/02/GHSA-hrxm-p844-p59w/GHSA-hrxm-p844-p59w.json index 5c92f194f4c..f71fbd747cb 100644 --- a/advisories/unreviewed/2024/02/GHSA-hrxm-p844-p59w/GHSA-hrxm-p844-p59w.json +++ b/advisories/unreviewed/2024/02/GHSA-hrxm-p844-p59w/GHSA-hrxm-p844-p59w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrxm-p844-p59w", - "modified": "2024-02-16T03:30:51Z", + "modified": "2024-08-28T18:31:52Z", "published": "2024-02-16T03:30:51Z", "aliases": [ "CVE-2024-0035" ], "details": "In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:50Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pxqq-9cx5-7w7f/GHSA-pxqq-9cx5-7w7f.json b/advisories/unreviewed/2024/02/GHSA-pxqq-9cx5-7w7f/GHSA-pxqq-9cx5-7w7f.json index 3d6fed70d43..fc5eb09b55b 100644 --- a/advisories/unreviewed/2024/02/GHSA-pxqq-9cx5-7w7f/GHSA-pxqq-9cx5-7w7f.json +++ b/advisories/unreviewed/2024/02/GHSA-pxqq-9cx5-7w7f/GHSA-pxqq-9cx5-7w7f.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-q37f-r342-4gq8/GHSA-q37f-r342-4gq8.json b/advisories/unreviewed/2024/02/GHSA-q37f-r342-4gq8/GHSA-q37f-r342-4gq8.json index 281f4bcdaec..a749e00e1bf 100644 --- a/advisories/unreviewed/2024/02/GHSA-q37f-r342-4gq8/GHSA-q37f-r342-4gq8.json +++ b/advisories/unreviewed/2024/02/GHSA-q37f-r342-4gq8/GHSA-q37f-r342-4gq8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-266" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-w2qq-h39r-39rh/GHSA-w2qq-h39r-39rh.json b/advisories/unreviewed/2024/02/GHSA-w2qq-h39r-39rh/GHSA-w2qq-h39r-39rh.json index fe325507c25..98223899b46 100644 --- a/advisories/unreviewed/2024/02/GHSA-w2qq-h39r-39rh/GHSA-w2qq-h39r-39rh.json +++ b/advisories/unreviewed/2024/02/GHSA-w2qq-h39r-39rh/GHSA-w2qq-h39r-39rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2qq-h39r-39rh", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-08-28T18:31:52Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-0021" ], "details": "In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T20:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json b/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json index 2307bb9401e..74a6caefdb0 100644 --- a/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json +++ b/advisories/unreviewed/2024/02/GHSA-wjv4-j3hc-gxvv/GHSA-wjv4-j3hc-gxvv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wjv4-j3hc-gxvv", - "modified": "2024-02-26T18:30:28Z", + "modified": "2024-08-28T18:31:52Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1670" ], "details": "Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T04:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-x57g-x9fg-576h/GHSA-x57g-x9fg-576h.json b/advisories/unreviewed/2024/02/GHSA-x57g-x9fg-576h/GHSA-x57g-x9fg-576h.json index 0626f84f2b7..d059d2f904e 100644 --- a/advisories/unreviewed/2024/02/GHSA-x57g-x9fg-576h/GHSA-x57g-x9fg-576h.json +++ b/advisories/unreviewed/2024/02/GHSA-x57g-x9fg-576h/GHSA-x57g-x9fg-576h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x57g-x9fg-576h", - "modified": "2024-02-29T03:33:18Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-24155" ], "details": "Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:11Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xpc2-r64x-8hr9/GHSA-xpc2-r64x-8hr9.json b/advisories/unreviewed/2024/02/GHSA-xpc2-r64x-8hr9/GHSA-xpc2-r64x-8hr9.json index f5d49aa64bb..d7fb2131979 100644 --- a/advisories/unreviewed/2024/02/GHSA-xpc2-r64x-8hr9/GHSA-xpc2-r64x-8hr9.json +++ b/advisories/unreviewed/2024/02/GHSA-xpc2-r64x-8hr9/GHSA-xpc2-r64x-8hr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xpc2-r64x-8hr9", - "modified": "2024-02-28T21:30:20Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-02-28T21:30:20Z", "aliases": [ "CVE-2024-25859" ], "details": "A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T20:15:41Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2c8c-h5pf-cx5h/GHSA-2c8c-h5pf-cx5h.json b/advisories/unreviewed/2024/03/GHSA-2c8c-h5pf-cx5h/GHSA-2c8c-h5pf-cx5h.json index 9b8c63a3ac2..2f2d31fd854 100644 --- a/advisories/unreviewed/2024/03/GHSA-2c8c-h5pf-cx5h/GHSA-2c8c-h5pf-cx5h.json +++ b/advisories/unreviewed/2024/03/GHSA-2c8c-h5pf-cx5h/GHSA-2c8c-h5pf-cx5h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2c8c-h5pf-cx5h", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23244" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4. An app from a standard user account may be able to escalate privilege after admin user login.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2p8x-96jq-92cm/GHSA-2p8x-96jq-92cm.json b/advisories/unreviewed/2024/03/GHSA-2p8x-96jq-92cm/GHSA-2p8x-96jq-92cm.json index 6d5b2371801..87f8ca54692 100644 --- a/advisories/unreviewed/2024/03/GHSA-2p8x-96jq-92cm/GHSA-2p8x-96jq-92cm.json +++ b/advisories/unreviewed/2024/03/GHSA-2p8x-96jq-92cm/GHSA-2p8x-96jq-92cm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2p8x-96jq-92cm", - "modified": "2024-03-05T00:31:14Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-05T00:31:14Z", "aliases": [ "CVE-2023-49546" ], "details": "Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T00:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5wqx-3cwh-cgg8/GHSA-5wqx-3cwh-cgg8.json b/advisories/unreviewed/2024/03/GHSA-5wqx-3cwh-cgg8/GHSA-5wqx-3cwh-cgg8.json index 9b5613daacb..a0723529c29 100644 --- a/advisories/unreviewed/2024/03/GHSA-5wqx-3cwh-cgg8/GHSA-5wqx-3cwh-cgg8.json +++ b/advisories/unreviewed/2024/03/GHSA-5wqx-3cwh-cgg8/GHSA-5wqx-3cwh-cgg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wqx-3cwh-cgg8", - "modified": "2024-03-16T06:30:29Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-16T06:30:29Z", "aliases": [ "CVE-2024-28640" ], "details": "Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-16T06:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json b/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json index 6d079f8605a..9b939d5922b 100644 --- a/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json +++ b/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6h2q-2x4r-5652", - "modified": "2024-03-19T21:30:29Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2615" ], "details": "Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T12:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6jrh-c34m-323q/GHSA-6jrh-c34m-323q.json b/advisories/unreviewed/2024/03/GHSA-6jrh-c34m-323q/GHSA-6jrh-c34m-323q.json index 35d5ae57494..9f2579c2fb2 100644 --- a/advisories/unreviewed/2024/03/GHSA-6jrh-c34m-323q/GHSA-6jrh-c34m-323q.json +++ b/advisories/unreviewed/2024/03/GHSA-6jrh-c34m-323q/GHSA-6jrh-c34m-323q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6jrh-c34m-323q", - "modified": "2024-03-18T15:30:49Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T15:30:49Z", "aliases": [ "CVE-2024-28537" ], "details": "Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T14:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8678-pm6w-2hg6/GHSA-8678-pm6w-2hg6.json b/advisories/unreviewed/2024/03/GHSA-8678-pm6w-2hg6/GHSA-8678-pm6w-2hg6.json index 984828dc116..cb3976a4b68 100644 --- a/advisories/unreviewed/2024/03/GHSA-8678-pm6w-2hg6/GHSA-8678-pm6w-2hg6.json +++ b/advisories/unreviewed/2024/03/GHSA-8678-pm6w-2hg6/GHSA-8678-pm6w-2hg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8678-pm6w-2hg6", - "modified": "2024-03-02T00:31:31Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-02T00:31:31Z", "aliases": [ "CVE-2024-27746" ], "details": "SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-948v-423x-38gw/GHSA-948v-423x-38gw.json b/advisories/unreviewed/2024/03/GHSA-948v-423x-38gw/GHSA-948v-423x-38gw.json index 18a4af9c1fd..5508037875e 100644 --- a/advisories/unreviewed/2024/03/GHSA-948v-423x-38gw/GHSA-948v-423x-38gw.json +++ b/advisories/unreviewed/2024/03/GHSA-948v-423x-38gw/GHSA-948v-423x-38gw.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-949c-m2f7-6cq9/GHSA-949c-m2f7-6cq9.json b/advisories/unreviewed/2024/03/GHSA-949c-m2f7-6cq9/GHSA-949c-m2f7-6cq9.json index 0f091a46311..0e9a85349cf 100644 --- a/advisories/unreviewed/2024/03/GHSA-949c-m2f7-6cq9/GHSA-949c-m2f7-6cq9.json +++ b/advisories/unreviewed/2024/03/GHSA-949c-m2f7-6cq9/GHSA-949c-m2f7-6cq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-949c-m2f7-6cq9", - "modified": "2024-03-07T03:30:40Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2023-49989" ], "details": "Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T01:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c39g-93pm-r85m/GHSA-c39g-93pm-r85m.json b/advisories/unreviewed/2024/03/GHSA-c39g-93pm-r85m/GHSA-c39g-93pm-r85m.json index c02c4ce7a86..c14336cc14f 100644 --- a/advisories/unreviewed/2024/03/GHSA-c39g-93pm-r85m/GHSA-c39g-93pm-r85m.json +++ b/advisories/unreviewed/2024/03/GHSA-c39g-93pm-r85m/GHSA-c39g-93pm-r85m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c39g-93pm-r85m", - "modified": "2024-03-18T06:30:50Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T06:30:50Z", "aliases": [ "CVE-2018-25099" ], "details": "In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T05:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f8c5-7mvv-crq3/GHSA-f8c5-7mvv-crq3.json b/advisories/unreviewed/2024/03/GHSA-f8c5-7mvv-crq3/GHSA-f8c5-7mvv-crq3.json index 1b7412431cf..9968425bb7b 100644 --- a/advisories/unreviewed/2024/03/GHSA-f8c5-7mvv-crq3/GHSA-f8c5-7mvv-crq3.json +++ b/advisories/unreviewed/2024/03/GHSA-f8c5-7mvv-crq3/GHSA-f8c5-7mvv-crq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8c5-7mvv-crq3", - "modified": "2024-03-18T21:31:23Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T21:31:23Z", "aliases": [ "CVE-2024-25655" ], "details": "Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T20:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json b/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json index f29f5f1d761..58e0eb32ab0 100644 --- a/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json +++ b/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fpr2-hvvq-5xh8", - "modified": "2024-03-28T06:30:45Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-03-28T06:30:45Z", "aliases": [ "CVE-2024-0673" ], "details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T05:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json b/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json index 4ef40f47843..e72fdcbfb2f 100644 --- a/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json +++ b/advisories/unreviewed/2024/03/GHSA-g3w4-gvhg-w64p/GHSA-g3w4-gvhg-w64p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3w4-gvhg-w64p", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23288" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to elevate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h8hf-rwc6-9296/GHSA-h8hf-rwc6-9296.json b/advisories/unreviewed/2024/03/GHSA-h8hf-rwc6-9296/GHSA-h8hf-rwc6-9296.json index b8fd63f3f81..97891fa8688 100644 --- a/advisories/unreviewed/2024/03/GHSA-h8hf-rwc6-9296/GHSA-h8hf-rwc6-9296.json +++ b/advisories/unreviewed/2024/03/GHSA-h8hf-rwc6-9296/GHSA-h8hf-rwc6-9296.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8hf-rwc6-9296", - "modified": "2024-03-22T00:31:14Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-03-22T00:31:14Z", "aliases": [ "CVE-2024-28521" ], "details": "SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T22:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h8qq-7cp6-5q6c/GHSA-h8qq-7cp6-5q6c.json b/advisories/unreviewed/2024/03/GHSA-h8qq-7cp6-5q6c/GHSA-h8qq-7cp6-5q6c.json index 3a3644553e2..5f48a1a6c89 100644 --- a/advisories/unreviewed/2024/03/GHSA-h8qq-7cp6-5q6c/GHSA-h8qq-7cp6-5q6c.json +++ b/advisories/unreviewed/2024/03/GHSA-h8qq-7cp6-5q6c/GHSA-h8qq-7cp6-5q6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8qq-7cp6-5q6c", - "modified": "2024-03-20T21:31:13Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-03-20T21:31:13Z", "aliases": [ "CVE-2024-23721" ], "details": "A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T20:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jjxx-788m-fv7g/GHSA-jjxx-788m-fv7g.json b/advisories/unreviewed/2024/03/GHSA-jjxx-788m-fv7g/GHSA-jjxx-788m-fv7g.json index ff06c2ab10a..60612f45ddf 100644 --- a/advisories/unreviewed/2024/03/GHSA-jjxx-788m-fv7g/GHSA-jjxx-788m-fv7g.json +++ b/advisories/unreviewed/2024/03/GHSA-jjxx-788m-fv7g/GHSA-jjxx-788m-fv7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjxx-788m-fv7g", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-1273" ], "details": "The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:17Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pwwp-85rf-2286/GHSA-pwwp-85rf-2286.json b/advisories/unreviewed/2024/03/GHSA-pwwp-85rf-2286/GHSA-pwwp-85rf-2286.json index 1a71f631f8a..74852bbd5e4 100644 --- a/advisories/unreviewed/2024/03/GHSA-pwwp-85rf-2286/GHSA-pwwp-85rf-2286.json +++ b/advisories/unreviewed/2024/03/GHSA-pwwp-85rf-2286/GHSA-pwwp-85rf-2286.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwwp-85rf-2286", - "modified": "2024-03-19T12:30:41Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2605" ], "details": "An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T12:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r4j8-hwcx-q55j/GHSA-r4j8-hwcx-q55j.json b/advisories/unreviewed/2024/03/GHSA-r4j8-hwcx-q55j/GHSA-r4j8-hwcx-q55j.json index 24527a90790..918cfc777b5 100644 --- a/advisories/unreviewed/2024/03/GHSA-r4j8-hwcx-q55j/GHSA-r4j8-hwcx-q55j.json +++ b/advisories/unreviewed/2024/03/GHSA-r4j8-hwcx-q55j/GHSA-r4j8-hwcx-q55j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4j8-hwcx-q55j", - "modified": "2024-03-15T18:30:38Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-15T18:30:38Z", "aliases": [ "CVE-2023-7017" ], "details": "Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T17:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vgj9-5c97-pwx2/GHSA-vgj9-5c97-pwx2.json b/advisories/unreviewed/2024/03/GHSA-vgj9-5c97-pwx2/GHSA-vgj9-5c97-pwx2.json index b41d8231a15..600110289e6 100644 --- a/advisories/unreviewed/2024/03/GHSA-vgj9-5c97-pwx2/GHSA-vgj9-5c97-pwx2.json +++ b/advisories/unreviewed/2024/03/GHSA-vgj9-5c97-pwx2/GHSA-vgj9-5c97-pwx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgj9-5c97-pwx2", - "modified": "2024-03-23T03:30:24Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-06T21:31:34Z", "aliases": [ "CVE-2024-2174" ], "details": "Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T19:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json b/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json index 70d6683ee4c..a4fec82b78f 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json +++ b/advisories/unreviewed/2024/03/GHSA-vhh4-7pjp-752m/GHSA-vhh4-7pjp-752m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhh4-7pjp-752m", - "modified": "2024-03-18T18:32:18Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T18:32:18Z", "aliases": [ "CVE-2024-1331" ], "details": "The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T16:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vmmc-658q-cfx9/GHSA-vmmc-658q-cfx9.json b/advisories/unreviewed/2024/03/GHSA-vmmc-658q-cfx9/GHSA-vmmc-658q-cfx9.json index 08b58d464f7..8244bdebc55 100644 --- a/advisories/unreviewed/2024/03/GHSA-vmmc-658q-cfx9/GHSA-vmmc-658q-cfx9.json +++ b/advisories/unreviewed/2024/03/GHSA-vmmc-658q-cfx9/GHSA-vmmc-658q-cfx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmmc-658q-cfx9", - "modified": "2024-03-18T21:31:23Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T21:31:23Z", "aliases": [ "CVE-2024-0973" ], "details": "The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T19:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wgfc-mmg5-p2xv/GHSA-wgfc-mmg5-p2xv.json b/advisories/unreviewed/2024/03/GHSA-wgfc-mmg5-p2xv/GHSA-wgfc-mmg5-p2xv.json index 1d15a499166..78eb016d2d0 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgfc-mmg5-p2xv/GHSA-wgfc-mmg5-p2xv.json +++ b/advisories/unreviewed/2024/03/GHSA-wgfc-mmg5-p2xv/GHSA-wgfc-mmg5-p2xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wgfc-mmg5-p2xv", - "modified": "2024-03-04T21:31:11Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-04T21:31:11Z", "aliases": [ "CVE-2024-1316" ], "details": "The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T21:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x9r9-48rm-4xm6/GHSA-x9r9-48rm-4xm6.json b/advisories/unreviewed/2024/03/GHSA-x9r9-48rm-4xm6/GHSA-x9r9-48rm-4xm6.json index 0a00964cd21..40928400ff5 100644 --- a/advisories/unreviewed/2024/03/GHSA-x9r9-48rm-4xm6/GHSA-x9r9-48rm-4xm6.json +++ b/advisories/unreviewed/2024/03/GHSA-x9r9-48rm-4xm6/GHSA-x9r9-48rm-4xm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9r9-48rm-4xm6", - "modified": "2024-03-18T09:30:30Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T09:30:30Z", "aliases": [ "CVE-2024-28125" ], "details": "FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json index 5b0bdd039fa..c4a3774f259 100644 --- a/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json +++ b/advisories/unreviewed/2024/03/GHSA-xr62-xhf5-qw2c/GHSA-xr62-xhf5-qw2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr62-xhf5-qw2c", - "modified": "2024-04-22T12:30:33Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-19T12:30:41Z", "aliases": [ "CVE-2024-2609" ], "details": "The permission prompt input delay could have expired while the window is not in focus, which made the prompt vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T12:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json b/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json index bb5aaa1bc19..722286ac97d 100644 --- a/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json +++ b/advisories/unreviewed/2024/03/GHSA-xv7q-36g9-3jc5/GHSA-xv7q-36g9-3jc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv7q-36g9-3jc5", - "modified": "2024-03-18T21:31:22Z", + "modified": "2024-08-28T18:31:53Z", "published": "2024-03-18T21:31:22Z", "aliases": [ "CVE-2023-7085" ], "details": "The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T19:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json b/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json index 5d993f6a863..042260cb21f 100644 --- a/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json +++ b/advisories/unreviewed/2024/04/GHSA-gmw5-2r8g-6fwc/GHSA-gmw5-2r8g-6fwc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmw5-2r8g-6fwc", - "modified": "2024-04-08T15:30:33Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-04-08T15:30:33Z", "aliases": [ "CVE-2024-31811" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2cjm-v4mj-6gvh/GHSA-2cjm-v4mj-6gvh.json b/advisories/unreviewed/2024/08/GHSA-2cjm-v4mj-6gvh/GHSA-2cjm-v4mj-6gvh.json index aeb9acc920c..902ebfc7581 100644 --- a/advisories/unreviewed/2024/08/GHSA-2cjm-v4mj-6gvh/GHSA-2cjm-v4mj-6gvh.json +++ b/advisories/unreviewed/2024/08/GHSA-2cjm-v4mj-6gvh/GHSA-2cjm-v4mj-6gvh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2cjm-v4mj-6gvh", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-08-02T18:31:10Z", "aliases": [ "CVE-2024-41310" ], "details": "AndServer 2.1.12 is vulnerable to Directory Traversal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T17:16:38Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json b/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json new file mode 100644 index 00000000000..e2c9bbbc518 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2hfc-mfgr-3gpf/GHSA-2hfc-mfgr-3gpf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hfc-mfgr-3gpf", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20285" + ], + "details": "A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.\n\nThe vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. \nNote: An attacker must be authenticated with Python execution privileges to exploit these vulnerabilities. For more information regarding Python execution privileges, see product-specific documentation, such as the section of the Cisco Nexus 9000 Series NX-OS Programmability Guide.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20285" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-psbe-ce-YvbTn5du" + }, + { + "type": "WEB", + "url": "https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/105x/programmability/cisco-nexus-9000-series-nx-os-programmability-guide-105x/m-n9k-python-api-101x.html?bookSearch=true#concept_A2CFF094ADCB414C983EA06AD8E9A410" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-653" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json b/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json new file mode 100644 index 00000000000..5467ed94986 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4j2j-4gr5-gr6h/GHSA-4j2j-4gr5-gr6h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j2j-4gr5-gr6h", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20286" + ], + "details": "A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.\n\nThe vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. \nNote: An attacker must be authenticated with Python execution privileges to exploit these vulnerabilities. For more information regarding Python execution privileges, see product-specific documentation, such as the section of the Cisco Nexus 9000 Series NX-OS Programmability Guide.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20286" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-psbe-ce-YvbTn5du" + }, + { + "type": "WEB", + "url": "https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/105x/programmability/cisco-nexus-9000-series-nx-os-programmability-guide-105x/m-n9k-python-api-101x.html?bookSearch=true#concept_A2CFF094ADCB414C983EA06AD8E9A410" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5fjm-vv45-vv2w/GHSA-5fjm-vv45-vv2w.json b/advisories/unreviewed/2024/08/GHSA-5fjm-vv45-vv2w/GHSA-5fjm-vv45-vv2w.json new file mode 100644 index 00000000000..9950019048c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5fjm-vv45-vv2w/GHSA-5fjm-vv45-vv2w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fjm-vv45-vv2w", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-44913" + ], + "details": "An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44913" + }, + { + "type": "WEB", + "url": "https://github.com/yuhano/irfanview_Poc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json b/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json new file mode 100644 index 00000000000..ee33f9f7a59 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5mh8-xjgp-m345/GHSA-5mh8-xjgp-m345.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mh8-xjgp-m345", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-42698" + ], + "details": "Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index and decrement stack count in the Roughly Enough Items (REI) mod for Minecraft, which allows in-game item duplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42698" + }, + { + "type": "WEB", + "url": "https://github.com/shedaniel/RoughlyEnoughItems/commit/e80ca84f1affb91d2388ddb298bfc6b141828cad" + }, + { + "type": "WEB", + "url": "https://gist.github.com/apple502j/7b1af0082449c9bfbf910e9a25ef3595" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6ccm-42m4-9qfp/GHSA-6ccm-42m4-9qfp.json b/advisories/unreviewed/2024/08/GHSA-6ccm-42m4-9qfp/GHSA-6ccm-42m4-9qfp.json new file mode 100644 index 00000000000..ef590381e5f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6ccm-42m4-9qfp/GHSA-6ccm-42m4-9qfp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ccm-42m4-9qfp", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20411" + ], + "details": "A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device.\n\nThis vulnerability is due to insufficient security restrictions when executing commands from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing a specific crafted command on the underlying operating system. A successful exploit could allow the attacker to execute arbitrary code with the privileges of root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20411" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-bshacepe-bApeHSx7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-267" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json b/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json new file mode 100644 index 00000000000..3863f3200bf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qpq-4383-4c38", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-41565" + ], + "details": "JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index in JEI for Minecraft, which allows in-game item duplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41565" + }, + { + "type": "WEB", + "url": "https://github.com/mezz/JustEnoughItems/commit/99ff43ba1009c44c6d935e2ab8a6c9292bb12873" + }, + { + "type": "WEB", + "url": "https://gist.github.com/apple502j/05123abb1d1c89c31afde15a9b34e2ae" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9v45-7xv5-9gw9/GHSA-9v45-7xv5-9gw9.json b/advisories/unreviewed/2024/08/GHSA-9v45-7xv5-9gw9/GHSA-9v45-7xv5-9gw9.json index 2fb2b187d30..415e53ded6f 100644 --- a/advisories/unreviewed/2024/08/GHSA-9v45-7xv5-9gw9/GHSA-9v45-7xv5-9gw9.json +++ b/advisories/unreviewed/2024/08/GHSA-9v45-7xv5-9gw9/GHSA-9v45-7xv5-9gw9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v45-7xv5-9gw9", - "modified": "2024-08-05T21:31:19Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-08-05T21:31:19Z", "aliases": [ "CVE-2024-6361" ], "details": "Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:M/U:Red" diff --git a/advisories/unreviewed/2024/08/GHSA-fxrw-j82w-pmhg/GHSA-fxrw-j82w-pmhg.json b/advisories/unreviewed/2024/08/GHSA-fxrw-j82w-pmhg/GHSA-fxrw-j82w-pmhg.json new file mode 100644 index 00000000000..0e20eae8de0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fxrw-j82w-pmhg/GHSA-fxrw-j82w-pmhg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxrw-j82w-pmhg", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20289" + ], + "details": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device. \n\nThis vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including crafted input as the argument of the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20289" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmdinj-Lq6jsZhH" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gxh9-2g8g-p2jm/GHSA-gxh9-2g8g-p2jm.json b/advisories/unreviewed/2024/08/GHSA-gxh9-2g8g-p2jm/GHSA-gxh9-2g8g-p2jm.json new file mode 100644 index 00000000000..3a2c5ce3e4d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gxh9-2g8g-p2jm/GHSA-gxh9-2g8g-p2jm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxh9-2g8g-p2jm", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-41564" + ], + "details": "EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index and decrement stack count in EMI mod for Minecraft, which allows in-game item duplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41564" + }, + { + "type": "WEB", + "url": "https://gist.github.com/apple502j/6d691b62c37fc37b03b0784917064df6" + }, + { + "type": "WEB", + "url": "https://github.com/emilyploszaj/emi/blob/1.21/xplat/src/main/java/dev/emi/emi/network/FillRecipeC2SPacket.java" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hvw3-j8wv-xpg5/GHSA-hvw3-j8wv-xpg5.json b/advisories/unreviewed/2024/08/GHSA-hvw3-j8wv-xpg5/GHSA-hvw3-j8wv-xpg5.json new file mode 100644 index 00000000000..a115a299739 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hvw3-j8wv-xpg5/GHSA-hvw3-j8wv-xpg5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvw3-j8wv-xpg5", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-42905" + ], + "details": "Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42905" + }, + { + "type": "WEB", + "url": "https://github.com/ZackSecurity/VulnerReport/blob/cve/DCN/1.md" + }, + { + "type": "WEB", + "url": "https://immense-mirror-b42.notion.site/Beijing-Digital-China-Yunke-Information-Technology-Co-Ltd-DCN-firewall-has-a-command-execution-vuln-31bdd1228f6d47c09e854af5f0e7059f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j3cr-gpf3-q8w2/GHSA-j3cr-gpf3-q8w2.json b/advisories/unreviewed/2024/08/GHSA-j3cr-gpf3-q8w2/GHSA-j3cr-gpf3-q8w2.json new file mode 100644 index 00000000000..3be8a71be31 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j3cr-gpf3-q8w2/GHSA-j3cr-gpf3-q8w2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3cr-gpf3-q8w2", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20478" + ], + "details": "A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary code injection on an affected system.\n\nThis vulnerability is due to insufficient signature validation of software images. An attacker could exploit this vulnerability by installing a modified software image. A successful exploit could allow the attacker to execute arbitrary code on the affected system and elevate their privileges to root.\nNote: Administrators should always validate the hash of any upgrade image before uploading it to Cisco APIC and Cisco Cloud Network Controller.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20478" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-priv-esc-uYQJjnuU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json b/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json index 0b0f3e6c585..2d617e97693 100644 --- a/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json +++ b/advisories/unreviewed/2024/08/GHSA-jh6g-rh4q-hcw2/GHSA-jh6g-rh4q-hcw2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-427" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-jr8c-49mm-qhr4/GHSA-jr8c-49mm-qhr4.json b/advisories/unreviewed/2024/08/GHSA-jr8c-49mm-qhr4/GHSA-jr8c-49mm-qhr4.json index 82abfa427dd..86a68d1aba7 100644 --- a/advisories/unreviewed/2024/08/GHSA-jr8c-49mm-qhr4/GHSA-jr8c-49mm-qhr4.json +++ b/advisories/unreviewed/2024/08/GHSA-jr8c-49mm-qhr4/GHSA-jr8c-49mm-qhr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr8c-49mm-qhr4", - "modified": "2024-08-26T06:30:46Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-08-26T06:30:46Z", "aliases": [ "CVE-2024-6879" ], "details": "The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json b/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json new file mode 100644 index 00000000000..a17862ec672 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9cp-9vc4-2wpg", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-7744" + ], + "details": "In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.\n \n\nAn authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7744" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-August-2024" + }, + { + "type": "WEB", + "url": "https://www.progress.com/ftp-server" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mpvq-wpj3-wjgw/GHSA-mpvq-wpj3-wjgw.json b/advisories/unreviewed/2024/08/GHSA-mpvq-wpj3-wjgw/GHSA-mpvq-wpj3-wjgw.json new file mode 100644 index 00000000000..f666f8b1557 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mpvq-wpj3-wjgw/GHSA-mpvq-wpj3-wjgw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpvq-wpj3-wjgw", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-6053" + ], + "details": "Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6053" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2024-1007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pf8v-w5wh-93wr/GHSA-pf8v-w5wh-93wr.json b/advisories/unreviewed/2024/08/GHSA-pf8v-w5wh-93wr/GHSA-pf8v-w5wh-93wr.json new file mode 100644 index 00000000000..0e647bdf0d3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pf8v-w5wh-93wr/GHSA-pf8v-w5wh-93wr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf8v-w5wh-93wr", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20413" + ], + "details": "A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device.\n\nThis vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to create new users with the privileges of network-admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20413" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-bshacepe-bApeHSx7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-prfv-75r3-hrjc/GHSA-prfv-75r3-hrjc.json b/advisories/unreviewed/2024/08/GHSA-prfv-75r3-hrjc/GHSA-prfv-75r3-hrjc.json new file mode 100644 index 00000000000..9a92b6f5ea6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-prfv-75r3-hrjc/GHSA-prfv-75r3-hrjc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prfv-75r3-hrjc", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-44915" + ], + "details": "An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44915" + }, + { + "type": "WEB", + "url": "https://github.com/yuhano/irfanview_Poc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json b/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json index 25cafb9d56b..a77b6f81b02 100644 --- a/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json +++ b/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pw2q-78xx-rv8j", - "modified": "2024-08-26T18:33:33Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-08-26T18:33:33Z", "aliases": [ "CVE-2024-34087" ], "details": "An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pwqf-cgf8-rx4x/GHSA-pwqf-cgf8-rx4x.json b/advisories/unreviewed/2024/08/GHSA-pwqf-cgf8-rx4x/GHSA-pwqf-cgf8-rx4x.json new file mode 100644 index 00000000000..3da75b7b023 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pwqf-cgf8-rx4x/GHSA-pwqf-cgf8-rx4x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwqf-cgf8-rx4x", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20446" + ], + "details": "A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThis vulnerability is due to improper handling of specific fields in a DHCPv6 RELAY-REPLY message. An attacker could exploit this vulnerability by sending a crafted DHCPv6 packet to any IPv6 address that is configured on an affected device. A successful exploit could allow the attacker to cause the dhcp_snoop process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20446" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-dhcp6-relay-dos-znEAA6xn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q35m-mgqf-ff28/GHSA-q35m-mgqf-ff28.json b/advisories/unreviewed/2024/08/GHSA-q35m-mgqf-ff28/GHSA-q35m-mgqf-ff28.json new file mode 100644 index 00000000000..425b3dbd804 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q35m-mgqf-ff28/GHSA-q35m-mgqf-ff28.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q35m-mgqf-ff28", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20284" + ], + "details": "A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.\n\nThe vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. \nNote: An attacker must be authenticated with Python execution privileges to exploit these vulnerabilities. For more information regarding Python execution privileges, see product-specific documentation, such as the section of the Cisco Nexus 9000 Series NX-OS Programmability Guide.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20284" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-psbe-ce-YvbTn5du" + }, + { + "type": "WEB", + "url": "https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/105x/programmability/cisco-nexus-9000-series-nx-os-programmability-guide-105x/m-n9k-python-api-101x.html?bookSearch=true#concept_A2CFF094ADCB414C983EA06AD8E9A410" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q3f9-5g39-v5vh/GHSA-q3f9-5g39-v5vh.json b/advisories/unreviewed/2024/08/GHSA-q3f9-5g39-v5vh/GHSA-q3f9-5g39-v5vh.json new file mode 100644 index 00000000000..a173f3ed581 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q3f9-5g39-v5vh/GHSA-q3f9-5g39-v5vh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3f9-5g39-v5vh", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-41236" + ], + "details": "A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the \"username\" parameter of the Admin Login Page", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41236" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Responsive%20School%20Management%20System%20v3.2.0/SQL%20Injection%20-%20Admin.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12362/responsive-school-management-system-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qpxx-j878-3553/GHSA-qpxx-j878-3553.json b/advisories/unreviewed/2024/08/GHSA-qpxx-j878-3553/GHSA-qpxx-j878-3553.json new file mode 100644 index 00000000000..a35fb089130 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qpxx-j878-3553/GHSA-qpxx-j878-3553.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpxx-j878-3553", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-42900" + ], + "details": "Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42900" + }, + { + "type": "WEB", + "url": "https://g03m0n.github.io/posts/cve-2024-42900" + }, + { + "type": "WEB", + "url": "https://gitee.com/y_project/RuoYi" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json b/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json new file mode 100644 index 00000000000..34b46ed2631 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v85v-4g2g-qmj9", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-7745" + ], + "details": "In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7745" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-August-2024" + }, + { + "type": "WEB", + "url": "https://www.progress.com/ftp-server" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vcvh-63gv-345g/GHSA-vcvh-63gv-345g.json b/advisories/unreviewed/2024/08/GHSA-vcvh-63gv-345g/GHSA-vcvh-63gv-345g.json new file mode 100644 index 00000000000..9631f0ade73 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vcvh-63gv-345g/GHSA-vcvh-63gv-345g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcvh-63gv-345g", + "modified": "2024-08-28T18:31:55Z", + "published": "2024-08-28T18:31:55Z", + "aliases": [ + "CVE-2024-44914" + ], + "details": "An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44914" + }, + { + "type": "WEB", + "url": "https://github.com/yuhano/irfanview_Poc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wxwr-gxwh-c78c/GHSA-wxwr-gxwh-c78c.json b/advisories/unreviewed/2024/08/GHSA-wxwr-gxwh-c78c/GHSA-wxwr-gxwh-c78c.json new file mode 100644 index 00000000000..e093adeef11 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wxwr-gxwh-c78c/GHSA-wxwr-gxwh-c78c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxwr-gxwh-c78c", + "modified": "2024-08-28T18:31:54Z", + "published": "2024-08-28T18:31:54Z", + "aliases": [ + "CVE-2024-20279" + ], + "details": "A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete child policies created under default system policies, which are implicitly used by all tenants in the fabric, resulting in disruption of network traffic. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20279" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cousmo-uBpBYGbq" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-28T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json b/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json index e86d7130dd3..ad5269e6a57 100644 --- a/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json +++ b/advisories/unreviewed/2024/08/GHSA-x34v-6wh4-m93r/GHSA-x34v-6wh4-m93r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x34v-6wh4-m93r", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-28T18:31:54Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-42845" ], "details": "An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T19:15:06Z"