Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-05-08 15:32:03 +00:00
parent b5c8971396
commit a24081ee85
48 changed files with 1823 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q8q-7qqw-cmj3",
"modified": "2022-03-17T00:01:18Z",
"modified": "2024-05-08T15:30:37Z",
"published": "2022-03-12T00:00:34Z",
"aliases": [
"CVE-2022-21819"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5321"
},
{
"type": "WEB",
"url": "https://www.thegoodpenguin.co.uk/blog/pcie-dma-attack-against-a-secured-jetson-nano-cve-2022-21819"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gvr-285q-pwc3",
"modified": "2024-04-18T06:30:45Z",
"modified": "2024-05-08T15:30:37Z",
"published": "2024-02-04T15:30:22Z",
"aliases": [
"CVE-2023-6240"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:1882"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2758"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-6240"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77mf-44mv-3m36",
"modified": "2024-05-07T18:30:32Z",
"modified": "2024-05-08T15:30:37Z",
"published": "2024-04-25T06:30:35Z",
"aliases": [
"CVE-2024-26925"
@@ -49,6 +49,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/05/07/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/05/08/2"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22j5-63rc-6cq9",
"modified": "2024-05-08T15:30:41Z",
"published": "2024-05-08T15:30:41Z",
"aliases": [
"CVE-2024-31270"
],
"details": "Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31270"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/arforms-form-builder/wordpress-arforms-form-builder-plugin-1-6-1-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T14:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xgc-j2vj-q7gf",
"modified": "2024-05-08T15:30:43Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-31156"
],
"details": "\nA stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31156"
},
{
"type": "WEB",
"url": "https://my.f5.com/manage/s/article/K000138636"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-339j-p2wf-p72r",
"modified": "2024-05-08T15:30:42Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-25525"
],
"details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25525"
},
{
"type": "WEB",
"url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#officefiledownloadaspx"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:08Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38cv-ch3v-j5cw",
"modified": "2024-05-08T15:30:43Z",
"published": "2024-05-08T15:30:43Z",
"aliases": [
"CVE-2024-32113"
],
"details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.\n\nUsers are recommended to upgrade to version 18.12.13, which fixes the issue.\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32113"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/OFBIZ-13006"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd"
},
{
"type": "WEB",
"url": "https://ofbiz.apache.org/download.html"
},
{
"type": "WEB",
"url": "https://ofbiz.apache.org/security.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39jg-cp5w-9278",
"modified": "2024-05-08T15:30:42Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-25524"
],
"details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25524"
},
{
"type": "WEB",
"url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#workplanattachdownloadaspx"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mrg-mh24-hx37",
"modified": "2024-05-08T15:30:41Z",
"published": "2024-05-08T15:30:41Z",
"aliases": [
"CVE-2024-33574"
],
"details": "Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33574"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/vitepos-lite/wordpress-vitepos-plugin-3-0-1-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T14:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qh7-pv9c-8cxc",
"modified": "2024-05-08T15:30:43Z",
"published": "2024-05-08T15:30:43Z",
"aliases": [
"CVE-2024-4654"
],
"details": "A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4654"
},
{
"type": "WEB",
"url": "https://github.com/Hefei-Coffee/cve/blob/main/sql2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.263499"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.263499"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.330631"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44gv-hrfj-mvj4",
"modified": "2024-05-08T15:30:42Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-4652"
],
"details": "A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/show_teacher2.php. The manipulation of the argument month leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263496.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4652"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2021.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.263496"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.263496"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.330126"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vgj-rwj6-4gwr",
"modified": "2024-05-08T15:30:43Z",
"published": "2024-05-08T15:30:43Z",
"aliases": [
"CVE-2024-33604"
],
"details": "\nA reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33604"
},
{
"type": "WEB",
"url": "https://my.f5.com/manage/s/article/K000138894"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:10Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4wj3-7p36-wmrw",
"modified": "2024-05-08T15:30:43Z",
"published": "2024-05-08T15:30:43Z",
"aliases": [
"CVE-2024-33612"
],
"details": "\n\n\nAn improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. A successful exploit of this vulnerability can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33612"
},
{
"type": "WEB",
"url": "https://my.f5.com/manage/s/article/K000139012"
}
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-69pf-4hfw-vpvh",
"modified": "2024-05-08T15:30:41Z",
"published": "2024-05-08T15:30:41Z",
"aliases": [
"CVE-2024-4649"
],
"details": "A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/student_exam_mark_insert_form1.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263493 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4649"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2018.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.263493"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.263493"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.330123"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T14:15:09Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pg9-7x5x-vg3x",
"modified": "2024-05-08T15:30:42Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-4651"
],
"details": "A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument year leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263495.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4651"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2020.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.263495"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.263495"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.330125"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7grh-8hh5-88pf",
"modified": "2024-05-08T15:30:43Z",
"published": "2024-05-08T15:30:43Z",
"aliases": [
"CVE-2024-32049"
],
"details": "BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32049"
},
{
"type": "WEB",
"url": "https://my.f5.com/manage/s/article/K000138634"
}
],
"database_specific": {
"cwe_ids": [
"CWE-300"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:09Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7grm-v449-2cv5",
"modified": "2024-05-08T15:30:40Z",
"published": "2024-05-08T15:30:39Z",
"aliases": [
"CVE-2024-4645"
],
"details": "A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /Admin/changepassword.php. The manipulation of the argument txtold_password/txtnew_password/txtconfirm_password leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263489 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4645"
},
{
"type": "WEB",
"url": "https://github.com/yylmm/CVE/blob/main/Prison%20Management%20System/xss4.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.263489"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.263489"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.330022"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T13:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7h9q-j3hq-cpc4",
"modified": "2024-05-08T15:30:42Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-25521"
],
"details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25521"
},
{
"type": "WEB",
"url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#get_companyaspx"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-96fg-696f-w9g3",
"modified": "2024-05-08T15:30:42Z",
"published": "2024-05-08T15:30:42Z",
"aliases": [
"CVE-2024-25520"
],
"details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25520"
},
{
"type": "WEB",
"url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#sys_blogtemplate_newaspx"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T15:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c592-6f6m-vm4h",
"modified": "2024-05-08T15:30:40Z",
"published": "2024-05-08T15:30:40Z",
"aliases": [
"CVE-2024-30459"
],
"details": "Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30459"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/ai-wp-writer/wordpress-ai-wp-writer-plugin-3-6-5-broken-access-control-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-08T14:15:07Z"
}
}

Some files were not shown because too many files have changed in this diff Show More