diff --git a/advisories/unreviewed/2022/03/GHSA-5q8q-7qqw-cmj3/GHSA-5q8q-7qqw-cmj3.json b/advisories/unreviewed/2022/03/GHSA-5q8q-7qqw-cmj3/GHSA-5q8q-7qqw-cmj3.json index bdda149ac87..b755a838f59 100644 --- a/advisories/unreviewed/2022/03/GHSA-5q8q-7qqw-cmj3/GHSA-5q8q-7qqw-cmj3.json +++ b/advisories/unreviewed/2022/03/GHSA-5q8q-7qqw-cmj3/GHSA-5q8q-7qqw-cmj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5q8q-7qqw-cmj3", - "modified": "2022-03-17T00:01:18Z", + "modified": "2024-05-08T15:30:37Z", "published": "2022-03-12T00:00:34Z", "aliases": [ "CVE-2022-21819" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5321" + }, + { + "type": "WEB", + "url": "https://www.thegoodpenguin.co.uk/blog/pcie-dma-attack-against-a-secured-jetson-nano-cve-2022-21819" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json b/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json index b78be7915a6..bc76da22ceb 100644 --- a/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json +++ b/advisories/unreviewed/2024/02/GHSA-5gvr-285q-pwc3/GHSA-5gvr-285q-pwc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gvr-285q-pwc3", - "modified": "2024-04-18T06:30:45Z", + "modified": "2024-05-08T15:30:37Z", "published": "2024-02-04T15:30:22Z", "aliases": [ "CVE-2023-6240" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:1882" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:2758" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6240" diff --git a/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json b/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json index 5104616e18c..1dd0992258c 100644 --- a/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json +++ b/advisories/unreviewed/2024/04/GHSA-77mf-44mv-3m36/GHSA-77mf-44mv-3m36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77mf-44mv-3m36", - "modified": "2024-05-07T18:30:32Z", + "modified": "2024-05-08T15:30:37Z", "published": "2024-04-25T06:30:35Z", "aliases": [ "CVE-2024-26925" @@ -49,6 +49,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/05/07/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/05/08/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-22j5-63rc-6cq9/GHSA-22j5-63rc-6cq9.json b/advisories/unreviewed/2024/05/GHSA-22j5-63rc-6cq9/GHSA-22j5-63rc-6cq9.json new file mode 100644 index 00000000000..8508f053667 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-22j5-63rc-6cq9/GHSA-22j5-63rc-6cq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22j5-63rc-6cq9", + "modified": "2024-05-08T15:30:41Z", + "published": "2024-05-08T15:30:41Z", + "aliases": [ + "CVE-2024-31270" + ], + "details": "Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/arforms-form-builder/wordpress-arforms-form-builder-plugin-1-6-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-2xgc-j2vj-q7gf/GHSA-2xgc-j2vj-q7gf.json b/advisories/unreviewed/2024/05/GHSA-2xgc-j2vj-q7gf/GHSA-2xgc-j2vj-q7gf.json new file mode 100644 index 00000000000..aa4f8ebbfa7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2xgc-j2vj-q7gf/GHSA-2xgc-j2vj-q7gf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xgc-j2vj-q7gf", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-31156" + ], + "details": "\nA stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31156" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138636" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json b/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json new file mode 100644 index 00000000000..dc2da21f9df --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-339j-p2wf-p72r/GHSA-339j-p2wf-p72r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-339j-p2wf-p72r", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25525" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25525" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#officefiledownloadaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json b/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json new file mode 100644 index 00000000000..02771173bda --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-38cv-ch3v-j5cw/GHSA-38cv-ch3v-j5cw.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38cv-ch3v-j5cw", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-32113" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13.\n\nUsers are recommended to upgrade to version 18.12.13, which fixes the issue.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32113" + }, + { + "type": "WEB", + "url": "https://issues.apache.org/jira/browse/OFBIZ-13006" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd" + }, + { + "type": "WEB", + "url": "https://ofbiz.apache.org/download.html" + }, + { + "type": "WEB", + "url": "https://ofbiz.apache.org/security.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json b/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json new file mode 100644 index 00000000000..08f26aee6f5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-39jg-cp5w-9278/GHSA-39jg-cp5w-9278.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39jg-cp5w-9278", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25524" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25524" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#workplanattachdownloadaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3mrg-mh24-hx37/GHSA-3mrg-mh24-hx37.json b/advisories/unreviewed/2024/05/GHSA-3mrg-mh24-hx37/GHSA-3mrg-mh24-hx37.json new file mode 100644 index 00000000000..0315250a906 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3mrg-mh24-hx37/GHSA-3mrg-mh24-hx37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mrg-mh24-hx37", + "modified": "2024-05-08T15:30:41Z", + "published": "2024-05-08T15:30:41Z", + "aliases": [ + "CVE-2024-33574" + ], + "details": "Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33574" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vitepos-lite/wordpress-vitepos-plugin-3-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3qh7-pv9c-8cxc/GHSA-3qh7-pv9c-8cxc.json b/advisories/unreviewed/2024/05/GHSA-3qh7-pv9c-8cxc/GHSA-3qh7-pv9c-8cxc.json new file mode 100644 index 00000000000..2fa6027cbcf --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3qh7-pv9c-8cxc/GHSA-3qh7-pv9c-8cxc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qh7-pv9c-8cxc", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-4654" + ], + "details": "A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4654" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263499" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263499" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-44gv-hrfj-mvj4/GHSA-44gv-hrfj-mvj4.json b/advisories/unreviewed/2024/05/GHSA-44gv-hrfj-mvj4/GHSA-44gv-hrfj-mvj4.json new file mode 100644 index 00000000000..2df7c8f810b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-44gv-hrfj-mvj4/GHSA-44gv-hrfj-mvj4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44gv-hrfj-mvj4", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-4652" + ], + "details": "A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/show_teacher2.php. The manipulation of the argument month leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263496.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4652" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2021.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263496" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263496" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4vgj-rwj6-4gwr/GHSA-4vgj-rwj6-4gwr.json b/advisories/unreviewed/2024/05/GHSA-4vgj-rwj6-4gwr/GHSA-4vgj-rwj6-4gwr.json new file mode 100644 index 00000000000..289d3e20733 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4vgj-rwj6-4gwr/GHSA-4vgj-rwj6-4gwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vgj-rwj6-4gwr", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-33604" + ], + "details": "\nA reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33604" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138894" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json b/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json new file mode 100644 index 00000000000..6b5e7559b7d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4wj3-7p36-wmrw/GHSA-4wj3-7p36-wmrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wj3-7p36-wmrw", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-33612" + ], + "details": "\n\n\nAn improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. A successful exploit of this vulnerability can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33612" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000139012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-69pf-4hfw-vpvh/GHSA-69pf-4hfw-vpvh.json b/advisories/unreviewed/2024/05/GHSA-69pf-4hfw-vpvh/GHSA-69pf-4hfw-vpvh.json new file mode 100644 index 00000000000..a40534ddaf8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-69pf-4hfw-vpvh/GHSA-69pf-4hfw-vpvh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69pf-4hfw-vpvh", + "modified": "2024-05-08T15:30:41Z", + "published": "2024-05-08T15:30:41Z", + "aliases": [ + "CVE-2024-4649" + ], + "details": "A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/student_exam_mark_insert_form1.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263493 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4649" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2018.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6pg9-7x5x-vg3x/GHSA-6pg9-7x5x-vg3x.json b/advisories/unreviewed/2024/05/GHSA-6pg9-7x5x-vg3x/GHSA-6pg9-7x5x-vg3x.json new file mode 100644 index 00000000000..a6e80e91fa0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6pg9-7x5x-vg3x/GHSA-6pg9-7x5x-vg3x.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pg9-7x5x-vg3x", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-4651" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument year leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263495.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4651" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2020.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7grh-8hh5-88pf/GHSA-7grh-8hh5-88pf.json b/advisories/unreviewed/2024/05/GHSA-7grh-8hh5-88pf/GHSA-7grh-8hh5-88pf.json new file mode 100644 index 00000000000..59542dd1213 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7grh-8hh5-88pf/GHSA-7grh-8hh5-88pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7grh-8hh5-88pf", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-32049" + ], + "details": "BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32049" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138634" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-300" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7grm-v449-2cv5/GHSA-7grm-v449-2cv5.json b/advisories/unreviewed/2024/05/GHSA-7grm-v449-2cv5/GHSA-7grm-v449-2cv5.json new file mode 100644 index 00000000000..5cd858dd977 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7grm-v449-2cv5/GHSA-7grm-v449-2cv5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7grm-v449-2cv5", + "modified": "2024-05-08T15:30:40Z", + "published": "2024-05-08T15:30:39Z", + "aliases": [ + "CVE-2024-4645" + ], + "details": "A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /Admin/changepassword.php. The manipulation of the argument txtold_password/txtnew_password/txtconfirm_password leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263489 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4645" + }, + { + "type": "WEB", + "url": "https://github.com/yylmm/CVE/blob/main/Prison%20Management%20System/xss4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json b/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json new file mode 100644 index 00000000000..8d33cd344f3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7h9q-j3hq-cpc4/GHSA-7h9q-j3hq-cpc4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h9q-j3hq-cpc4", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25521" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25521" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#get_companyaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json b/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json new file mode 100644 index 00000000000..f25a832459c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-96fg-696f-w9g3/GHSA-96fg-696f-w9g3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96fg-696f-w9g3", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25520" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25520" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#sys_blogtemplate_newaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c592-6f6m-vm4h/GHSA-c592-6f6m-vm4h.json b/advisories/unreviewed/2024/05/GHSA-c592-6f6m-vm4h/GHSA-c592-6f6m-vm4h.json new file mode 100644 index 00000000000..bd387e87663 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c592-6f6m-vm4h/GHSA-c592-6f6m-vm4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c592-6f6m-vm4h", + "modified": "2024-05-08T15:30:40Z", + "published": "2024-05-08T15:30:40Z", + "aliases": [ + "CVE-2024-30459" + ], + "details": "Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ai-wp-writer/wordpress-ai-wp-writer-plugin-3-6-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f6pr-3mcc-9v92/GHSA-f6pr-3mcc-9v92.json b/advisories/unreviewed/2024/05/GHSA-f6pr-3mcc-9v92/GHSA-f6pr-3mcc-9v92.json new file mode 100644 index 00000000000..72cde4c3a30 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f6pr-3mcc-9v92/GHSA-f6pr-3mcc-9v92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6pr-3mcc-9v92", + "modified": "2024-05-08T15:30:39Z", + "published": "2024-05-08T15:30:39Z", + "aliases": [ + "CVE-2024-1438" + ], + "details": "Missing Authorization vulnerability in PressFore Rolo Slider.This issue affects Rolo Slider: from n/a through 1.0.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rolo-slider/wordpress-rolo-slider-plugin-1-0-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json b/advisories/unreviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json new file mode 100644 index 00000000000..fd4e7e47050 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgh3-pwmp-3qw3", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-26579" + ], + "details": "Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, \n\n the attackers can bypass using malicious parameters.\n\nUsers are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it.\n\n[1] https://github.com/apache/inlong/pull/9694 \n\n[2]  https://github.com/apache/inlong/pull/9707 \n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26579" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/d2hndtvh6bll4pkl91o2oqxyynhr54k3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json b/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json new file mode 100644 index 00000000000..1f1079c9965 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fj43-9cjj-qw2v/GHSA-fj43-9cjj-qw2v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj43-9cjj-qw2v", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-26026" + ], + "details": "\n\n\nAn SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26026" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fq23-5997-3879/GHSA-fq23-5997-3879.json b/advisories/unreviewed/2024/05/GHSA-fq23-5997-3879/GHSA-fq23-5997-3879.json new file mode 100644 index 00000000000..afb1bd3b5ad --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fq23-5997-3879/GHSA-fq23-5997-3879.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq23-5997-3879", + "modified": "2024-05-08T15:30:40Z", + "published": "2024-05-08T15:30:39Z", + "aliases": [ + "CVE-2024-4646" + ], + "details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/student_payment_details.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263490 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4646" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2015.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-frv4-f3cq-3x3v/GHSA-frv4-f3cq-3x3v.json b/advisories/unreviewed/2024/05/GHSA-frv4-f3cq-3x3v/GHSA-frv4-f3cq-3x3v.json new file mode 100644 index 00000000000..ea9436a8941 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-frv4-f3cq-3x3v/GHSA-frv4-f3cq-3x3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frv4-f3cq-3x3v", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-27202" + ], + "details": "\nA DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27202" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138520" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json b/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json new file mode 100644 index 00000000000..ee814776194 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fxfv-f99m-vfjq/GHSA-fxfv-f99m-vfjq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxfv-f99m-vfjq", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25522" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25522" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#wf_work_form_saveaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json b/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json new file mode 100644 index 00000000000..fb75d85726a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-g8rr-54r4-95mg/GHSA-g8rr-54r4-95mg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8rr-54r4-95mg", + "modified": "2024-05-08T15:30:39Z", + "published": "2024-05-08T15:30:39Z", + "aliases": [ + "CVE-2024-34255" + ], + "details": "jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34255" + }, + { + "type": "WEB", + "url": "https://github.com/Cherry-toto/jizhicms/issues/93" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gv23-mcr7-vrqf/GHSA-gv23-mcr7-vrqf.json b/advisories/unreviewed/2024/05/GHSA-gv23-mcr7-vrqf/GHSA-gv23-mcr7-vrqf.json new file mode 100644 index 00000000000..ede2583ead9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gv23-mcr7-vrqf/GHSA-gv23-mcr7-vrqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv23-mcr7-vrqf", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-3951" + ], + "details": "\nPTC Codebeamer is vulnerable to a cross site scripting vulnerability that could allow an attacker to inject and execute malicious code.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3951" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-128-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h6g7-66rp-7w92/GHSA-h6g7-66rp-7w92.json b/advisories/unreviewed/2024/05/GHSA-h6g7-66rp-7w92/GHSA-h6g7-66rp-7w92.json new file mode 100644 index 00000000000..0508e46af24 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h6g7-66rp-7w92/GHSA-h6g7-66rp-7w92.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6g7-66rp-7w92", + "modified": "2024-05-08T15:30:40Z", + "published": "2024-05-08T15:30:40Z", + "aliases": [ + "CVE-2024-4647" + ], + "details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/student_first_payment.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263491.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4647" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2016.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json b/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json new file mode 100644 index 00000000000..23593345196 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hv8p-cqc6-r6pm/GHSA-hv8p-cqc6-r6pm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv8p-cqc6-r6pm", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25515" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work_finish_file_down.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25515" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#wf_work_finish_file_downaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hwq4-p9m3-4cjm/GHSA-hwq4-p9m3-4cjm.json b/advisories/unreviewed/2024/05/GHSA-hwq4-p9m3-4cjm/GHSA-hwq4-p9m3-4cjm.json new file mode 100644 index 00000000000..037c97867d1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hwq4-p9m3-4cjm/GHSA-hwq4-p9m3-4cjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwq4-p9m3-4cjm", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-28132" + ], + "details": "\nExposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28132" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j5j7-c96c-3p39/GHSA-j5j7-c96c-3p39.json b/advisories/unreviewed/2024/05/GHSA-j5j7-c96c-3p39/GHSA-j5j7-c96c-3p39.json new file mode 100644 index 00000000000..0fb3e2a94bc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j5j7-c96c-3p39/GHSA-j5j7-c96c-3p39.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5j7-c96c-3p39", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-28889" + ], + "details": "\n\n\nWhen an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28889" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138912" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-825" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j5jg-9jr3-xg7w/GHSA-j5jg-9jr3-xg7w.json b/advisories/unreviewed/2024/05/GHSA-j5jg-9jr3-xg7w/GHSA-j5jg-9jr3-xg7w.json new file mode 100644 index 00000000000..b57c5194029 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j5jg-9jr3-xg7w/GHSA-j5jg-9jr3-xg7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5jg-9jr3-xg7w", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25560" + ], + "details": "\nWhen BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25560" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000139037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json b/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json new file mode 100644 index 00000000000..ff113d76aa7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jw4v-xfx4-pv7q/GHSA-jw4v-xfx4-pv7q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw4v-xfx4-pv7q", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25519" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25519" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#wf_work_printaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-m2h2-wwx2-whpr/GHSA-m2h2-wwx2-whpr.json b/advisories/unreviewed/2024/05/GHSA-m2h2-wwx2-whpr/GHSA-m2h2-wwx2-whpr.json new file mode 100644 index 00000000000..b5f7a6ef7f4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-m2h2-wwx2-whpr/GHSA-m2h2-wwx2-whpr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2h2-wwx2-whpr", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-4653" + ], + "details": "A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /xds/outIndex.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263498 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4653" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json b/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json new file mode 100644 index 00000000000..64189eb78b7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pg9r-hpv4-c9cq/GHSA-pg9r-hpv4-c9cq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg9r-hpv4-c9cq", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25526" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25526" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#pm_gatt_incaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qffg-p58p-854c/GHSA-qffg-p58p-854c.json b/advisories/unreviewed/2024/05/GHSA-qffg-p58p-854c/GHSA-qffg-p58p-854c.json new file mode 100644 index 00000000000..55d6c77be2a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qffg-p58p-854c/GHSA-qffg-p58p-854c.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qffg-p58p-854c", + "modified": "2024-05-08T15:30:40Z", + "published": "2024-05-08T15:30:40Z", + "aliases": [ + "CVE-2024-4648" + ], + "details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /view/student_exam_mark_update_form.php. The manipulation of the argument std_index leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263492.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4648" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2017.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json b/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json new file mode 100644 index 00000000000..62c6696bcbb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qxcf-7fw9-mhjf/GHSA-qxcf-7fw9-mhjf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxcf-7fw9-mhjf", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25523" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25523" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#file_memoaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v4r4-qxjg-89q5/GHSA-v4r4-qxjg-89q5.json b/advisories/unreviewed/2024/05/GHSA-v4r4-qxjg-89q5/GHSA-v4r4-qxjg-89q5.json new file mode 100644 index 00000000000..83ffe3eafb4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v4r4-qxjg-89q5/GHSA-v4r4-qxjg-89q5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4r4-qxjg-89q5", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-33608" + ], + "details": "When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33608" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138728" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v5mc-ffgc-f77v/GHSA-v5mc-ffgc-f77v.json b/advisories/unreviewed/2024/05/GHSA-v5mc-ffgc-f77v/GHSA-v5mc-ffgc-f77v.json new file mode 100644 index 00000000000..26229dc0c52 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v5mc-ffgc-f77v/GHSA-v5mc-ffgc-f77v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5mc-ffgc-f77v", + "modified": "2024-05-08T15:30:43Z", + "published": "2024-05-08T15:30:43Z", + "aliases": [ + "CVE-2024-32761" + ], + "details": "\nUnder certain conditions, a potential data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. However, this issue cannot be exploited by an attacker because it is not consistently reproducible and is beyond an attacker's control.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32761" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000139217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json b/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json new file mode 100644 index 00000000000..3d6cd470500 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vgjf-wg4r-wfgj/GHSA-vgjf-wg4r-wfgj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgjf-wg4r-wfgj", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25518" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_approve.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25518" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#wf_get_fields_approveaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vhmj-v5p6-jwhv/GHSA-vhmj-v5p6-jwhv.json b/advisories/unreviewed/2024/05/GHSA-vhmj-v5p6-jwhv/GHSA-vhmj-v5p6-jwhv.json new file mode 100644 index 00000000000..a97d9643486 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vhmj-v5p6-jwhv/GHSA-vhmj-v5p6-jwhv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhmj-v5p6-jwhv", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-4650" + ], + "details": "A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file /view/student_due_payment.php. The manipulation of the argument due_month leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263494 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4650" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2019.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.330124" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w6q8-c6q3-jvxr/GHSA-w6q8-c6q3-jvxr.json b/advisories/unreviewed/2024/05/GHSA-w6q8-c6q3-jvxr/GHSA-w6q8-c6q3-jvxr.json new file mode 100644 index 00000000000..d8d43c5c2a3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w6q8-c6q3-jvxr/GHSA-w6q8-c6q3-jvxr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6q8-c6q3-jvxr", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-28883" + ], + "details": "An origin validation vulnerability exists in \n\nBIG-IP APM browser network access VPN client \n\n\n\n for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28883" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138744" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json b/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json new file mode 100644 index 00000000000..fbacf5139bf --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w9q2-p57h-r357/GHSA-w9q2-p57h-r357.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9q2-p57h-r357", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-21793" + ], + "details": "\nAn OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21793" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138732" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json b/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json new file mode 100644 index 00000000000..7243c372a0a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wcjc-qwhg-vfmr/GHSA-wcjc-qwhg-vfmr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcjc-qwhg-vfmr", + "modified": "2024-05-08T15:30:42Z", + "published": "2024-05-08T15:30:42Z", + "aliases": [ + "CVE-2024-25517" + ], + "details": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25517" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#mfaspx" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wg7h-v937-9wh2/GHSA-wg7h-v937-9wh2.json b/advisories/unreviewed/2024/05/GHSA-wg7h-v937-9wh2/GHSA-wg7h-v937-9wh2.json new file mode 100644 index 00000000000..658ebca235d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wg7h-v937-9wh2/GHSA-wg7h-v937-9wh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg7h-v937-9wh2", + "modified": "2024-05-08T15:30:40Z", + "published": "2024-05-08T15:30:40Z", + "aliases": [ + "CVE-2024-24833" + ], + "details": "Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24833" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/happy-elementor-addons/wordpress-happy-addons-for-elementor-plugin-3-10-1-broken-access-control-on-post-clone-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x3r4-5hf3-cxgc/GHSA-x3r4-5hf3-cxgc.json b/advisories/unreviewed/2024/05/GHSA-x3r4-5hf3-cxgc/GHSA-x3r4-5hf3-cxgc.json new file mode 100644 index 00000000000..5299d0e7c9c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x3r4-5hf3-cxgc/GHSA-x3r4-5hf3-cxgc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3r4-5hf3-cxgc", + "modified": "2024-05-08T15:30:41Z", + "published": "2024-05-08T15:30:41Z", + "aliases": [ + "CVE-2024-4233" + ], + "details": "Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/arconix-faq/wordpress-arconix-faq-plugin-1-9-3-broken-access-control-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/arconix-shortcodes/wordpress-arconix-shortcodes-plugin-2-1-10-broken-access-control-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-delivery-notes/wordpress-print-invoice-delivery-notes-for-woocommerce-plugin-4-8-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x865-q275-326g/GHSA-x865-q275-326g.json b/advisories/unreviewed/2024/05/GHSA-x865-q275-326g/GHSA-x865-q275-326g.json new file mode 100644 index 00000000000..1f1303f8a24 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x865-q275-326g/GHSA-x865-q275-326g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x865-q275-326g", + "modified": "2024-05-08T15:30:41Z", + "published": "2024-05-08T15:30:41Z", + "aliases": [ + "CVE-2024-33573" + ], + "details": "Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33573" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/eprolo-dropshipping/wordpress-eprolo-dropshipping-plugin-1-7-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-08T14:15:08Z" + } +} \ No newline at end of file