diff --git a/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json b/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json index f72e9438e2a..e163c17a22d 100644 --- a/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json +++ b/advisories/unreviewed/2023/10/GHSA-4473-7649-rj9x/GHSA-4473-7649-rj9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4473-7649-rj9x", - "modified": "2024-04-04T08:45:24Z", + "modified": "2024-09-30T18:31:35Z", "published": "2023-10-18T00:31:42Z", "aliases": [ "CVE-2023-3042" diff --git a/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json b/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json index 63c2075b9c5..f20714c51ac 100644 --- a/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json +++ b/advisories/unreviewed/2024/04/GHSA-4mm4-33wm-56jr/GHSA-4mm4-33wm-56jr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mm4-33wm-56jr", - "modified": "2024-07-26T15:31:48Z", + "modified": "2024-09-30T18:31:35Z", "published": "2024-04-02T00:30:47Z", "aliases": [ "CVE-2024-3165" @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-522" + "CWE-522", + "CWE-532" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json b/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json index dc44e2cac09..2ce0a4d3a5f 100644 --- a/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json +++ b/advisories/unreviewed/2024/04/GHSA-vhhq-fxg5-hvp8/GHSA-vhhq-fxg5-hvp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhhq-fxg5-hvp8", - "modified": "2024-07-26T15:31:48Z", + "modified": "2024-09-30T18:31:35Z", "published": "2024-04-02T00:30:46Z", "aliases": [ "CVE-2024-3164" @@ -44,6 +44,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-552" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json b/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json new file mode 100644 index 00000000000..a62a276b02b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3vv9-hcm7-cvjm/GHSA-3vv9-hcm7-cvjm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vv9-hcm7-cvjm", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46475" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46475" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/qq_45744104/article/details/141903463" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5h87-x2jh-f8f9/GHSA-5h87-x2jh-f8f9.json b/advisories/unreviewed/2024/09/GHSA-5h87-x2jh-f8f9/GHSA-5h87-x2jh-f8f9.json index a5d44ae9cdb..c11ddcbc1bd 100644 --- a/advisories/unreviewed/2024/09/GHSA-5h87-x2jh-f8f9/GHSA-5h87-x2jh-f8f9.json +++ b/advisories/unreviewed/2024/09/GHSA-5h87-x2jh-f8f9/GHSA-5h87-x2jh-f8f9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-74jr-9xc3-xccr/GHSA-74jr-9xc3-xccr.json b/advisories/unreviewed/2024/09/GHSA-74jr-9xc3-xccr/GHSA-74jr-9xc3-xccr.json index c89cc120950..84f6f744de4 100644 --- a/advisories/unreviewed/2024/09/GHSA-74jr-9xc3-xccr/GHSA-74jr-9xc3-xccr.json +++ b/advisories/unreviewed/2024/09/GHSA-74jr-9xc3-xccr/GHSA-74jr-9xc3-xccr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74jr-9xc3-xccr", - "modified": "2024-09-23T09:30:46Z", + "modified": "2024-09-30T18:31:35Z", "published": "2024-09-23T09:30:46Z", "aliases": [ "CVE-2024-8606" ], "details": "Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json b/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json index 73274d0de3d..448ccffea3e 100644 --- a/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json +++ b/advisories/unreviewed/2024/09/GHSA-8g8m-p65c-g42p/GHSA-8g8m-p65c-g42p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g8m-p65c-g42p", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-30T18:31:36Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-8877" ], "details": "Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-9636-h6xg-ch93/GHSA-9636-h6xg-ch93.json b/advisories/unreviewed/2024/09/GHSA-9636-h6xg-ch93/GHSA-9636-h6xg-ch93.json index 58fc15bb98f..0ad128403f2 100644 --- a/advisories/unreviewed/2024/09/GHSA-9636-h6xg-ch93/GHSA-9636-h6xg-ch93.json +++ b/advisories/unreviewed/2024/09/GHSA-9636-h6xg-ch93/GHSA-9636-h6xg-ch93.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-209" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json b/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json index 05e64ad853e..10f88c9d0db 100644 --- a/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json +++ b/advisories/unreviewed/2024/09/GHSA-f93h-pcqv-5rf7/GHSA-f93h-pcqv-5rf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f93h-pcqv-5rf7", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-30T18:31:36Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-46610" ], "details": "An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-25T01:15:44Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json b/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json index ae523594205..c531dbe3d70 100644 --- a/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json +++ b/advisories/unreviewed/2024/09/GHSA-g2w3-jpfv-qffv/GHSA-g2w3-jpfv-qffv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2w3-jpfv-qffv", - "modified": "2024-09-18T21:30:48Z", + "modified": "2024-09-30T18:31:35Z", "published": "2024-09-18T21:30:48Z", "aliases": [ "CVE-2024-43025" ], "details": "An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload injected into a sent e-mail.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-18T20:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-grj2-m3x4-7f2m/GHSA-grj2-m3x4-7f2m.json b/advisories/unreviewed/2024/09/GHSA-grj2-m3x4-7f2m/GHSA-grj2-m3x4-7f2m.json new file mode 100644 index 00000000000..33cf8761c8e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-grj2-m3x4-7f2m/GHSA-grj2-m3x4-7f2m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grj2-m3x4-7f2m", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46869" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btintel_pcie: Allocate memory for driver private data\n\nFix driver not allocating memory for struct btintel_data which is used\nto store internal data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46869" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b4545f08cc68d2fc835f5c490b36e0264750030" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ffaa200251871980af12e57649ad57c70bf0f43" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa9e1c1b1f389a8e6d987ac6cb3e2ba04f8ec875" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h496-35px-76wp/GHSA-h496-35px-76wp.json b/advisories/unreviewed/2024/09/GHSA-h496-35px-76wp/GHSA-h496-35px-76wp.json new file mode 100644 index 00000000000..b546b2d4269 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h496-35px-76wp/GHSA-h496-35px-76wp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h496-35px-76wp", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46549" + ], + "details": "An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46549" + }, + { + "type": "WEB", + "url": "https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-46549.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hg56-xvvv-cj4c/GHSA-hg56-xvvv-cj4c.json b/advisories/unreviewed/2024/09/GHSA-hg56-xvvv-cj4c/GHSA-hg56-xvvv-cj4c.json new file mode 100644 index 00000000000..c0ccacd0c25 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hg56-xvvv-cj4c/GHSA-hg56-xvvv-cj4c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg56-xvvv-cj4c", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46548" + ], + "details": "TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46548" + }, + { + "type": "WEB", + "url": "https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-46548.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json b/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json new file mode 100644 index 00000000000..82ab86947c5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hgwc-f2wf-xrf8/GHSA-hgwc-f2wf-xrf8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgwc-f2wf-xrf8", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46540" + ], + "details": "A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46540" + }, + { + "type": "WEB", + "url": "https://gist.github.com/microvorld/1c1ef9c3390a5d88a5ede9f9424a8bd2" + }, + { + "type": "WEB", + "url": "https://github.com/emlog/emlog" + }, + { + "type": "WEB", + "url": "https://github.com/microvorld/CVE-2024/blob/main/emlog.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json b/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json new file mode 100644 index 00000000000..1dbac154f06 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hjpg-cfqw-g6jv/GHSA-hjpg-cfqw-g6jv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjpg-cfqw-g6jv", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-42017" + ], + "details": "An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42017" + }, + { + "type": "WEB", + "url": "https://eviden.com" + }, + { + "type": "WEB", + "url": "https://support.bull.com/ols/product/security/psirt/security-bulletins/multiple-critical-vulnerabilities-in-icare-psirt-625-tlp-clear-version-0-7-cve-2024-42017/view" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json b/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json new file mode 100644 index 00000000000..9a1dc4b33c4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hrqj-68hr-6cvc/GHSA-hrqj-68hr-6cvc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrqj-68hr-6cvc", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-35495" + ], + "details": "An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35495" + }, + { + "type": "WEB", + "url": "https://github.com/Chapoly1305/tp-link-cve/blob/main/CVE-2024-35495.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jv5j-9qxg-rrh2/GHSA-jv5j-9qxg-rrh2.json b/advisories/unreviewed/2024/09/GHSA-jv5j-9qxg-rrh2/GHSA-jv5j-9qxg-rrh2.json index 8fd4b6f1876..e801837799c 100644 --- a/advisories/unreviewed/2024/09/GHSA-jv5j-9qxg-rrh2/GHSA-jv5j-9qxg-rrh2.json +++ b/advisories/unreviewed/2024/09/GHSA-jv5j-9qxg-rrh2/GHSA-jv5j-9qxg-rrh2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json b/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json new file mode 100644 index 00000000000..9f8bf8bdf76 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pp67-vh85-488h/GHSA-pp67-vh85-488h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp67-vh85-488h", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-45993" + ], + "details": "Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45993" + }, + { + "type": "WEB", + "url": "https://gitlab.com/mthandazo/project-pov" + }, + { + "type": "WEB", + "url": "http://giflib.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T17:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-px7r-w6rw-3r67/GHSA-px7r-w6rw-3r67.json b/advisories/unreviewed/2024/09/GHSA-px7r-w6rw-3r67/GHSA-px7r-w6rw-3r67.json index 6b010edfd22..e9499dcd4f8 100644 --- a/advisories/unreviewed/2024/09/GHSA-px7r-w6rw-3r67/GHSA-px7r-w6rw-3r67.json +++ b/advisories/unreviewed/2024/09/GHSA-px7r-w6rw-3r67/GHSA-px7r-w6rw-3r67.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json b/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json index 8d7d3c6e3b5..58ad9b09801 100644 --- a/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json +++ b/advisories/unreviewed/2024/09/GHSA-q586-q77x-838f/GHSA-q586-q77x-838f.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q586-q77x-838f", - "modified": "2024-09-23T21:30:48Z", + "modified": "2024-09-30T18:31:36Z", "published": "2024-09-23T21:30:47Z", "aliases": [ "CVE-2024-8263" ], "details": "An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-qm4j-mqq4-36gx/GHSA-qm4j-mqq4-36gx.json b/advisories/unreviewed/2024/09/GHSA-qm4j-mqq4-36gx/GHSA-qm4j-mqq4-36gx.json new file mode 100644 index 00000000000..d90e879d34a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qm4j-mqq4-36gx/GHSA-qm4j-mqq4-36gx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm4j-mqq4-36gx", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-28809" + ], + "details": "An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28809" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28809" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r4r3-6cgv-2w75/GHSA-r4r3-6cgv-2w75.json b/advisories/unreviewed/2024/09/GHSA-r4r3-6cgv-2w75/GHSA-r4r3-6cgv-2w75.json index c29b128dedc..0dc8f5d562b 100644 --- a/advisories/unreviewed/2024/09/GHSA-r4r3-6cgv-2w75/GHSA-r4r3-6cgv-2w75.json +++ b/advisories/unreviewed/2024/09/GHSA-r4r3-6cgv-2w75/GHSA-r4r3-6cgv-2w75.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-r8j4-h2xg-f955/GHSA-r8j4-h2xg-f955.json b/advisories/unreviewed/2024/09/GHSA-r8j4-h2xg-f955/GHSA-r8j4-h2xg-f955.json new file mode 100644 index 00000000000..dde81ed1945 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r8j4-h2xg-f955/GHSA-r8j4-h2xg-f955.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8j4-h2xg-f955", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46510" + ], + "details": "ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46510" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/c7784cff-2840-4761-8d1b-621016b6b1b9?code=G8A6P3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v2c6-mhjv-vm9x/GHSA-v2c6-mhjv-vm9x.json b/advisories/unreviewed/2024/09/GHSA-v2c6-mhjv-vm9x/GHSA-v2c6-mhjv-vm9x.json new file mode 100644 index 00000000000..ae6c18dba17 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v2c6-mhjv-vm9x/GHSA-v2c6-mhjv-vm9x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2c6-mhjv-vm9x", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-46635" + ], + "details": "An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46635" + }, + { + "type": "WEB", + "url": "https://hithub.notion.site/Sensitive-Information-Disclosure-in-GongZhiDao-System-aaad25d2430f4a638d462194cfa87c8b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json b/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json index 41466708e89..9cfaf8c1eac 100644 --- a/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json +++ b/advisories/unreviewed/2024/09/GHSA-wpw2-69v8-6f9h/GHSA-wpw2-69v8-6f9h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1004" + "CWE-1004", + "CWE-732" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-x6r9-hvfc-r4m7/GHSA-x6r9-hvfc-r4m7.json b/advisories/unreviewed/2024/09/GHSA-x6r9-hvfc-r4m7/GHSA-x6r9-hvfc-r4m7.json new file mode 100644 index 00000000000..71d57af5ee0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x6r9-hvfc-r4m7/GHSA-x6r9-hvfc-r4m7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6r9-hvfc-r4m7", + "modified": "2024-09-30T18:31:36Z", + "published": "2024-09-30T18:31:36Z", + "aliases": [ + "CVE-2024-9158" + ], + "details": "A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9158" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2024-17" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-30T17:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json b/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json index f10659b95d8..71beb62f53b 100644 --- a/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json +++ b/advisories/unreviewed/2024/09/GHSA-xgfh-jv6x-46xv/GHSA-xgfh-jv6x-46xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xgfh-jv6x-46xv", - "modified": "2024-09-23T21:30:47Z", + "modified": "2024-09-30T18:31:36Z", "published": "2024-09-23T21:30:47Z", "aliases": [ "CVE-2024-42861" ], "details": "An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-23T21:15:12Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json b/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json index b67148d6ce7..e5c6f57f684 100644 --- a/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json +++ b/advisories/unreviewed/2024/09/GHSA-xpx9-f724-2jfc/GHSA-xpx9-f724-2jfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xpx9-f724-2jfc", - "modified": "2024-09-25T03:30:36Z", + "modified": "2024-09-30T18:31:36Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-8942"