diff --git a/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json b/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json index 0dc65dceaeb..1edd318045d 100644 --- a/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json +++ b/advisories/unreviewed/2022/05/GHSA-gxmr-w5mj-v8hh/GHSA-gxmr-w5mj-v8hh.json @@ -105,34 +105,78 @@ "type": "WEB", "url": "https://kubernetes.io/blog/2019/02/11/runc-and-cve-2019-5736/" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/24e54e3c6b2259e3903b6b8fe26896ac649c481ea99c5739468c92a3%40%3Cdev.dlab.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/24e54e3c6b2259e3903b6b8fe26896ac649c481ea99c5739468c92a3@%3Cdev.dlab.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/a258757af84c5074dc7bf932622020fd4f60cef65a84290380386706%40%3Cuser.mesos.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/a258757af84c5074dc7bf932622020fd4f60cef65a84290380386706@%3Cuser.mesos.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/a585f64d14c31ab393b90c5f17e41d9765a1a17eec63856ce750af46%40%3Cdev.dlab.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/a585f64d14c31ab393b90c5f17e41d9765a1a17eec63856ce750af46@%3Cdev.dlab.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/acacf018c12636e41667e94ac0a1e9244e887eef2debdd474640aa6e%40%3Cdev.dlab.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/acacf018c12636e41667e94ac0a1e9244e887eef2debdd474640aa6e@%3Cdev.dlab.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c%40%3Cdev.mesos.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c@%3Cdev.mesos.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rc494623986d76593873ce5a40dd69cb3629400d10750d5d7e96b8587%40%3Cdev.dlab.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rc494623986d76593873ce5a40dd69cb3629400d10750d5d7e96b8587@%3Cdev.dlab.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLC52IOJN6IQJWJ6CUI6AIUP6GVVG2QP/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EGZKRCKI3Y7FMADO2MENMT4TU24QGHFR/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWFJGIPYAAAMVSWWI3QWYXGA3ZBU2H4W/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6A4OSFM5GGOWW4ECELV5OHX2XRAUSPH/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLC52IOJN6IQJWJ6CUI6AIUP6GVVG2QP/" @@ -269,6 +313,10 @@ "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2019/10/29/3" }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/01/31/6" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/106976" diff --git a/advisories/unreviewed/2022/05/GHSA-vfq3-4hcr-qmqp/GHSA-vfq3-4hcr-qmqp.json b/advisories/unreviewed/2022/05/GHSA-vfq3-4hcr-qmqp/GHSA-vfq3-4hcr-qmqp.json index 06be2f4defc..8d589ec0922 100644 --- a/advisories/unreviewed/2022/05/GHSA-vfq3-4hcr-qmqp/GHSA-vfq3-4hcr-qmqp.json +++ b/advisories/unreviewed/2022/05/GHSA-vfq3-4hcr-qmqp/GHSA-vfq3-4hcr-qmqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfq3-4hcr-qmqp", - "modified": "2022-05-24T19:05:20Z", + "modified": "2024-01-31T21:31:02Z", "published": "2022-05-24T19:05:20Z", "aliases": [ "CVE-2020-29215" ], "details": "A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json b/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json index a230dbe92e4..0214af8cede 100644 --- a/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json +++ b/advisories/unreviewed/2024/01/GHSA-23p4-xxgc-xqvf/GHSA-23p4-xxgc-xqvf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-23p4-xxgc-xqvf", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2021-42143" ], "details": "An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-2798-r58g-fffv/GHSA-2798-r58g-fffv.json b/advisories/unreviewed/2024/01/GHSA-2798-r58g-fffv/GHSA-2798-r58g-fffv.json new file mode 100644 index 00000000000..a00d15a5ff4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2798-r58g-fffv/GHSA-2798-r58g-fffv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2798-r58g-fffv", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-21916" + ], + "details": "\nA denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device will restart itself to recover from the MNRF.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21916" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1661.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-29g4-35pw-347h/GHSA-29g4-35pw-347h.json b/advisories/unreviewed/2024/01/GHSA-29g4-35pw-347h/GHSA-29g4-35pw-347h.json index 8c7bcf9b833..a1ba3a088ae 100644 --- a/advisories/unreviewed/2024/01/GHSA-29g4-35pw-347h/GHSA-29g4-35pw-347h.json +++ b/advisories/unreviewed/2024/01/GHSA-29g4-35pw-347h/GHSA-29g4-35pw-347h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-2g55-8535-gp6f/GHSA-2g55-8535-gp6f.json b/advisories/unreviewed/2024/01/GHSA-2g55-8535-gp6f/GHSA-2g55-8535-gp6f.json index 05611bec2aa..26ae4e4054d 100644 --- a/advisories/unreviewed/2024/01/GHSA-2g55-8535-gp6f/GHSA-2g55-8535-gp6f.json +++ b/advisories/unreviewed/2024/01/GHSA-2g55-8535-gp6f/GHSA-2g55-8535-gp6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g55-8535-gp6f", - "modified": "2024-01-25T09:30:21Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T09:30:21Z", "aliases": [ "CVE-2023-33758" ], "details": "Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T08:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-2hpw-wm7x-857p/GHSA-2hpw-wm7x-857p.json b/advisories/unreviewed/2024/01/GHSA-2hpw-wm7x-857p/GHSA-2hpw-wm7x-857p.json new file mode 100644 index 00000000000..2809a56fee0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2hpw-wm7x-857p/GHSA-2hpw-wm7x-857p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hpw-wm7x-857p", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-1116" + ], + "details": "A vulnerability was found in openBI up to 1.0.8. It has been classified as critical. Affected is the function index of the file /application/plugins/controller/Upload.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252474 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1116" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/uCElTQRGWVyw" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252474" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3gg4-v4m9-rj55/GHSA-3gg4-v4m9-rj55.json b/advisories/unreviewed/2024/01/GHSA-3gg4-v4m9-rj55/GHSA-3gg4-v4m9-rj55.json index 94c301cdac8..168c14304f6 100644 --- a/advisories/unreviewed/2024/01/GHSA-3gg4-v4m9-rj55/GHSA-3gg4-v4m9-rj55.json +++ b/advisories/unreviewed/2024/01/GHSA-3gg4-v4m9-rj55/GHSA-3gg4-v4m9-rj55.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-326" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3rv5-pgj2-5frg/GHSA-3rv5-pgj2-5frg.json b/advisories/unreviewed/2024/01/GHSA-3rv5-pgj2-5frg/GHSA-3rv5-pgj2-5frg.json index 6393340b0ff..43c6c2b926a 100644 --- a/advisories/unreviewed/2024/01/GHSA-3rv5-pgj2-5frg/GHSA-3rv5-pgj2-5frg.json +++ b/advisories/unreviewed/2024/01/GHSA-3rv5-pgj2-5frg/GHSA-3rv5-pgj2-5frg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-3w6g-cv32-6cpq/GHSA-3w6g-cv32-6cpq.json b/advisories/unreviewed/2024/01/GHSA-3w6g-cv32-6cpq/GHSA-3w6g-cv32-6cpq.json index 3f0e1ec337a..dd5d74f6b55 100644 --- a/advisories/unreviewed/2024/01/GHSA-3w6g-cv32-6cpq/GHSA-3w6g-cv32-6cpq.json +++ b/advisories/unreviewed/2024/01/GHSA-3w6g-cv32-6cpq/GHSA-3w6g-cv32-6cpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w6g-cv32-6cpq", - "modified": "2024-01-24T21:30:33Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-24T21:30:33Z", "aliases": [ "CVE-2021-43584" ], "details": "DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0 allows attackers to run arbitrary code via the name element when filtering for a log.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T20:15:53Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4624-w8j8-pr46/GHSA-4624-w8j8-pr46.json b/advisories/unreviewed/2024/01/GHSA-4624-w8j8-pr46/GHSA-4624-w8j8-pr46.json index ac5b0f402a4..edb8ca1d44d 100644 --- a/advisories/unreviewed/2024/01/GHSA-4624-w8j8-pr46/GHSA-4624-w8j8-pr46.json +++ b/advisories/unreviewed/2024/01/GHSA-4624-w8j8-pr46/GHSA-4624-w8j8-pr46.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-131" + "CWE-131", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-4723-qmx5-q5h4/GHSA-4723-qmx5-q5h4.json b/advisories/unreviewed/2024/01/GHSA-4723-qmx5-q5h4/GHSA-4723-qmx5-q5h4.json index 1635fc98437..bb97d7e9256 100644 --- a/advisories/unreviewed/2024/01/GHSA-4723-qmx5-q5h4/GHSA-4723-qmx5-q5h4.json +++ b/advisories/unreviewed/2024/01/GHSA-4723-qmx5-q5h4/GHSA-4723-qmx5-q5h4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-131" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/01/GHSA-47g8-q2w5-x9jm/GHSA-47g8-q2w5-x9jm.json b/advisories/unreviewed/2024/01/GHSA-47g8-q2w5-x9jm/GHSA-47g8-q2w5-x9jm.json index 5f8df2b5c91..1757d7d138a 100644 --- a/advisories/unreviewed/2024/01/GHSA-47g8-q2w5-x9jm/GHSA-47g8-q2w5-x9jm.json +++ b/advisories/unreviewed/2024/01/GHSA-47g8-q2w5-x9jm/GHSA-47g8-q2w5-x9jm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47g8-q2w5-x9jm", - "modified": "2024-01-25T03:30:59Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T03:30:59Z", "aliases": [ "CVE-2024-0624" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-4vwj-x32h-m4vj/GHSA-4vwj-x32h-m4vj.json b/advisories/unreviewed/2024/01/GHSA-4vwj-x32h-m4vj/GHSA-4vwj-x32h-m4vj.json index adc9e44463e..ffb48b4994b 100644 --- a/advisories/unreviewed/2024/01/GHSA-4vwj-x32h-m4vj/GHSA-4vwj-x32h-m4vj.json +++ b/advisories/unreviewed/2024/01/GHSA-4vwj-x32h-m4vj/GHSA-4vwj-x32h-m4vj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1390" + "CWE-1390", + "CWE-287" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json b/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json new file mode 100644 index 00000000000..3c64b734986 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55jq-jhw2-2vmp", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-22159" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional allows Reflected XSS.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22159" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bulk-editor/wordpress-wolf-wordpress-posts-bulk-editor-and-manager-professional-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5h2x-6j9f-vr5g/GHSA-5h2x-6j9f-vr5g.json b/advisories/unreviewed/2024/01/GHSA-5h2x-6j9f-vr5g/GHSA-5h2x-6j9f-vr5g.json new file mode 100644 index 00000000000..aa101c09dd2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5h2x-6j9f-vr5g/GHSA-5h2x-6j9f-vr5g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h2x-6j9f-vr5g", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-1113" + ], + "details": "A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/index/controller/Unity.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252471.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1113" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/hPSx8li8LFfJ" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252471" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252471" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5rh9-jc57-95mr/GHSA-5rh9-jc57-95mr.json b/advisories/unreviewed/2024/01/GHSA-5rh9-jc57-95mr/GHSA-5rh9-jc57-95mr.json new file mode 100644 index 00000000000..5e27b298d01 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5rh9-jc57-95mr/GHSA-5rh9-jc57-95mr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rh9-jc57-95mr", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-21917" + ], + "details": "\nA vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.  If exploited, a malicious user could potentially retrieve user information and modify settings without any authentication.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21917" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1660.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5rr9-mqhj-7cr2/GHSA-5rr9-mqhj-7cr2.json b/advisories/unreviewed/2024/01/GHSA-5rr9-mqhj-7cr2/GHSA-5rr9-mqhj-7cr2.json index da0c2b52756..858006343af 100644 --- a/advisories/unreviewed/2024/01/GHSA-5rr9-mqhj-7cr2/GHSA-5rr9-mqhj-7cr2.json +++ b/advisories/unreviewed/2024/01/GHSA-5rr9-mqhj-7cr2/GHSA-5rr9-mqhj-7cr2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-6wrq-j9qq-5v7v/GHSA-6wrq-j9qq-5v7v.json b/advisories/unreviewed/2024/01/GHSA-6wrq-j9qq-5v7v/GHSA-6wrq-j9qq-5v7v.json index a99a1cbe9fa..6707d3fde14 100644 --- a/advisories/unreviewed/2024/01/GHSA-6wrq-j9qq-5v7v/GHSA-6wrq-j9qq-5v7v.json +++ b/advisories/unreviewed/2024/01/GHSA-6wrq-j9qq-5v7v/GHSA-6wrq-j9qq-5v7v.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json b/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json index 628d8230711..bc971a0d556 100644 --- a/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json +++ b/advisories/unreviewed/2024/01/GHSA-7r27-33fg-9cpx/GHSA-7r27-33fg-9cpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7r27-33fg-9cpx", - "modified": "2024-01-24T18:31:01Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-24T18:31:01Z", "aliases": [ "CVE-2021-42144" ], "details": "Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T18:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7vrx-mj2w-52mf/GHSA-7vrx-mj2w-52mf.json b/advisories/unreviewed/2024/01/GHSA-7vrx-mj2w-52mf/GHSA-7vrx-mj2w-52mf.json index c3cbd49df44..39b4163c8f6 100644 --- a/advisories/unreviewed/2024/01/GHSA-7vrx-mj2w-52mf/GHSA-7vrx-mj2w-52mf.json +++ b/advisories/unreviewed/2024/01/GHSA-7vrx-mj2w-52mf/GHSA-7vrx-mj2w-52mf.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-84m5-rqxq-483p/GHSA-84m5-rqxq-483p.json b/advisories/unreviewed/2024/01/GHSA-84m5-rqxq-483p/GHSA-84m5-rqxq-483p.json index a858bfc0670..70bcb3bc8bc 100644 --- a/advisories/unreviewed/2024/01/GHSA-84m5-rqxq-483p/GHSA-84m5-rqxq-483p.json +++ b/advisories/unreviewed/2024/01/GHSA-84m5-rqxq-483p/GHSA-84m5-rqxq-483p.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-87hh-r9jv-r2jq/GHSA-87hh-r9jv-r2jq.json b/advisories/unreviewed/2024/01/GHSA-87hh-r9jv-r2jq/GHSA-87hh-r9jv-r2jq.json new file mode 100644 index 00000000000..a82ce0b9265 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-87hh-r9jv-r2jq/GHSA-87hh-r9jv-r2jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87hh-r9jv-r2jq", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-22146" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.25.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22146" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/schema-and-structured-data-for-wp/wordpress-schema-structured-data-for-wp-amp-plugin-1-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-93v2-7c6x-23m2/GHSA-93v2-7c6x-23m2.json b/advisories/unreviewed/2024/01/GHSA-93v2-7c6x-23m2/GHSA-93v2-7c6x-23m2.json index 4fcd00a5268..008136de4d2 100644 --- a/advisories/unreviewed/2024/01/GHSA-93v2-7c6x-23m2/GHSA-93v2-7c6x-23m2.json +++ b/advisories/unreviewed/2024/01/GHSA-93v2-7c6x-23m2/GHSA-93v2-7c6x-23m2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-9gf5-vf62-9578/GHSA-9gf5-vf62-9578.json b/advisories/unreviewed/2024/01/GHSA-9gf5-vf62-9578/GHSA-9gf5-vf62-9578.json new file mode 100644 index 00000000000..49720a41a6b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9gf5-vf62-9578/GHSA-9gf5-vf62-9578.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gf5-vf62-9578", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-22153" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood & Alexandre Faustino Stock Locations for WooCommerce allows Stored XSS.This issue affects Stock Locations for WooCommerce: from n/a through 2.5.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22153" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stock-locations-for-woocommerce/wordpress-stock-locations-for-woocommerce-plugin-2-5-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9m6f-83hx-8wwr/GHSA-9m6f-83hx-8wwr.json b/advisories/unreviewed/2024/01/GHSA-9m6f-83hx-8wwr/GHSA-9m6f-83hx-8wwr.json new file mode 100644 index 00000000000..27264e7155d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9m6f-83hx-8wwr/GHSA-9m6f-83hx-8wwr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m6f-83hx-8wwr", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-1111" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Login System 1.0. Affected by this issue is some unknown functionality of the file add-user.php. The manipulation of the argument qr-code leads to cross site scripting. The attack may be launched remotely. VDB-252470 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252470" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252470" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c2h4-p5j3-jcgh/GHSA-c2h4-p5j3-jcgh.json b/advisories/unreviewed/2024/01/GHSA-c2h4-p5j3-jcgh/GHSA-c2h4-p5j3-jcgh.json index a285613ef77..fbc0be3dfd9 100644 --- a/advisories/unreviewed/2024/01/GHSA-c2h4-p5j3-jcgh/GHSA-c2h4-p5j3-jcgh.json +++ b/advisories/unreviewed/2024/01/GHSA-c2h4-p5j3-jcgh/GHSA-c2h4-p5j3-jcgh.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-c39j-wph3-8c3c/GHSA-c39j-wph3-8c3c.json b/advisories/unreviewed/2024/01/GHSA-c39j-wph3-8c3c/GHSA-c39j-wph3-8c3c.json new file mode 100644 index 00000000000..06580f35258 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c39j-wph3-8c3c/GHSA-c39j-wph3-8c3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c39j-wph3-8c3c", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2022-47072" + ], + "details": "SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47072" + }, + { + "type": "WEB", + "url": "https://github.com/DojoSecurity/Enterprise-Architect-SQL-Injection" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-ccxg-74mw-mcc5/GHSA-ccxg-74mw-mcc5.json b/advisories/unreviewed/2024/01/GHSA-ccxg-74mw-mcc5/GHSA-ccxg-74mw-mcc5.json index 0a29e9e6ef7..4f4f8a5fad1 100644 --- a/advisories/unreviewed/2024/01/GHSA-ccxg-74mw-mcc5/GHSA-ccxg-74mw-mcc5.json +++ b/advisories/unreviewed/2024/01/GHSA-ccxg-74mw-mcc5/GHSA-ccxg-74mw-mcc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccxg-74mw-mcc5", - "modified": "2024-01-25T09:30:21Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T09:30:21Z", "aliases": [ "CVE-2023-33757" ], "details": "A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T08:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-fw69-fp6v-v235/GHSA-fw69-fp6v-v235.json b/advisories/unreviewed/2024/01/GHSA-fw69-fp6v-v235/GHSA-fw69-fp6v-v235.json index f1062c27ff5..0d1e72a8c52 100644 --- a/advisories/unreviewed/2024/01/GHSA-fw69-fp6v-v235/GHSA-fw69-fp6v-v235.json +++ b/advisories/unreviewed/2024/01/GHSA-fw69-fp6v-v235/GHSA-fw69-fp6v-v235.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw69-fp6v-v235", - "modified": "2024-01-25T15:31:53Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T15:31:53Z", "aliases": [ "CVE-2024-0879" diff --git a/advisories/unreviewed/2024/01/GHSA-hc6c-m8v3-634f/GHSA-hc6c-m8v3-634f.json b/advisories/unreviewed/2024/01/GHSA-hc6c-m8v3-634f/GHSA-hc6c-m8v3-634f.json new file mode 100644 index 00000000000..28817980de3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hc6c-m8v3-634f/GHSA-hc6c-m8v3-634f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc6c-m8v3-634f", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-22158" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles allows Stored XSS.This issue affects Community by PeepSo – Social Network, Membership, Registration, User Profiles: from n/a before 6.3.1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22158" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/peepso-photos/wordpress-peepso-photos-add-on-plugin-6-3-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hx7j-w75q-79h5/GHSA-hx7j-w75q-79h5.json b/advisories/unreviewed/2024/01/GHSA-hx7j-w75q-79h5/GHSA-hx7j-w75q-79h5.json index bb9914e7755..e3d497fde4b 100644 --- a/advisories/unreviewed/2024/01/GHSA-hx7j-w75q-79h5/GHSA-hx7j-w75q-79h5.json +++ b/advisories/unreviewed/2024/01/GHSA-hx7j-w75q-79h5/GHSA-hx7j-w75q-79h5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx7j-w75q-79h5", - "modified": "2024-01-25T06:30:31Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T06:30:31Z", "aliases": [ "CVE-2023-50785" ], "details": "Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T06:15:50Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jhv9-m6q4-wc38/GHSA-jhv9-m6q4-wc38.json b/advisories/unreviewed/2024/01/GHSA-jhv9-m6q4-wc38/GHSA-jhv9-m6q4-wc38.json new file mode 100644 index 00000000000..52197f5898e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jhv9-m6q4-wc38/GHSA-jhv9-m6q4-wc38.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhv9-m6q4-wc38", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-1114" + ], + "details": "A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /application/index/controller/Screen.php. The manipulation of the argument fileUrl leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252472.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1114" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/9wv48TygKRxo" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252472" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m866-467g-64fm/GHSA-m866-467g-64fm.json b/advisories/unreviewed/2024/01/GHSA-m866-467g-64fm/GHSA-m866-467g-64fm.json new file mode 100644 index 00000000000..e9b1d74ecb7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m866-467g-64fm/GHSA-m866-467g-64fm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m866-467g-64fm", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-1117" + ], + "details": "A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /application/index/controller/Screen.php. The manipulation of the argument fileurl leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252475.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1117" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/Liu1nbjddxu4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252475" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p774-6cp5-x7cj/GHSA-p774-6cp5-x7cj.json b/advisories/unreviewed/2024/01/GHSA-p774-6cp5-x7cj/GHSA-p774-6cp5-x7cj.json new file mode 100644 index 00000000000..dad7e866cb9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p774-6cp5-x7cj/GHSA-p774-6cp5-x7cj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p774-6cp5-x7cj", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2023-28807" + ], + "details": "In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28807" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/zia/configuring-advanced-settings#dns-optimization" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/zia/configuring-advanced-settings#domain-fronting" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T20:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p969-49ff-hx55/GHSA-p969-49ff-hx55.json b/advisories/unreviewed/2024/01/GHSA-p969-49ff-hx55/GHSA-p969-49ff-hx55.json new file mode 100644 index 00000000000..11379996017 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p969-49ff-hx55/GHSA-p969-49ff-hx55.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p969-49ff-hx55", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-1115" + ], + "details": "A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function dlfile of the file /application/websocket/controller/Setting.php. The manipulation of the argument phpPath leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252473 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1115" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/81JmiyogcYL7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252473" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252473" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pqh2-qcg3-9x62/GHSA-pqh2-qcg3-9x62.json b/advisories/unreviewed/2024/01/GHSA-pqh2-qcg3-9x62/GHSA-pqh2-qcg3-9x62.json index 5536f42eb95..729f9db8db5 100644 --- a/advisories/unreviewed/2024/01/GHSA-pqh2-qcg3-9x62/GHSA-pqh2-qcg3-9x62.json +++ b/advisories/unreviewed/2024/01/GHSA-pqh2-qcg3-9x62/GHSA-pqh2-qcg3-9x62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqh2-qcg3-9x62", - "modified": "2024-01-25T21:32:14Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T21:32:14Z", "aliases": [ "CVE-2023-41474" ], "details": "Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T20:15:36Z" diff --git a/advisories/unreviewed/2024/01/GHSA-q9p8-42p3-gq3h/GHSA-q9p8-42p3-gq3h.json b/advisories/unreviewed/2024/01/GHSA-q9p8-42p3-gq3h/GHSA-q9p8-42p3-gq3h.json index ef73c7d73c9..2887b593a27 100644 --- a/advisories/unreviewed/2024/01/GHSA-q9p8-42p3-gq3h/GHSA-q9p8-42p3-gq3h.json +++ b/advisories/unreviewed/2024/01/GHSA-q9p8-42p3-gq3h/GHSA-q9p8-42p3-gq3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9p8-42p3-gq3h", - "modified": "2024-01-25T09:30:21Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T09:30:21Z", "aliases": [ "CVE-2023-33759" ], "details": "SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T08:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rx6w-gc3r-2fh2/GHSA-rx6w-gc3r-2fh2.json b/advisories/unreviewed/2024/01/GHSA-rx6w-gc3r-2fh2/GHSA-rx6w-gc3r-2fh2.json index b45f5cecf6c..8c48fadd744 100644 --- a/advisories/unreviewed/2024/01/GHSA-rx6w-gc3r-2fh2/GHSA-rx6w-gc3r-2fh2.json +++ b/advisories/unreviewed/2024/01/GHSA-rx6w-gc3r-2fh2/GHSA-rx6w-gc3r-2fh2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rx6w-gc3r-2fh2", - "modified": "2024-01-25T18:30:51Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T18:30:51Z", "aliases": [ "CVE-2024-22529" ], "details": "TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T16:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-v3pc-xh3w-h68j/GHSA-v3pc-xh3w-h68j.json b/advisories/unreviewed/2024/01/GHSA-v3pc-xh3w-h68j/GHSA-v3pc-xh3w-h68j.json new file mode 100644 index 00000000000..2555d822651 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v3pc-xh3w-h68j/GHSA-v3pc-xh3w-h68j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3pc-xh3w-h68j", + "modified": "2024-01-31T21:31:03Z", + "published": "2024-01-31T21:31:03Z", + "aliases": [ + "CVE-2024-22150" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PWR Plugins Portfolio & Image Gallery for WordPress | PowerFolio allows Stored XSS.This issue affects Portfolio & Image Gallery for WordPress | PowerFolio: from n/a through 3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22150" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/portfolio-elementor/wordpress-powerfolio-plugin-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vwwf-cxx3-3hpv/GHSA-vwwf-cxx3-3hpv.json b/advisories/unreviewed/2024/01/GHSA-vwwf-cxx3-3hpv/GHSA-vwwf-cxx3-3hpv.json index 06dc568e508..f59b34b8975 100644 --- a/advisories/unreviewed/2024/01/GHSA-vwwf-cxx3-3hpv/GHSA-vwwf-cxx3-3hpv.json +++ b/advisories/unreviewed/2024/01/GHSA-vwwf-cxx3-3hpv/GHSA-vwwf-cxx3-3hpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwwf-cxx3-3hpv", - "modified": "2024-01-24T21:30:33Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-24T21:30:33Z", "aliases": [ "CVE-2021-42145" ], "details": "An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-24T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-x4g7-cr9m-3wfr/GHSA-x4g7-cr9m-3wfr.json b/advisories/unreviewed/2024/01/GHSA-x4g7-cr9m-3wfr/GHSA-x4g7-cr9m-3wfr.json index e8264d8e1d7..4c8e1c63f57 100644 --- a/advisories/unreviewed/2024/01/GHSA-x4g7-cr9m-3wfr/GHSA-x4g7-cr9m-3wfr.json +++ b/advisories/unreviewed/2024/01/GHSA-x4g7-cr9m-3wfr/GHSA-x4g7-cr9m-3wfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x4g7-cr9m-3wfr", - "modified": "2024-01-24T00:30:32Z", + "modified": "2024-01-31T21:31:02Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2023-35836" ], "details": "An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PSK, during device setup and reconfiguration. Upon success, the attacker is able to further infiltrate the target's Wi-Fi networks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-23T23:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xr44-2pv4-gw8r/GHSA-xr44-2pv4-gw8r.json b/advisories/unreviewed/2024/01/GHSA-xr44-2pv4-gw8r/GHSA-xr44-2pv4-gw8r.json index 57da513e302..142698165e6 100644 --- a/advisories/unreviewed/2024/01/GHSA-xr44-2pv4-gw8r/GHSA-xr44-2pv4-gw8r.json +++ b/advisories/unreviewed/2024/01/GHSA-xr44-2pv4-gw8r/GHSA-xr44-2pv4-gw8r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr44-2pv4-gw8r", - "modified": "2024-01-25T09:30:21Z", + "modified": "2024-01-31T21:31:03Z", "published": "2024-01-25T09:30:21Z", "aliases": [ "CVE-2023-33760" ], "details": "SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-25T08:15:08Z"