Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-10-16 21:32:13 +00:00
parent cc0a27e482
commit ac66c5fa85
43 changed files with 364 additions and 99 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8x46-qpq3-2pgp",
"modified": "2023-11-15T06:30:28Z",
"modified": "2024-10-16T21:31:05Z",
"published": "2023-08-29T06:30:14Z",
"aliases": [
"CVE-2023-41360"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32mc-xh24-9378",
"modified": "2024-02-13T03:30:21Z",
"modified": "2024-10-16T21:31:05Z",
"published": "2024-02-13T03:30:21Z",
"aliases": [
"CVE-2024-22130"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crh3-fj9c-p494",
"modified": "2024-02-13T03:30:21Z",
"modified": "2024-10-16T21:31:05Z",
"published": "2024-02-13T03:30:21Z",
"aliases": [
"CVE-2024-22131"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1021"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg7g-ghrw-94pc",
"modified": "2024-02-13T03:30:20Z",
"modified": "2024-10-16T21:31:05Z",
"published": "2024-02-13T03:30:20Z",
"aliases": [
"CVE-2024-25407"
],
"details": "SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-331"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-13T01:15:08Z"
@@ -48,7 +48,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37gm-h5wr-pf25",
"modified": "2024-10-16T21:31:09Z",
"published": "2024-10-16T21:31:09Z",
"aliases": [
"CVE-2024-46212"
],
"details": "An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46212"
},
{
"type": "WEB",
"url": "https://github.com/Purposex7/Vulns4Study/blob/main/REDAXO%20File%20Download%20Exploit.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T21:15:12Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j36-mj45-fgp4",
"modified": "2024-10-15T21:30:39Z",
"modified": "2024-10-16T21:31:09Z",
"published": "2024-10-15T21:30:39Z",
"aliases": [
"CVE-2024-9960"
],
"details": "Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T21:15:12Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p3h-5g54-qmc8",
"modified": "2024-10-16T21:31:09Z",
"published": "2024-10-16T21:31:09Z",
"aliases": [
"CVE-2024-48180"
],
"details": "ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48180"
},
{
"type": "WEB",
"url": "https://github.com/J-0k3r/CVE-2024-48180"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T21:15:13Z"
}
}
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-126"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4grf-rmf5-ch9r",
"modified": "2024-10-11T18:32:50Z",
"modified": "2024-10-16T21:31:07Z",
"published": "2024-10-11T18:32:50Z",
"aliases": [
"CVE-2024-44734"
],
"details": "Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-346"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-11T17:15:04Z"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-126"
],
"severity": "HIGH",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-822"
],
"severity": "HIGH",
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-126"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88j8-mfjr-vw9q",
"modified": "2024-10-16T15:32:08Z",
"modified": "2024-10-16T21:31:09Z",
"published": "2024-10-16T15:32:08Z",
"aliases": [
"CVE-2024-48744"
],
"details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via \"searchinput\" POST request parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T15:15:16Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-89v2-8rj2-3464",
"modified": "2024-10-15T21:30:39Z",
"modified": "2024-10-16T21:31:09Z",
"published": "2024-10-15T21:30:39Z",
"aliases": [
"CVE-2024-9961"
],
"details": "Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T21:15:12Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
"CWE-121",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jg2-v5f3-rqf2",
"modified": "2024-10-16T21:31:09Z",
"published": "2024-10-16T21:31:09Z",
"aliases": [
"CVE-2024-44762"
],
"details": "A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44762"
},
{
"type": "WEB",
"url": "https://senscybersecurity.nl/cve-2024-44762-explained"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T21:15:12Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jwm-2cwm-2g9m",
"modified": "2024-10-11T18:32:49Z",
"modified": "2024-10-16T21:31:07Z",
"published": "2024-10-11T18:32:49Z",
"aliases": [
"CVE-2024-44729"
],
"details": "Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -37,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-11T16:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9w49-jqr4-2979",
"modified": "2024-10-15T21:30:39Z",
"modified": "2024-10-16T21:31:08Z",
"published": "2024-10-15T21:30:39Z",
"aliases": [
"CVE-2024-48782"
],
"details": "File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T21:15:11Z"

Some files were not shown because too many files have changed in this diff Show More