From ac66c5fa85e930673f0c1edbf3a8f9c1093bb707 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 16 Oct 2024 21:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8x46-qpq3-2pgp.json | 2 +- .../GHSA-32mc-xh24-9378.json | 2 +- .../GHSA-crh3-fj9c-p494.json | 2 +- .../GHSA-cv4w-8c77-w5jw.json | 2 +- .../GHSA-hg7g-ghrw-94pc.json | 11 +++--- .../GHSA-mj66-pjg9-59mj.json | 3 +- .../GHSA-37gm-h5wr-pf25.json | 35 +++++++++++++++++++ .../GHSA-3j36-mj45-fgp4.json | 9 +++-- .../GHSA-3p3h-5g54-qmc8.json | 35 +++++++++++++++++++ .../GHSA-46p9-g8f2-qj87.json | 1 + .../GHSA-4grf-rmf5-ch9r.json | 11 +++--- .../GHSA-5gm8-rjrv-q6hj.json | 1 + .../GHSA-5vgv-f6wh-xq94.json | 1 + .../GHSA-72r8-34hv-3qjh.json | 1 + .../GHSA-88j8-mfjr-vw9q.json | 11 +++--- .../GHSA-89v2-8rj2-3464.json | 9 +++-- .../GHSA-923r-gp72-rmm4.json | 3 +- .../GHSA-9jg2-v5f3-rqf2.json | 35 +++++++++++++++++++ .../GHSA-9jwm-2cwm-2g9m.json | 11 +++--- .../GHSA-9w49-jqr4-2979.json | 11 +++--- .../GHSA-c2h4-jx6m-jp2q.json | 9 +++-- .../GHSA-gj3r-7jjv-636h.json | 9 +++-- .../GHSA-h5h2-jj79-rjrp.json | 9 +++-- .../GHSA-h6vc-pxj4-pcch.json | 35 +++++++++++++++++++ .../GHSA-mf33-2wpg-fv43.json | 6 +++- .../GHSA-mrwv-hx59-25f7.json | 11 +++--- .../GHSA-mwf7-wfvq-vc32.json | 11 +++--- .../GHSA-ppxj-8w78-35rf.json | 9 +++-- .../GHSA-pq4q-5xx3-76hf.json | 11 +++--- .../GHSA-px5g-45ff-hqqc.json | 11 +++--- .../GHSA-q77p-j5gj-rmw2.json | 11 +++--- .../GHSA-qfc4-qvg8-vmjr.json | 11 +++--- .../GHSA-qg3h-rf5x-68cv.json | 11 +++--- .../GHSA-qgvh-3gr3-j9ph.json | 1 + .../GHSA-r25f-mfgv-vq97.json | 6 +++- .../GHSA-r63v-hfc4-mg32.json | 9 +++-- .../GHSA-r7cm-7xjc-5g35.json | 9 +++-- .../GHSA-rwhp-3v8j-67m2.json | 35 +++++++++++++++++++ .../GHSA-vv5g-xq9c-77w7.json | 11 +++--- .../GHSA-w2p9-j475-2wp5.json | 9 +++-- .../GHSA-wh67-cc45-g7cf.json | 11 +++--- .../GHSA-x25g-7892-q6v6.json | 11 +++--- .../GHSA-xcmw-x3c5-ppmh.json | 11 +++--- 43 files changed, 364 insertions(+), 99 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json diff --git a/advisories/unreviewed/2023/08/GHSA-8x46-qpq3-2pgp/GHSA-8x46-qpq3-2pgp.json b/advisories/unreviewed/2023/08/GHSA-8x46-qpq3-2pgp/GHSA-8x46-qpq3-2pgp.json index 19a963733ef..e3090be3e0a 100644 --- a/advisories/unreviewed/2023/08/GHSA-8x46-qpq3-2pgp/GHSA-8x46-qpq3-2pgp.json +++ b/advisories/unreviewed/2023/08/GHSA-8x46-qpq3-2pgp/GHSA-8x46-qpq3-2pgp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x46-qpq3-2pgp", - "modified": "2023-11-15T06:30:28Z", + "modified": "2024-10-16T21:31:05Z", "published": "2023-08-29T06:30:14Z", "aliases": [ "CVE-2023-41360" diff --git a/advisories/unreviewed/2024/02/GHSA-32mc-xh24-9378/GHSA-32mc-xh24-9378.json b/advisories/unreviewed/2024/02/GHSA-32mc-xh24-9378/GHSA-32mc-xh24-9378.json index 5b2c8aa5b0d..ddbc9faaf95 100644 --- a/advisories/unreviewed/2024/02/GHSA-32mc-xh24-9378/GHSA-32mc-xh24-9378.json +++ b/advisories/unreviewed/2024/02/GHSA-32mc-xh24-9378/GHSA-32mc-xh24-9378.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32mc-xh24-9378", - "modified": "2024-02-13T03:30:21Z", + "modified": "2024-10-16T21:31:05Z", "published": "2024-02-13T03:30:21Z", "aliases": [ "CVE-2024-22130" diff --git a/advisories/unreviewed/2024/02/GHSA-crh3-fj9c-p494/GHSA-crh3-fj9c-p494.json b/advisories/unreviewed/2024/02/GHSA-crh3-fj9c-p494/GHSA-crh3-fj9c-p494.json index 526e0ba7c8a..03c3c116e93 100644 --- a/advisories/unreviewed/2024/02/GHSA-crh3-fj9c-p494/GHSA-crh3-fj9c-p494.json +++ b/advisories/unreviewed/2024/02/GHSA-crh3-fj9c-p494/GHSA-crh3-fj9c-p494.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-crh3-fj9c-p494", - "modified": "2024-02-13T03:30:21Z", + "modified": "2024-10-16T21:31:05Z", "published": "2024-02-13T03:30:21Z", "aliases": [ "CVE-2024-22131" diff --git a/advisories/unreviewed/2024/02/GHSA-cv4w-8c77-w5jw/GHSA-cv4w-8c77-w5jw.json b/advisories/unreviewed/2024/02/GHSA-cv4w-8c77-w5jw/GHSA-cv4w-8c77-w5jw.json index d2e5e46ccd4..77508a353c4 100644 --- a/advisories/unreviewed/2024/02/GHSA-cv4w-8c77-w5jw/GHSA-cv4w-8c77-w5jw.json +++ b/advisories/unreviewed/2024/02/GHSA-cv4w-8c77-w5jw/GHSA-cv4w-8c77-w5jw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-hg7g-ghrw-94pc/GHSA-hg7g-ghrw-94pc.json b/advisories/unreviewed/2024/02/GHSA-hg7g-ghrw-94pc/GHSA-hg7g-ghrw-94pc.json index c0ca8fa1731..c2974330ef7 100644 --- a/advisories/unreviewed/2024/02/GHSA-hg7g-ghrw-94pc/GHSA-hg7g-ghrw-94pc.json +++ b/advisories/unreviewed/2024/02/GHSA-hg7g-ghrw-94pc/GHSA-hg7g-ghrw-94pc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg7g-ghrw-94pc", - "modified": "2024-02-13T03:30:20Z", + "modified": "2024-10-16T21:31:05Z", "published": "2024-02-13T03:30:20Z", "aliases": [ "CVE-2024-25407" ], "details": "SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-331" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T01:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mj66-pjg9-59mj/GHSA-mj66-pjg9-59mj.json b/advisories/unreviewed/2024/08/GHSA-mj66-pjg9-59mj/GHSA-mj66-pjg9-59mj.json index 945e544bb47..a1c4fdebf20 100644 --- a/advisories/unreviewed/2024/08/GHSA-mj66-pjg9-59mj/GHSA-mj66-pjg9-59mj.json +++ b/advisories/unreviewed/2024/08/GHSA-mj66-pjg9-59mj/GHSA-mj66-pjg9-59mj.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json b/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json new file mode 100644 index 00000000000..ba7640a2a5b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-37gm-h5wr-pf25/GHSA-37gm-h5wr-pf25.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37gm-h5wr-pf25", + "modified": "2024-10-16T21:31:09Z", + "published": "2024-10-16T21:31:09Z", + "aliases": [ + "CVE-2024-46212" + ], + "details": "An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46212" + }, + { + "type": "WEB", + "url": "https://github.com/Purposex7/Vulns4Study/blob/main/REDAXO%20File%20Download%20Exploit.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json b/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json index 5fe5bd4bbcb..548af8d573a 100644 --- a/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json +++ b/advisories/unreviewed/2024/10/GHSA-3j36-mj45-fgp4/GHSA-3j36-mj45-fgp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j36-mj45-fgp4", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9960" ], "details": "Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json b/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json new file mode 100644 index 00000000000..e8297458dbc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3p3h-5g54-qmc8/GHSA-3p3h-5g54-qmc8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p3h-5g54-qmc8", + "modified": "2024-10-16T21:31:09Z", + "published": "2024-10-16T21:31:09Z", + "aliases": [ + "CVE-2024-48180" + ], + "details": "ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48180" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/CVE-2024-48180" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json b/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json index 89af8ea317d..3d0b8d02927 100644 --- a/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json +++ b/advisories/unreviewed/2024/10/GHSA-46p9-g8f2-qj87/GHSA-46p9-g8f2-qj87.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-4grf-rmf5-ch9r/GHSA-4grf-rmf5-ch9r.json b/advisories/unreviewed/2024/10/GHSA-4grf-rmf5-ch9r/GHSA-4grf-rmf5-ch9r.json index cf15d1b1bf0..4f5b73a2f77 100644 --- a/advisories/unreviewed/2024/10/GHSA-4grf-rmf5-ch9r/GHSA-4grf-rmf5-ch9r.json +++ b/advisories/unreviewed/2024/10/GHSA-4grf-rmf5-ch9r/GHSA-4grf-rmf5-ch9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4grf-rmf5-ch9r", - "modified": "2024-10-11T18:32:50Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-44734" ], "details": "Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T17:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json b/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json index abbc13193b7..c39e6afacbe 100644 --- a/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json +++ b/advisories/unreviewed/2024/10/GHSA-5gm8-rjrv-q6hj/GHSA-5gm8-rjrv-q6hj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json b/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json index 082a6cb5676..a55bc279c9e 100644 --- a/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json +++ b/advisories/unreviewed/2024/10/GHSA-5vgv-f6wh-xq94/GHSA-5vgv-f6wh-xq94.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-822" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json b/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json index da7321fb89b..c0ed4a570bb 100644 --- a/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json +++ b/advisories/unreviewed/2024/10/GHSA-72r8-34hv-3qjh/GHSA-72r8-34hv-3qjh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json b/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json index 399d73312b2..b42fa518a2d 100644 --- a/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json +++ b/advisories/unreviewed/2024/10/GHSA-88j8-mfjr-vw9q/GHSA-88j8-mfjr-vw9q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-88j8-mfjr-vw9q", - "modified": "2024-10-16T15:32:08Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-16T15:32:08Z", "aliases": [ "CVE-2024-48744" ], "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via \"searchinput\" POST request parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T15:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json b/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json index b1a601be9a8..25a75a09785 100644 --- a/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json +++ b/advisories/unreviewed/2024/10/GHSA-89v2-8rj2-3464/GHSA-89v2-8rj2-3464.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89v2-8rj2-3464", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9961" ], "details": "Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json b/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json index eecd846f2ee..3f8c924077f 100644 --- a/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json +++ b/advisories/unreviewed/2024/10/GHSA-923r-gp72-rmm4/GHSA-923r-gp72-rmm4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json b/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json new file mode 100644 index 00000000000..e09dbd021b2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9jg2-v5f3-rqf2/GHSA-9jg2-v5f3-rqf2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jg2-v5f3-rqf2", + "modified": "2024-10-16T21:31:09Z", + "published": "2024-10-16T21:31:09Z", + "aliases": [ + "CVE-2024-44762" + ], + "details": "A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44762" + }, + { + "type": "WEB", + "url": "https://senscybersecurity.nl/cve-2024-44762-explained" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9jwm-2cwm-2g9m/GHSA-9jwm-2cwm-2g9m.json b/advisories/unreviewed/2024/10/GHSA-9jwm-2cwm-2g9m/GHSA-9jwm-2cwm-2g9m.json index defb70d3bd6..ae048d8923d 100644 --- a/advisories/unreviewed/2024/10/GHSA-9jwm-2cwm-2g9m/GHSA-9jwm-2cwm-2g9m.json +++ b/advisories/unreviewed/2024/10/GHSA-9jwm-2cwm-2g9m/GHSA-9jwm-2cwm-2g9m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jwm-2cwm-2g9m", - "modified": "2024-10-11T18:32:49Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-11T18:32:49Z", "aliases": [ "CVE-2024-44729" ], "details": "Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T16:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json b/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json index e161e6e5efb..ab1e6f307b4 100644 --- a/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json +++ b/advisories/unreviewed/2024/10/GHSA-9w49-jqr4-2979/GHSA-9w49-jqr4-2979.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w49-jqr4-2979", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-48782" ], "details": "File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json b/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json index 87523c3d6a2..6706d2224f2 100644 --- a/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json +++ b/advisories/unreviewed/2024/10/GHSA-c2h4-jx6m-jp2q/GHSA-c2h4-jx6m-jp2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2h4-jx6m-jp2q", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9957" ], "details": "Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json b/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json index 1346d275039..87989864887 100644 --- a/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json +++ b/advisories/unreviewed/2024/10/GHSA-gj3r-7jjv-636h/GHSA-gj3r-7jjv-636h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gj3r-7jjv-636h", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9955" ], "details": "Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json b/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json index cfb00ba0ead..3b693373dc5 100644 --- a/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json +++ b/advisories/unreviewed/2024/10/GHSA-h5h2-jj79-rjrp/GHSA-h5h2-jj79-rjrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5h2-jj79-rjrp", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9959" ], "details": "Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json b/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json new file mode 100644 index 00000000000..2475171b52f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h6vc-pxj4-pcch/GHSA-h6vc-pxj4-pcch.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6vc-pxj4-pcch", + "modified": "2024-10-16T21:31:09Z", + "published": "2024-10-16T21:31:09Z", + "aliases": [ + "CVE-2024-46213" + ], + "details": "REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46213" + }, + { + "type": "WEB", + "url": "https://github.com/Purposex7/Vulns4Study/blob/main/REDAXO%20Cronjobs%20%20AddOns%20RCE.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json b/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json index 6de19b72963..3d519675ab1 100644 --- a/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json +++ b/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf33-2wpg-fv43", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-16T21:31:06Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-43686" ], "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green" diff --git a/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json b/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json index 44bf278ce7f..5c094a35588 100644 --- a/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json +++ b/advisories/unreviewed/2024/10/GHSA-mrwv-hx59-25f7/GHSA-mrwv-hx59-25f7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrwv-hx59-25f7", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-48781" ], "details": "An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json b/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json index 0a9e821f6a6..2fd7a586022 100644 --- a/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json +++ b/advisories/unreviewed/2024/10/GHSA-mwf7-wfvq-vc32/GHSA-mwf7-wfvq-vc32.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwf7-wfvq-vc32", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-41311" ], "details": "In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json b/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json index 4a2d646a6c7..7a555fd692a 100644 --- a/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json +++ b/advisories/unreviewed/2024/10/GHSA-ppxj-8w78-35rf/GHSA-ppxj-8w78-35rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppxj-8w78-35rf", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48795" ], "details": "An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pq4q-5xx3-76hf/GHSA-pq4q-5xx3-76hf.json b/advisories/unreviewed/2024/10/GHSA-pq4q-5xx3-76hf/GHSA-pq4q-5xx3-76hf.json index a31f8f8cb40..7e568a6ecb8 100644 --- a/advisories/unreviewed/2024/10/GHSA-pq4q-5xx3-76hf/GHSA-pq4q-5xx3-76hf.json +++ b/advisories/unreviewed/2024/10/GHSA-pq4q-5xx3-76hf/GHSA-pq4q-5xx3-76hf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq4q-5xx3-76hf", - "modified": "2024-10-16T18:31:47Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-16T18:31:47Z", "aliases": [ "CVE-2024-46605" ], "details": "A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-px5g-45ff-hqqc/GHSA-px5g-45ff-hqqc.json b/advisories/unreviewed/2024/10/GHSA-px5g-45ff-hqqc/GHSA-px5g-45ff-hqqc.json index afb7487d349..6f97525cc3b 100644 --- a/advisories/unreviewed/2024/10/GHSA-px5g-45ff-hqqc/GHSA-px5g-45ff-hqqc.json +++ b/advisories/unreviewed/2024/10/GHSA-px5g-45ff-hqqc/GHSA-px5g-45ff-hqqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-px5g-45ff-hqqc", - "modified": "2024-10-11T18:32:49Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-11T18:32:49Z", "aliases": [ "CVE-2024-44730" ], "details": "Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-924" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T16:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json b/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json index 5af723e6408..7c06ba1d912 100644 --- a/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json +++ b/advisories/unreviewed/2024/10/GHSA-q77p-j5gj-rmw2/GHSA-q77p-j5gj-rmw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q77p-j5gj-rmw2", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-44775" ], "details": "An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service(DoS) via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json b/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json index 4284fe88559..5c89c09958a 100644 --- a/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json +++ b/advisories/unreviewed/2024/10/GHSA-qfc4-qvg8-vmjr/GHSA-qfc4-qvg8-vmjr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfc4-qvg8-vmjr", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-48411" ], "details": "itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json b/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json index aba268649c0..2f469808d78 100644 --- a/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json +++ b/advisories/unreviewed/2024/10/GHSA-qg3h-rf5x-68cv/GHSA-qg3h-rf5x-68cv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qg3h-rf5x-68cv", - "modified": "2024-10-15T21:30:37Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:37Z", "aliases": [ "CVE-2024-35584" ], "details": "SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1, 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from \"X-Forwarded-For\" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T19:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json b/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json index ad8896f782b..8cee6e88b75 100644 --- a/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json +++ b/advisories/unreviewed/2024/10/GHSA-qgvh-3gr3-j9ph/GHSA-qgvh-3gr3-j9ph.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json b/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json index e4b11294ea9..2ea999de19d 100644 --- a/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json +++ b/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r25f-mfgv-vq97", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-16T21:31:05Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-43687" ], "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green" diff --git a/advisories/unreviewed/2024/10/GHSA-r63v-hfc4-mg32/GHSA-r63v-hfc4-mg32.json b/advisories/unreviewed/2024/10/GHSA-r63v-hfc4-mg32/GHSA-r63v-hfc4-mg32.json index 5dadeed0d3b..a21383d5cb4 100644 --- a/advisories/unreviewed/2024/10/GHSA-r63v-hfc4-mg32/GHSA-r63v-hfc4-mg32.json +++ b/advisories/unreviewed/2024/10/GHSA-r63v-hfc4-mg32/GHSA-r63v-hfc4-mg32.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r63v-hfc4-mg32", - "modified": "2024-10-16T03:31:33Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-16T03:31:33Z", "aliases": [ "CVE-2024-10018" ], "details": "Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-732" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-16T03:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json b/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json index 3ab150ab6b9..f3131f099b9 100644 --- a/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json +++ b/advisories/unreviewed/2024/10/GHSA-r7cm-7xjc-5g35/GHSA-r7cm-7xjc-5g35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7cm-7xjc-5g35", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48790" ], "details": "An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json b/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json new file mode 100644 index 00000000000..741d6dcc2b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rwhp-3v8j-67m2/GHSA-rwhp-3v8j-67m2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwhp-3v8j-67m2", + "modified": "2024-10-16T21:31:10Z", + "published": "2024-10-16T21:31:10Z", + "aliases": [ + "CVE-2024-48758" + ], + "details": "dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48758" + }, + { + "type": "WEB", + "url": "https://github.com/Yllxx03/CVE/blob/main/CVE-2024-48758/CVE-2024-48758.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-16T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vv5g-xq9c-77w7/GHSA-vv5g-xq9c-77w7.json b/advisories/unreviewed/2024/10/GHSA-vv5g-xq9c-77w7/GHSA-vv5g-xq9c-77w7.json index b1c48803977..7681057d2c9 100644 --- a/advisories/unreviewed/2024/10/GHSA-vv5g-xq9c-77w7/GHSA-vv5g-xq9c-77w7.json +++ b/advisories/unreviewed/2024/10/GHSA-vv5g-xq9c-77w7/GHSA-vv5g-xq9c-77w7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vv5g-xq9c-77w7", - "modified": "2024-10-12T15:30:42Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-12T15:30:42Z", "aliases": [ "CVE-2024-49193" ], "details": "Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-12T14:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json index 5c8e84fdaf8..9affb3f5f3d 100644 --- a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json +++ b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2p9-j475-2wp5", - "modified": "2024-10-15T21:30:39Z", + "modified": "2024-10-16T21:31:08Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9956" ], "details": "Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T21:15:12Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wh67-cc45-g7cf/GHSA-wh67-cc45-g7cf.json b/advisories/unreviewed/2024/10/GHSA-wh67-cc45-g7cf/GHSA-wh67-cc45-g7cf.json index 81494496008..3915a2b072c 100644 --- a/advisories/unreviewed/2024/10/GHSA-wh67-cc45-g7cf/GHSA-wh67-cc45-g7cf.json +++ b/advisories/unreviewed/2024/10/GHSA-wh67-cc45-g7cf/GHSA-wh67-cc45-g7cf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wh67-cc45-g7cf", - "modified": "2024-10-16T00:30:58Z", + "modified": "2024-10-16T21:31:09Z", "published": "2024-10-16T00:30:58Z", "aliases": [ "CVE-2024-10004" ], "details": "Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T22:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json b/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json index 458ee882012..f191c54de33 100644 --- a/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json +++ b/advisories/unreviewed/2024/10/GHSA-x25g-7892-q6v6/GHSA-x25g-7892-q6v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x25g-7892-q6v6", - "modified": "2024-10-14T18:30:25Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-14T18:30:25Z", "aliases": [ "CVE-2024-41997" ], "details": "An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/docker/open_subshell` intent that when clicked by the victim results in command execution on the victim's machine.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T16:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-xcmw-x3c5-ppmh/GHSA-xcmw-x3c5-ppmh.json b/advisories/unreviewed/2024/10/GHSA-xcmw-x3c5-ppmh/GHSA-xcmw-x3c5-ppmh.json index c637bb46f81..8af48a0e124 100644 --- a/advisories/unreviewed/2024/10/GHSA-xcmw-x3c5-ppmh/GHSA-xcmw-x3c5-ppmh.json +++ b/advisories/unreviewed/2024/10/GHSA-xcmw-x3c5-ppmh/GHSA-xcmw-x3c5-ppmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xcmw-x3c5-ppmh", - "modified": "2024-10-11T18:32:50Z", + "modified": "2024-10-16T21:31:07Z", "published": "2024-10-11T18:32:50Z", "aliases": [ "CVE-2024-46532" ], "details": "SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T18:15:08Z"