diff --git a/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json b/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json index f0d579bcaef..78ba636f5f5 100644 --- a/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json +++ b/advisories/unreviewed/2024/09/GHSA-974p-hhmc-6h46/GHSA-974p-hhmc-6h46.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-974p-hhmc-6h46", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-11-11T21:31:47Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-39924" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" + }, + { + "type": "WEB", + "url": "https://www.mgm-sp.com/cve/missing-authentication-check-for-emergency-access" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json index 75c38723a28..b9047aee57b 100644 --- a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json +++ b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r89w-9fr4-c7c9", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-11-11T21:31:47Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-39925" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" + }, + { + "type": "WEB", + "url": "https://www.mgm-sp.com/cve/missing-rotation-of-the-organization-key" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json b/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json index 03ac2b86be9..d3b79a9ff4e 100644 --- a/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json +++ b/advisories/unreviewed/2024/09/GHSA-vfwm-h968-g65h/GHSA-vfwm-h968-g65h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfwm-h968-g65h", - "modified": "2024-09-13T21:31:22Z", + "modified": "2024-11-11T21:31:47Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-39926" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.0" + }, + { + "type": "WEB", + "url": "https://www.mgm-sp.com/cve/html-injection-in-vaultwarden" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json b/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json new file mode 100644 index 00000000000..524e320aa1e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-37r8-854r-595c/GHSA-37r8-854r-595c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37r8-854r-595c", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-52530" + ], + "details": "GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\\0' characters at the end of header names are ignored, i.e., a \"Transfer-Encoding\\0: chunked\" header is treated the same as a \"Transfer-Encoding: chunked\" header.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52530" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libsoup/-/issues/377" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/402" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json b/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json new file mode 100644 index 00000000000..8fb317c7003 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5jpp-jp5m-8w78/GHSA-5jpp-jp5m-8w78.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jpp-jp5m-8w78", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-46963" + ], + "details": "The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46963" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.superfast.video.downloader/blob/main/CVE-2024-46963" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.superfast.video.downloader" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json b/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json new file mode 100644 index 00000000000..92bd0bd1c48 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5mc3-gwcr-mgc3/GHSA-5mc3-gwcr-mgc3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mc3-gwcr-mgc3", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-52531" + ], + "details": "GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. Input received over the network cannot trigger this.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52531" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/407" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-62gp-cqpw-rgh4/GHSA-62gp-cqpw-rgh4.json b/advisories/unreviewed/2024/11/GHSA-62gp-cqpw-rgh4/GHSA-62gp-cqpw-rgh4.json new file mode 100644 index 00000000000..dc784ab2b95 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-62gp-cqpw-rgh4/GHSA-62gp-cqpw-rgh4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gp-cqpw-rgh4", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-10315" + ], + "details": "In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10315" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SZVJYA4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-942" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-62pq-m3vv-gfjj/GHSA-62pq-m3vv-gfjj.json b/advisories/unreviewed/2024/11/GHSA-62pq-m3vv-gfjj/GHSA-62pq-m3vv-gfjj.json new file mode 100644 index 00000000000..cd7f61fc571 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-62pq-m3vv-gfjj/GHSA-62pq-m3vv-gfjj.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62pq-m3vv-gfjj", + "modified": "2024-11-11T21:31:47Z", + "published": "2024-11-11T21:31:47Z", + "aliases": [ + "CVE-2024-11077" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11077" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/UnrealdDei/cve/blob/main/sql3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json b/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json new file mode 100644 index 00000000000..d35bfaa7f02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6r2c-554q-5q54/GHSA-6r2c-554q-5q54.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r2c-554q-5q54", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-51186" + ], + "details": "D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51186" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/D-Link/DIR-820L/CI_ping_addr/README.md" + }, + { + "type": "WEB", + "url": "https://legacy.us.dlink.com/pages/product.aspx?id=00c2150966b046b58ba95d8ae3a8f73d" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-742m-mjf5-8f66/GHSA-742m-mjf5-8f66.json b/advisories/unreviewed/2024/11/GHSA-742m-mjf5-8f66/GHSA-742m-mjf5-8f66.json new file mode 100644 index 00000000000..9595c58967d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-742m-mjf5-8f66/GHSA-742m-mjf5-8f66.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-742m-mjf5-8f66", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-11078" + ], + "details": "A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11078" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/UnrealdDei/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.283873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.283873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.441187" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json b/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json new file mode 100644 index 00000000000..0248a9ec505 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8pj5-4fw9-jfjq/GHSA-8pj5-4fw9-jfjq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pj5-4fw9-jfjq", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-46965" + ], + "details": "The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46965" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/allvideo.downloader.browser/blob/main/CVE-2024-46965" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=allvideo.downloader.browser" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8x5h-hfqw-552w/GHSA-8x5h-hfqw-552w.json b/advisories/unreviewed/2024/11/GHSA-8x5h-hfqw-552w/GHSA-8x5h-hfqw-552w.json new file mode 100644 index 00000000000..caf52849c02 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-8x5h-hfqw-552w/GHSA-8x5h-hfqw-552w.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x5h-hfqw-552w", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-51190" + ], + "details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51190" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Special_AP/README.md" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json b/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json new file mode 100644 index 00000000000..2df9d61c28a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92m5-rpfj-8332/GHSA-92m5-rpfj-8332.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92m5-rpfj-8332", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-44546" + ], + "details": "Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44546" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jwx0539/5151f53ec497474cab6af4fa8ee6b6f7" + }, + { + "type": "WEB", + "url": "https://github.com/PowerJob/PowerJob" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json b/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json new file mode 100644 index 00000000000..65ccfdfbf3a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c6xg-p6mw-qxxr/GHSA-c6xg-p6mw-qxxr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6xg-p6mw-qxxr", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-46962" + ], + "details": "The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46962" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.downloader.video.fast/blob/main/CVE-2024-46962" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.downloader.video.fast" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cj5q-856p-33fg/GHSA-cj5q-856p-33fg.json b/advisories/unreviewed/2024/11/GHSA-cj5q-856p-33fg/GHSA-cj5q-856p-33fg.json new file mode 100644 index 00000000000..a483d94e1ce --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cj5q-856p-33fg/GHSA-cj5q-856p-33fg.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj5q-856p-33fg", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-51189" + ], + "details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51189" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Filter/README.md" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json b/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json new file mode 100644 index 00000000000..7392521c0be --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cx99-h4rf-2j49/GHSA-cx99-h4rf-2j49.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx99-h4rf-2j49", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-50667" + ], + "details": "The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50667" + }, + { + "type": "WEB", + "url": "https://github.com/ixout/iotVuls/blob/main/Trendnet/TEW_820/report.md" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/support/support-detail.asp?prod=100_TEW-820AP" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T19:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json b/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json new file mode 100644 index 00000000000..185b4ca2c39 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f6qg-rg6j-cxgf/GHSA-f6qg-rg6j-cxgf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6qg-rg6j-cxgf", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-52532" + ], + "details": "GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52532" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libsoup/-/issues/391" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/410" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json b/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json new file mode 100644 index 00000000000..b20da165419 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g6gg-3vqf-rfrx/GHSA-g6gg-3vqf-rfrx.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6gg-3vqf-rfrx", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-48322" + ], + "details": "UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48322" + }, + { + "type": "WEB", + "url": "https://github.com/runcodes-icmc/server/issues/12" + }, + { + "type": "WEB", + "url": "https://github.com/runcodes-icmc/server" + }, + { + "type": "WEB", + "url": "https://github.com/runcodes-icmc/server/releases/tag/v1.5.3" + }, + { + "type": "WEB", + "url": "https://github.com/trqt/CVE-2024-48322" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gf2c-phc6-4g3w/GHSA-gf2c-phc6-4g3w.json b/advisories/unreviewed/2024/11/GHSA-gf2c-phc6-4g3w/GHSA-gf2c-phc6-4g3w.json new file mode 100644 index 00000000000..2906d754c5d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gf2c-phc6-4g3w/GHSA-gf2c-phc6-4g3w.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf2c-phc6-4g3w", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-51188" + ], + "details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51188" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Virtual_Server/README.md" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json b/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json new file mode 100644 index 00000000000..68453a3f056 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h2xv-hq2x-rvxq/GHSA-h2xv-hq2x-rvxq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2xv-hq2x-rvxq", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-51026" + ], + "details": "The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51026" + }, + { + "type": "WEB", + "url": "https://github.com/BrotherOfJhonny/CVE-2024-51026_Overview" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json b/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json new file mode 100644 index 00000000000..45e4eada29f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pgrc-8wp5-5mvq/GHSA-pgrc-8wp5-5mvq.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgrc-8wp5-5mvq", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-51135" + ], + "details": "An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51135" + }, + { + "type": "WEB", + "url": "https://github.com/powertac/powertac-server/issues/1166" + }, + { + "type": "WEB", + "url": "https://github.com/powertac/powertac-server" + }, + { + "type": "WEB", + "url": "https://mvnrepository.com/artifact/org.powertac/server-interface" + }, + { + "type": "WEB", + "url": "http://www.powertac.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T19:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json b/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json new file mode 100644 index 00000000000..d9b3e2ce69c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qpj8-6r97-qxq6/GHSA-qpj8-6r97-qxq6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpj8-6r97-qxq6", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-46966" + ], + "details": "The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46966" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/mn.ikhgur.khotoch/blob/main/CVE-2024-46966" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=mn.ikhgur.khotoch" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json b/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json new file mode 100644 index 00000000000..ca0a3ae10e0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v8h2-p73v-3whx/GHSA-v8h2-p73v-3whx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8h2-p73v-3whx", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-36061" + ], + "details": "EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36061" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Engenius/CVE-2024-36061" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wr9r-499g-57gv/GHSA-wr9r-499g-57gv.json b/advisories/unreviewed/2024/11/GHSA-wr9r-499g-57gv/GHSA-wr9r-499g-57gv.json new file mode 100644 index 00000000000..fe96642d154 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wr9r-499g-57gv/GHSA-wr9r-499g-57gv.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr9r-499g-57gv", + "modified": "2024-11-11T21:31:48Z", + "published": "2024-11-11T21:31:48Z", + "aliases": [ + "CVE-2024-51187" + ], + "details": "TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51187" + }, + { + "type": "WEB", + "url": "https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Firewall_Rule/README.md" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP" + }, + { + "type": "WEB", + "url": "https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json b/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json new file mode 100644 index 00000000000..b3d21d4ebff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xqm3-rc5r-j547/GHSA-xqm3-rc5r-j547.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqm3-rc5r-j547", + "modified": "2024-11-11T21:31:49Z", + "published": "2024-11-11T21:31:49Z", + "aliases": [ + "CVE-2024-46964" + ], + "details": "The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46964" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/com.video.downloader.all/blob/main/CVE-2024-46964" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.video.downloader.all" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-11T21:15:06Z" + } +} \ No newline at end of file