Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-08-27 21:32:34 +00:00
parent ffeb761979
commit b0054ff2d9
91 changed files with 1155 additions and 280 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4cj-v28g-9hh9",
"modified": "2023-11-17T21:30:26Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-07-18T00:31:08Z",
"aliases": [
"CVE-2023-38427"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ph9g-g7m5-2pg5",
"modified": "2023-12-04T15:31:54Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-07-24T18:30:43Z",
"aliases": [
"CVE-2023-32247"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxv8-6x37-53r6",
"modified": "2023-11-24T09:30:27Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-07-24T18:30:43Z",
"aliases": [
"CVE-2023-32252"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67f2-j5vg-639w",
"modified": "2023-11-10T18:30:19Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-10-15T03:30:30Z",
"aliases": [
"CVE-2023-45871"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p37-96m9-9qq9",
"modified": "2023-12-27T21:31:00Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-12-22T21:30:23Z",
"aliases": [
"CVE-2023-51015"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9fc-wq66-mpcr",
"modified": "2023-12-22T12:31:46Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-12-19T15:30:30Z",
"aliases": [
"CVE-2023-6866"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hrfw-pwjg-7prc",
"modified": "2024-01-05T00:30:28Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2023-12-29T06:30:29Z",
"aliases": [
"CVE-2023-31296"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1236"
"CWE-1236",
"CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3m2w-jxjv-4wfv",
"modified": "2024-02-15T00:30:33Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-15T00:30:33Z",
"aliases": [
"CVE-2024-24301"
],
"details": "Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-14T23:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53fp-rvgh-5wr6",
"modified": "2024-02-29T00:30:23Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-29T00:30:23Z",
"aliases": [
"CVE-2024-25868"
],
"details": "A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the add_type.php component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-28T22:15:26Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-599j-qj67-hr6x",
"modified": "2024-02-27T00:32:04Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-27T00:32:04Z",
"aliases": [
"CVE-2024-25751"
],
"details": "A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T22:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g9g-vh54-q73c",
"modified": "2024-02-24T00:30:20Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-24T00:30:20Z",
"aliases": [
"CVE-2024-25469"
],
"details": "SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-23T23:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9426-vxhj-rxm5",
"modified": "2024-02-29T03:33:09Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-29T03:33:09Z",
"aliases": [
"CVE-2022-34269"
],
"details": "An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:35:13Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c2cc-r8fq-338p",
"modified": "2024-02-16T00:30:28Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-16T00:30:28Z",
"aliases": [
"CVE-2023-40106"
],
"details": "In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-15T23:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hhg5-qh7h-f99g",
"modified": "2024-02-22T00:31:01Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-22T00:31:00Z",
"aliases": [
"CVE-2023-51828"
],
"details": "A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-21T22:15:48Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxr4-5qvc-pqfm",
"modified": "2024-02-27T03:31:02Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-27T03:31:02Z",
"aliases": [
"CVE-2023-41506"
],
"details": "An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-27T02:15:06Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjr7-7f86-j28r",
"modified": "2024-02-29T03:33:18Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-29T03:33:18Z",
"aliases": [
"CVE-2024-26471"
],
"details": "A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:44:18Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2cr-gm62-vm8v",
"modified": "2024-02-29T03:33:17Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-29T03:33:17Z",
"aliases": [
"CVE-2024-23052"
],
"details": "An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:44:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjx3-xwwm-jhj5",
"modified": "2024-05-01T21:30:30Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-25081"
],
"details": "Splinefont in FontForge through 20230101 allows command injection via crafted filenames.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:58Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqx4-jcwp-8g92",
"modified": "2024-02-29T03:33:17Z",
"modified": "2024-08-27T21:31:10Z",
"published": "2024-02-29T03:33:17Z",
"aliases": [
"CVE-2024-22939"
],
"details": "Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:44:07Z"

Some files were not shown because too many files have changed in this diff Show More