From b157f9dafff0eb1497573340138d6975166ea90c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 14 Aug 2024 21:34:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-j6mx-66rf-6rxq.json | 3 +- .../GHSA-7997-4r78-h34m.json | 2 +- .../GHSA-pj5c-qr29-6746.json | 3 +- .../GHSA-3xmr-xg4j-24rr.json | 1 + .../GHSA-qm6p-w2qq-fv6f.json | 2 +- .../GHSA-wvwp-cgr6-m5rx.json | 2 +- .../GHSA-82gg-6vvf-fm37.json | 11 ++-- .../GHSA-6j88-4936-7r36.json | 11 ++-- .../GHSA-8c44-wv8g-r976.json | 11 ++-- .../GHSA-fr95-rvfm-4wwm.json | 11 ++-- .../GHSA-h54h-77gg-v4vm.json | 11 ++-- .../GHSA-mw76-72hw-4357.json | 4 +- .../GHSA-2qhf-4crg-6c2w.json | 11 ++-- .../GHSA-9h58-5xgm-2682.json | 11 ++-- .../GHSA-p5q9-4vg3-6x89.json | 11 ++-- .../GHSA-qcfv-94fj-42jc.json | 11 ++-- .../GHSA-qqpr-fvmc-87j3.json | 9 ++-- .../GHSA-h37q-x6pv-4p48.json | 11 ++-- .../GHSA-hvhc-8w3j-pf54.json | 11 ++-- .../GHSA-jrvv-3x7m-vqjc.json | 11 ++-- .../GHSA-r3w6-h4cp-32x7.json | 11 ++-- .../GHSA-3g7r-r3cr-q6f8.json | 11 ++-- .../GHSA-74jr-x2w7-635g.json | 11 ++-- .../GHSA-pf8g-8pmm-2xcp.json | 11 ++-- .../GHSA-qxgm-2hhj-rw7f.json | 1 + .../GHSA-8qw7-q76p-7f4h.json | 1 + .../GHSA-3799-rgwr-cfc9.json | 42 +++++++++++++++ .../GHSA-5mv6-gwjh-xjf6.json | 54 +++++++++++++++++++ .../GHSA-5vxw-hpgc-992j.json | 38 +++++++++++++ .../GHSA-63qm-6ghj-xgg9.json | 46 ++++++++++++++++ .../GHSA-6cpv-q9vf-2h3j.json | 38 +++++++++++++ .../GHSA-89fm-3w27-7c7q.json | 38 +++++++++++++ .../GHSA-g73r-h5v6-mxx2.json | 38 +++++++++++++ .../GHSA-hx72-825v-wv3p.json | 38 +++++++++++++ .../GHSA-qw7m-5v7h-8vqf.json | 38 +++++++++++++ .../GHSA-w287-4mr4-4v3v.json | 11 ++-- .../GHSA-xm84-j48f-46w5.json | 54 +++++++++++++++++++ .../GHSA-xw9h-mxp6-gf7c.json | 54 +++++++++++++++++++ 38 files changed, 615 insertions(+), 78 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-3799-rgwr-cfc9/GHSA-3799-rgwr-cfc9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5mv6-gwjh-xjf6/GHSA-5mv6-gwjh-xjf6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-63qm-6ghj-xgg9/GHSA-63qm-6ghj-xgg9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g73r-h5v6-mxx2/GHSA-g73r-h5v6-mxx2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xm84-j48f-46w5/GHSA-xm84-j48f-46w5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xw9h-mxp6-gf7c/GHSA-xw9h-mxp6-gf7c.json diff --git a/advisories/unreviewed/2023/02/GHSA-j6mx-66rf-6rxq/GHSA-j6mx-66rf-6rxq.json b/advisories/unreviewed/2023/02/GHSA-j6mx-66rf-6rxq/GHSA-j6mx-66rf-6rxq.json index 6f54012041d..04d5227bbcc 100644 --- a/advisories/unreviewed/2023/02/GHSA-j6mx-66rf-6rxq/GHSA-j6mx-66rf-6rxq.json +++ b/advisories/unreviewed/2023/02/GHSA-j6mx-66rf-6rxq/GHSA-j6mx-66rf-6rxq.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-7997-4r78-h34m/GHSA-7997-4r78-h34m.json b/advisories/unreviewed/2023/10/GHSA-7997-4r78-h34m/GHSA-7997-4r78-h34m.json index 341eacbbc00..e6164279efb 100644 --- a/advisories/unreviewed/2023/10/GHSA-7997-4r78-h34m/GHSA-7997-4r78-h34m.json +++ b/advisories/unreviewed/2023/10/GHSA-7997-4r78-h34m/GHSA-7997-4r78-h34m.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json b/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json index 1d7c5a4f03a..7f5b82137b5 100644 --- a/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json +++ b/advisories/unreviewed/2023/10/GHSA-pj5c-qr29-6746/GHSA-pj5c-qr29-6746.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-502" + "CWE-502", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-3xmr-xg4j-24rr/GHSA-3xmr-xg4j-24rr.json b/advisories/unreviewed/2023/11/GHSA-3xmr-xg4j-24rr/GHSA-3xmr-xg4j-24rr.json index 473c3d4bc92..363ac2780af 100644 --- a/advisories/unreviewed/2023/11/GHSA-3xmr-xg4j-24rr/GHSA-3xmr-xg4j-24rr.json +++ b/advisories/unreviewed/2023/11/GHSA-3xmr-xg4j-24rr/GHSA-3xmr-xg4j-24rr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-476" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/11/GHSA-qm6p-w2qq-fv6f/GHSA-qm6p-w2qq-fv6f.json b/advisories/unreviewed/2023/11/GHSA-qm6p-w2qq-fv6f/GHSA-qm6p-w2qq-fv6f.json index 1d107438ec4..bb22e3741e4 100644 --- a/advisories/unreviewed/2023/11/GHSA-qm6p-w2qq-fv6f/GHSA-qm6p-w2qq-fv6f.json +++ b/advisories/unreviewed/2023/11/GHSA-qm6p-w2qq-fv6f/GHSA-qm6p-w2qq-fv6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm6p-w2qq-fv6f", - "modified": "2023-11-21T21:30:23Z", + "modified": "2024-08-14T21:33:10Z", "published": "2023-11-15T06:30:29Z", "aliases": [ "CVE-2023-47580" diff --git a/advisories/unreviewed/2023/11/GHSA-wvwp-cgr6-m5rx/GHSA-wvwp-cgr6-m5rx.json b/advisories/unreviewed/2023/11/GHSA-wvwp-cgr6-m5rx/GHSA-wvwp-cgr6-m5rx.json index d5a352d2f74..5b3ac2585ce 100644 --- a/advisories/unreviewed/2023/11/GHSA-wvwp-cgr6-m5rx/GHSA-wvwp-cgr6-m5rx.json +++ b/advisories/unreviewed/2023/11/GHSA-wvwp-cgr6-m5rx/GHSA-wvwp-cgr6-m5rx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-82gg-6vvf-fm37/GHSA-82gg-6vvf-fm37.json b/advisories/unreviewed/2024/02/GHSA-82gg-6vvf-fm37/GHSA-82gg-6vvf-fm37.json index 3cadd04a788..806e8c8826e 100644 --- a/advisories/unreviewed/2024/02/GHSA-82gg-6vvf-fm37/GHSA-82gg-6vvf-fm37.json +++ b/advisories/unreviewed/2024/02/GHSA-82gg-6vvf-fm37/GHSA-82gg-6vvf-fm37.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82gg-6vvf-fm37", - "modified": "2024-02-22T15:30:39Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-02-22T15:30:39Z", "aliases": [ "CVE-2024-26352" ], "details": "flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T14:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6j88-4936-7r36/GHSA-6j88-4936-7r36.json b/advisories/unreviewed/2024/03/GHSA-6j88-4936-7r36/GHSA-6j88-4936-7r36.json index cf454dd9143..51aca91480a 100644 --- a/advisories/unreviewed/2024/03/GHSA-6j88-4936-7r36/GHSA-6j88-4936-7r36.json +++ b/advisories/unreviewed/2024/03/GHSA-6j88-4936-7r36/GHSA-6j88-4936-7r36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6j88-4936-7r36", - "modified": "2024-03-15T00:30:22Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-03-15T00:30:22Z", "aliases": [ "CVE-2023-50677" ], "details": "An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T22:15:22Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8c44-wv8g-r976/GHSA-8c44-wv8g-r976.json b/advisories/unreviewed/2024/03/GHSA-8c44-wv8g-r976/GHSA-8c44-wv8g-r976.json index 686673ada64..720a7e30d6c 100644 --- a/advisories/unreviewed/2024/03/GHSA-8c44-wv8g-r976/GHSA-8c44-wv8g-r976.json +++ b/advisories/unreviewed/2024/03/GHSA-8c44-wv8g-r976/GHSA-8c44-wv8g-r976.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c44-wv8g-r976", - "modified": "2024-03-07T09:30:30Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-03-07T09:30:30Z", "aliases": [ "CVE-2022-46499" ], "details": "Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T09:15:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-fr95-rvfm-4wwm/GHSA-fr95-rvfm-4wwm.json b/advisories/unreviewed/2024/03/GHSA-fr95-rvfm-4wwm/GHSA-fr95-rvfm-4wwm.json index 7e1440eb0cd..add162fdfd0 100644 --- a/advisories/unreviewed/2024/03/GHSA-fr95-rvfm-4wwm/GHSA-fr95-rvfm-4wwm.json +++ b/advisories/unreviewed/2024/03/GHSA-fr95-rvfm-4wwm/GHSA-fr95-rvfm-4wwm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fr95-rvfm-4wwm", - "modified": "2024-03-11T18:31:08Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-03-11T18:31:08Z", "aliases": [ "CVE-2024-0050" ], "details": "In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could lead to a local non-security issue with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T17:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h54h-77gg-v4vm/GHSA-h54h-77gg-v4vm.json b/advisories/unreviewed/2024/03/GHSA-h54h-77gg-v4vm/GHSA-h54h-77gg-v4vm.json index 7888c2ad467..e9fa2879243 100644 --- a/advisories/unreviewed/2024/03/GHSA-h54h-77gg-v4vm/GHSA-h54h-77gg-v4vm.json +++ b/advisories/unreviewed/2024/03/GHSA-h54h-77gg-v4vm/GHSA-h54h-77gg-v4vm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h54h-77gg-v4vm", - "modified": "2024-03-15T18:30:38Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-03-15T18:30:38Z", "aliases": [ "CVE-2024-28404" ], "details": "TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T17:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mw76-72hw-4357/GHSA-mw76-72hw-4357.json b/advisories/unreviewed/2024/03/GHSA-mw76-72hw-4357/GHSA-mw76-72hw-4357.json index 16d0522a4ba..300d05337b6 100644 --- a/advisories/unreviewed/2024/03/GHSA-mw76-72hw-4357/GHSA-mw76-72hw-4357.json +++ b/advisories/unreviewed/2024/03/GHSA-mw76-72hw-4357/GHSA-mw76-72hw-4357.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw76-72hw-4357", - "modified": "2024-03-05T18:31:14Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-03-05T18:31:14Z", "aliases": [ "CVE-2024-22254" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-2qhf-4crg-6c2w/GHSA-2qhf-4crg-6c2w.json b/advisories/unreviewed/2024/04/GHSA-2qhf-4crg-6c2w/GHSA-2qhf-4crg-6c2w.json index ca99f11ed68..7bc94edf433 100644 --- a/advisories/unreviewed/2024/04/GHSA-2qhf-4crg-6c2w/GHSA-2qhf-4crg-6c2w.json +++ b/advisories/unreviewed/2024/04/GHSA-2qhf-4crg-6c2w/GHSA-2qhf-4crg-6c2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qhf-4crg-6c2w", - "modified": "2024-04-11T03:34:59Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-04-11T03:34:59Z", "aliases": [ "CVE-2024-27683" ], "details": "D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T01:25:05Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json b/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json index 953db905cb7..f93639e6de5 100644 --- a/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json +++ b/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9h58-5xgm-2682", - "modified": "2024-04-03T06:30:47Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-04-03T06:30:47Z", "aliases": [ "CVE-2024-31010" ], "details": "SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T04:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p5q9-4vg3-6x89/GHSA-p5q9-4vg3-6x89.json b/advisories/unreviewed/2024/04/GHSA-p5q9-4vg3-6x89/GHSA-p5q9-4vg3-6x89.json index 81d6380a05b..a052973f606 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5q9-4vg3-6x89/GHSA-p5q9-4vg3-6x89.json +++ b/advisories/unreviewed/2024/04/GHSA-p5q9-4vg3-6x89/GHSA-p5q9-4vg3-6x89.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5q9-4vg3-6x89", - "modified": "2024-04-11T21:30:52Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-04-11T21:30:52Z", "aliases": [ "CVE-2024-25852" ], "details": "Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the \"AccessControlList\" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json b/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json index a789efb0a6f..da52e690e20 100644 --- a/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json +++ b/advisories/unreviewed/2024/04/GHSA-qcfv-94fj-42jc/GHSA-qcfv-94fj-42jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qcfv-94fj-42jc", - "modified": "2024-04-07T09:30:29Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-04-07T09:30:29Z", "aliases": [ "CVE-2023-52714" ], "details": "Vulnerability of defects introduced in the design process in the hwnff module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-657" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qqpr-fvmc-87j3/GHSA-qqpr-fvmc-87j3.json b/advisories/unreviewed/2024/04/GHSA-qqpr-fvmc-87j3/GHSA-qqpr-fvmc-87j3.json index 6d00e6b6c33..70f0942cffd 100644 --- a/advisories/unreviewed/2024/04/GHSA-qqpr-fvmc-87j3/GHSA-qqpr-fvmc-87j3.json +++ b/advisories/unreviewed/2024/04/GHSA-qqpr-fvmc-87j3/GHSA-qqpr-fvmc-87j3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qqpr-fvmc-87j3", - "modified": "2024-04-23T18:30:38Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-04-17T09:30:31Z", "aliases": [ "CVE-2024-3832" ], "details": "Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h37q-x6pv-4p48/GHSA-h37q-x6pv-4p48.json b/advisories/unreviewed/2024/05/GHSA-h37q-x6pv-4p48/GHSA-h37q-x6pv-4p48.json index 3d0699d86ce..16388cd6314 100644 --- a/advisories/unreviewed/2024/05/GHSA-h37q-x6pv-4p48/GHSA-h37q-x6pv-4p48.json +++ b/advisories/unreviewed/2024/05/GHSA-h37q-x6pv-4p48/GHSA-h37q-x6pv-4p48.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h37q-x6pv-4p48", - "modified": "2024-05-06T15:30:35Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-05-06T15:30:35Z", "aliases": [ "CVE-2024-33749" ], "details": "DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hvhc-8w3j-pf54/GHSA-hvhc-8w3j-pf54.json b/advisories/unreviewed/2024/05/GHSA-hvhc-8w3j-pf54/GHSA-hvhc-8w3j-pf54.json index 70bd5be1bf6..4f0595f68c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-hvhc-8w3j-pf54/GHSA-hvhc-8w3j-pf54.json +++ b/advisories/unreviewed/2024/05/GHSA-hvhc-8w3j-pf54/GHSA-hvhc-8w3j-pf54.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hvhc-8w3j-pf54", - "modified": "2024-05-14T18:30:45Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-05-14T18:30:45Z", "aliases": [ "CVE-2022-32509" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:42Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jrvv-3x7m-vqjc/GHSA-jrvv-3x7m-vqjc.json b/advisories/unreviewed/2024/05/GHSA-jrvv-3x7m-vqjc/GHSA-jrvv-3x7m-vqjc.json index e30a0176fa6..08787a14082 100644 --- a/advisories/unreviewed/2024/05/GHSA-jrvv-3x7m-vqjc/GHSA-jrvv-3x7m-vqjc.json +++ b/advisories/unreviewed/2024/05/GHSA-jrvv-3x7m-vqjc/GHSA-jrvv-3x7m-vqjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrvv-3x7m-vqjc", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32507" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r3w6-h4cp-32x7/GHSA-r3w6-h4cp-32x7.json b/advisories/unreviewed/2024/05/GHSA-r3w6-h4cp-32x7/GHSA-r3w6-h4cp-32x7.json index 07bfc4ea555..6bab9a85d79 100644 --- a/advisories/unreviewed/2024/05/GHSA-r3w6-h4cp-32x7/GHSA-r3w6-h4cp-32x7.json +++ b/advisories/unreviewed/2024/05/GHSA-r3w6-h4cp-32x7/GHSA-r3w6-h4cp-32x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3w6-h4cp-32x7", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34310" ], "details": "Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:38Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3g7r-r3cr-q6f8/GHSA-3g7r-r3cr-q6f8.json b/advisories/unreviewed/2024/06/GHSA-3g7r-r3cr-q6f8/GHSA-3g7r-r3cr-q6f8.json index 6f7c3eb6a8d..fe7a7cb2bdd 100644 --- a/advisories/unreviewed/2024/06/GHSA-3g7r-r3cr-q6f8/GHSA-3g7r-r3cr-q6f8.json +++ b/advisories/unreviewed/2024/06/GHSA-3g7r-r3cr-q6f8/GHSA-3g7r-r3cr-q6f8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g7r-r3cr-q6f8", - "modified": "2024-06-07T15:30:40Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-06-07T15:30:40Z", "aliases": [ "CVE-2024-36790" ], "details": "Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T15:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-74jr-x2w7-635g/GHSA-74jr-x2w7-635g.json b/advisories/unreviewed/2024/06/GHSA-74jr-x2w7-635g/GHSA-74jr-x2w7-635g.json index ec169b3e172..bedf207809a 100644 --- a/advisories/unreviewed/2024/06/GHSA-74jr-x2w7-635g/GHSA-74jr-x2w7-635g.json +++ b/advisories/unreviewed/2024/06/GHSA-74jr-x2w7-635g/GHSA-74jr-x2w7-635g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74jr-x2w7-635g", - "modified": "2024-06-18T21:30:35Z", + "modified": "2024-08-14T21:33:11Z", "published": "2024-06-03T21:30:45Z", "aliases": [ "CVE-2024-34987" ], "details": "A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T20:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pf8g-8pmm-2xcp/GHSA-pf8g-8pmm-2xcp.json b/advisories/unreviewed/2024/06/GHSA-pf8g-8pmm-2xcp/GHSA-pf8g-8pmm-2xcp.json index 9d8a6357b6e..279352d97fb 100644 --- a/advisories/unreviewed/2024/06/GHSA-pf8g-8pmm-2xcp/GHSA-pf8g-8pmm-2xcp.json +++ b/advisories/unreviewed/2024/06/GHSA-pf8g-8pmm-2xcp/GHSA-pf8g-8pmm-2xcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pf8g-8pmm-2xcp", - "modified": "2024-06-25T15:31:08Z", + "modified": "2024-08-14T21:33:12Z", "published": "2024-06-25T15:31:08Z", "aliases": [ "CVE-2024-38952" ], "details": "PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T14:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json b/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json index 49351148bbc..6ee47fafea2 100644 --- a/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json +++ b/advisories/unreviewed/2024/06/GHSA-qxgm-2hhj-rw7f/GHSA-qxgm-2hhj-rw7f.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-670", "CWE-783" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json b/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json index 2c6713f7146..cc36aab20bb 100644 --- a/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json +++ b/advisories/unreviewed/2024/07/GHSA-8qw7-q76p-7f4h/GHSA-8qw7-q76p-7f4h.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-303" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/08/GHSA-3799-rgwr-cfc9/GHSA-3799-rgwr-cfc9.json b/advisories/unreviewed/2024/08/GHSA-3799-rgwr-cfc9/GHSA-3799-rgwr-cfc9.json new file mode 100644 index 00000000000..a0494b3875b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3799-rgwr-cfc9/GHSA-3799-rgwr-cfc9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3799-rgwr-cfc9", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-27120" + ], + "details": "A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Red" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27120" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2024-27120" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2024-00031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5mv6-gwjh-xjf6/GHSA-5mv6-gwjh-xjf6.json b/advisories/unreviewed/2024/08/GHSA-5mv6-gwjh-xjf6/GHSA-5mv6-gwjh-xjf6.json new file mode 100644 index 00000000000..838d94b8808 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5mv6-gwjh-xjf6/GHSA-5mv6-gwjh-xjf6.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mv6-gwjh-xjf6", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-7792" + ], + "details": "A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. The manipulation of the argument task leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7792" + }, + { + "type": "WEB", + "url": "https://github.com/joinia/webray.com.cn/blob/main/Task-Progress-Tracker/Task-Progress-Trackersql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.389360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json b/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json new file mode 100644 index 00000000000..57ca7579c74 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5vxw-hpgc-992j/GHSA-5vxw-hpgc-992j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vxw-hpgc-992j", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-7515" + ], + "details": "CVE-2024-7515 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7515" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201686.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-63qm-6ghj-xgg9/GHSA-63qm-6ghj-xgg9.json b/advisories/unreviewed/2024/08/GHSA-63qm-6ghj-xgg9/GHSA-63qm-6ghj-xgg9.json new file mode 100644 index 00000000000..0381542676c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-63qm-6ghj-xgg9/GHSA-63qm-6ghj-xgg9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63qm-6ghj-xgg9", + "modified": "2024-08-14T21:33:11Z", + "published": "2024-08-14T21:33:11Z", + "aliases": [ + "CVE-2024-23789" + ], + "details": "Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23789" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf" + }, + { + "type": "WEB", + "url": "https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU94591337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json b/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json new file mode 100644 index 00000000000..7723e65aaf8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6cpv-q9vf-2h3j/GHSA-6cpv-q9vf-2h3j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cpv-q9vf-2h3j", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-7513" + ], + "details": "CVE-2024-7513 IMPACT\n\nA code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7513" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201688.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json b/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json new file mode 100644 index 00000000000..42a192bb658 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-89fm-3w27-7c7q/GHSA-89fm-3w27-7c7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89fm-3w27-7c7q", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-40619" + ], + "details": "CVE-2024-40619 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40619" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201690.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g73r-h5v6-mxx2/GHSA-g73r-h5v6-mxx2.json b/advisories/unreviewed/2024/08/GHSA-g73r-h5v6-mxx2/GHSA-g73r-h5v6-mxx2.json new file mode 100644 index 00000000000..833907ab1af --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g73r-h5v6-mxx2/GHSA-g73r-h5v6-mxx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g73r-h5v6-mxx2", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-6078" + ], + "details": "CVE-2024-6078 IMPACT\n\nAn improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6078" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201687.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json b/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json new file mode 100644 index 00000000000..e0983f3ba08 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hx72-825v-wv3p/GHSA-hx72-825v-wv3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx72-825v-wv3p", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-7507" + ], + "details": "CVE-2024-7507 IMPACT\n\nA denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7507" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201685.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json b/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json new file mode 100644 index 00000000000..4fb6b4ae47b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qw7m-5v7h-8vqf/GHSA-qw7m-5v7h-8vqf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw7m-5v7h-8vqf", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-40620" + ], + "details": "CVE-2024-40620 IMPACT\n\nA vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40620" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T20:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json b/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json index c6c872acd15..5d10800d3a4 100644 --- a/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json +++ b/advisories/unreviewed/2024/08/GHSA-w287-4mr4-4v3v/GHSA-w287-4mr4-4v3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w287-4mr4-4v3v", - "modified": "2024-08-13T18:31:14Z", + "modified": "2024-08-14T21:33:12Z", "published": "2024-08-12T21:31:34Z", "aliases": [ "CVE-2024-41710" ], "details": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-88" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T19:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xm84-j48f-46w5/GHSA-xm84-j48f-46w5.json b/advisories/unreviewed/2024/08/GHSA-xm84-j48f-46w5/GHSA-xm84-j48f-46w5.json new file mode 100644 index 00000000000..ad713f90c22 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xm84-j48f-46w5/GHSA-xm84-j48f-46w5.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm84-j48f-46w5", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-7793" + ], + "details": "A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-task.php. The manipulation of the argument task_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7793" + }, + { + "type": "WEB", + "url": "https://github.com/joinia/webray.com.cn/blob/main/Task-Progress-Tracker/Task-Progress-Trackerxss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.389362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xw9h-mxp6-gf7c/GHSA-xw9h-mxp6-gf7c.json b/advisories/unreviewed/2024/08/GHSA-xw9h-mxp6-gf7c/GHSA-xw9h-mxp6-gf7c.json new file mode 100644 index 00000000000..902e35ce683 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xw9h-mxp6-gf7c/GHSA-xw9h-mxp6-gf7c.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw9h-mxp6-gf7c", + "modified": "2024-08-14T21:33:12Z", + "published": "2024-08-14T21:33:12Z", + "aliases": [ + "CVE-2024-7794" + ], + "details": "A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7794" + }, + { + "type": "WEB", + "url": "https://github.com/ppp-src/ha/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.389900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-14T21:15:17Z" + } +} \ No newline at end of file