From bb10df1d428eb68133078e92b6a97f6842be3372 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 26 Aug 2024 21:31:54 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-226m-fqfj-v6xp.json | 11 ++-- .../GHSA-283x-r7vm-882q.json | 11 ++-- .../GHSA-3q8j-579q-jx44.json | 8 ++- .../GHSA-3rhh-97v9-2g42.json | 9 ++-- .../GHSA-3vf3-8x3v-cfhr.json | 11 ++-- .../GHSA-3wcf-84jq-4rxx.json | 11 ++-- .../GHSA-4mwq-x2m3-qxc6.json | 9 ++-- .../GHSA-6hvh-59wp-qgpm.json | 11 ++-- .../GHSA-74rv-fq96-j6vr.json | 11 ++-- .../GHSA-754f-f3pv-5vpq.json | 11 ++-- .../GHSA-77c4-m4jj-64q2.json | 2 +- .../GHSA-824x-hcr6-cqgr.json | 11 ++-- .../GHSA-89x3-jgxj-39cx.json | 3 +- .../GHSA-mmc3-qp8j-6fpj.json | 2 +- .../GHSA-mmrc-cc78-9f9w.json | 3 +- .../GHSA-v57p-q7g2-4g2r.json | 11 ++-- .../GHSA-6vrh-rgrg-f5x4.json | 11 ++-- .../GHSA-6xfp-g425-7cw6.json | 11 ++-- .../GHSA-726f-22p9-pqrr.json | 11 ++-- .../GHSA-89cw-fq2g-5v94.json | 11 ++-- .../GHSA-jjxf-7hh9-8j8m.json | 9 ++-- .../GHSA-pwmf-6266-xrmc.json | 11 ++-- .../GHSA-2p97-c8vf-r4rf.json | 11 ++-- .../GHSA-gpf5-g943-4fxx.json | 11 ++-- .../GHSA-jx7f-v5r5-55j4.json | 9 ++-- .../GHSA-mq6j-35mg-9rj6.json | 11 ++-- .../GHSA-r247-cqp5-chrp.json | 11 ++-- .../GHSA-wgrq-q2w8-p9x4.json | 11 ++-- .../GHSA-wxvv-7x57-mjgj.json | 11 ++-- .../GHSA-qvwq-g2x2-px28.json | 11 ++-- .../GHSA-2gg8-w5vr-ghvj.json | 38 ++++++++++++++ .../GHSA-2v3g-4chr-x8h3.json | 38 ++++++++++++++ .../GHSA-329h-fcrp-rfh4.json | 39 ++++++++++++++ .../GHSA-3f48-f2h7-6g73.json | 38 ++++++++++++++ .../GHSA-42m4-gw8j-vjvg.json | 43 ++++++++++++++++ .../GHSA-4638-h2rx-8qf2.json | 38 ++++++++++++++ .../GHSA-5fhp-588g-xh47.json | 38 ++++++++++++++ .../GHSA-5mw8-h933-2hv5.json | 38 ++++++++++++++ .../GHSA-5vrp-5g78-5924.json | 11 ++-- .../GHSA-5xg9-v43g-xgcj.json | 51 +++++++++++++++++++ .../GHSA-62f7-866g-78gg.json | 38 ++++++++++++++ .../GHSA-67w9-6p7h-rc7m.json | 11 ++-- .../GHSA-6c7m-rqmp-2r87.json | 38 ++++++++++++++ .../GHSA-6fw8-252j-cr2j.json | 38 ++++++++++++++ .../GHSA-6q42-8j33-m2fc.json | 38 ++++++++++++++ .../GHSA-7pr7-8f3r-ffxj.json | 38 ++++++++++++++ .../GHSA-7q36-59qh-gqjv.json | 11 ++-- .../GHSA-8797-vvp8-wj9v.json | 9 ++-- .../GHSA-87jf-8g46-rh2g.json | 38 ++++++++++++++ .../GHSA-9pxm-gmqm-gp3r.json | 38 ++++++++++++++ .../GHSA-c844-4fjf-3jhf.json | 38 ++++++++++++++ .../GHSA-c84x-657q-q6vq.json | 9 ++-- .../GHSA-cfq4-896j-74qc.json | 43 ++++++++++++++++ .../GHSA-crm2-q2cq-rqhj.json | 31 +++++++++++ .../GHSA-cv6v-3gfj-x2f5.json | 38 ++++++++++++++ .../GHSA-cwhx-w267-r8qh.json | 43 ++++++++++++++++ .../GHSA-f3fj-wq8c-9fq8.json | 38 ++++++++++++++ .../GHSA-f4h5-j74p-qq45.json | 38 ++++++++++++++ .../GHSA-fg93-gp73-8497.json | 11 ++-- .../GHSA-gj2j-3p2j-pmwr.json | 11 ++-- .../GHSA-h2xr-f73x-x5xm.json | 39 ++++++++++++++ .../GHSA-hmrp-qqm4-qjf7.json | 11 ++-- .../GHSA-hw6m-6w6g-wxq7.json | 43 ++++++++++++++++ .../GHSA-j7m9-gwcg-6hp9.json | 38 ++++++++++++++ .../GHSA-m5j8-89q3-q39q.json | 43 ++++++++++++++++ .../GHSA-mcpp-jhwq-85qq.json | 4 +- .../GHSA-mp47-48q3-3vmr.json | 38 ++++++++++++++ .../GHSA-mx5v-6xw3-6p2w.json | 38 ++++++++++++++ .../GHSA-p997-wfmc-cvcj.json | 6 ++- .../GHSA-pc8g-cqpp-27hp.json | 38 ++++++++++++++ .../GHSA-pg2r-prx2-mw84.json | 11 ++-- .../GHSA-qffh-9pr5-jcqg.json | 38 ++++++++++++++ .../GHSA-qv78-7pxw-jgx2.json | 38 ++++++++++++++ .../GHSA-v25r-h42w-j2vq.json | 2 +- .../GHSA-v3c5-gq46-x5cm.json | 11 ++-- .../GHSA-v56f-cfvv-mvc9.json | 38 ++++++++++++++ .../GHSA-v6fm-w4p3-p8mv.json | 38 ++++++++++++++ .../GHSA-vqf8-44qw-c23j.json | 38 ++++++++++++++ .../GHSA-w48h-jh8w-wm43.json | 11 ++-- .../GHSA-wpp2-87q7-h53v.json | 11 ++-- .../GHSA-wx8r-wq52-37w7.json | 38 ++++++++++++++ .../GHSA-x2xr-j725-65qf.json | 38 ++++++++++++++ .../GHSA-x6qp-hxvf-rr5v.json | 38 ++++++++++++++ 83 files changed, 1750 insertions(+), 152 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-2gg8-w5vr-ghvj/GHSA-2gg8-w5vr-ghvj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2v3g-4chr-x8h3/GHSA-2v3g-4chr-x8h3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3f48-f2h7-6g73/GHSA-3f48-f2h7-6g73.json create mode 100644 advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4638-h2rx-8qf2/GHSA-4638-h2rx-8qf2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5fhp-588g-xh47/GHSA-5fhp-588g-xh47.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5mw8-h933-2hv5/GHSA-5mw8-h933-2hv5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-62f7-866g-78gg/GHSA-62f7-866g-78gg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6c7m-rqmp-2r87/GHSA-6c7m-rqmp-2r87.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6fw8-252j-cr2j/GHSA-6fw8-252j-cr2j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6q42-8j33-m2fc/GHSA-6q42-8j33-m2fc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7pr7-8f3r-ffxj/GHSA-7pr7-8f3r-ffxj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-87jf-8g46-rh2g/GHSA-87jf-8g46-rh2g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9pxm-gmqm-gp3r/GHSA-9pxm-gmqm-gp3r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c844-4fjf-3jhf/GHSA-c844-4fjf-3jhf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-crm2-q2cq-rqhj/GHSA-crm2-q2cq-rqhj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cv6v-3gfj-x2f5/GHSA-cv6v-3gfj-x2f5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-cwhx-w267-r8qh/GHSA-cwhx-w267-r8qh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f3fj-wq8c-9fq8/GHSA-f3fj-wq8c-9fq8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f4h5-j74p-qq45/GHSA-f4h5-j74p-qq45.json create mode 100644 advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j7m9-gwcg-6hp9/GHSA-j7m9-gwcg-6hp9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m5j8-89q3-q39q/GHSA-m5j8-89q3-q39q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mp47-48q3-3vmr/GHSA-mp47-48q3-3vmr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mx5v-6xw3-6p2w/GHSA-mx5v-6xw3-6p2w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pc8g-cqpp-27hp/GHSA-pc8g-cqpp-27hp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qffh-9pr5-jcqg/GHSA-qffh-9pr5-jcqg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qv78-7pxw-jgx2/GHSA-qv78-7pxw-jgx2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v56f-cfvv-mvc9/GHSA-v56f-cfvv-mvc9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v6fm-w4p3-p8mv/GHSA-v6fm-w4p3-p8mv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vqf8-44qw-c23j/GHSA-vqf8-44qw-c23j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wx8r-wq52-37w7/GHSA-wx8r-wq52-37w7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x2xr-j725-65qf/GHSA-x2xr-j725-65qf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x6qp-hxvf-rr5v/GHSA-x6qp-hxvf-rr5v.json diff --git a/advisories/unreviewed/2024/02/GHSA-226m-fqfj-v6xp/GHSA-226m-fqfj-v6xp.json b/advisories/unreviewed/2024/02/GHSA-226m-fqfj-v6xp/GHSA-226m-fqfj-v6xp.json index 9f6c802781d..9852db0108e 100644 --- a/advisories/unreviewed/2024/02/GHSA-226m-fqfj-v6xp/GHSA-226m-fqfj-v6xp.json +++ b/advisories/unreviewed/2024/02/GHSA-226m-fqfj-v6xp/GHSA-226m-fqfj-v6xp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-226m-fqfj-v6xp", - "modified": "2024-02-29T03:33:11Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-29T03:33:11Z", "aliases": [ "CVE-2022-36677" ], "details": "Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:35:29Z" diff --git a/advisories/unreviewed/2024/02/GHSA-283x-r7vm-882q/GHSA-283x-r7vm-882q.json b/advisories/unreviewed/2024/02/GHSA-283x-r7vm-882q/GHSA-283x-r7vm-882q.json index 68f9a2552d1..1679a412387 100644 --- a/advisories/unreviewed/2024/02/GHSA-283x-r7vm-882q/GHSA-283x-r7vm-882q.json +++ b/advisories/unreviewed/2024/02/GHSA-283x-r7vm-882q/GHSA-283x-r7vm-882q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-283x-r7vm-882q", - "modified": "2024-02-29T03:33:17Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-22936" ], "details": "Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:44:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json b/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json index adc6a3d4517..4efea8a01ec 100644 --- a/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json +++ b/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q8j-579q-jx44", - "modified": "2024-02-15T06:31:36Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-15T06:31:36Z", "aliases": [ "CVE-2022-23090" @@ -21,11 +21,15 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:10.aio.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240415-0007" } ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json b/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json index ebea7f250ec..7286685098b 100644 --- a/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json +++ b/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rhh-97v9-2g42", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40111" ], "details": "In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3vf3-8x3v-cfhr/GHSA-3vf3-8x3v-cfhr.json b/advisories/unreviewed/2024/02/GHSA-3vf3-8x3v-cfhr/GHSA-3vf3-8x3v-cfhr.json index d05bc40c81a..f6eeeb02fd4 100644 --- a/advisories/unreviewed/2024/02/GHSA-3vf3-8x3v-cfhr/GHSA-3vf3-8x3v-cfhr.json +++ b/advisories/unreviewed/2024/02/GHSA-3vf3-8x3v-cfhr/GHSA-3vf3-8x3v-cfhr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3vf3-8x3v-cfhr", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2023-21165" ], "details": "In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T19:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3wcf-84jq-4rxx/GHSA-3wcf-84jq-4rxx.json b/advisories/unreviewed/2024/02/GHSA-3wcf-84jq-4rxx/GHSA-3wcf-84jq-4rxx.json index 1e3ae824b6b..56ec625f208 100644 --- a/advisories/unreviewed/2024/02/GHSA-3wcf-84jq-4rxx/GHSA-3wcf-84jq-4rxx.json +++ b/advisories/unreviewed/2024/02/GHSA-3wcf-84jq-4rxx/GHSA-3wcf-84jq-4rxx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wcf-84jq-4rxx", - "modified": "2024-05-02T00:30:47Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-02-29T18:30:59Z", "aliases": [ "CVE-2024-25180" ], "details": "An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the path '/pdf'.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T18:15:16Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json b/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json index 46d463bc174..ea866873a50 100644 --- a/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json +++ b/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mwq-x2m3-qxc6", - "modified": "2024-02-16T03:30:50Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-16T03:30:50Z", "aliases": [ "CVE-2024-0014" ], "details": "In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:50Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6hvh-59wp-qgpm/GHSA-6hvh-59wp-qgpm.json b/advisories/unreviewed/2024/02/GHSA-6hvh-59wp-qgpm/GHSA-6hvh-59wp-qgpm.json index 589a33f8933..5c4c4e315fe 100644 --- a/advisories/unreviewed/2024/02/GHSA-6hvh-59wp-qgpm/GHSA-6hvh-59wp-qgpm.json +++ b/advisories/unreviewed/2024/02/GHSA-6hvh-59wp-qgpm/GHSA-6hvh-59wp-qgpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hvh-59wp-qgpm", - "modified": "2024-02-29T00:30:22Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-29T00:30:22Z", "aliases": [ "CVE-2024-25351" ], "details": "SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T22:15:26Z" diff --git a/advisories/unreviewed/2024/02/GHSA-74rv-fq96-j6vr/GHSA-74rv-fq96-j6vr.json b/advisories/unreviewed/2024/02/GHSA-74rv-fq96-j6vr/GHSA-74rv-fq96-j6vr.json index 54832378db6..67fa740cfa9 100644 --- a/advisories/unreviewed/2024/02/GHSA-74rv-fq96-j6vr/GHSA-74rv-fq96-j6vr.json +++ b/advisories/unreviewed/2024/02/GHSA-74rv-fq96-j6vr/GHSA-74rv-fq96-j6vr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74rv-fq96-j6vr", - "modified": "2024-02-13T00:30:27Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-13T00:30:27Z", "aliases": [ "CVE-2024-24337" ], "details": "CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-12T22:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-754f-f3pv-5vpq/GHSA-754f-f3pv-5vpq.json b/advisories/unreviewed/2024/02/GHSA-754f-f3pv-5vpq/GHSA-754f-f3pv-5vpq.json index fcb380d0522..0722b3a0bef 100644 --- a/advisories/unreviewed/2024/02/GHSA-754f-f3pv-5vpq/GHSA-754f-f3pv-5vpq.json +++ b/advisories/unreviewed/2024/02/GHSA-754f-f3pv-5vpq/GHSA-754f-f3pv-5vpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-754f-f3pv-5vpq", - "modified": "2024-02-27T09:31:15Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-22T06:30:33Z", "aliases": [ "CVE-2024-26484" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T05:15:10Z" diff --git a/advisories/unreviewed/2024/02/GHSA-77c4-m4jj-64q2/GHSA-77c4-m4jj-64q2.json b/advisories/unreviewed/2024/02/GHSA-77c4-m4jj-64q2/GHSA-77c4-m4jj-64q2.json index 82ac7a9db5c..8cbc0668952 100644 --- a/advisories/unreviewed/2024/02/GHSA-77c4-m4jj-64q2/GHSA-77c4-m4jj-64q2.json +++ b/advisories/unreviewed/2024/02/GHSA-77c4-m4jj-64q2/GHSA-77c4-m4jj-64q2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-824x-hcr6-cqgr/GHSA-824x-hcr6-cqgr.json b/advisories/unreviewed/2024/02/GHSA-824x-hcr6-cqgr/GHSA-824x-hcr6-cqgr.json index 06346dfdc7c..14c7953b1a1 100644 --- a/advisories/unreviewed/2024/02/GHSA-824x-hcr6-cqgr/GHSA-824x-hcr6-cqgr.json +++ b/advisories/unreviewed/2024/02/GHSA-824x-hcr6-cqgr/GHSA-824x-hcr6-cqgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-824x-hcr6-cqgr", - "modified": "2024-02-14T21:30:33Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-14T21:30:33Z", "aliases": [ "CVE-2024-25165" ], "details": "A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T20:15:46Z" diff --git a/advisories/unreviewed/2024/02/GHSA-89x3-jgxj-39cx/GHSA-89x3-jgxj-39cx.json b/advisories/unreviewed/2024/02/GHSA-89x3-jgxj-39cx/GHSA-89x3-jgxj-39cx.json index 137d6b49cc8..bafcb8938d4 100644 --- a/advisories/unreviewed/2024/02/GHSA-89x3-jgxj-39cx/GHSA-89x3-jgxj-39cx.json +++ b/advisories/unreviewed/2024/02/GHSA-89x3-jgxj-39cx/GHSA-89x3-jgxj-39cx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-mmc3-qp8j-6fpj/GHSA-mmc3-qp8j-6fpj.json b/advisories/unreviewed/2024/02/GHSA-mmc3-qp8j-6fpj/GHSA-mmc3-qp8j-6fpj.json index 14f9e60060b..fa93da78267 100644 --- a/advisories/unreviewed/2024/02/GHSA-mmc3-qp8j-6fpj/GHSA-mmc3-qp8j-6fpj.json +++ b/advisories/unreviewed/2024/02/GHSA-mmc3-qp8j-6fpj/GHSA-mmc3-qp8j-6fpj.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json b/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json index 1f95ae28b0d..5a686dfe9ea 100644 --- a/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json +++ b/advisories/unreviewed/2024/02/GHSA-mmrc-cc78-9f9w/GHSA-mmrc-cc78-9f9w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-352" + "CWE-352", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-v57p-q7g2-4g2r/GHSA-v57p-q7g2-4g2r.json b/advisories/unreviewed/2024/02/GHSA-v57p-q7g2-4g2r/GHSA-v57p-q7g2-4g2r.json index b5abb4fb789..e7d88f53b88 100644 --- a/advisories/unreviewed/2024/02/GHSA-v57p-q7g2-4g2r/GHSA-v57p-q7g2-4g2r.json +++ b/advisories/unreviewed/2024/02/GHSA-v57p-q7g2-4g2r/GHSA-v57p-q7g2-4g2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v57p-q7g2-4g2r", - "modified": "2024-02-22T15:30:38Z", + "modified": "2024-08-26T21:30:31Z", "published": "2024-02-22T15:30:38Z", "aliases": [ "CVE-2024-25873" ], "details": "Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T14:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6vrh-rgrg-f5x4/GHSA-6vrh-rgrg-f5x4.json b/advisories/unreviewed/2024/03/GHSA-6vrh-rgrg-f5x4/GHSA-6vrh-rgrg-f5x4.json index e362cafc78d..606bfe43a48 100644 --- a/advisories/unreviewed/2024/03/GHSA-6vrh-rgrg-f5x4/GHSA-6vrh-rgrg-f5x4.json +++ b/advisories/unreviewed/2024/03/GHSA-6vrh-rgrg-f5x4/GHSA-6vrh-rgrg-f5x4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6vrh-rgrg-f5x4", - "modified": "2024-03-03T09:30:38Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-03-03T09:30:38Z", "aliases": [ "CVE-2024-25839" ], "details": "An issue was discovered in Webbax \"Super Newsletter\" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-03T09:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6xfp-g425-7cw6/GHSA-6xfp-g425-7cw6.json b/advisories/unreviewed/2024/03/GHSA-6xfp-g425-7cw6/GHSA-6xfp-g425-7cw6.json index f960e58247c..093383932dc 100644 --- a/advisories/unreviewed/2024/03/GHSA-6xfp-g425-7cw6/GHSA-6xfp-g425-7cw6.json +++ b/advisories/unreviewed/2024/03/GHSA-6xfp-g425-7cw6/GHSA-6xfp-g425-7cw6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xfp-g425-7cw6", - "modified": "2024-03-14T03:31:15Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-03-14T03:31:15Z", "aliases": [ "CVE-2024-28388" ], "details": "SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T03:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-726f-22p9-pqrr/GHSA-726f-22p9-pqrr.json b/advisories/unreviewed/2024/03/GHSA-726f-22p9-pqrr/GHSA-726f-22p9-pqrr.json index 8c29c3250de..acd35533fe4 100644 --- a/advisories/unreviewed/2024/03/GHSA-726f-22p9-pqrr/GHSA-726f-22p9-pqrr.json +++ b/advisories/unreviewed/2024/03/GHSA-726f-22p9-pqrr/GHSA-726f-22p9-pqrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-726f-22p9-pqrr", - "modified": "2024-03-06T00:31:27Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-03-06T00:31:27Z", "aliases": [ "CVE-2023-38946" ], "details": "An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplying a crafted cookie.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T00:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-89cw-fq2g-5v94/GHSA-89cw-fq2g-5v94.json b/advisories/unreviewed/2024/03/GHSA-89cw-fq2g-5v94/GHSA-89cw-fq2g-5v94.json index ba5e45a8cb9..4d6ddddb762 100644 --- a/advisories/unreviewed/2024/03/GHSA-89cw-fq2g-5v94/GHSA-89cw-fq2g-5v94.json +++ b/advisories/unreviewed/2024/03/GHSA-89cw-fq2g-5v94/GHSA-89cw-fq2g-5v94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89cw-fq2g-5v94", - "modified": "2024-04-24T03:30:45Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-03-14T15:34:06Z", "aliases": [ "CVE-2024-28323" ], "details": "The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T14:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jjxf-7hh9-8j8m/GHSA-jjxf-7hh9-8j8m.json b/advisories/unreviewed/2024/03/GHSA-jjxf-7hh9-8j8m/GHSA-jjxf-7hh9-8j8m.json index e84bf60792c..bc6ccba6755 100644 --- a/advisories/unreviewed/2024/03/GHSA-jjxf-7hh9-8j8m/GHSA-jjxf-7hh9-8j8m.json +++ b/advisories/unreviewed/2024/03/GHSA-jjxf-7hh9-8j8m/GHSA-jjxf-7hh9-8j8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjxf-7hh9-8j8m", - "modified": "2024-03-11T18:31:09Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-1068" ], "details": "The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:17Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pwmf-6266-xrmc/GHSA-pwmf-6266-xrmc.json b/advisories/unreviewed/2024/03/GHSA-pwmf-6266-xrmc/GHSA-pwmf-6266-xrmc.json index 487380bbbcd..d6f80d79953 100644 --- a/advisories/unreviewed/2024/03/GHSA-pwmf-6266-xrmc/GHSA-pwmf-6266-xrmc.json +++ b/advisories/unreviewed/2024/03/GHSA-pwmf-6266-xrmc/GHSA-pwmf-6266-xrmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pwmf-6266-xrmc", - "modified": "2024-03-02T00:31:31Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-03-02T00:31:31Z", "aliases": [ "CVE-2023-49545" ], "details": "A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json b/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json index 550bc67b488..040f4f84e8b 100644 --- a/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json +++ b/advisories/unreviewed/2024/04/GHSA-2p97-c8vf-r4rf/GHSA-2p97-c8vf-r4rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2p97-c8vf-r4rf", - "modified": "2024-04-08T12:30:32Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-08T12:30:32Z", "aliases": [ "CVE-2024-26574" ], "details": "Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-277" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T12:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json b/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json index abc56046319..6415b6d88a1 100644 --- a/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json +++ b/advisories/unreviewed/2024/04/GHSA-gpf5-g943-4fxx/GHSA-gpf5-g943-4fxx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpf5-g943-4fxx", - "modified": "2024-04-08T15:30:33Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-08T15:30:33Z", "aliases": [ "CVE-2024-31815" ], "details": "In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json b/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json index a54532f2c13..d7060055698 100644 --- a/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json +++ b/advisories/unreviewed/2024/04/GHSA-jx7f-v5r5-55j4/GHSA-jx7f-v5r5-55j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx7f-v5r5-55j4", - "modified": "2024-06-30T12:31:10Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-08T00:30:46Z", "aliases": [ "CVE-2020-36829" ], "details": "The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T00:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json b/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json index a0aa05112d9..655c892eaa0 100644 --- a/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json +++ b/advisories/unreviewed/2024/04/GHSA-mq6j-35mg-9rj6/GHSA-mq6j-35mg-9rj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mq6j-35mg-9rj6", - "modified": "2024-04-08T03:30:52Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-08T03:30:52Z", "aliases": [ "CVE-2023-52533" ], "details": "In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-391" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json b/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json index 5aacb5325ce..7d1e171b205 100644 --- a/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json +++ b/advisories/unreviewed/2024/04/GHSA-r247-cqp5-chrp/GHSA-r247-cqp5-chrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r247-cqp5-chrp", - "modified": "2024-04-05T21:32:44Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-05T21:32:44Z", "aliases": [ "CVE-2024-29752" ], "details": "In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json b/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json index 40a636bd559..45b85566163 100644 --- a/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json +++ b/advisories/unreviewed/2024/04/GHSA-wgrq-q2w8-p9x4/GHSA-wgrq-q2w8-p9x4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wgrq-q2w8-p9x4", - "modified": "2024-04-08T21:31:16Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-08T21:31:16Z", "aliases": [ "CVE-2024-23086" ], "details": "Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json b/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json index 42b12c61fd9..150ed9e7cb9 100644 --- a/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json +++ b/advisories/unreviewed/2024/04/GHSA-wxvv-7x57-mjgj/GHSA-wxvv-7x57-mjgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxvv-7x57-mjgj", - "modified": "2024-04-09T00:30:41Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-04-09T00:30:41Z", "aliases": [ "CVE-2024-22949" ], "details": "JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T23:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qvwq-g2x2-px28/GHSA-qvwq-g2x2-px28.json b/advisories/unreviewed/2024/05/GHSA-qvwq-g2x2-px28/GHSA-qvwq-g2x2-px28.json index d4f27c45204..81dce2f23c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-qvwq-g2x2-px28/GHSA-qvwq-g2x2-px28.json +++ b/advisories/unreviewed/2024/05/GHSA-qvwq-g2x2-px28/GHSA-qvwq-g2x2-px28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvwq-g2x2-px28", - "modified": "2024-05-22T18:30:40Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-05-22T18:30:40Z", "aliases": [ "CVE-2024-33225" ], "details": "An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T16:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2gg8-w5vr-ghvj/GHSA-2gg8-w5vr-ghvj.json b/advisories/unreviewed/2024/08/GHSA-2gg8-w5vr-ghvj/GHSA-2gg8-w5vr-ghvj.json new file mode 100644 index 00000000000..45b272dfb09 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2gg8-w5vr-ghvj/GHSA-2gg8-w5vr-ghvj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gg8-w5vr-ghvj", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43299" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Team SpeedyCache.This issue affects SpeedyCache: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/speedycache/wordpress-speedycache-plugin-1-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2v3g-4chr-x8h3/GHSA-2v3g-4chr-x8h3.json b/advisories/unreviewed/2024/08/GHSA-2v3g-4chr-x8h3/GHSA-2v3g-4chr-x8h3.json new file mode 100644 index 00000000000..ca6d02e18e0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2v3g-4chr-x8h3/GHSA-2v3g-4chr-x8h3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v3g-4chr-x8h3", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43258" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/store-locator-le/wordpress-store-locator-plus-for-wordpress-plugin-2311-17-01-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json b/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json new file mode 100644 index 00000000000..4976cfbdc48 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-329h-fcrp-rfh4/GHSA-329h-fcrp-rfh4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-329h-fcrp-rfh4", + "modified": "2024-08-26T21:30:33Z", + "published": "2024-08-26T21:30:33Z", + "aliases": [ + "CVE-2024-42906" + ], + "details": "TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42906" + }, + { + "type": "WEB", + "url": "https://github.com/Alkatraz97/CVEs/blob/main/CVE-2024-42906.md" + }, + { + "type": "WEB", + "url": "https://testlink.org" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3f48-f2h7-6g73/GHSA-3f48-f2h7-6g73.json b/advisories/unreviewed/2024/08/GHSA-3f48-f2h7-6g73/GHSA-3f48-f2h7-6g73.json new file mode 100644 index 00000000000..b8c3b14c908 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3f48-f2h7-6g73/GHSA-3f48-f2h7-6g73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f48-f2h7-6g73", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43287" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mailin/wordpress-brevo-plugin-3-1-82-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json b/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json new file mode 100644 index 00000000000..d7c3b4db827 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-42m4-gw8j-vjvg/GHSA-42m4-gw8j-vjvg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42m4-gw8j-vjvg", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-44793" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44793" + }, + { + "type": "WEB", + "url": "https://github.com/WhatCD/Gazelle/issues/131" + }, + { + "type": "WEB", + "url": "https://github.com/WhatCD/Gazelle" + }, + { + "type": "WEB", + "url": "http://gazelle.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4638-h2rx-8qf2/GHSA-4638-h2rx-8qf2.json b/advisories/unreviewed/2024/08/GHSA-4638-h2rx-8qf2/GHSA-4638-h2rx-8qf2.json new file mode 100644 index 00000000000..2b111aeda30 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4638-h2rx-8qf2/GHSA-4638-h2rx-8qf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4638-h2rx-8qf2", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43337" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43337" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/brave-popup-builder/wordpress-brave-plugin-0-7-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5fhp-588g-xh47/GHSA-5fhp-588g-xh47.json b/advisories/unreviewed/2024/08/GHSA-5fhp-588g-xh47/GHSA-5fhp-588g-xh47.json new file mode 100644 index 00000000000..99d1fbecbe5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5fhp-588g-xh47/GHSA-5fhp-588g-xh47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fhp-588g-xh47", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43295" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43295" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-data-access/wordpress-wp-data-access-plugin-5-5-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5mw8-h933-2hv5/GHSA-5mw8-h933-2hv5.json b/advisories/unreviewed/2024/08/GHSA-5mw8-h933-2hv5/GHSA-5mw8-h933-2hv5.json new file mode 100644 index 00000000000..4d1600d84d3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5mw8-h933-2hv5/GHSA-5mw8-h933-2hv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mw8-h933-2hv5", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43116" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43116" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-local-avatars/wordpress-simple-local-avatars-plugin-2-7-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json b/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json index 660ae43a7c8..5f0dde6fc35 100644 --- a/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json +++ b/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vrp-5g78-5924", - "modified": "2024-08-26T18:33:34Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:34Z", "aliases": [ "CVE-2024-44555" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json b/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json new file mode 100644 index 00000000000..a9d87a1a2cb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5xg9-v43g-xgcj/GHSA-5xg9-v43g-xgcj.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xg9-v43g-xgcj", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-8105" + ], + "details": "A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8105" + }, + { + "type": "WEB", + "url": "https://github.com/binarly-io/Vulnerability-REsearch/blob/main/PKfail/BRLY-2024-005.md" + }, + { + "type": "WEB", + "url": "https://security.ts.fujitsu.com/ProductSecurity/content/Fujitsu-PSIRT-FJ-ISS-2024-072412-Security-Notice.pdf" + }, + { + "type": "WEB", + "url": "https://uefi.org/specs/UEFI/2.9_A/32_Secure_Boot_and_Driver_Signing.html" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-07-25-001.html" + }, + { + "type": "WEB", + "url": "https://www.supermicro.com/en/support/security_PKFAIL_Jul_2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-62f7-866g-78gg/GHSA-62f7-866g-78gg.json b/advisories/unreviewed/2024/08/GHSA-62f7-866g-78gg/GHSA-62f7-866g-78gg.json new file mode 100644 index 00000000000..f5cae905c4a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-62f7-866g-78gg/GHSA-62f7-866g-78gg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62f7-866g-78gg", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43259" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in JEM Plugins Order Export for WooCommerce.This issue affects Order Export for WooCommerce: from n/a through 3.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/order-export-and-more-for-woocommerce/wordpress-order-export-for-woocommerce-plugin-3-23-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json b/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json index 97ff23b0cfe..ab24c1929e8 100644 --- a/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json +++ b/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67w9-6p7h-rc7m", - "modified": "2024-08-26T18:33:33Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:33Z", "aliases": [ "CVE-2024-41285" ], "details": "A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6c7m-rqmp-2r87/GHSA-6c7m-rqmp-2r87.json b/advisories/unreviewed/2024/08/GHSA-6c7m-rqmp-2r87/GHSA-6c7m-rqmp-2r87.json new file mode 100644 index 00000000000..179a881e8c9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6c7m-rqmp-2r87/GHSA-6c7m-rqmp-2r87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c7m-rqmp-2r87", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43269" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43269" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-backitup/wordpress-backup-and-restore-wordpress-plugin-1-50-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6fw8-252j-cr2j/GHSA-6fw8-252j-cr2j.json b/advisories/unreviewed/2024/08/GHSA-6fw8-252j-cr2j/GHSA-6fw8-252j-cr2j.json new file mode 100644 index 00000000000..8836ae11d00 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6fw8-252j-cr2j/GHSA-6fw8-252j-cr2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fw8-252j-cr2j", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43325" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dark-mode-for-wp-dashboard/wordpress-dark-mode-for-wp-dashboard-plugin-1-2-3-cross-site-request-forgery-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6q42-8j33-m2fc/GHSA-6q42-8j33-m2fc.json b/advisories/unreviewed/2024/08/GHSA-6q42-8j33-m2fc/GHSA-6q42-8j33-m2fc.json new file mode 100644 index 00000000000..4ae7292d801 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6q42-8j33-m2fc/GHSA-6q42-8j33-m2fc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q42-8j33-m2fc", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-39657" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39657" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sender-net-automated-emails/wordpress-sender-newsletter-sms-and-email-marketing-automation-for-woocommerce-plugin-2-6-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7pr7-8f3r-ffxj/GHSA-7pr7-8f3r-ffxj.json b/advisories/unreviewed/2024/08/GHSA-7pr7-8f3r-ffxj/GHSA-7pr7-8f3r-ffxj.json new file mode 100644 index 00000000000..b66c3699068 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7pr7-8f3r-ffxj/GHSA-7pr7-8f3r-ffxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pr7-8f3r-ffxj", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43230" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Shared Files – File Upload Form Shared Files.This issue affects Shared Files: from n/a through 1.7.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shared-files/wordpress-shared-files-premium-download-manager-secure-file-sharing-with-frontend-file-upload-plugin-1-7-28-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json b/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json index 7f38750d847..bd8f1583d6d 100644 --- a/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json +++ b/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7q36-59qh-gqjv", - "modified": "2024-08-26T18:33:33Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:33Z", "aliases": [ "CVE-2024-42791" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json b/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json index 60720427759..11512c08819 100644 --- a/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json +++ b/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8797-vvp8-wj9v", - "modified": "2024-08-26T18:33:34Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:34Z", "aliases": [ "CVE-2024-44552" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-87jf-8g46-rh2g/GHSA-87jf-8g46-rh2g.json b/advisories/unreviewed/2024/08/GHSA-87jf-8g46-rh2g/GHSA-87jf-8g46-rh2g.json new file mode 100644 index 00000000000..9f71eb3a244 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-87jf-8g46-rh2g/GHSA-87jf-8g46-rh2g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87jf-8g46-rh2g", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43915" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43915" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zephyr-project-manager/wordpress-zephyr-project-manager-plugin-3-3-102-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9pxm-gmqm-gp3r/GHSA-9pxm-gmqm-gp3r.json b/advisories/unreviewed/2024/08/GHSA-9pxm-gmqm-gp3r/GHSA-9pxm-gmqm-gp3r.json new file mode 100644 index 00000000000..263d8891cf3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9pxm-gmqm-gp3r/GHSA-9pxm-gmqm-gp3r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pxm-gmqm-gp3r", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43264" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mediavine Create by Mediavine.This issue affects Create by Mediavine: from n/a through 1.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mediavine-create/wordpress-create-by-mediavine-plugin-1-9-7-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c844-4fjf-3jhf/GHSA-c844-4fjf-3jhf.json b/advisories/unreviewed/2024/08/GHSA-c844-4fjf-3jhf/GHSA-c844-4fjf-3jhf.json new file mode 100644 index 00000000000..d57159cfd52 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c844-4fjf-3jhf/GHSA-c844-4fjf-3jhf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c844-4fjf-3jhf", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43255" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore allows Cross-Site Scripting (XSS).This issue affects MyBookTable Bookstore: from n/a through 3.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43255" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mybooktable/wordpress-mybooktable-bookstore-by-stormhill-media-plugin-3-3-9-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json b/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json index 29d4b0e51d5..ffcf9d46ae8 100644 --- a/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json +++ b/advisories/unreviewed/2024/08/GHSA-c84x-657q-q6vq/GHSA-c84x-657q-q6vq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c84x-657q-q6vq", - "modified": "2024-08-26T06:30:47Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T06:30:47Z", "aliases": [ "CVE-2024-7313" ], "details": "The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json b/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json new file mode 100644 index 00000000000..6ad63acf605 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cfq4-896j-74qc/GHSA-cfq4-896j-74qc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfq4-896j-74qc", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-44795" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44795" + }, + { + "type": "WEB", + "url": "https://github.com/WhatCD/Gazelle/issues/129" + }, + { + "type": "WEB", + "url": "https://github.com/WhatCD/Gazelle" + }, + { + "type": "WEB", + "url": "http://gazelle.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-crm2-q2cq-rqhj/GHSA-crm2-q2cq-rqhj.json b/advisories/unreviewed/2024/08/GHSA-crm2-q2cq-rqhj/GHSA-crm2-q2cq-rqhj.json new file mode 100644 index 00000000000..b02449cb414 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-crm2-q2cq-rqhj/GHSA-crm2-q2cq-rqhj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crm2-q2cq-rqhj", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-7989" + ], + "details": "Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that the issue does not pose a security risk as it falls within the expected functionality and security controls of the application. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7989" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cv6v-3gfj-x2f5/GHSA-cv6v-3gfj-x2f5.json b/advisories/unreviewed/2024/08/GHSA-cv6v-3gfj-x2f5/GHSA-cv6v-3gfj-x2f5.json new file mode 100644 index 00000000000..87ce6902264 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cv6v-3gfj-x2f5/GHSA-cv6v-3gfj-x2f5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv6v-3gfj-x2f5", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-39645" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tutor/wordpress-tutor-lms-plugin-2-7-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cwhx-w267-r8qh/GHSA-cwhx-w267-r8qh.json b/advisories/unreviewed/2024/08/GHSA-cwhx-w267-r8qh/GHSA-cwhx-w267-r8qh.json new file mode 100644 index 00000000000..cd63b1a91ca --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cwhx-w267-r8qh/GHSA-cwhx-w267-r8qh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwhx-w267-r8qh", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-44794" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44794" + }, + { + "type": "WEB", + "url": "https://github.com/xiebruce/PicUploader/issues/91" + }, + { + "type": "WEB", + "url": "https://github.com/xiebruce/PicUploader" + }, + { + "type": "WEB", + "url": "http://picuploader.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f3fj-wq8c-9fq8/GHSA-f3fj-wq8c-9fq8.json b/advisories/unreviewed/2024/08/GHSA-f3fj-wq8c-9fq8/GHSA-f3fj-wq8c-9fq8.json new file mode 100644 index 00000000000..a60e5e7603d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f3fj-wq8c-9fq8/GHSA-f3fj-wq8c-9fq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3fj-wq8c-9fq8", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43265" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-analytify/wordpress-analytify-plugin-5-3-1-csrf-leading-to-optout-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f4h5-j74p-qq45/GHSA-f4h5-j74p-qq45.json b/advisories/unreviewed/2024/08/GHSA-f4h5-j74p-qq45/GHSA-f4h5-j74p-qq45.json new file mode 100644 index 00000000000..004f2fe66f4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f4h5-j74p-qq45/GHSA-f4h5-j74p-qq45.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4h5-j74p-qq45", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43251" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bitformpro/wordpress-bit-form-pro-plugin-2-6-4-authenticated-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json b/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json index daf11f1c484..16fb6f77ebc 100644 --- a/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json +++ b/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fg93-gp73-8497", - "modified": "2024-08-26T18:33:33Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:33Z", "aliases": [ "CVE-2024-42788" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/music/ajax.php?action=save_music\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via \"title\" & \"artist\" parameter fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json b/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json index f5044d2ecc1..9fa0cc464f9 100644 --- a/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json +++ b/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gj2j-3p2j-pmwr", - "modified": "2024-08-26T18:33:34Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:34Z", "aliases": [ "CVE-2024-44549" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json b/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json new file mode 100644 index 00000000000..a102adb769f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h2xr-f73x-x5xm/GHSA-h2xr-f73x-x5xm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2xr-f73x-x5xm", + "modified": "2024-08-26T21:30:33Z", + "published": "2024-08-26T21:30:33Z", + "aliases": [ + "CVE-2024-28077" + ], + "details": "A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28077" + }, + { + "type": "WEB", + "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Denial%20of%20service.md" + }, + { + "type": "WEB", + "url": "https://gl-inet.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json b/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json index ad3ad48589e..3338efc182e 100644 --- a/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json +++ b/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmrp-qqm4-qjf7", - "modified": "2024-08-26T18:33:34Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:34Z", "aliases": [ "CVE-2024-44557" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T16:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json b/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json new file mode 100644 index 00000000000..6f9b5dc8f11 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hw6m-6w6g-wxq7/GHSA-hw6m-6w6g-wxq7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw6m-6w6g-wxq7", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-44797" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44797" + }, + { + "type": "WEB", + "url": "https://github.com/WhatCD/Gazelle/issues/130" + }, + { + "type": "WEB", + "url": "https://github.com/WhatCD/Gazelle" + }, + { + "type": "WEB", + "url": "http://gazelle.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j7m9-gwcg-6hp9/GHSA-j7m9-gwcg-6hp9.json b/advisories/unreviewed/2024/08/GHSA-j7m9-gwcg-6hp9/GHSA-j7m9-gwcg-6hp9.json new file mode 100644 index 00000000000..e831daa2608 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j7m9-gwcg-6hp9/GHSA-j7m9-gwcg-6hp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7m9-gwcg-6hp9", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-39641" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-plugin-4-2-6-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m5j8-89q3-q39q/GHSA-m5j8-89q3-q39q.json b/advisories/unreviewed/2024/08/GHSA-m5j8-89q3-q39q/GHSA-m5j8-89q3-q39q.json new file mode 100644 index 00000000000..535099e3d50 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m5j8-89q3-q39q/GHSA-m5j8-89q3-q39q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5j8-89q3-q39q", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-44796" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44796" + }, + { + "type": "WEB", + "url": "https://github.com/xiebruce/PicUploader/issues/90" + }, + { + "type": "WEB", + "url": "https://github.com/xiebruce/PicUploader" + }, + { + "type": "WEB", + "url": "http://picuploader.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json b/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json index c297cbce384..03d15b8c327 100644 --- a/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json +++ b/advisories/unreviewed/2024/08/GHSA-mcpp-jhwq-85qq/GHSA-mcpp-jhwq-85qq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcpp-jhwq-85qq", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-7987" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-mp47-48q3-3vmr/GHSA-mp47-48q3-3vmr.json b/advisories/unreviewed/2024/08/GHSA-mp47-48q3-3vmr/GHSA-mp47-48q3-3vmr.json new file mode 100644 index 00000000000..0d8fc121c54 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mp47-48q3-3vmr/GHSA-mp47-48q3-3vmr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp47-48q3-3vmr", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43356" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43356" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/oik/wordpress-oik-plugin-4-12-0-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mx5v-6xw3-6p2w/GHSA-mx5v-6xw3-6p2w.json b/advisories/unreviewed/2024/08/GHSA-mx5v-6xw3-6p2w/GHSA-mx5v-6xw3-6p2w.json new file mode 100644 index 00000000000..51e0e5424a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mx5v-6xw3-6p2w/GHSA-mx5v-6xw3-6p2w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx5v-6xw3-6p2w", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43117" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43117" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hummingbird-performance/wordpress-hummingbird-plugin-3-9-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json b/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json index bd3a7edc5fa..aadfa7e47ba 100644 --- a/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json +++ b/advisories/unreviewed/2024/08/GHSA-p997-wfmc-cvcj/GHSA-p997-wfmc-cvcj.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p997-wfmc-cvcj", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-7988" ], "details": "A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-pc8g-cqpp-27hp/GHSA-pc8g-cqpp-27hp.json b/advisories/unreviewed/2024/08/GHSA-pc8g-cqpp-27hp/GHSA-pc8g-cqpp-27hp.json new file mode 100644 index 00000000000..de393c6cb58 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pc8g-cqpp-27hp/GHSA-pc8g-cqpp-27hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc8g-cqpp-27hp", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-39628" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ninja-forms/wordpress-ninja-forms-plugin-3-8-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json b/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json index d5604abd618..2e08896df28 100644 --- a/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json +++ b/advisories/unreviewed/2024/08/GHSA-pg2r-prx2-mw84/GHSA-pg2r-prx2-mw84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pg2r-prx2-mw84", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-44556" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T13:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qffh-9pr5-jcqg/GHSA-qffh-9pr5-jcqg.json b/advisories/unreviewed/2024/08/GHSA-qffh-9pr5-jcqg/GHSA-qffh-9pr5-jcqg.json new file mode 100644 index 00000000000..52882c52588 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qffh-9pr5-jcqg/GHSA-qffh-9pr5-jcqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qffh-9pr5-jcqg", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43257" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leopard-wordpress-offload-media/wordpress-leopard-wordpress-offload-media-plugin-2-0-36-subscriber-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qv78-7pxw-jgx2/GHSA-qv78-7pxw-jgx2.json b/advisories/unreviewed/2024/08/GHSA-qv78-7pxw-jgx2/GHSA-qv78-7pxw-jgx2.json new file mode 100644 index 00000000000..38f1714fb2e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qv78-7pxw-jgx2/GHSA-qv78-7pxw-jgx2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv78-7pxw-jgx2", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43316" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43316" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/checkout-plugins-stripe-woo/wordpress-stripe-payments-for-woocommerce-plugin-1-9-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v25r-h42w-j2vq/GHSA-v25r-h42w-j2vq.json b/advisories/unreviewed/2024/08/GHSA-v25r-h42w-j2vq/GHSA-v25r-h42w-j2vq.json index 44aef0a76ae..aea0911fe44 100644 --- a/advisories/unreviewed/2024/08/GHSA-v25r-h42w-j2vq/GHSA-v25r-h42w-j2vq.json +++ b/advisories/unreviewed/2024/08/GHSA-v25r-h42w-j2vq/GHSA-v25r-h42w-j2vq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v25r-h42w-j2vq", - "modified": "2024-08-20T03:32:24Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-08-20T03:32:24Z", "aliases": [ "CVE-2024-5932" diff --git a/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json b/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json index 56460f943e1..4663cc2a9dd 100644 --- a/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json +++ b/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3c5-gq46-x5cm", - "modified": "2024-08-26T18:33:34Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:34Z", "aliases": [ "CVE-2024-42792" ], "details": "A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T17:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-v56f-cfvv-mvc9/GHSA-v56f-cfvv-mvc9.json b/advisories/unreviewed/2024/08/GHSA-v56f-cfvv-mvc9/GHSA-v56f-cfvv-mvc9.json new file mode 100644 index 00000000000..d9757ecd523 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v56f-cfvv-mvc9/GHSA-v56f-cfvv-mvc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v56f-cfvv-mvc9", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43336" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager.This issue affects WP User Manager: from n/a through 2.9.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43336" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-user-manager/wordpress-wp-user-manager-user-profile-builder-membership-plugin-2-9-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v6fm-w4p3-p8mv/GHSA-v6fm-w4p3-p8mv.json b/advisories/unreviewed/2024/08/GHSA-v6fm-w4p3-p8mv/GHSA-v6fm-w4p3-p8mv.json new file mode 100644 index 00000000000..400f1155d91 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v6fm-w4p3-p8mv/GHSA-v6fm-w4p3-p8mv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6fm-w4p3-p8mv", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43916" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43916" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zephyr-project-manager/wordpress-zephyr-project-manager-plugin-3-3-102-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vqf8-44qw-c23j/GHSA-vqf8-44qw-c23j.json b/advisories/unreviewed/2024/08/GHSA-vqf8-44qw-c23j/GHSA-vqf8-44qw-c23j.json new file mode 100644 index 00000000000..1b6b16b881f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vqf8-44qw-c23j/GHSA-vqf8-44qw-c23j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqf8-44qw-c23j", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43301" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/olympus-google-fonts/wordpress-fonts-plugin-3-7-7-cross-site-request-forgery-csrf-to-stored-xssvulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json b/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json index 0613790ddf7..844b7c2ffa8 100644 --- a/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json +++ b/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w48h-jh8w-wm43", - "modified": "2024-08-26T18:33:34Z", + "modified": "2024-08-26T21:30:33Z", "published": "2024-08-26T18:33:34Z", "aliases": [ "CVE-2024-41444" ], "details": "SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T17:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wpp2-87q7-h53v/GHSA-wpp2-87q7-h53v.json b/advisories/unreviewed/2024/08/GHSA-wpp2-87q7-h53v/GHSA-wpp2-87q7-h53v.json index 7de8296d528..a2a2fa17350 100644 --- a/advisories/unreviewed/2024/08/GHSA-wpp2-87q7-h53v/GHSA-wpp2-87q7-h53v.json +++ b/advisories/unreviewed/2024/08/GHSA-wpp2-87q7-h53v/GHSA-wpp2-87q7-h53v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpp2-87q7-h53v", - "modified": "2024-08-25T00:30:32Z", + "modified": "2024-08-26T21:30:32Z", "published": "2024-08-25T00:30:32Z", "aliases": [ "CVE-2024-45237" ], "details": "An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a 2-byte buffer without properly sanitizing its length, leading to a buffer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-24T23:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wx8r-wq52-37w7/GHSA-wx8r-wq52-37w7.json b/advisories/unreviewed/2024/08/GHSA-wx8r-wq52-37w7/GHSA-wx8r-wq52-37w7.json new file mode 100644 index 00000000000..093d228af54 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wx8r-wq52-37w7/GHSA-wx8r-wq52-37w7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx8r-wq52-37w7", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43340" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43340" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-form-integration/wordpress-afi-the-easiest-integration-plugin-plugin-1-89-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x2xr-j725-65qf/GHSA-x2xr-j725-65qf.json b/advisories/unreviewed/2024/08/GHSA-x2xr-j725-65qf/GHSA-x2xr-j725-65qf.json new file mode 100644 index 00000000000..a457b2584ee --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x2xr-j725-65qf/GHSA-x2xr-j725-65qf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2xr-j725-65qf", + "modified": "2024-08-26T21:30:35Z", + "published": "2024-08-26T21:30:35Z", + "aliases": [ + "CVE-2024-43339" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43339" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-webinarsystem/wordpress-wordpress-webinar-plugin-webinarpress-plugin-1-33-20-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x6qp-hxvf-rr5v/GHSA-x6qp-hxvf-rr5v.json b/advisories/unreviewed/2024/08/GHSA-x6qp-hxvf-rr5v/GHSA-x6qp-hxvf-rr5v.json new file mode 100644 index 00000000000..1888d768364 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6qp-hxvf-rr5v/GHSA-x6qp-hxvf-rr5v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6qp-hxvf-rr5v", + "modified": "2024-08-26T21:30:34Z", + "published": "2024-08-26T21:30:34Z", + "aliases": [ + "CVE-2024-43214" + ], + "details": "Missing Authorization vulnerability in myCred.This issue affects myCred: from n/a through 2.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mycred/wordpress-mycred-plugin-2-7-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T21:15:24Z" + } +} \ No newline at end of file