diff --git a/advisories/unreviewed/2024/06/GHSA-2f47-vffr-pwwf/GHSA-2f47-vffr-pwwf.json b/advisories/unreviewed/2024/06/GHSA-2f47-vffr-pwwf/GHSA-2f47-vffr-pwwf.json new file mode 100644 index 00000000000..5eb61bd99c3 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-2f47-vffr-pwwf/GHSA-2f47-vffr-pwwf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f47-vffr-pwwf", + "modified": "2024-06-25T12:30:58Z", + "published": "2024-06-25T12:30:58Z", + "aliases": [ + "CVE-2024-6307" + ], + "details": "WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6307" + }, + { + "type": "WEB", + "url": "https://core.trac.wordpress.org/changeset/58472" + }, + { + "type": "WEB", + "url": "https://core.trac.wordpress.org/changeset/58473" + }, + { + "type": "WEB", + "url": "https://wordpress.org/news/2024/06/wordpress-6-5-5" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bc0d36f8-6569-49a1-b722-5cf57c4bb32a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json b/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json new file mode 100644 index 00000000000..1a98142bae8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-4wv7-jg5w-qpfh/GHSA-4wv7-jg5w-qpfh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wv7-jg5w-qpfh", + "modified": "2024-06-25T12:30:58Z", + "published": "2024-06-25T12:30:58Z", + "aliases": [ + "CVE-2024-28832" + ], + "details": "Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28832" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json b/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json new file mode 100644 index 00000000000..649e754fbcb --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-5cpc-fv98-27hq/GHSA-5cpc-fv98-27hq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cpc-fv98-27hq", + "modified": "2024-06-25T12:30:55Z", + "published": "2024-06-25T12:30:55Z", + "aliases": [ + "CVE-2024-4640" + ], + "details": "OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4640" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-242550-oncell-g3470a-lte-series-multiple-web-application-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9jqr-jfvv-cj9j/GHSA-9jqr-jfvv-cj9j.json b/advisories/unreviewed/2024/06/GHSA-9jqr-jfvv-cj9j/GHSA-9jqr-jfvv-cj9j.json new file mode 100644 index 00000000000..5cb475cd912 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9jqr-jfvv-cj9j/GHSA-9jqr-jfvv-cj9j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jqr-jfvv-cj9j", + "modified": "2024-06-25T12:30:55Z", + "published": "2024-06-25T12:30:55Z", + "aliases": [ + "CVE-2024-4641" + ], + "details": "OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4641" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-242550-oncell-g3470a-lte-series-multiple-web-application-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-134" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json b/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json new file mode 100644 index 00000000000..2da00068ef0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-c8f8-j53j-393c/GHSA-c8f8-j53j-393c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8f8-j53j-393c", + "modified": "2024-06-25T12:30:55Z", + "published": "2024-06-25T12:30:55Z", + "aliases": [ + "CVE-2024-4639" + ], + "details": "OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4639" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-242550-oncell-g3470a-lte-series-multiple-web-application-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-f8vg-5x7g-9fr8/GHSA-f8vg-5x7g-9fr8.json b/advisories/unreviewed/2024/06/GHSA-f8vg-5x7g-9fr8/GHSA-f8vg-5x7g-9fr8.json new file mode 100644 index 00000000000..0f563dbc642 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-f8vg-5x7g-9fr8/GHSA-f8vg-5x7g-9fr8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8vg-5x7g-9fr8", + "modified": "2024-06-25T12:30:56Z", + "published": "2024-06-25T12:30:56Z", + "aliases": [ + "CVE-2024-5216" + ], + "details": "A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to create users with excessively bulky texts in the username field. This exploit results in the user management panel becoming unresponsive, preventing administrators from performing critical user management actions such as editing, suspending, or deleting users. The impact of this vulnerability includes administrative paralysis, compromised security, and operational disruption, as it allows malicious users to perpetuate their presence within the system indefinitely, undermines the system's security posture, and degrades overall system performance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5216" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/3ef009de73c837f9025df8bba62572885c70c72f" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8ec14991-ee35-493d-a8d3-21a1cfd57869" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ffj2-4hgp-mvgh/GHSA-ffj2-4hgp-mvgh.json b/advisories/unreviewed/2024/06/GHSA-ffj2-4hgp-mvgh/GHSA-ffj2-4hgp-mvgh.json new file mode 100644 index 00000000000..a9c7ab4d485 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-ffj2-4hgp-mvgh/GHSA-ffj2-4hgp-mvgh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffj2-4hgp-mvgh", + "modified": "2024-06-25T12:30:57Z", + "published": "2024-06-25T12:30:57Z", + "aliases": [ + "CVE-2024-6305" + ], + "details": "WordPress Core is vulnerable to Stored Cross-Site Scripting via the Template Part Block in various versions up to 6.5.5 due to insufficient input sanitization and output escaping on the 'tagName' attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6305" + }, + { + "type": "WEB", + "url": "https://core.trac.wordpress.org/changeset/58471" + }, + { + "type": "WEB", + "url": "https://wordpress.org/news/2024/06/wordpress-6-5-5" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2a225ccb-a7dc-4437-bd97-b309d6ae6a47?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json b/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json new file mode 100644 index 00000000000..3c34a29f303 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hx7g-cqpx-p72r/GHSA-hx7g-cqpx-p72r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx7g-cqpx-p72r", + "modified": "2024-06-25T12:30:58Z", + "published": "2024-06-25T12:30:57Z", + "aliases": [ + "CVE-2024-28831" + ], + "details": "Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28831" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vh29-7vg4-p7f4/GHSA-vh29-7vg4-p7f4.json b/advisories/unreviewed/2024/06/GHSA-vh29-7vg4-p7f4/GHSA-vh29-7vg4-p7f4.json new file mode 100644 index 00000000000..68cac957db0 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-vh29-7vg4-p7f4/GHSA-vh29-7vg4-p7f4.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh29-7vg4-p7f4", + "modified": "2024-06-25T12:30:57Z", + "published": "2024-06-25T12:30:57Z", + "aliases": [ + "CVE-2024-6306" + ], + "details": "WordPress Core is vulnerable to Directory Traversal in various versions up to 6.5.5 via the Template Part block. This makes it possible for authenticated attackers, with Contributor-level access and above, to include arbitrary HTML Files on sites running Windows.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6306" + }, + { + "type": "WEB", + "url": "https://core.trac.wordpress.org/changeset/58470" + }, + { + "type": "WEB", + "url": "https://wordpress.org/news/2024/06/wordpress-6-5-5" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4af2b01b-2dcb-44ae-a764-8ecc5f8caa81?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-25T11:15:50Z" + } +} \ No newline at end of file