From ce57c0eccfbc602310f299bf77808f242f5b1e83 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 16 Dec 2024 18:32:30 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2794-c693-53gf.json | 52 +++++++++++++++++++ .../GHSA-2c63-4337-p6h8.json | 36 +++++++++++++ .../GHSA-3gpq-5q6x-q7pf.json | 36 +++++++++++++ .../GHSA-3gr3-rr4m-976p.json | 11 ++-- .../GHSA-3jgh-cx2h-h5xp.json | 15 ++++-- .../GHSA-59fp-r79g-c22h.json | 6 ++- .../GHSA-5wc6-6p3c-6qx2.json | 6 ++- .../GHSA-62jh-qwjh-cgr7.json | 52 +++++++++++++++++++ .../GHSA-64v9-jgpj-cjqg.json | 11 ++-- .../GHSA-68gp-7m2f-pch3.json | 36 +++++++++++++ .../GHSA-6pgr-38pf-3863.json | 40 ++++++++++++++ .../GHSA-887q-rm9x-7wg9.json | 4 +- .../GHSA-8hvf-h3fh-qgpv.json | 15 ++++-- .../GHSA-8j65-hvp5-w9jp.json | 36 +++++++++++++ .../GHSA-8vr8-mrh4-728w.json | 15 ++++-- .../GHSA-92jc-wxh9-49gf.json | 36 +++++++++++++ .../GHSA-987w-wp8x-h99m.json | 15 ++++-- .../GHSA-9pc9-px3j-hxmw.json | 2 +- .../GHSA-cgf3-4cm8-wh3p.json | 15 ++++-- .../GHSA-cpgh-chqx-qm3c.json | 11 ++-- .../GHSA-f2mh-h264-8qrw.json | 36 +++++++++++++ .../GHSA-f2v7-2jgq-j53q.json | 36 +++++++++++++ .../GHSA-f44c-8fc3-c52q.json | 36 +++++++++++++ .../GHSA-f8wm-cjfc-xpmm.json | 36 +++++++++++++ .../GHSA-g2mr-f5hm-6x69.json | 52 +++++++++++++++++++ .../GHSA-h73v-7w7m-qj4r.json | 52 +++++++++++++++++++ .../GHSA-hjr5-pr64-8mc2.json | 52 +++++++++++++++++++ .../GHSA-hx59-p22r-49rv.json | 15 ++++-- .../GHSA-jf72-28rf-27vg.json | 4 +- .../GHSA-jvhw-99gp-9j83.json | 25 +++++++++ .../GHSA-m8m3-3pmc-xj5p.json | 36 +++++++++++++ .../GHSA-mqj4-rjv9-gp22.json | 36 +++++++++++++ .../GHSA-php5-h4gr-q7j6.json | 15 ++++-- .../GHSA-pxf8-qv37-3xxp.json | 36 +++++++++++++ .../GHSA-q5vw-gwwh-j8r7.json | 2 +- .../GHSA-q73v-pp5w-q5mq.json | 52 +++++++++++++++++++ .../GHSA-q7fg-xj64-qmm7.json | 15 ++++-- .../GHSA-r438-q28f-28gp.json | 15 ++++-- .../GHSA-rp94-8pgp-q8f5.json | 15 ++++-- .../GHSA-rpq3-9v7c-qwm4.json | 37 +++++++++++++ .../GHSA-rrjw-vh74-2hwv.json | 52 +++++++++++++++++++ .../GHSA-v87c-pw6c-99w6.json | 15 ++++-- .../GHSA-v8f4-pqh6-gjpr.json | 36 +++++++++++++ .../GHSA-vg9c-h9cw-9m5j.json | 36 +++++++++++++ .../GHSA-vhcm-29fv-3vx5.json | 36 +++++++++++++ .../GHSA-vwvq-gh67-jhjv.json | 15 ++++-- .../GHSA-wg9r-cvfj-5cg2.json | 11 ++-- .../GHSA-wq3x-7666-hhgc.json | 36 +++++++++++++ .../GHSA-wx24-g8wj-27rf.json | 36 +++++++++++++ .../GHSA-x89m-rvq3-8g32.json | 15 ++++-- .../GHSA-xf3g-mfwq-4jvm.json | 36 +++++++++++++ .../GHSA-xf4j-mpgp-536j.json | 52 +++++++++++++++++++ 52 files changed, 1359 insertions(+), 70 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-2794-c693-53gf/GHSA-2794-c693-53gf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2c63-4337-p6h8/GHSA-2c63-4337-p6h8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3gpq-5q6x-q7pf/GHSA-3gpq-5q6x-q7pf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-68gp-7m2f-pch3/GHSA-68gp-7m2f-pch3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6pgr-38pf-3863/GHSA-6pgr-38pf-3863.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8j65-hvp5-w9jp/GHSA-8j65-hvp5-w9jp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-92jc-wxh9-49gf/GHSA-92jc-wxh9-49gf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f2mh-h264-8qrw/GHSA-f2mh-h264-8qrw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f2v7-2jgq-j53q/GHSA-f2v7-2jgq-j53q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f44c-8fc3-c52q/GHSA-f44c-8fc3-c52q.json create mode 100644 advisories/unreviewed/2024/12/GHSA-f8wm-cjfc-xpmm/GHSA-f8wm-cjfc-xpmm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h73v-7w7m-qj4r/GHSA-h73v-7w7m-qj4r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jvhw-99gp-9j83/GHSA-jvhw-99gp-9j83.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m8m3-3pmc-xj5p/GHSA-m8m3-3pmc-xj5p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mqj4-rjv9-gp22/GHSA-mqj4-rjv9-gp22.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pxf8-qv37-3xxp/GHSA-pxf8-qv37-3xxp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rpq3-9v7c-qwm4/GHSA-rpq3-9v7c-qwm4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v8f4-pqh6-gjpr/GHSA-v8f4-pqh6-gjpr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vg9c-h9cw-9m5j/GHSA-vg9c-h9cw-9m5j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vhcm-29fv-3vx5/GHSA-vhcm-29fv-3vx5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wq3x-7666-hhgc/GHSA-wq3x-7666-hhgc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wx24-g8wj-27rf/GHSA-wx24-g8wj-27rf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xf3g-mfwq-4jvm/GHSA-xf3g-mfwq-4jvm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json diff --git a/advisories/unreviewed/2024/12/GHSA-2794-c693-53gf/GHSA-2794-c693-53gf.json b/advisories/unreviewed/2024/12/GHSA-2794-c693-53gf/GHSA-2794-c693-53gf.json new file mode 100644 index 00000000000..fe3f1c50367 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2794-c693-53gf/GHSA-2794-c693-53gf.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2794-c693-53gf", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12653" + ], + "details": "A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12653" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/FabulaTech-USB-over-Network-Client-ftusbbus2-0x22040C-NPD-DOS-15160437bb1e80228995f9a74a5c233c?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288522" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288522" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2c63-4337-p6h8/GHSA-2c63-4337-p6h8.json b/advisories/unreviewed/2024/12/GHSA-2c63-4337-p6h8/GHSA-2c63-4337-p6h8.json new file mode 100644 index 00000000000..1dd33927ad6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2c63-4337-p6h8/GHSA-2c63-4337-p6h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c63-4337-p6h8", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54376" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54376" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eazydocs/vulnerability/wordpress-eazydocs-plugin-2-5-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3gpq-5q6x-q7pf/GHSA-3gpq-5q6x-q7pf.json b/advisories/unreviewed/2024/12/GHSA-3gpq-5q6x-q7pf/GHSA-3gpq-5q6x-q7pf.json new file mode 100644 index 00000000000..699c9700536 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3gpq-5q6x-q7pf/GHSA-3gpq-5q6x-q7pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gpq-5q6x-q7pf", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-10095" + ], + "details": "In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10095" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/wpf/knowledge-base/kb-security-unsafe-deserialization-vulnerability-cve-2024-10095" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json b/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json index 551bc587e3a..ed3bd9656d2 100644 --- a/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json +++ b/advisories/unreviewed/2024/12/GHSA-3gr3-rr4m-976p/GHSA-3gr3-rr4m-976p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3gr3-rr4m-976p", - "modified": "2024-12-13T18:31:56Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-13T18:31:56Z", "aliases": [ "CVE-2024-46971" ], "details": "Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-13T18:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json b/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json index a8cedbb97cf..9efcd51b695 100644 --- a/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json +++ b/advisories/unreviewed/2024/12/GHSA-3jgh-cx2h-h5xp/GHSA-3jgh-cx2h-h5xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3jgh-cx2h-h5xp", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:43Z", "aliases": [ "CVE-2024-56084" ], "details": "An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-59fp-r79g-c22h/GHSA-59fp-r79g-c22h.json b/advisories/unreviewed/2024/12/GHSA-59fp-r79g-c22h/GHSA-59fp-r79g-c22h.json index d2d7b5ac3d3..7f4696bf8d2 100644 --- a/advisories/unreviewed/2024/12/GHSA-59fp-r79g-c22h/GHSA-59fp-r79g-c22h.json +++ b/advisories/unreviewed/2024/12/GHSA-59fp-r79g-c22h/GHSA-59fp-r79g-c22h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59fp-r79g-c22h", - "modified": "2024-12-13T06:30:58Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-13T06:30:58Z", "aliases": [ "CVE-2024-11834" ], "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red" diff --git a/advisories/unreviewed/2024/12/GHSA-5wc6-6p3c-6qx2/GHSA-5wc6-6p3c-6qx2.json b/advisories/unreviewed/2024/12/GHSA-5wc6-6p3c-6qx2/GHSA-5wc6-6p3c-6qx2.json index 1e240945a54..c2240d484e5 100644 --- a/advisories/unreviewed/2024/12/GHSA-5wc6-6p3c-6qx2/GHSA-5wc6-6p3c-6qx2.json +++ b/advisories/unreviewed/2024/12/GHSA-5wc6-6p3c-6qx2/GHSA-5wc6-6p3c-6qx2.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wc6-6p3c-6qx2", - "modified": "2024-12-13T12:31:48Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-13T12:31:48Z", "aliases": [ "CVE-2024-52063" ], "details": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json b/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json new file mode 100644 index 00000000000..18268d4485a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-62jh-qwjh-cgr7/GHSA-62jh-qwjh-cgr7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62jh-qwjh-cgr7", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12660" + ], + "details": "A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function 0x8001E018 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12660" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/IOBit-Advanced-SystemCare-Utimate-AscRegistryFilter-0x8001E018-NPD-DOS-15260437bb1e80c5ab28da895ed46227" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288529" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288529" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json b/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json index e1456eccc95..907740ee6d5 100644 --- a/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json +++ b/advisories/unreviewed/2024/12/GHSA-64v9-jgpj-cjqg/GHSA-64v9-jgpj-cjqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-64v9-jgpj-cjqg", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:44Z", "aliases": [ "CVE-2024-5333" ], "details": "The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-68gp-7m2f-pch3/GHSA-68gp-7m2f-pch3.json b/advisories/unreviewed/2024/12/GHSA-68gp-7m2f-pch3/GHSA-68gp-7m2f-pch3.json new file mode 100644 index 00000000000..ec41fc6881d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-68gp-7m2f-pch3/GHSA-68gp-7m2f-pch3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68gp-7m2f-pch3", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-43234" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Envato Security Team Woffice allows Authentication Bypass.This issue affects Woffice: from n/a through 5.4.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/woffice/vulnerability/wordpress-woffice-theme-5-4-14-unauthenticated-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6pgr-38pf-3863/GHSA-6pgr-38pf-3863.json b/advisories/unreviewed/2024/12/GHSA-6pgr-38pf-3863/GHSA-6pgr-38pf-3863.json new file mode 100644 index 00000000000..4aa769ed802 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6pgr-38pf-3863/GHSA-6pgr-38pf-3863.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pgr-38pf-3863", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-11144" + ], + "details": "The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file upload or download, it could lead to incomplete file transfers, potentially corrupting data. The repeated crash might also affect the stability of the underlying system, especially if it leads to resource leaks or affects other services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11144" + }, + { + "type": "WEB", + "url": "https://www.blackduck.com/blog/cyrc-advisory-LightFTP.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json b/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json index 4fc20bf0aa4..8b581eafd69 100644 --- a/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json +++ b/advisories/unreviewed/2024/12/GHSA-887q-rm9x-7wg9/GHSA-887q-rm9x-7wg9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json b/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json index 51262bb2f0f..c497fe7bc79 100644 --- a/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json +++ b/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8hvf-h3fh-qgpv", - "modified": "2024-12-15T06:32:50Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-15T06:32:50Z", "aliases": [ "CVE-2024-56082" ], "details": "ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-15T05:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8j65-hvp5-w9jp/GHSA-8j65-hvp5-w9jp.json b/advisories/unreviewed/2024/12/GHSA-8j65-hvp5-w9jp/GHSA-8j65-hvp5-w9jp.json new file mode 100644 index 00000000000..6e55ee5b426 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8j65-hvp5-w9jp/GHSA-8j65-hvp5-w9jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j65-hvp5-w9jp", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54285" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd Pro: from n/a through 6.18.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seedprod-coming-soon-pro-5/vulnerability/wordpress-seedprod-pro-plugin-6-18-10-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json b/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json index 149ef4af1f9..1029b00d569 100644 --- a/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json +++ b/advisories/unreviewed/2024/12/GHSA-8vr8-mrh4-728w/GHSA-8vr8-mrh4-728w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vr8-mrh4-728w", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:44Z", "aliases": [ "CVE-2024-56087" ], "details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-92jc-wxh9-49gf/GHSA-92jc-wxh9-49gf.json b/advisories/unreviewed/2024/12/GHSA-92jc-wxh9-49gf/GHSA-92jc-wxh9-49gf.json new file mode 100644 index 00000000000..9b9e6a5777e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-92jc-wxh9-49gf/GHSA-92jc-wxh9-49gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92jc-wxh9-49gf", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54348" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YayCommerce Brand allows Stored XSS.This issue affects Brand: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54348" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/brand/vulnerability/wordpress-brandy-theme-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json b/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json index ee0efba049f..858f8acf4a8 100644 --- a/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json +++ b/advisories/unreviewed/2024/12/GHSA-987w-wp8x-h99m/GHSA-987w-wp8x-h99m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-987w-wp8x-h99m", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:44Z", "aliases": [ "CVE-2024-56112" ], "details": "CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json b/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json index 797c6e12868..c960036827a 100644 --- a/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json +++ b/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pc9-px3j-hxmw", - "modified": "2024-12-16T15:31:34Z", + "modified": "2024-12-16T18:31:09Z", "published": "2024-12-16T15:31:34Z", "aliases": [ "CVE-2024-12668" diff --git a/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json b/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json index c46f1216b38..6450aa165f4 100644 --- a/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json +++ b/advisories/unreviewed/2024/12/GHSA-cgf3-4cm8-wh3p/GHSA-cgf3-4cm8-wh3p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cgf3-4cm8-wh3p", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:44Z", "aliases": [ "CVE-2024-56086" ], "details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json b/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json index 2613383dc33..dae5832018a 100644 --- a/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json +++ b/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cpgh-chqx-qm3c", - "modified": "2024-12-15T06:32:50Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-15T06:32:50Z", "aliases": [ "CVE-2024-55969" ], "details": "DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-15T04:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f2mh-h264-8qrw/GHSA-f2mh-h264-8qrw.json b/advisories/unreviewed/2024/12/GHSA-f2mh-h264-8qrw/GHSA-f2mh-h264-8qrw.json new file mode 100644 index 00000000000..897b8fe72ff --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f2mh-h264-8qrw/GHSA-f2mh-h264-8qrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2mh-h264-8qrw", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-55999" + ], + "details": "Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator.This issue affects XML Multilanguage Sitemap Generator: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55999" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xml-multilanguage-sitemap-generator/vulnerability/wordpress-xml-multilanguage-sitemap-generator-plugin-2-0-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f2v7-2jgq-j53q/GHSA-f2v7-2jgq-j53q.json b/advisories/unreviewed/2024/12/GHSA-f2v7-2jgq-j53q/GHSA-f2v7-2jgq-j53q.json new file mode 100644 index 00000000000..22246f84d98 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f2v7-2jgq-j53q/GHSA-f2v7-2jgq-j53q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2v7-2jgq-j53q", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54279" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPNERD WP-NERD Toolkit.This issue affects WP-NERD Toolkit: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54279" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-nerd-toolkit/vulnerability/wordpress-wp-nerd-toolkit-plugin-1-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f44c-8fc3-c52q/GHSA-f44c-8fc3-c52q.json b/advisories/unreviewed/2024/12/GHSA-f44c-8fc3-c52q/GHSA-f44c-8fc3-c52q.json new file mode 100644 index 00000000000..050d1051919 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f44c-8fc3-c52q/GHSA-f44c-8fc3-c52q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f44c-8fc3-c52q", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54249" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Advanced Options Editor allows Reflected XSS.This issue affects Advanced Options Editor: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-options-editor/vulnerability/wordpress-advanced-options-editor-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f8wm-cjfc-xpmm/GHSA-f8wm-cjfc-xpmm.json b/advisories/unreviewed/2024/12/GHSA-f8wm-cjfc-xpmm/GHSA-f8wm-cjfc-xpmm.json new file mode 100644 index 00000000000..1b70d9df3f3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f8wm-cjfc-xpmm/GHSA-f8wm-cjfc-xpmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8wm-cjfc-xpmm", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54284" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seedprod-coming-soon-pro-5/vulnerability/wordpress-seedprod-pro-plugin-6-18-10-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json b/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json new file mode 100644 index 00000000000..f19fe0438db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g2mr-f5hm-6x69/GHSA-g2mr-f5hm-6x69.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2mr-f5hm-6x69", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12657" + ], + "details": "A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12657" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/IOBit-Advanced-SystemCare-Utimate-AscRegistryFilter-0x8001E000-NPD-DOS-15160437bb1e8068a470ca1611fd7317" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288526" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288526" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h73v-7w7m-qj4r/GHSA-h73v-7w7m-qj4r.json b/advisories/unreviewed/2024/12/GHSA-h73v-7w7m-qj4r/GHSA-h73v-7w7m-qj4r.json new file mode 100644 index 00000000000..ff6c3ba119d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h73v-7w7m-qj4r/GHSA-h73v-7w7m-qj4r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h73v-7w7m-qj4r", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12654" + ], + "details": "A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1. Affected by this vulnerability is the function 0x220408 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12654" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/FabulaTech-USB-over-Network-Client-ftusbbus2-0x220408-NPD-DOS-15160437bb1e803e9b3df784e61c6dcd" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288523" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288523" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json b/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json new file mode 100644 index 00000000000..65b5ff3f73c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hjr5-pr64-8mc2/GHSA-hjr5-pr64-8mc2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjr5-pr64-8mc2", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12656" + ], + "details": "A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12656" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/FabulaTech-USB-over-Network-Client-ftusbbus2-0x220448-NPD-DOS-15160437bb1e80cb837cd715680be6ea" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288525" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288525" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json b/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json index 6fe30602d94..8298b69e4b3 100644 --- a/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json +++ b/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx59-p22r-49rv", - "modified": "2024-12-15T06:32:50Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-15T06:32:50Z", "aliases": [ "CVE-2024-56074" ], "details": "gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-15T04:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json b/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json index ecd84cb036a..7816e86431d 100644 --- a/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json +++ b/advisories/unreviewed/2024/12/GHSA-jf72-28rf-27vg/GHSA-jf72-28rf-27vg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-jvhw-99gp-9j83/GHSA-jvhw-99gp-9j83.json b/advisories/unreviewed/2024/12/GHSA-jvhw-99gp-9j83/GHSA-jvhw-99gp-9j83.json new file mode 100644 index 00000000000..b5c18375bb4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jvhw-99gp-9j83/GHSA-jvhw-99gp-9j83.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvhw-99gp-9j83", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-6002" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6002" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m8m3-3pmc-xj5p/GHSA-m8m3-3pmc-xj5p.json b/advisories/unreviewed/2024/12/GHSA-m8m3-3pmc-xj5p/GHSA-m8m3-3pmc-xj5p.json new file mode 100644 index 00000000000..4ba217123e6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m8m3-3pmc-xj5p/GHSA-m8m3-3pmc-xj5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8m3-3pmc-xj5p", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-6001" + ], + "details": "An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6001" + }, + { + "type": "WEB", + "url": "https://support.lenovo.co/us/en/product_security/LEN-174319" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mqj4-rjv9-gp22/GHSA-mqj4-rjv9-gp22.json b/advisories/unreviewed/2024/12/GHSA-mqj4-rjv9-gp22/GHSA-mqj4-rjv9-gp22.json new file mode 100644 index 00000000000..6c14233a273 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mqj4-rjv9-gp22/GHSA-mqj4-rjv9-gp22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqj4-rjv9-gp22", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54357" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54357" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/avada/vulnerability/wordpress-avada-theme-7-11-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-php5-h4gr-q7j6/GHSA-php5-h4gr-q7j6.json b/advisories/unreviewed/2024/12/GHSA-php5-h4gr-q7j6/GHSA-php5-h4gr-q7j6.json index 958d7517bb5..f9d9db554c3 100644 --- a/advisories/unreviewed/2024/12/GHSA-php5-h4gr-q7j6/GHSA-php5-h4gr-q7j6.json +++ b/advisories/unreviewed/2024/12/GHSA-php5-h4gr-q7j6/GHSA-php5-h4gr-q7j6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-php5-h4gr-q7j6", - "modified": "2024-12-14T03:32:49Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-14T03:32:49Z", "aliases": [ "CVE-2023-29476" ], "details": "In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-444" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-14T02:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pxf8-qv37-3xxp/GHSA-pxf8-qv37-3xxp.json b/advisories/unreviewed/2024/12/GHSA-pxf8-qv37-3xxp/GHSA-pxf8-qv37-3xxp.json new file mode 100644 index 00000000000..2ca3855f94e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pxf8-qv37-3xxp/GHSA-pxf8-qv37-3xxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxf8-qv37-3xxp", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-11358" + ], + "details": "Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11358" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json b/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json index 06f0fe36681..19afb2ca6f1 100644 --- a/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json +++ b/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q5vw-gwwh-j8r7", - "modified": "2024-12-16T15:31:34Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T15:31:34Z", "aliases": [ "CVE-2024-10972" diff --git a/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json b/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json new file mode 100644 index 00000000000..fe6ea720a92 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q73v-pp5w-q5mq/GHSA-q73v-pp5w-q5mq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q73v-pp5w-q5mq", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12658" + ], + "details": "A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This issue affects the function 0x8001E01C in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12658" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/IOBit-Advanced-SystemCare-Utimate-AscRegistryFilter-0x8001E01C-NPD-DOS-15160437bb1e800eb1cadd53b224d088" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288527" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288527" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456036" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json b/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json index fad0062e1de..c8c8e7b840b 100644 --- a/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json +++ b/advisories/unreviewed/2024/12/GHSA-q7fg-xj64-qmm7/GHSA-q7fg-xj64-qmm7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7fg-xj64-qmm7", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:44Z", "aliases": [ "CVE-2024-56085" ], "details": "An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-r438-q28f-28gp/GHSA-r438-q28f-28gp.json b/advisories/unreviewed/2024/12/GHSA-r438-q28f-28gp/GHSA-r438-q28f-28gp.json index fcf76759f3b..182229b5e13 100644 --- a/advisories/unreviewed/2024/12/GHSA-r438-q28f-28gp/GHSA-r438-q28f-28gp.json +++ b/advisories/unreviewed/2024/12/GHSA-r438-q28f-28gp/GHSA-r438-q28f-28gp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r438-q28f-28gp", - "modified": "2024-12-16T03:33:59Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T03:33:59Z", "aliases": [ "CVE-2024-56083" ], "details": "Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific \"Use Devin's Machine\" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin session to social media, or publicly streams their Devin session.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T03:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json b/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json index 63778facad7..49b8f862737 100644 --- a/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json +++ b/advisories/unreviewed/2024/12/GHSA-rp94-8pgp-q8f5/GHSA-rp94-8pgp-q8f5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rp94-8pgp-q8f5", - "modified": "2024-12-15T03:30:42Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-15T03:30:42Z", "aliases": [ "CVE-2024-55970" ], "details": "File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-15T03:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rpq3-9v7c-qwm4/GHSA-rpq3-9v7c-qwm4.json b/advisories/unreviewed/2024/12/GHSA-rpq3-9v7c-qwm4/GHSA-rpq3-9v7c-qwm4.json new file mode 100644 index 00000000000..b0722717bcd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rpq3-9v7c-qwm4/GHSA-rpq3-9v7c-qwm4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpq3-9v7c-qwm4", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-8058" + ], + "details": "An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8058" + }, + { + "type": "WEB", + "url": "https://www.filez.com/securityPolicy/1.html?1733849740" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125", + "CWE-1287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json b/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json new file mode 100644 index 00000000000..7a93006e96c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rrjw-vh74-2hwv/GHSA-rrjw-vh74-2hwv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrjw-vh74-2hwv", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12659" + ], + "details": "A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12659" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/IOBit-Advanced-SystemCare-Utimate-AscRegistryFilter-0x8001E004-NPD-DOS-15160437bb1e804cbe8fd4d826f8564f" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288528" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288528" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v87c-pw6c-99w6/GHSA-v87c-pw6c-99w6.json b/advisories/unreviewed/2024/12/GHSA-v87c-pw6c-99w6/GHSA-v87c-pw6c-99w6.json index 7c712d70faa..3bbf3f1fafd 100644 --- a/advisories/unreviewed/2024/12/GHSA-v87c-pw6c-99w6/GHSA-v87c-pw6c-99w6.json +++ b/advisories/unreviewed/2024/12/GHSA-v87c-pw6c-99w6/GHSA-v87c-pw6c-99w6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v87c-pw6c-99w6", - "modified": "2024-12-14T00:31:11Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-13T21:30:36Z", "aliases": [ "CVE-2024-55956" ], "details": "In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-13T21:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v8f4-pqh6-gjpr/GHSA-v8f4-pqh6-gjpr.json b/advisories/unreviewed/2024/12/GHSA-v8f4-pqh6-gjpr/GHSA-v8f4-pqh6-gjpr.json new file mode 100644 index 00000000000..c35b5a4b98a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v8f4-pqh6-gjpr/GHSA-v8f4-pqh6-gjpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8f4-pqh6-gjpr", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54283" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seedprod-coming-soon-pro-5/vulnerability/wordpress-seedprod-pro-plugin-6-18-10-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vg9c-h9cw-9m5j/GHSA-vg9c-h9cw-9m5j.json b/advisories/unreviewed/2024/12/GHSA-vg9c-h9cw-9m5j/GHSA-vg9c-h9cw-9m5j.json new file mode 100644 index 00000000000..90601ca075a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vg9c-h9cw-9m5j/GHSA-vg9c-h9cw-9m5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg9c-h9cw-9m5j", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-56003" + ], + "details": "Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer.This issue affects Caldera SMTP Mailer: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/caldera-smtp-mailer/vulnerability/wordpress-caldera-smtp-mailer-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vhcm-29fv-3vx5/GHSA-vhcm-29fv-3vx5.json b/advisories/unreviewed/2024/12/GHSA-vhcm-29fv-3vx5/GHSA-vhcm-29fv-3vx5.json new file mode 100644 index 00000000000..75d6ed526ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vhcm-29fv-3vx5/GHSA-vhcm-29fv-3vx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhcm-29fv-3vx5", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-4762" + ], + "details": "An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4762" + }, + { + "type": "WEB", + "url": "https://support.lenovo.co/us/en/product_security/LEN-174319" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json b/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json index cf5faf6a19d..2fcb0b11bb5 100644 --- a/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json +++ b/advisories/unreviewed/2024/12/GHSA-vwvq-gh67-jhjv/GHSA-vwvq-gh67-jhjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vwvq-gh67-jhjv", - "modified": "2024-12-15T03:30:42Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-15T03:30:42Z", "aliases": [ "CVE-2024-56073" ], "details": "An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote attackers to cause a denial of service (divide-by-zero error and application crash).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-15T03:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json b/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json index 39eb48d1ab7..e5a900559c6 100644 --- a/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json +++ b/advisories/unreviewed/2024/12/GHSA-wg9r-cvfj-5cg2/GHSA-wg9r-cvfj-5cg2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wg9r-cvfj-5cg2", - "modified": "2024-12-16T06:30:44Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-16T06:30:44Z", "aliases": [ "CVE-2024-11841" ], "details": "The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-16T06:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wq3x-7666-hhgc/GHSA-wq3x-7666-hhgc.json b/advisories/unreviewed/2024/12/GHSA-wq3x-7666-hhgc/GHSA-wq3x-7666-hhgc.json new file mode 100644 index 00000000000..558b9d10e69 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wq3x-7666-hhgc/GHSA-wq3x-7666-hhgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq3x-7666-hhgc", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54229" + ], + "details": "Incorrect Privilege Assignment vulnerability in Straightvisions GmbH SV100 Companion allows Privilege Escalation.This issue affects SV100 Companion: from n/a through 2.0.02.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sv100-companion/vulnerability/wordpress-sv100-companion-plugin-2-0-02-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wx24-g8wj-27rf/GHSA-wx24-g8wj-27rf.json b/advisories/unreviewed/2024/12/GHSA-wx24-g8wj-27rf/GHSA-wx24-g8wj-27rf.json new file mode 100644 index 00000000000..1e9c8f60686 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wx24-g8wj-27rf/GHSA-wx24-g8wj-27rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx24-g8wj-27rf", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54257" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Reflected XSS.This issue affects tydskrif: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tydskrif/vulnerability/wordpress-tydskrif-theme-1-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json b/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json index f2380fea916..c3cf64cf75c 100644 --- a/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json +++ b/advisories/unreviewed/2024/12/GHSA-x89m-rvq3-8g32/GHSA-x89m-rvq3-8g32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x89m-rvq3-8g32", - "modified": "2024-12-15T03:30:42Z", + "modified": "2024-12-16T18:31:08Z", "published": "2024-12-15T03:30:42Z", "aliases": [ "CVE-2024-56072" ], "details": "An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of service (application crash) via a crafted packet that specifies many sFlow samples.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-15T03:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xf3g-mfwq-4jvm/GHSA-xf3g-mfwq-4jvm.json b/advisories/unreviewed/2024/12/GHSA-xf3g-mfwq-4jvm/GHSA-xf3g-mfwq-4jvm.json new file mode 100644 index 00000000000..8c133d014f7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xf3g-mfwq-4jvm/GHSA-xf3g-mfwq-4jvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf3g-mfwq-4jvm", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-54280" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit allows SQL Injection.This issue affects WPBookit: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpbookit/vulnerability/wordpress-wpbookit-plugin-1-6-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json b/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json new file mode 100644 index 00000000000..d45e869fa6f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xf4j-mpgp-536j/GHSA-xf4j-mpgp-536j.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf4j-mpgp-536j", + "modified": "2024-12-16T18:31:09Z", + "published": "2024-12-16T18:31:09Z", + "aliases": [ + "CVE-2024-12655" + ], + "details": "A vulnerability, which was classified as problematic, has been found in FabulaTech USB over Network 6.0.6.1. Affected by this issue is the function 0x220420 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12655" + }, + { + "type": "WEB", + "url": "https://shareforall.notion.site/FabulaTech-USB-over-Network-Client-ftusbbus2-0x220420-NPD-DOS-15160437bb1e80898c8bf2dc1f7a24e7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.288524" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.288524" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.456029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T17:15:09Z" + } +} \ No newline at end of file