diff --git a/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json b/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json index 794e858ae4a..b89b1e6cd44 100644 --- a/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json +++ b/advisories/unreviewed/2024/01/GHSA-3p6c-w37j-m7g3/GHSA-3p6c-w37j-m7g3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json b/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json index c5b74c3b713..c2b19a244e7 100644 --- a/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json +++ b/advisories/unreviewed/2024/01/GHSA-g89w-hcgw-6g9p/GHSA-g89w-hcgw-6g9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g89w-hcgw-6g9p", - "modified": "2024-01-30T00:30:29Z", + "modified": "2024-10-18T18:30:35Z", "published": "2024-01-23T15:30:58Z", "aliases": [ "CVE-2024-0755" @@ -48,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json b/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json index f13a280a489..2bd786a5958 100644 --- a/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json +++ b/advisories/unreviewed/2024/01/GHSA-h4gg-fj5r-8573/GHSA-h4gg-fj5r-8573.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json b/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json index ac02557ba63..5b0b7ea87af 100644 --- a/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json +++ b/advisories/unreviewed/2024/01/GHSA-m295-r33q-79rg/GHSA-m295-r33q-79rg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m295-r33q-79rg", - "modified": "2024-01-26T00:30:30Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-01-26T00:30:30Z", "aliases": [ "CVE-2024-23629" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json b/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json index c3e19998341..77dab4ec70e 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json +++ b/advisories/unreviewed/2024/01/GHSA-p5q6-j3pf-jwc7/GHSA-p5q6-j3pf-jwc7.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json b/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json index d19f7e079c2..e7592fa450b 100644 --- a/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json +++ b/advisories/unreviewed/2024/01/GHSA-v7w7-wwgq-qmfw/GHSA-v7w7-wwgq-qmfw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json b/advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json new file mode 100644 index 00000000000..11895af050b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5gwf-rpm9-v6f8/GHSA-5gwf-rpm9-v6f8.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gwf-rpm9-v6f8", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-10120" + ], + "details": "A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10120" + }, + { + "type": "WEB", + "url": "https://github.com/weliveby/ForCVE/blob/main/radar%20Arbitrary%20file%20upload%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280912" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.420959" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json index 72ba60fe686..af948854016 100644 --- a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json +++ b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5p85-p472-x7wv", - "modified": "2024-10-08T00:31:40Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-10-07T21:33:31Z", "aliases": [ "CVE-2024-47967" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://https://www.solidigm.com/support-page/support-security.html" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json b/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json new file mode 100644 index 00000000000..90291c855bd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-75pc-2p8w-2hhf/GHSA-75pc-2p8w-2hhf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75pc-2p8w-2hhf", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:36Z", + "aliases": [ + "CVE-2023-6080" + ], + "details": "Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6080" + }, + { + "type": "WEB", + "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024-0009.md" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2023-6080" + }, + { + "type": "WEB", + "url": "https://www.lakesidesoftware.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-379" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json b/advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json new file mode 100644 index 00000000000..28e72c9d009 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7p23-xhhw-3gg3/GHSA-7p23-xhhw-3gg3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p23-xhhw-3gg3", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-9593" + ], + "details": "The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9593" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/time-clock/tags/1.2.2/includes/admin/ajax_functions_admin.php#L58" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3171046/time-clock#file40" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/247e599a-74e2-41d5-a1ba-978a807e6544?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T18:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json index 7ada2dd68e7..32620b758e5 100644 --- a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json +++ b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jgmx-4v96-mgr5", - "modified": "2024-10-07T21:33:31Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-10-07T21:33:31Z", "aliases": [ "CVE-2024-47974" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://https://www.solidigm.com/support-page/support-security.html" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json b/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json new file mode 100644 index 00000000000..75b35c67a77 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m5h5-93gh-rvhm/GHSA-m5h5-93gh-rvhm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5h5-93gh-rvhm", + "modified": "2024-10-18T18:30:36Z", + "published": "2024-10-18T18:30:36Z", + "aliases": [ + "CVE-2024-42508" + ], + "details": "This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42508" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04721en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T16:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json b/advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json new file mode 100644 index 00000000000..2583287c9b6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pcwq-6cr8-wvr3/GHSA-pcwq-6cr8-wvr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcwq-6cr8-wvr3", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-48016" + ], + "details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. The attacker may be able to use exposed credentials to access the system with privileges of the compromised account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48016" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000237211/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json b/advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json new file mode 100644 index 00000000000..71bfd9e6681 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r5r8-96pf-6r57/GHSA-r5r8-96pf-6r57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5r8-96pf-6r57", + "modified": "2024-10-18T18:30:37Z", + "published": "2024-10-18T18:30:37Z", + "aliases": [ + "CVE-2024-47241" + ], + "details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access and modification of transmitted data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47241" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000237211/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-18T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json b/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json index 3554ee6637f..718f07a801c 100644 --- a/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json +++ b/advisories/unreviewed/2024/10/GHSA-v9vv-8xcq-rpqg/GHSA-v9vv-8xcq-rpqg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9vv-8xcq-rpqg", - "modified": "2024-10-18T00:31:16Z", + "modified": "2024-10-18T18:30:36Z", "published": "2024-10-18T00:31:16Z", "aliases": [ "CVE-2024-27766" ], "details": "An issue in MYSQL MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-17T22:15:02Z"