diff --git a/advisories/unreviewed/2024/03/GHSA-3967-4r54-74c9/GHSA-3967-4r54-74c9.json b/advisories/unreviewed/2024/03/GHSA-3967-4r54-74c9/GHSA-3967-4r54-74c9.json index f56808b14e3..424c66fe208 100644 --- a/advisories/unreviewed/2024/03/GHSA-3967-4r54-74c9/GHSA-3967-4r54-74c9.json +++ b/advisories/unreviewed/2024/03/GHSA-3967-4r54-74c9/GHSA-3967-4r54-74c9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3967-4r54-74c9", - "modified": "2024-03-27T06:30:30Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-27T06:30:30Z", "aliases": [ "CVE-2023-40284" ], "details": "An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-45f8-rqfm-rh3c/GHSA-45f8-rqfm-rh3c.json b/advisories/unreviewed/2024/03/GHSA-45f8-rqfm-rh3c/GHSA-45f8-rqfm-rh3c.json index d4ec0591772..6da4cf7bba3 100644 --- a/advisories/unreviewed/2024/03/GHSA-45f8-rqfm-rh3c/GHSA-45f8-rqfm-rh3c.json +++ b/advisories/unreviewed/2024/03/GHSA-45f8-rqfm-rh3c/GHSA-45f8-rqfm-rh3c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45f8-rqfm-rh3c", - "modified": "2024-03-27T06:30:31Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-27T06:30:31Z", "aliases": [ "CVE-2023-40288" ], "details": "An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-56rx-5jgh-c8q2/GHSA-56rx-5jgh-c8q2.json b/advisories/unreviewed/2024/03/GHSA-56rx-5jgh-c8q2/GHSA-56rx-5jgh-c8q2.json index d0d312d1683..d3fc1239e2e 100644 --- a/advisories/unreviewed/2024/03/GHSA-56rx-5jgh-c8q2/GHSA-56rx-5jgh-c8q2.json +++ b/advisories/unreviewed/2024/03/GHSA-56rx-5jgh-c8q2/GHSA-56rx-5jgh-c8q2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56rx-5jgh-c8q2", - "modified": "2024-03-26T21:30:47Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-26T21:30:46Z", "aliases": [ "CVE-2024-28442" ], "details": "Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T20:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6pgr-6fjc-hf4m/GHSA-6pgr-6fjc-hf4m.json b/advisories/unreviewed/2024/03/GHSA-6pgr-6fjc-hf4m/GHSA-6pgr-6fjc-hf4m.json index 4a7401967ce..17def13685a 100644 --- a/advisories/unreviewed/2024/03/GHSA-6pgr-6fjc-hf4m/GHSA-6pgr-6fjc-hf4m.json +++ b/advisories/unreviewed/2024/03/GHSA-6pgr-6fjc-hf4m/GHSA-6pgr-6fjc-hf4m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pgr-6fjc-hf4m", - "modified": "2024-03-05T15:32:41Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-05T15:32:41Z", "aliases": [ "CVE-2024-27627" ], "details": "A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T14:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-72vh-mwjv-25fq/GHSA-72vh-mwjv-25fq.json b/advisories/unreviewed/2024/03/GHSA-72vh-mwjv-25fq/GHSA-72vh-mwjv-25fq.json index 0dcae20434e..9b43308a966 100644 --- a/advisories/unreviewed/2024/03/GHSA-72vh-mwjv-25fq/GHSA-72vh-mwjv-25fq.json +++ b/advisories/unreviewed/2024/03/GHSA-72vh-mwjv-25fq/GHSA-72vh-mwjv-25fq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72vh-mwjv-25fq", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27211" ], "details": "In AtiHandleAPOMsgType of ati_Main.c, there is a possible OOB write due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json b/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json index ed55757464b..566ad26daad 100644 --- a/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json +++ b/advisories/unreviewed/2024/03/GHSA-7qpm-3qf3-fjgw/GHSA-7qpm-3qf3-fjgw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7qpm-3qf3-fjgw", - "modified": "2024-03-26T00:32:02Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-26T00:32:02Z", "aliases": [ "CVE-2024-29301" ], "details": "SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T00:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json b/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json index 56c77403b06..4e0320c26ff 100644 --- a/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json +++ b/advisories/unreviewed/2024/03/GHSA-8x7g-6cjv-9w4w/GHSA-8x7g-6cjv-9w4w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8x7g-6cjv-9w4w", - "modified": "2024-03-20T15:32:21Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-20T15:32:21Z", "aliases": [ "CVE-2024-28394" ], "details": "An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-73" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T20:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json b/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json index c9d6e5a4d41..60966effadb 100644 --- a/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json +++ b/advisories/unreviewed/2024/03/GHSA-925f-cxg2-4483/GHSA-925f-cxg2-4483.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-925f-cxg2-4483", - "modified": "2024-03-26T00:32:01Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-26T00:32:01Z", "aliases": [ "CVE-2024-21914" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-994w-h7w5-73v7/GHSA-994w-h7w5-73v7.json b/advisories/unreviewed/2024/03/GHSA-994w-h7w5-73v7/GHSA-994w-h7w5-73v7.json index 3148fb85b29..f16c34717fb 100644 --- a/advisories/unreviewed/2024/03/GHSA-994w-h7w5-73v7/GHSA-994w-h7w5-73v7.json +++ b/advisories/unreviewed/2024/03/GHSA-994w-h7w5-73v7/GHSA-994w-h7w5-73v7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-994w-h7w5-73v7", - "modified": "2024-03-21T03:36:45Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2023-49981" ], "details": "A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:49:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f4hc-7j8c-cj6p/GHSA-f4hc-7j8c-cj6p.json b/advisories/unreviewed/2024/03/GHSA-f4hc-7j8c-cj6p/GHSA-f4hc-7j8c-cj6p.json index b1dab5a2bf1..dad0926a69b 100644 --- a/advisories/unreviewed/2024/03/GHSA-f4hc-7j8c-cj6p/GHSA-f4hc-7j8c-cj6p.json +++ b/advisories/unreviewed/2024/03/GHSA-f4hc-7j8c-cj6p/GHSA-f4hc-7j8c-cj6p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f4hc-7j8c-cj6p", - "modified": "2024-03-21T03:36:46Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T03:36:46Z", "aliases": [ "CVE-2024-27626" ], "details": "A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:52:20Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g3rh-v79v-97pc/GHSA-g3rh-v79v-97pc.json b/advisories/unreviewed/2024/03/GHSA-g3rh-v79v-97pc/GHSA-g3rh-v79v-97pc.json index 09fe6a7491b..0b5d4223a1d 100644 --- a/advisories/unreviewed/2024/03/GHSA-g3rh-v79v-97pc/GHSA-g3rh-v79v-97pc.json +++ b/advisories/unreviewed/2024/03/GHSA-g3rh-v79v-97pc/GHSA-g3rh-v79v-97pc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3rh-v79v-97pc", - "modified": "2024-03-21T03:36:45Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2023-49982" ], "details": "Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:49:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g52c-2cj5-jgxg/GHSA-g52c-2cj5-jgxg.json b/advisories/unreviewed/2024/03/GHSA-g52c-2cj5-jgxg/GHSA-g52c-2cj5-jgxg.json index d7af9620647..ddf1bdbee2c 100644 --- a/advisories/unreviewed/2024/03/GHSA-g52c-2cj5-jgxg/GHSA-g52c-2cj5-jgxg.json +++ b/advisories/unreviewed/2024/03/GHSA-g52c-2cj5-jgxg/GHSA-g52c-2cj5-jgxg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g52c-2cj5-jgxg", - "modified": "2024-03-21T06:33:04Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T06:33:04Z", "aliases": [ "CVE-2024-29859" ], "details": "In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gp58-x96h-756r/GHSA-gp58-x96h-756r.json b/advisories/unreviewed/2024/03/GHSA-gp58-x96h-756r/GHSA-gp58-x96h-756r.json index 1b74070c6b1..b9d3c44280d 100644 --- a/advisories/unreviewed/2024/03/GHSA-gp58-x96h-756r/GHSA-gp58-x96h-756r.json +++ b/advisories/unreviewed/2024/03/GHSA-gp58-x96h-756r/GHSA-gp58-x96h-756r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp58-x96h-756r", - "modified": "2024-03-12T06:30:46Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-12T06:30:45Z", "aliases": [ "CVE-2024-25331" ], "details": "DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T06:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hfjg-hg9j-49p2/GHSA-hfjg-hg9j-49p2.json b/advisories/unreviewed/2024/03/GHSA-hfjg-hg9j-49p2/GHSA-hfjg-hg9j-49p2.json index 500582e720a..77777596885 100644 --- a/advisories/unreviewed/2024/03/GHSA-hfjg-hg9j-49p2/GHSA-hfjg-hg9j-49p2.json +++ b/advisories/unreviewed/2024/03/GHSA-hfjg-hg9j-49p2/GHSA-hfjg-hg9j-49p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfjg-hg9j-49p2", - "modified": "2024-03-07T03:30:40Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2023-49986" ], "details": "A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T01:15:51Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m22p-rxw5-75fw/GHSA-m22p-rxw5-75fw.json b/advisories/unreviewed/2024/03/GHSA-m22p-rxw5-75fw/GHSA-m22p-rxw5-75fw.json index 42a0750122b..da90769dace 100644 --- a/advisories/unreviewed/2024/03/GHSA-m22p-rxw5-75fw/GHSA-m22p-rxw5-75fw.json +++ b/advisories/unreviewed/2024/03/GHSA-m22p-rxw5-75fw/GHSA-m22p-rxw5-75fw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m22p-rxw5-75fw", - "modified": "2024-03-21T03:36:45Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2023-49984" ], "details": "A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:49:38Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json b/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json index 2a388f2767f..218e2c5c1db 100644 --- a/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json +++ b/advisories/unreviewed/2024/03/GHSA-mr24-cf69-5chq/GHSA-mr24-cf69-5chq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mr24-cf69-5chq", - "modified": "2024-03-26T12:31:28Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-26T12:31:28Z", "aliases": [ "CVE-2024-29644" ], "details": "Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T12:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json b/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json index 3fcf157e04f..bda56265dcc 100644 --- a/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json +++ b/advisories/unreviewed/2024/03/GHSA-pcj3-p7wg-9c68/GHSA-pcj3-p7wg-9c68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcj3-p7wg-9c68", - "modified": "2024-03-20T15:32:30Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-20T15:32:30Z", "aliases": [ "CVE-2024-22079" ], "details": "An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-24" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T05:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json b/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json index 4173a1c2724..ffa40816673 100644 --- a/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json +++ b/advisories/unreviewed/2024/03/GHSA-qmw9-5q6h-hjxj/GHSA-qmw9-5q6h-hjxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmw9-5q6h-hjxj", - "modified": "2024-03-20T15:32:28Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-20T15:32:28Z", "aliases": [ "CVE-2023-7246" ], "details": "The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T05:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v7cq-82w7-gpxq/GHSA-v7cq-82w7-gpxq.json b/advisories/unreviewed/2024/03/GHSA-v7cq-82w7-gpxq/GHSA-v7cq-82w7-gpxq.json index 8a9e0b751a4..c7db5fd6d9b 100644 --- a/advisories/unreviewed/2024/03/GHSA-v7cq-82w7-gpxq/GHSA-v7cq-82w7-gpxq.json +++ b/advisories/unreviewed/2024/03/GHSA-v7cq-82w7-gpxq/GHSA-v7cq-82w7-gpxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7cq-82w7-gpxq", - "modified": "2024-03-07T09:30:30Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-07T09:30:30Z", "aliases": [ "CVE-2022-46091" ], "details": "Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T09:15:37Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v884-7rcp-mpm4/GHSA-v884-7rcp-mpm4.json b/advisories/unreviewed/2024/03/GHSA-v884-7rcp-mpm4/GHSA-v884-7rcp-mpm4.json index d595b7a05a2..ee6f197c817 100644 --- a/advisories/unreviewed/2024/03/GHSA-v884-7rcp-mpm4/GHSA-v884-7rcp-mpm4.json +++ b/advisories/unreviewed/2024/03/GHSA-v884-7rcp-mpm4/GHSA-v884-7rcp-mpm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v884-7rcp-mpm4", - "modified": "2024-03-21T03:36:45Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T03:36:45Z", "aliases": [ "CVE-2023-38825" ], "details": "SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:48:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vwc8-vmvr-qqcf/GHSA-vwc8-vmvr-qqcf.json b/advisories/unreviewed/2024/03/GHSA-vwc8-vmvr-qqcf/GHSA-vwc8-vmvr-qqcf.json index 9191d555ef1..c3ef1bdf363 100644 --- a/advisories/unreviewed/2024/03/GHSA-vwc8-vmvr-qqcf/GHSA-vwc8-vmvr-qqcf.json +++ b/advisories/unreviewed/2024/03/GHSA-vwc8-vmvr-qqcf/GHSA-vwc8-vmvr-qqcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwc8-vmvr-qqcf", - "modified": "2024-03-27T09:30:39Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-27T09:30:39Z", "aliases": [ "CVE-2023-43768" ], "details": "An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T07:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json b/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json index cbbe238b2fe..17c8f028a27 100644 --- a/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json +++ b/advisories/unreviewed/2024/03/GHSA-w33g-cw2w-4vrq/GHSA-w33g-cw2w-4vrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w33g-cw2w-4vrq", - "modified": "2024-03-26T15:30:50Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-26T15:30:50Z", "aliases": [ "CVE-2023-50894" ], "details": "In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password encryption function allows remote authenticated administrative users to discover cleartext database credentials contained in error report information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T15:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xg9v-76c9-465p/GHSA-xg9v-76c9-465p.json b/advisories/unreviewed/2024/03/GHSA-xg9v-76c9-465p/GHSA-xg9v-76c9-465p.json index 6f67cc6f088..26f74cc6c40 100644 --- a/advisories/unreviewed/2024/03/GHSA-xg9v-76c9-465p/GHSA-xg9v-76c9-465p.json +++ b/advisories/unreviewed/2024/03/GHSA-xg9v-76c9-465p/GHSA-xg9v-76c9-465p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xg9v-76c9-465p", - "modified": "2024-03-27T06:30:31Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-27T06:30:31Z", "aliases": [ "CVE-2023-40287" ], "details": "An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xq7r-8p25-r3gh/GHSA-xq7r-8p25-r3gh.json b/advisories/unreviewed/2024/03/GHSA-xq7r-8p25-r3gh/GHSA-xq7r-8p25-r3gh.json index e356308c6a0..4a598032c2e 100644 --- a/advisories/unreviewed/2024/03/GHSA-xq7r-8p25-r3gh/GHSA-xq7r-8p25-r3gh.json +++ b/advisories/unreviewed/2024/03/GHSA-xq7r-8p25-r3gh/GHSA-xq7r-8p25-r3gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq7r-8p25-r3gh", - "modified": "2024-03-21T03:36:44Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-03-21T03:36:44Z", "aliases": [ "CVE-2020-26942" ], "details": "An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T02:36:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-88jw-43wf-p3wr/GHSA-88jw-43wf-p3wr.json b/advisories/unreviewed/2024/05/GHSA-88jw-43wf-p3wr/GHSA-88jw-43wf-p3wr.json index 762ec943cd9..61279a6b159 100644 --- a/advisories/unreviewed/2024/05/GHSA-88jw-43wf-p3wr/GHSA-88jw-43wf-p3wr.json +++ b/advisories/unreviewed/2024/05/GHSA-88jw-43wf-p3wr/GHSA-88jw-43wf-p3wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-88jw-43wf-p3wr", - "modified": "2024-05-31T03:30:31Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-05-31T03:30:31Z", "aliases": [ "CVE-2024-37018" ], "details": "The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-648" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-31T01:15:54Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hh39-vjv8-j337/GHSA-hh39-vjv8-j337.json b/advisories/unreviewed/2024/05/GHSA-hh39-vjv8-j337/GHSA-hh39-vjv8-j337.json index 6e628cadf48..f51ff4854c8 100644 --- a/advisories/unreviewed/2024/05/GHSA-hh39-vjv8-j337/GHSA-hh39-vjv8-j337.json +++ b/advisories/unreviewed/2024/05/GHSA-hh39-vjv8-j337/GHSA-hh39-vjv8-j337.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hh39-vjv8-j337", - "modified": "2024-05-06T15:30:40Z", + "modified": "2024-08-05T18:31:42Z", "published": "2024-05-06T15:30:39Z", "aliases": [ "CVE-2024-34252" ], "details": "wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function \"PreserveRegisterIfOccupied\" in wasm3/source/m3_compile.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T15:15:24Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2vpq-2h36-8fq9/GHSA-2vpq-2h36-8fq9.json b/advisories/unreviewed/2024/06/GHSA-2vpq-2h36-8fq9/GHSA-2vpq-2h36-8fq9.json index da6f0e310a9..9836f689f9b 100644 --- a/advisories/unreviewed/2024/06/GHSA-2vpq-2h36-8fq9/GHSA-2vpq-2h36-8fq9.json +++ b/advisories/unreviewed/2024/06/GHSA-2vpq-2h36-8fq9/GHSA-2vpq-2h36-8fq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vpq-2h36-8fq9", - "modified": "2024-06-17T21:31:10Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-06-17T21:31:10Z", "aliases": [ "CVE-2024-34833" ], "details": "Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the \"save_settings\" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T21:15:50Z" diff --git a/advisories/unreviewed/2024/06/GHSA-52mm-rqxx-gfq6/GHSA-52mm-rqxx-gfq6.json b/advisories/unreviewed/2024/06/GHSA-52mm-rqxx-gfq6/GHSA-52mm-rqxx-gfq6.json index 74145c5a4cc..91200c07bde 100644 --- a/advisories/unreviewed/2024/06/GHSA-52mm-rqxx-gfq6/GHSA-52mm-rqxx-gfq6.json +++ b/advisories/unreviewed/2024/06/GHSA-52mm-rqxx-gfq6/GHSA-52mm-rqxx-gfq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52mm-rqxx-gfq6", - "modified": "2024-06-30T12:31:10Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38440" ], "details": "Netatalk 3.2.0 has an off-by-one error and resultant heap-based buffer overflow because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-193" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T13:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json b/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json index ba62c135339..27b9f1c8d25 100644 --- a/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json +++ b/advisories/unreviewed/2024/06/GHSA-j764-4v6h-pqp7/GHSA-j764-4v6h-pqp7.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-193" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6fx9-prp6-gh76/GHSA-6fx9-prp6-gh76.json b/advisories/unreviewed/2024/08/GHSA-6fx9-prp6-gh76/GHSA-6fx9-prp6-gh76.json new file mode 100644 index 00000000000..1c08cab9f6c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6fx9-prp6-gh76/GHSA-6fx9-prp6-gh76.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fx9-prp6-gh76", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-41200" + ], + "details": "A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41200" + }, + { + "type": "WEB", + "url": "https://gist.github.com/SecZone-SFuzz/3cf2d8b50ffe4b4951c193d8c0cd65a9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7jmc-v9fw-3rgr/GHSA-7jmc-v9fw-3rgr.json b/advisories/unreviewed/2024/08/GHSA-7jmc-v9fw-3rgr/GHSA-7jmc-v9fw-3rgr.json index 1651d814aab..002717c6469 100644 --- a/advisories/unreviewed/2024/08/GHSA-7jmc-v9fw-3rgr/GHSA-7jmc-v9fw-3rgr.json +++ b/advisories/unreviewed/2024/08/GHSA-7jmc-v9fw-3rgr/GHSA-7jmc-v9fw-3rgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jmc-v9fw-3rgr", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-08-02T18:31:10Z", "aliases": [ "CVE-2024-33894" ], "details": "Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-02T18:16:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8694-9wwj-rvph/GHSA-8694-9wwj-rvph.json b/advisories/unreviewed/2024/08/GHSA-8694-9wwj-rvph/GHSA-8694-9wwj-rvph.json new file mode 100644 index 00000000000..d46b5413473 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8694-9wwj-rvph/GHSA-8694-9wwj-rvph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8694-9wwj-rvph", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-41376" + ], + "details": "dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41376" + }, + { + "type": "WEB", + "url": "https://github.com/zyx0814/dzzoffice/issues/252" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json b/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json new file mode 100644 index 00000000000..d2411f350a2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8x2c-hh3c-77q8/GHSA-8x2c-hh3c-77q8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x2c-hh3c-77q8", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-40530" + ], + "details": "Insecure Permissions vulnerability in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to execute arbitrary code via modification of the X-Forwarded-For header component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40530" + }, + { + "type": "WEB", + "url": "https://critical.lt/blog/authorization-bypass-and-mass-assignment-in-pantera-crm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json b/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json index 92c9b4fbbf0..ac4d337a806 100644 --- a/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json +++ b/advisories/unreviewed/2024/08/GHSA-h4hq-473r-4m3x/GHSA-h4hq-473r-4m3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4hq-473r-4m3x", - "modified": "2024-08-05T12:31:15Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-08-05T12:31:15Z", "aliases": [ "CVE-2024-4607" ], "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p0; Valhall GPU Kernel Driver: from r41p0 through r49p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T12:15:34Z" diff --git a/advisories/unreviewed/2024/08/GHSA-h4xf-wx99-jmv4/GHSA-h4xf-wx99-jmv4.json b/advisories/unreviewed/2024/08/GHSA-h4xf-wx99-jmv4/GHSA-h4xf-wx99-jmv4.json new file mode 100644 index 00000000000..d85b8a45102 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h4xf-wx99-jmv4/GHSA-h4xf-wx99-jmv4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4xf-wx99-jmv4", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-41381" + ], + "details": "microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\\modules\\settings\\admin.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41381" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/issues/1110" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hf66-xfgj-42g8/GHSA-hf66-xfgj-42g8.json b/advisories/unreviewed/2024/08/GHSA-hf66-xfgj-42g8/GHSA-hf66-xfgj-42g8.json new file mode 100644 index 00000000000..dc220f8f7cd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hf66-xfgj-42g8/GHSA-hf66-xfgj-42g8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf66-xfgj-42g8", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-41380" + ], + "details": "microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\\modules\\tags\\add_tagging_tagged.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41380" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/issues/1111" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json b/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json index cb461385c03..1b7ad041b6a 100644 --- a/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json +++ b/advisories/unreviewed/2024/08/GHSA-p5q6-fgv9-mf6h/GHSA-p5q6-fgv9-mf6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5q6-fgv9-mf6h", - "modified": "2024-08-05T12:31:15Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-08-05T12:31:15Z", "aliases": [ "CVE-2024-2937" ], "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p0; Valhall GPU Kernel Driver: from r41p0 through r49p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T12:15:34Z" diff --git a/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json b/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json new file mode 100644 index 00000000000..d2fca9dfff8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q9j5-9g8p-5h5q/GHSA-q9j5-9g8p-5h5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9j5-9g8p-5h5q", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-21980" + ], + "details": "Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21980" + }, + { + "type": "WEB", + "url": "https://https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3011.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rf8m-mggj-3g74/GHSA-rf8m-mggj-3g74.json b/advisories/unreviewed/2024/08/GHSA-rf8m-mggj-3g74/GHSA-rf8m-mggj-3g74.json new file mode 100644 index 00000000000..0a01589c856 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rf8m-mggj-3g74/GHSA-rf8m-mggj-3g74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf8m-mggj-3g74", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-21978" + ], + "details": "Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21978" + }, + { + "type": "WEB", + "url": "https://https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3011.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vm46-9fq2-ghm4/GHSA-vm46-9fq2-ghm4.json b/advisories/unreviewed/2024/08/GHSA-vm46-9fq2-ghm4/GHSA-vm46-9fq2-ghm4.json new file mode 100644 index 00000000000..f3ff7f26de5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vm46-9fq2-ghm4/GHSA-vm46-9fq2-ghm4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm46-9fq2-ghm4", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-40531" + ], + "details": "An issue in UAB Lexita PanteraCRM CMS v.401.152 and Patera CRM CMS v.402.072 allows a remote attacker to escalate privileges via the user profile management function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40531" + }, + { + "type": "WEB", + "url": "https://critical.lt/blog/authorization-bypass-and-mass-assignment-in-pantera-crm" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json b/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json new file mode 100644 index 00000000000..cd50d97b5b0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ww7v-5cpr-4v77/GHSA-ww7v-5cpr-4v77.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww7v-5cpr-4v77", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2024-40498" + ], + "details": "SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40498" + }, + { + "type": "WEB", + "url": "https://github.com/Dirac231/CVE-2024-40498" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json b/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json new file mode 100644 index 00000000000..2f05645d87c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6rx-7w39-qpg5/GHSA-x6rx-7w39-qpg5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6rx-7w39-qpg5", + "modified": "2024-08-05T18:31:43Z", + "published": "2024-08-05T18:31:43Z", + "aliases": [ + "CVE-2023-31355" + ], + "details": "Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31355" + }, + { + "type": "WEB", + "url": "https://https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3011.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-05T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json b/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json index b44a851a20f..21acdcceeb3 100644 --- a/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json +++ b/advisories/unreviewed/2024/08/GHSA-xr9f-3r4j-v7r6/GHSA-xr9f-3r4j-v7r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xr9f-3r4j-v7r6", - "modified": "2024-08-05T06:30:37Z", + "modified": "2024-08-05T18:31:43Z", "published": "2024-08-05T06:30:37Z", "aliases": [ "CVE-2024-5081" ], "details": "The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-05T06:16:41Z"