diff --git a/advisories/unreviewed/2024/04/GHSA-22q4-f5r6-3xqw/GHSA-22q4-f5r6-3xqw.json b/advisories/unreviewed/2024/04/GHSA-22q4-f5r6-3xqw/GHSA-22q4-f5r6-3xqw.json index f69f6bf99a9..c24fc6a1616 100644 --- a/advisories/unreviewed/2024/04/GHSA-22q4-f5r6-3xqw/GHSA-22q4-f5r6-3xqw.json +++ b/advisories/unreviewed/2024/04/GHSA-22q4-f5r6-3xqw/GHSA-22q4-f5r6-3xqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22q4-f5r6-3xqw", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:34:55Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-2961" ], "details": "The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -83,7 +86,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T18:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-22qj-8xm8-83m5/GHSA-22qj-8xm8-83m5.json b/advisories/unreviewed/2024/04/GHSA-22qj-8xm8-83m5/GHSA-22qj-8xm8-83m5.json index 96b05061cb3..f80955e6885 100644 --- a/advisories/unreviewed/2024/04/GHSA-22qj-8xm8-83m5/GHSA-22qj-8xm8-83m5.json +++ b/advisories/unreviewed/2024/04/GHSA-22qj-8xm8-83m5/GHSA-22qj-8xm8-83m5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22qj-8xm8-83m5", - "modified": "2024-04-17T06:30:52Z", + "modified": "2024-07-03T18:34:39Z", "published": "2024-04-17T06:30:52Z", "aliases": [ "CVE-2024-1219" ], "details": "The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T05:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-238w-4442-vh7q/GHSA-238w-4442-vh7q.json b/advisories/unreviewed/2024/04/GHSA-238w-4442-vh7q/GHSA-238w-4442-vh7q.json index be6977eea5a..4e4e9bd3cec 100644 --- a/advisories/unreviewed/2024/04/GHSA-238w-4442-vh7q/GHSA-238w-4442-vh7q.json +++ b/advisories/unreviewed/2024/04/GHSA-238w-4442-vh7q/GHSA-238w-4442-vh7q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json b/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json index d34d9f0a824..6b417826c97 100644 --- a/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json +++ b/advisories/unreviewed/2024/04/GHSA-23c8-gv7j-76hv/GHSA-23c8-gv7j-76hv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-25qp-v6p8-wggj/GHSA-25qp-v6p8-wggj.json b/advisories/unreviewed/2024/04/GHSA-25qp-v6p8-wggj/GHSA-25qp-v6p8-wggj.json index 3efac2ee9e7..f7037730c35 100644 --- a/advisories/unreviewed/2024/04/GHSA-25qp-v6p8-wggj/GHSA-25qp-v6p8-wggj.json +++ b/advisories/unreviewed/2024/04/GHSA-25qp-v6p8-wggj/GHSA-25qp-v6p8-wggj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-25qp-v6p8-wggj", - "modified": "2024-04-02T09:30:42Z", + "modified": "2024-07-03T18:34:03Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-31005" ], "details": "An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T08:16:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json b/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json index fd219e3b89e..163c83e5a93 100644 --- a/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json +++ b/advisories/unreviewed/2024/04/GHSA-26cp-j6f9-2w7c/GHSA-26cp-j6f9-2w7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26cp-j6f9-2w7c", - "modified": "2024-04-19T18:31:12Z", + "modified": "2024-07-03T18:36:04Z", "published": "2024-04-19T18:31:12Z", "aliases": [ "CVE-2024-32206" ], "details": "A stored cross-site scripting (XSS) vulnerability in the component \\affiche\\admin\\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T16:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-29fh-mw96-pcjc/GHSA-29fh-mw96-pcjc.json b/advisories/unreviewed/2024/04/GHSA-29fh-mw96-pcjc/GHSA-29fh-mw96-pcjc.json index 0d449bebe54..bab91f229e3 100644 --- a/advisories/unreviewed/2024/04/GHSA-29fh-mw96-pcjc/GHSA-29fh-mw96-pcjc.json +++ b/advisories/unreviewed/2024/04/GHSA-29fh-mw96-pcjc/GHSA-29fh-mw96-pcjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29fh-mw96-pcjc", - "modified": "2024-04-17T21:30:46Z", + "modified": "2024-07-03T18:35:04Z", "published": "2024-04-17T21:30:46Z", "aliases": [ "CVE-2024-30950" ], "details": "A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json b/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json index 367726d6803..22e16b5f6c6 100644 --- a/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json +++ b/advisories/unreviewed/2024/04/GHSA-2cww-rcpx-vmvj/GHSA-2cww-rcpx-vmvj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2cww-rcpx-vmvj", - "modified": "2024-04-18T18:30:41Z", + "modified": "2024-07-03T18:35:23Z", "published": "2024-04-18T18:30:41Z", "aliases": [ "CVE-2024-32325" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T17:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2f2w-fjg5-6g8c/GHSA-2f2w-fjg5-6g8c.json b/advisories/unreviewed/2024/04/GHSA-2f2w-fjg5-6g8c/GHSA-2f2w-fjg5-6g8c.json index b8c366ca715..0588b0ac162 100644 --- a/advisories/unreviewed/2024/04/GHSA-2f2w-fjg5-6g8c/GHSA-2f2w-fjg5-6g8c.json +++ b/advisories/unreviewed/2024/04/GHSA-2f2w-fjg5-6g8c/GHSA-2f2w-fjg5-6g8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2f2w-fjg5-6g8c", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:34Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30929" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2fhp-49gm-838v/GHSA-2fhp-49gm-838v.json b/advisories/unreviewed/2024/04/GHSA-2fhp-49gm-838v/GHSA-2fhp-49gm-838v.json index 56fb40506c5..80ca352458a 100644 --- a/advisories/unreviewed/2024/04/GHSA-2fhp-49gm-838v/GHSA-2fhp-49gm-838v.json +++ b/advisories/unreviewed/2024/04/GHSA-2fhp-49gm-838v/GHSA-2fhp-49gm-838v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2fhp-49gm-838v", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:19Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32746" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2g4w-cqhh-m9w9/GHSA-2g4w-cqhh-m9w9.json b/advisories/unreviewed/2024/04/GHSA-2g4w-cqhh-m9w9/GHSA-2g4w-cqhh-m9w9.json index 62023ac2de3..7a6aaf03e34 100644 --- a/advisories/unreviewed/2024/04/GHSA-2g4w-cqhh-m9w9/GHSA-2g4w-cqhh-m9w9.json +++ b/advisories/unreviewed/2024/04/GHSA-2g4w-cqhh-m9w9/GHSA-2g4w-cqhh-m9w9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-2g9g-66pp-8rq7/GHSA-2g9g-66pp-8rq7.json b/advisories/unreviewed/2024/04/GHSA-2g9g-66pp-8rq7/GHSA-2g9g-66pp-8rq7.json index a1f02a88b8e..be3e284e34f 100644 --- a/advisories/unreviewed/2024/04/GHSA-2g9g-66pp-8rq7/GHSA-2g9g-66pp-8rq7.json +++ b/advisories/unreviewed/2024/04/GHSA-2g9g-66pp-8rq7/GHSA-2g9g-66pp-8rq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g9g-66pp-8rq7", - "modified": "2024-04-11T06:30:35Z", + "modified": "2024-07-03T18:34:17Z", "published": "2024-04-11T06:30:35Z", "aliases": [ "CVE-2024-30915" ], "details": "An issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service and obtain sensitive information via the max_samples parameter within the DataReaderQoS component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T06:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2hh4-qfh8-22w2/GHSA-2hh4-qfh8-22w2.json b/advisories/unreviewed/2024/04/GHSA-2hh4-qfh8-22w2/GHSA-2hh4-qfh8-22w2.json index d8f86feabeb..2ec2c855102 100644 --- a/advisories/unreviewed/2024/04/GHSA-2hh4-qfh8-22w2/GHSA-2hh4-qfh8-22w2.json +++ b/advisories/unreviewed/2024/04/GHSA-2hh4-qfh8-22w2/GHSA-2hh4-qfh8-22w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2hh4-qfh8-22w2", - "modified": "2024-04-16T00:30:32Z", + "modified": "2024-07-03T18:34:25Z", "published": "2024-04-16T00:30:32Z", "aliases": [ "CVE-2024-27794" ], "details": "Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T23:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2qhq-j5fg-qqg8/GHSA-2qhq-j5fg-qqg8.json b/advisories/unreviewed/2024/04/GHSA-2qhq-j5fg-qqg8/GHSA-2qhq-j5fg-qqg8.json index 73f5718f411..cf03a39a0bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-2qhq-j5fg-qqg8/GHSA-2qhq-j5fg-qqg8.json +++ b/advisories/unreviewed/2024/04/GHSA-2qhq-j5fg-qqg8/GHSA-2qhq-j5fg-qqg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qhq-j5fg-qqg8", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:33Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30927" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json b/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json index ab0065437b3..88af17ea5a3 100644 --- a/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json +++ b/advisories/unreviewed/2024/04/GHSA-36pg-p326-9j9j/GHSA-36pg-p326-9j9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36pg-p326-9j9j", - "modified": "2024-04-18T18:30:42Z", + "modified": "2024-07-03T18:35:27Z", "published": "2024-04-18T18:30:42Z", "aliases": [ "CVE-2024-32327" ], "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T17:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-37g3-3m5c-7mjc/GHSA-37g3-3m5c-7mjc.json b/advisories/unreviewed/2024/04/GHSA-37g3-3m5c-7mjc/GHSA-37g3-3m5c-7mjc.json index 14bb5b83ddb..2bafd0b88f7 100644 --- a/advisories/unreviewed/2024/04/GHSA-37g3-3m5c-7mjc/GHSA-37g3-3m5c-7mjc.json +++ b/advisories/unreviewed/2024/04/GHSA-37g3-3m5c-7mjc/GHSA-37g3-3m5c-7mjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37g3-3m5c-7mjc", - "modified": "2024-04-17T18:31:36Z", + "modified": "2024-07-03T18:34:58Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-30982" ], "details": "SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T18:15:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-37h8-7f9x-vvj8/GHSA-37h8-7f9x-vvj8.json b/advisories/unreviewed/2024/04/GHSA-37h8-7f9x-vvj8/GHSA-37h8-7f9x-vvj8.json index 5303df0be2e..b1f4c5e6f1f 100644 --- a/advisories/unreviewed/2024/04/GHSA-37h8-7f9x-vvj8/GHSA-37h8-7f9x-vvj8.json +++ b/advisories/unreviewed/2024/04/GHSA-37h8-7f9x-vvj8/GHSA-37h8-7f9x-vvj8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37h8-7f9x-vvj8", - "modified": "2024-04-01T03:30:41Z", + "modified": "2024-07-03T18:34:02Z", "published": "2024-04-01T03:30:41Z", "aliases": [ "CVE-2024-20053" ], "details": "In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-37vm-pmrf-r3cp/GHSA-37vm-pmrf-r3cp.json b/advisories/unreviewed/2024/04/GHSA-37vm-pmrf-r3cp/GHSA-37vm-pmrf-r3cp.json index 2234de3d8ae..08e00c8edb2 100644 --- a/advisories/unreviewed/2024/04/GHSA-37vm-pmrf-r3cp/GHSA-37vm-pmrf-r3cp.json +++ b/advisories/unreviewed/2024/04/GHSA-37vm-pmrf-r3cp/GHSA-37vm-pmrf-r3cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-37vm-pmrf-r3cp", - "modified": "2024-04-17T15:30:42Z", + "modified": "2024-07-03T18:34:49Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-32283" ], "details": "Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-38mp-fjx9-rc96/GHSA-38mp-fjx9-rc96.json b/advisories/unreviewed/2024/04/GHSA-38mp-fjx9-rc96/GHSA-38mp-fjx9-rc96.json index a56de022f0f..fab5b9ad463 100644 --- a/advisories/unreviewed/2024/04/GHSA-38mp-fjx9-rc96/GHSA-38mp-fjx9-rc96.json +++ b/advisories/unreviewed/2024/04/GHSA-38mp-fjx9-rc96/GHSA-38mp-fjx9-rc96.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-38mp-fjx9-rc96", - "modified": "2024-04-17T18:31:35Z", + "modified": "2024-07-03T18:34:54Z", "published": "2024-04-17T18:31:35Z", "aliases": [ "CVE-2023-5405" diff --git a/advisories/unreviewed/2024/04/GHSA-3c2h-px55-3fmw/GHSA-3c2h-px55-3fmw.json b/advisories/unreviewed/2024/04/GHSA-3c2h-px55-3fmw/GHSA-3c2h-px55-3fmw.json index b2f33e19d50..ef2fbb2b93b 100644 --- a/advisories/unreviewed/2024/04/GHSA-3c2h-px55-3fmw/GHSA-3c2h-px55-3fmw.json +++ b/advisories/unreviewed/2024/04/GHSA-3c2h-px55-3fmw/GHSA-3c2h-px55-3fmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3c2h-px55-3fmw", - "modified": "2024-04-01T18:30:56Z", + "modified": "2024-07-03T18:34:03Z", "published": "2024-04-01T18:30:56Z", "aliases": [ "CVE-2024-30862" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T16:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3g64-2wg6-7p8r/GHSA-3g64-2wg6-7p8r.json b/advisories/unreviewed/2024/04/GHSA-3g64-2wg6-7p8r/GHSA-3g64-2wg6-7p8r.json index 51413c94578..6a03bac13ad 100644 --- a/advisories/unreviewed/2024/04/GHSA-3g64-2wg6-7p8r/GHSA-3g64-2wg6-7p8r.json +++ b/advisories/unreviewed/2024/04/GHSA-3g64-2wg6-7p8r/GHSA-3g64-2wg6-7p8r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g64-2wg6-7p8r", - "modified": "2024-04-18T21:30:31Z", + "modified": "2024-07-03T18:35:30Z", "published": "2024-04-18T21:30:31Z", "aliases": [ "CVE-2024-30921" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json b/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json index cbf38bcb1b3..e440a195633 100644 --- a/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json +++ b/advisories/unreviewed/2024/04/GHSA-3mxv-473p-h624/GHSA-3mxv-473p-h624.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3mxv-473p-h624", - "modified": "2024-06-10T18:30:56Z", + "modified": "2024-07-03T18:36:10Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51797" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-43cm-g4rg-jr2r/GHSA-43cm-g4rg-jr2r.json b/advisories/unreviewed/2024/04/GHSA-43cm-g4rg-jr2r/GHSA-43cm-g4rg-jr2r.json index b0270a35952..ced891c55f0 100644 --- a/advisories/unreviewed/2024/04/GHSA-43cm-g4rg-jr2r/GHSA-43cm-g4rg-jr2r.json +++ b/advisories/unreviewed/2024/04/GHSA-43cm-g4rg-jr2r/GHSA-43cm-g4rg-jr2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-43cm-g4rg-jr2r", - "modified": "2024-04-10T21:30:34Z", + "modified": "2024-07-03T18:34:17Z", "published": "2024-04-10T21:30:34Z", "aliases": [ "CVE-2024-26362" ], "details": "HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T21:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-452r-p733-r4gh/GHSA-452r-p733-r4gh.json b/advisories/unreviewed/2024/04/GHSA-452r-p733-r4gh/GHSA-452r-p733-r4gh.json index b6c9814bdf2..588c6f044eb 100644 --- a/advisories/unreviewed/2024/04/GHSA-452r-p733-r4gh/GHSA-452r-p733-r4gh.json +++ b/advisories/unreviewed/2024/04/GHSA-452r-p733-r4gh/GHSA-452r-p733-r4gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-452r-p733-r4gh", - "modified": "2024-04-01T03:30:41Z", + "modified": "2024-07-03T18:34:02Z", "published": "2024-04-01T03:30:41Z", "aliases": [ "CVE-2024-20054" ], "details": "In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-48g7-q26h-567w/GHSA-48g7-q26h-567w.json b/advisories/unreviewed/2024/04/GHSA-48g7-q26h-567w/GHSA-48g7-q26h-567w.json index 1f0b5fd70ee..f727917f0d9 100644 --- a/advisories/unreviewed/2024/04/GHSA-48g7-q26h-567w/GHSA-48g7-q26h-567w.json +++ b/advisories/unreviewed/2024/04/GHSA-48g7-q26h-567w/GHSA-48g7-q26h-567w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48g7-q26h-567w", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:52Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32311" ], "details": "Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json b/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json index b4bd26a752b..d7157a8fe81 100644 --- a/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json +++ b/advisories/unreviewed/2024/04/GHSA-4m4g-p795-cmq7/GHSA-4m4g-p795-cmq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4m4g-p795-cmq7", - "modified": "2024-04-20T00:31:52Z", + "modified": "2024-07-03T18:34:15Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2024-3157" ], "details": "Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4pg7-hw8j-rmpq/GHSA-4pg7-hw8j-rmpq.json b/advisories/unreviewed/2024/04/GHSA-4pg7-hw8j-rmpq/GHSA-4pg7-hw8j-rmpq.json index f5531d475a5..cc6b3981e80 100644 --- a/advisories/unreviewed/2024/04/GHSA-4pg7-hw8j-rmpq/GHSA-4pg7-hw8j-rmpq.json +++ b/advisories/unreviewed/2024/04/GHSA-4pg7-hw8j-rmpq/GHSA-4pg7-hw8j-rmpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pg7-hw8j-rmpq", - "modified": "2024-04-17T18:31:33Z", + "modified": "2024-07-03T18:34:54Z", "published": "2024-04-17T18:31:33Z", "aliases": [ "CVE-2024-32320" ], "details": "Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T16:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json b/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json index 7d65238445a..f73c4ead53d 100644 --- a/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json +++ b/advisories/unreviewed/2024/04/GHSA-4pvq-mcwh-v9jc/GHSA-4pvq-mcwh-v9jc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pvq-mcwh-v9jc", - "modified": "2024-04-19T15:30:46Z", + "modified": "2024-07-03T18:36:01Z", "published": "2024-04-19T15:30:46Z", "aliases": [ "CVE-2024-31744" ], "details": "In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T13:15:13Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json b/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json index 424a81cd14d..5d7d7ab7479 100644 --- a/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json +++ b/advisories/unreviewed/2024/04/GHSA-4rw9-59ch-c9mh/GHSA-4rw9-59ch-c9mh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rw9-59ch-c9mh", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:07Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51791" ], "details": "Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json b/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json index cce1ae009d9..2bf3defd777 100644 --- a/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json +++ b/advisories/unreviewed/2024/04/GHSA-4v53-9g52-rm7v/GHSA-4v53-9g52-rm7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4v53-9g52-rm7v", - "modified": "2024-04-08T18:30:48Z", + "modified": "2024-07-03T18:34:12Z", "published": "2024-04-08T18:30:48Z", "aliases": [ "CVE-2023-7164" ], "details": "The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T18:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json b/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json index 1062462e964..2f4a6a8ac76 100644 --- a/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json +++ b/advisories/unreviewed/2024/04/GHSA-4xpx-694q-f2wv/GHSA-4xpx-694q-f2wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4xpx-694q-f2wv", - "modified": "2024-04-17T06:30:52Z", + "modified": "2024-07-03T18:34:40Z", "published": "2024-04-17T06:30:52Z", "aliases": [ "CVE-2024-2101" ], "details": "The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T05:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-55rx-qj7r-7rwp/GHSA-55rx-qj7r-7rwp.json b/advisories/unreviewed/2024/04/GHSA-55rx-qj7r-7rwp/GHSA-55rx-qj7r-7rwp.json index 8bff253eaeb..d17ff536b97 100644 --- a/advisories/unreviewed/2024/04/GHSA-55rx-qj7r-7rwp/GHSA-55rx-qj7r-7rwp.json +++ b/advisories/unreviewed/2024/04/GHSA-55rx-qj7r-7rwp/GHSA-55rx-qj7r-7rwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55rx-qj7r-7rwp", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:14Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-3323" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json b/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json index 6517eab47ad..9d2b11f062a 100644 --- a/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json +++ b/advisories/unreviewed/2024/04/GHSA-56vm-qxhc-5p2f/GHSA-56vm-qxhc-5p2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56vm-qxhc-5p2f", - "modified": "2024-04-28T09:30:30Z", + "modified": "2024-07-03T18:34:12Z", "published": "2024-04-07T21:30:28Z", "aliases": [ "CVE-2024-31948" ], "details": "In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-56vv-v57v-fgmr/GHSA-56vv-v57v-fgmr.json b/advisories/unreviewed/2024/04/GHSA-56vv-v57v-fgmr/GHSA-56vv-v57v-fgmr.json index 7f993cadd16..e71664b679d 100644 --- a/advisories/unreviewed/2024/04/GHSA-56vv-v57v-fgmr/GHSA-56vv-v57v-fgmr.json +++ b/advisories/unreviewed/2024/04/GHSA-56vv-v57v-fgmr/GHSA-56vv-v57v-fgmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-56vv-v57v-fgmr", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:34:48Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-31578" ], "details": "FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-595h-5jvm-pm7p/GHSA-595h-5jvm-pm7p.json b/advisories/unreviewed/2024/04/GHSA-595h-5jvm-pm7p/GHSA-595h-5jvm-pm7p.json index 6dbbc1c4bb8..8feb3d9a2a0 100644 --- a/advisories/unreviewed/2024/04/GHSA-595h-5jvm-pm7p/GHSA-595h-5jvm-pm7p.json +++ b/advisories/unreviewed/2024/04/GHSA-595h-5jvm-pm7p/GHSA-595h-5jvm-pm7p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-595h-5jvm-pm7p", - "modified": "2024-04-01T03:30:40Z", + "modified": "2024-07-03T18:34:01Z", "published": "2024-04-01T03:30:40Z", "aliases": [ "CVE-2024-20048" ], "details": "In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-248" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json b/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json index 0c96aaa7527..1d48682de9b 100644 --- a/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json +++ b/advisories/unreviewed/2024/04/GHSA-5fhg-238q-4c3r/GHSA-5fhg-238q-4c3r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5g36-q32h-jr9h/GHSA-5g36-q32h-jr9h.json b/advisories/unreviewed/2024/04/GHSA-5g36-q32h-jr9h/GHSA-5g36-q32h-jr9h.json index 9ae62148bc8..133d08fc9d6 100644 --- a/advisories/unreviewed/2024/04/GHSA-5g36-q32h-jr9h/GHSA-5g36-q32h-jr9h.json +++ b/advisories/unreviewed/2024/04/GHSA-5g36-q32h-jr9h/GHSA-5g36-q32h-jr9h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5pcm-hx3q-hm94/GHSA-5pcm-hx3q-hm94.json b/advisories/unreviewed/2024/04/GHSA-5pcm-hx3q-hm94/GHSA-5pcm-hx3q-hm94.json index 5a4e3420e60..fd552b50ce4 100644 --- a/advisories/unreviewed/2024/04/GHSA-5pcm-hx3q-hm94/GHSA-5pcm-hx3q-hm94.json +++ b/advisories/unreviewed/2024/04/GHSA-5pcm-hx3q-hm94/GHSA-5pcm-hx3q-hm94.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json b/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json index 5b0b219ef4a..32de72ef9d7 100644 --- a/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json +++ b/advisories/unreviewed/2024/04/GHSA-5v68-73xh-wcgw/GHSA-5v68-73xh-wcgw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-5x5p-mx9q-gjm3/GHSA-5x5p-mx9q-gjm3.json b/advisories/unreviewed/2024/04/GHSA-5x5p-mx9q-gjm3/GHSA-5x5p-mx9q-gjm3.json index b6b72460389..dd03697d6ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-5x5p-mx9q-gjm3/GHSA-5x5p-mx9q-gjm3.json +++ b/advisories/unreviewed/2024/04/GHSA-5x5p-mx9q-gjm3/GHSA-5x5p-mx9q-gjm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x5p-mx9q-gjm3", - "modified": "2024-04-17T18:31:36Z", + "modified": "2024-07-03T18:35:00Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-30985" ], "details": "SQL Injection vulnerability in \"B/W Dates Reports\" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via \"todate\" and \"fromdate\" parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T18:15:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json b/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json index 7d6ce9ce02a..cf93b5f2d85 100644 --- a/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json +++ b/advisories/unreviewed/2024/04/GHSA-5xm4-9p77-7mjp/GHSA-5xm4-9p77-7mjp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-66qx-hfv2-c44c/GHSA-66qx-hfv2-c44c.json b/advisories/unreviewed/2024/04/GHSA-66qx-hfv2-c44c/GHSA-66qx-hfv2-c44c.json index 7944c9bd67c..aebefa778e0 100644 --- a/advisories/unreviewed/2024/04/GHSA-66qx-hfv2-c44c/GHSA-66qx-hfv2-c44c.json +++ b/advisories/unreviewed/2024/04/GHSA-66qx-hfv2-c44c/GHSA-66qx-hfv2-c44c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-66qx-hfv2-c44c", - "modified": "2024-06-10T18:30:54Z", + "modified": "2024-07-03T18:34:20Z", "published": "2024-04-12T06:33:24Z", "aliases": [ "CVE-2023-49528" ], "details": "Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T06:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json b/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json index 86f66c2e04f..d2e61a938ae 100644 --- a/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json +++ b/advisories/unreviewed/2024/04/GHSA-66x4-8vc7-5pm4/GHSA-66x4-8vc7-5pm4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-359" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json b/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json index d25dbe2cdad..e0f372c8206 100644 --- a/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json +++ b/advisories/unreviewed/2024/04/GHSA-67wm-85xj-pgvv/GHSA-67wm-85xj-pgvv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67wm-85xj-pgvv", - "modified": "2024-04-17T06:30:52Z", + "modified": "2024-07-03T18:34:40Z", "published": "2024-04-17T06:30:52Z", "aliases": [ "CVE-2024-2309" ], "details": "The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T05:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-68jw-xf9h-cqhm/GHSA-68jw-xf9h-cqhm.json b/advisories/unreviewed/2024/04/GHSA-68jw-xf9h-cqhm/GHSA-68jw-xf9h-cqhm.json index d9f71e0e2f2..7f7f7446c62 100644 --- a/advisories/unreviewed/2024/04/GHSA-68jw-xf9h-cqhm/GHSA-68jw-xf9h-cqhm.json +++ b/advisories/unreviewed/2024/04/GHSA-68jw-xf9h-cqhm/GHSA-68jw-xf9h-cqhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68jw-xf9h-cqhm", - "modified": "2024-04-17T15:30:42Z", + "modified": "2024-07-03T18:34:45Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-32301" ], "details": "Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6cx5-pwpx-7g84/GHSA-6cx5-pwpx-7g84.json b/advisories/unreviewed/2024/04/GHSA-6cx5-pwpx-7g84/GHSA-6cx5-pwpx-7g84.json index 1614ebb9a3e..51e6e8e358a 100644 --- a/advisories/unreviewed/2024/04/GHSA-6cx5-pwpx-7g84/GHSA-6cx5-pwpx-7g84.json +++ b/advisories/unreviewed/2024/04/GHSA-6cx5-pwpx-7g84/GHSA-6cx5-pwpx-7g84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cx5-pwpx-7g84", - "modified": "2024-04-02T15:30:37Z", + "modified": "2024-07-03T18:34:05Z", "published": "2024-04-02T15:30:37Z", "aliases": [ "CVE-2024-30946" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T13:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json index 61b62adc68a..71481408fa8 100644 --- a/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json +++ b/advisories/unreviewed/2024/04/GHSA-6f82-r7wj-8fxf/GHSA-6f82-r7wj-8fxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f82-r7wj-8fxf", - "modified": "2024-04-22T12:30:33Z", + "modified": "2024-07-03T18:34:30Z", "published": "2024-04-16T18:31:35Z", "aliases": [ "CVE-2024-3859" ], "details": "On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6mpg-x75c-hw5v/GHSA-6mpg-x75c-hw5v.json b/advisories/unreviewed/2024/04/GHSA-6mpg-x75c-hw5v/GHSA-6mpg-x75c-hw5v.json index 1514789efa0..f300443ee1f 100644 --- a/advisories/unreviewed/2024/04/GHSA-6mpg-x75c-hw5v/GHSA-6mpg-x75c-hw5v.json +++ b/advisories/unreviewed/2024/04/GHSA-6mpg-x75c-hw5v/GHSA-6mpg-x75c-hw5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mpg-x75c-hw5v", - "modified": "2024-04-15T06:30:34Z", + "modified": "2024-07-03T18:34:22Z", "published": "2024-04-15T06:30:34Z", "aliases": [ "CVE-2024-1204" ], "details": "The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:14Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6ppw-252q-r2mf/GHSA-6ppw-252q-r2mf.json b/advisories/unreviewed/2024/04/GHSA-6ppw-252q-r2mf/GHSA-6ppw-252q-r2mf.json index a389e38758b..d75ef848732 100644 --- a/advisories/unreviewed/2024/04/GHSA-6ppw-252q-r2mf/GHSA-6ppw-252q-r2mf.json +++ b/advisories/unreviewed/2024/04/GHSA-6ppw-252q-r2mf/GHSA-6ppw-252q-r2mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6ppw-252q-r2mf", - "modified": "2024-04-17T18:31:37Z", + "modified": "2024-07-03T18:35:00Z", "published": "2024-04-17T18:31:37Z", "aliases": [ "CVE-2024-32161" ], "details": "jizhiCMS 2.5 suffers from a File upload vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T18:15:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6rv4-8gr8-8q77/GHSA-6rv4-8gr8-8q77.json b/advisories/unreviewed/2024/04/GHSA-6rv4-8gr8-8q77/GHSA-6rv4-8gr8-8q77.json index 007cf6d7098..7855b773117 100644 --- a/advisories/unreviewed/2024/04/GHSA-6rv4-8gr8-8q77/GHSA-6rv4-8gr8-8q77.json +++ b/advisories/unreviewed/2024/04/GHSA-6rv4-8gr8-8q77/GHSA-6rv4-8gr8-8q77.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6rv4-8gr8-8q77", - "modified": "2024-04-15T21:30:45Z", + "modified": "2024-07-03T18:34:24Z", "published": "2024-04-15T21:30:45Z", "aliases": [ "CVE-2024-24487" ], "details": "An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T19:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json b/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json index a6d57b79251..0afc2284b51 100644 --- a/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json +++ b/advisories/unreviewed/2024/04/GHSA-6wx8-g7xc-9qp2/GHSA-6wx8-g7xc-9qp2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-72rp-2fhc-9m4p/GHSA-72rp-2fhc-9m4p.json b/advisories/unreviewed/2024/04/GHSA-72rp-2fhc-9m4p/GHSA-72rp-2fhc-9m4p.json index 88bc9b02f07..b1ab6211855 100644 --- a/advisories/unreviewed/2024/04/GHSA-72rp-2fhc-9m4p/GHSA-72rp-2fhc-9m4p.json +++ b/advisories/unreviewed/2024/04/GHSA-72rp-2fhc-9m4p/GHSA-72rp-2fhc-9m4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72rp-2fhc-9m4p", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:18Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32345" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Configuration parameter under the Language section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-746v-52x5-j9vg/GHSA-746v-52x5-j9vg.json b/advisories/unreviewed/2024/04/GHSA-746v-52x5-j9vg/GHSA-746v-52x5-j9vg.json index 2c822da6c85..7456aa8ceb4 100644 --- a/advisories/unreviewed/2024/04/GHSA-746v-52x5-j9vg/GHSA-746v-52x5-j9vg.json +++ b/advisories/unreviewed/2024/04/GHSA-746v-52x5-j9vg/GHSA-746v-52x5-j9vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-746v-52x5-j9vg", - "modified": "2024-04-17T18:31:33Z", + "modified": "2024-07-03T18:34:54Z", "published": "2024-04-17T18:31:33Z", "aliases": [ "CVE-2024-32318" ], "details": "Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T16:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json b/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json index 326c8f814f4..311c7c587c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json +++ b/advisories/unreviewed/2024/04/GHSA-76f8-6hfx-w3xj/GHSA-76f8-6hfx-w3xj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json b/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json index 3ae7e83b9bc..c5c72bf1726 100644 --- a/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json +++ b/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json b/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json index 4c2e7340dad..2dd0561be77 100644 --- a/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json +++ b/advisories/unreviewed/2024/04/GHSA-7ghv-4mjc-99wp/GHSA-7ghv-4mjc-99wp.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json b/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json index 8389c8b6d79..4ea3f0a958d 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json +++ b/advisories/unreviewed/2024/04/GHSA-7jw6-8f8g-469v/GHSA-7jw6-8f8g-469v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jw6-8f8g-469v", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:34:44Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3844" ], "details": "Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json b/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json index 5efc18873de..c692ab3c430 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json +++ b/advisories/unreviewed/2024/04/GHSA-7pmg-vmj4-qjp4/GHSA-7pmg-vmj4-qjp4.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-7qg2-g3pg-pg55/GHSA-7qg2-g3pg-pg55.json b/advisories/unreviewed/2024/04/GHSA-7qg2-g3pg-pg55/GHSA-7qg2-g3pg-pg55.json index bcc1ef41023..eaa2d7a813b 100644 --- a/advisories/unreviewed/2024/04/GHSA-7qg2-g3pg-pg55/GHSA-7qg2-g3pg-pg55.json +++ b/advisories/unreviewed/2024/04/GHSA-7qg2-g3pg-pg55/GHSA-7qg2-g3pg-pg55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7qg2-g3pg-pg55", - "modified": "2024-04-12T15:37:21Z", + "modified": "2024-07-03T18:34:22Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-31818" ], "details": "Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T13:15:20Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7x3h-4w94-p57x/GHSA-7x3h-4w94-p57x.json b/advisories/unreviewed/2024/04/GHSA-7x3h-4w94-p57x/GHSA-7x3h-4w94-p57x.json index d59ba481f25..2034e168d46 100644 --- a/advisories/unreviewed/2024/04/GHSA-7x3h-4w94-p57x/GHSA-7x3h-4w94-p57x.json +++ b/advisories/unreviewed/2024/04/GHSA-7x3h-4w94-p57x/GHSA-7x3h-4w94-p57x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-82vh-p4jp-wgfg/GHSA-82vh-p4jp-wgfg.json b/advisories/unreviewed/2024/04/GHSA-82vh-p4jp-wgfg/GHSA-82vh-p4jp-wgfg.json index 6977bfc89cd..1377c340c6b 100644 --- a/advisories/unreviewed/2024/04/GHSA-82vh-p4jp-wgfg/GHSA-82vh-p4jp-wgfg.json +++ b/advisories/unreviewed/2024/04/GHSA-82vh-p4jp-wgfg/GHSA-82vh-p4jp-wgfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82vh-p4jp-wgfg", - "modified": "2024-04-12T06:33:24Z", + "modified": "2024-07-03T18:34:19Z", "published": "2024-04-12T06:33:24Z", "aliases": [ "CVE-2023-44857" ], "details": "An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T04:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json index 215d951f369..459350b71ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json +++ b/advisories/unreviewed/2024/04/GHSA-8564-m639-jh8r/GHSA-8564-m639-jh8r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8564-m639-jh8r", - "modified": "2024-04-22T12:30:33Z", + "modified": "2024-07-03T18:34:30Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3857" ], "details": "The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json b/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json index 9b5f6bf80d7..a1626eb8917 100644 --- a/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json +++ b/advisories/unreviewed/2024/04/GHSA-85c2-wjfm-h4fw/GHSA-85c2-wjfm-h4fw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json b/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json index 2458f06010a..af27f5d4809 100644 --- a/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json +++ b/advisories/unreviewed/2024/04/GHSA-8c8m-p9jj-3j4j/GHSA-8c8m-p9jj-3j4j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-8h3w-mgw8-gj45/GHSA-8h3w-mgw8-gj45.json b/advisories/unreviewed/2024/04/GHSA-8h3w-mgw8-gj45/GHSA-8h3w-mgw8-gj45.json index 19f79d1198e..ff943107eca 100644 --- a/advisories/unreviewed/2024/04/GHSA-8h3w-mgw8-gj45/GHSA-8h3w-mgw8-gj45.json +++ b/advisories/unreviewed/2024/04/GHSA-8h3w-mgw8-gj45/GHSA-8h3w-mgw8-gj45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8h3w-mgw8-gj45", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:33Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30926" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8hrj-6457-w65j/GHSA-8hrj-6457-w65j.json b/advisories/unreviewed/2024/04/GHSA-8hrj-6457-w65j/GHSA-8hrj-6457-w65j.json index bcbf1cfd779..f37f210607e 100644 --- a/advisories/unreviewed/2024/04/GHSA-8hrj-6457-w65j/GHSA-8hrj-6457-w65j.json +++ b/advisories/unreviewed/2024/04/GHSA-8hrj-6457-w65j/GHSA-8hrj-6457-w65j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hrj-6457-w65j", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:35:08Z", "published": "2024-04-17T21:30:47Z", "aliases": [ "CVE-2024-31031" ], "details": "An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json b/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json index 329f818dc57..e7522b503eb 100644 --- a/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json +++ b/advisories/unreviewed/2024/04/GHSA-8mqr-jgw7-9phj/GHSA-8mqr-jgw7-9phj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-8pmq-8vgm-m482/GHSA-8pmq-8vgm-m482.json b/advisories/unreviewed/2024/04/GHSA-8pmq-8vgm-m482/GHSA-8pmq-8vgm-m482.json index 7a0b269f468..ae9fc1ce4b2 100644 --- a/advisories/unreviewed/2024/04/GHSA-8pmq-8vgm-m482/GHSA-8pmq-8vgm-m482.json +++ b/advisories/unreviewed/2024/04/GHSA-8pmq-8vgm-m482/GHSA-8pmq-8vgm-m482.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pmq-8vgm-m482", - "modified": "2024-04-17T18:31:36Z", + "modified": "2024-07-03T18:34:55Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-30951" ], "details": "FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T18:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json b/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json index 8806486bca1..00748076cd9 100644 --- a/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json +++ b/advisories/unreviewed/2024/04/GHSA-8q63-w3px-vg38/GHSA-8q63-w3px-vg38.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8q63-w3px-vg38", - "modified": "2024-06-10T18:30:56Z", + "modified": "2024-07-03T18:36:11Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51798" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json b/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json index 308768c0c73..d69a7483877 100644 --- a/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json +++ b/advisories/unreviewed/2024/04/GHSA-8qhf-fjfw-g5r8/GHSA-8qhf-fjfw-g5r8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1223" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json b/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json index 12f1419ff56..a9e39be4335 100644 --- a/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json +++ b/advisories/unreviewed/2024/04/GHSA-8rg3-xv33-hfpc/GHSA-8rg3-xv33-hfpc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rg3-xv33-hfpc", - "modified": "2024-04-18T18:30:43Z", + "modified": "2024-07-03T18:35:29Z", "published": "2024-04-18T18:30:43Z", "aliases": [ "CVE-2024-24910" ], "details": "A local attacker can escalate privileges on affected Check Point ZoneAlarm Extreme Security NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-732" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T18:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-93jv-mjxf-3w6q/GHSA-93jv-mjxf-3w6q.json b/advisories/unreviewed/2024/04/GHSA-93jv-mjxf-3w6q/GHSA-93jv-mjxf-3w6q.json index 04e81b0992c..ffea34bdfb8 100644 --- a/advisories/unreviewed/2024/04/GHSA-93jv-mjxf-3w6q/GHSA-93jv-mjxf-3w6q.json +++ b/advisories/unreviewed/2024/04/GHSA-93jv-mjxf-3w6q/GHSA-93jv-mjxf-3w6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-93jv-mjxf-3w6q", - "modified": "2024-04-04T00:33:13Z", + "modified": "2024-07-03T18:34:06Z", "published": "2024-04-04T00:33:13Z", "aliases": [ "CVE-2024-26258" ], "details": "OS command injection vulnerability in WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T00:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json b/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json index fedde5cee89..663de07c69d 100644 --- a/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json +++ b/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9726-xp73-4p4q", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:06Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-50009" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json b/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json index 1e86a5c4beb..f10ec1356b1 100644 --- a/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json +++ b/advisories/unreviewed/2024/04/GHSA-9frh-fcfq-fv6f/GHSA-9frh-fcfq-fv6f.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-9g2g-x3hx-xmw8/GHSA-9g2g-x3hx-xmw8.json b/advisories/unreviewed/2024/04/GHSA-9g2g-x3hx-xmw8/GHSA-9g2g-x3hx-xmw8.json index 8c6cec9e756..8c21c2ce8d1 100644 --- a/advisories/unreviewed/2024/04/GHSA-9g2g-x3hx-xmw8/GHSA-9g2g-x3hx-xmw8.json +++ b/advisories/unreviewed/2024/04/GHSA-9g2g-x3hx-xmw8/GHSA-9g2g-x3hx-xmw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9g2g-x3hx-xmw8", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:16Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-32342" ], "details": "A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Permalink parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9pjp-3cgr-w3hw/GHSA-9pjp-3cgr-w3hw.json b/advisories/unreviewed/2024/04/GHSA-9pjp-3cgr-w3hw/GHSA-9pjp-3cgr-w3hw.json index 2d62f8385ac..017a6b3dd37 100644 --- a/advisories/unreviewed/2024/04/GHSA-9pjp-3cgr-w3hw/GHSA-9pjp-3cgr-w3hw.json +++ b/advisories/unreviewed/2024/04/GHSA-9pjp-3cgr-w3hw/GHSA-9pjp-3cgr-w3hw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9pjp-3cgr-w3hw", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:18Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32744" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the PAGE KEYWORDS parameter under the CURRENT PAGE module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9q6r-354c-h8c2/GHSA-9q6r-354c-h8c2.json b/advisories/unreviewed/2024/04/GHSA-9q6r-354c-h8c2/GHSA-9q6r-354c-h8c2.json index 5b01f27f8fd..918a1c5539d 100644 --- a/advisories/unreviewed/2024/04/GHSA-9q6r-354c-h8c2/GHSA-9q6r-354c-h8c2.json +++ b/advisories/unreviewed/2024/04/GHSA-9q6r-354c-h8c2/GHSA-9q6r-354c-h8c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9q6r-354c-h8c2", - "modified": "2024-04-17T15:30:42Z", + "modified": "2024-07-03T18:34:45Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-32281" ], "details": "Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9qx9-7q55-qhq4/GHSA-9qx9-7q55-qhq4.json b/advisories/unreviewed/2024/04/GHSA-9qx9-7q55-qhq4/GHSA-9qx9-7q55-qhq4.json index fcd9d663a3c..460eaebdf25 100644 --- a/advisories/unreviewed/2024/04/GHSA-9qx9-7q55-qhq4/GHSA-9qx9-7q55-qhq4.json +++ b/advisories/unreviewed/2024/04/GHSA-9qx9-7q55-qhq4/GHSA-9qx9-7q55-qhq4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qx9-7q55-qhq4", - "modified": "2024-04-15T06:30:34Z", + "modified": "2024-07-03T18:34:22Z", "published": "2024-04-15T06:30:34Z", "aliases": [ "CVE-2024-1849" ], "details": "The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9rxh-hjp4-932m/GHSA-9rxh-hjp4-932m.json b/advisories/unreviewed/2024/04/GHSA-9rxh-hjp4-932m/GHSA-9rxh-hjp4-932m.json index b0870271459..db93a139175 100644 --- a/advisories/unreviewed/2024/04/GHSA-9rxh-hjp4-932m/GHSA-9rxh-hjp4-932m.json +++ b/advisories/unreviewed/2024/04/GHSA-9rxh-hjp4-932m/GHSA-9rxh-hjp4-932m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9rxh-hjp4-932m", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:14Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-32163" ], "details": "CMSeasy 7.7.7.9 is vulnerable to code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json b/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json index b83c2977463..6f7472fc672 100644 --- a/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json +++ b/advisories/unreviewed/2024/04/GHSA-9w6g-r3rj-g5xg/GHSA-9w6g-r3rj-g5xg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json b/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json index 32e3a84c78a..db8b44490b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json +++ b/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c2pq-wjfc-hxwr", - "modified": "2024-04-19T09:30:47Z", + "modified": "2024-07-03T18:35:59Z", "published": "2024-04-19T09:30:47Z", "aliases": [ "CVE-2024-0671" ], "details": "Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Midgard GPU Kernel Driver: from r19p0 through r32p0; Bifrost GPU Kernel Driver: from r7p0 through r48p0; Valhall GPU Kernel Driver: from r19p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r48p0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T09:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json b/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json index 9bdeb39900b..5ce6c7923c4 100644 --- a/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json +++ b/advisories/unreviewed/2024/04/GHSA-c3p2-8x6x-wvh2/GHSA-c3p2-8x6x-wvh2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json b/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json index 0993741157d..5f63affd012 100644 --- a/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json +++ b/advisories/unreviewed/2024/04/GHSA-c47q-h9w3-rcwg/GHSA-c47q-h9w3-rcwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c47q-h9w3-rcwg", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:34:44Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3845" ], "details": "Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1068" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json b/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json index 0857d1b3de1..c6535c2311b 100644 --- a/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json +++ b/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c7qm-83h5-vx5f", - "modified": "2024-04-17T18:31:32Z", + "modified": "2024-07-03T18:34:52Z", "published": "2024-04-17T18:31:32Z", "aliases": [ "CVE-2023-46060" ], "details": "A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at the goform/setVlanInfo component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T16:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json b/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json index 145f2b611a5..b2a0c75aaef 100644 --- a/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json +++ b/advisories/unreviewed/2024/04/GHSA-c9m8-7p4q-vfm3/GHSA-c9m8-7p4q-vfm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c9m8-7p4q-vfm3", - "modified": "2024-04-15T06:30:35Z", + "modified": "2024-07-03T18:34:23Z", "published": "2024-04-15T06:30:35Z", "aliases": [ "CVE-2024-2836" ], "details": "The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json b/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json index 05a55d40f81..47aeee7930d 100644 --- a/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json +++ b/advisories/unreviewed/2024/04/GHSA-cmrp-gx54-8xq7/GHSA-cmrp-gx54-8xq7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmrp-gx54-8xq7", - "modified": "2024-04-19T18:31:12Z", + "modified": "2024-07-03T18:36:05Z", "published": "2024-04-19T18:31:12Z", "aliases": [ "CVE-2024-32409" ], "details": "An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T16:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cq73-mwp9-qgj2/GHSA-cq73-mwp9-qgj2.json b/advisories/unreviewed/2024/04/GHSA-cq73-mwp9-qgj2/GHSA-cq73-mwp9-qgj2.json index 78e3d8699f8..aa9c1c92e7d 100644 --- a/advisories/unreviewed/2024/04/GHSA-cq73-mwp9-qgj2/GHSA-cq73-mwp9-qgj2.json +++ b/advisories/unreviewed/2024/04/GHSA-cq73-mwp9-qgj2/GHSA-cq73-mwp9-qgj2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq73-mwp9-qgj2", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:34:44Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3846" ], "details": "Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json b/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json index 3bf7addb7f3..58df1d0b967 100644 --- a/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json +++ b/advisories/unreviewed/2024/04/GHSA-f72f-6w6j-jj9v/GHSA-f72f-6w6j-jj9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f72f-6w6j-jj9v", - "modified": "2024-06-10T18:30:56Z", + "modified": "2024-07-03T18:36:10Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51796" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json b/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json index 1ccdd1b0bc4..ecec7ca5f6b 100644 --- a/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json +++ b/advisories/unreviewed/2024/04/GHSA-f8vm-c6wx-cc8g/GHSA-f8vm-c6wx-cc8g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json b/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json index 8e25bae24f7..49c4a222399 100644 --- a/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json +++ b/advisories/unreviewed/2024/04/GHSA-f99r-65w5-r273/GHSA-f99r-65w5-r273.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f99r-65w5-r273", - "modified": "2024-04-19T18:31:11Z", + "modified": "2024-07-03T18:36:01Z", "published": "2024-04-19T18:31:11Z", "aliases": [ "CVE-2024-27752" ], "details": "Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T16:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-ff25-p529-q982/GHSA-ff25-p529-q982.json b/advisories/unreviewed/2024/04/GHSA-ff25-p529-q982/GHSA-ff25-p529-q982.json index b7927197431..2659ed86315 100644 --- a/advisories/unreviewed/2024/04/GHSA-ff25-p529-q982/GHSA-ff25-p529-q982.json +++ b/advisories/unreviewed/2024/04/GHSA-ff25-p529-q982/GHSA-ff25-p529-q982.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ff25-p529-q982", - "modified": "2024-04-17T21:30:46Z", + "modified": "2024-07-03T18:35:04Z", "published": "2024-04-17T21:30:46Z", "aliases": [ "CVE-2024-30953" ], "details": "A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link Name parameter of Menu Editor module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fwqx-9f23-5p7c/GHSA-fwqx-9f23-5p7c.json b/advisories/unreviewed/2024/04/GHSA-fwqx-9f23-5p7c/GHSA-fwqx-9f23-5p7c.json index d8e1b6a79ed..811ffb35eaf 100644 --- a/advisories/unreviewed/2024/04/GHSA-fwqx-9f23-5p7c/GHSA-fwqx-9f23-5p7c.json +++ b/advisories/unreviewed/2024/04/GHSA-fwqx-9f23-5p7c/GHSA-fwqx-9f23-5p7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fwqx-9f23-5p7c", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:16Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32343" ], "details": "A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json b/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json index 904d7e40678..b52f21e8b2d 100644 --- a/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json +++ b/advisories/unreviewed/2024/04/GHSA-g23v-56px-8cqm/GHSA-g23v-56px-8cqm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json b/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json index afeb226867f..87bc783246e 100644 --- a/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json +++ b/advisories/unreviewed/2024/04/GHSA-g2j7-fw82-h6x5/GHSA-g2j7-fw82-h6x5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g2j7-fw82-h6x5", - "modified": "2024-04-18T06:30:45Z", + "modified": "2024-07-03T18:35:23Z", "published": "2024-04-18T06:30:45Z", "aliases": [ "CVE-2024-2729" ], "details": "The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T05:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json b/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json index b568346e9bf..2effc9a06c8 100644 --- a/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json +++ b/advisories/unreviewed/2024/04/GHSA-g3wm-f7gr-3fwh/GHSA-g3wm-f7gr-3fwh.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-349" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json b/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json index adfa1e22df5..7a45b87802b 100644 --- a/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json +++ b/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g3wp-whmx-cpqj", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:06Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-50010" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the set_encoder_id function in /fftools/ffmpeg_enc.c component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json b/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json index f0076b8026f..6c99122c217 100644 --- a/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json +++ b/advisories/unreviewed/2024/04/GHSA-g7pg-ghhx-ph55/GHSA-g7pg-ghhx-ph55.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-g8vg-q9j5-3vf5/GHSA-g8vg-q9j5-3vf5.json b/advisories/unreviewed/2024/04/GHSA-g8vg-q9j5-3vf5/GHSA-g8vg-q9j5-3vf5.json index 7a389293387..c1ea84b1cc4 100644 --- a/advisories/unreviewed/2024/04/GHSA-g8vg-q9j5-3vf5/GHSA-g8vg-q9j5-3vf5.json +++ b/advisories/unreviewed/2024/04/GHSA-g8vg-q9j5-3vf5/GHSA-g8vg-q9j5-3vf5.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-gcgc-cr4r-c8xx/GHSA-gcgc-cr4r-c8xx.json b/advisories/unreviewed/2024/04/GHSA-gcgc-cr4r-c8xx/GHSA-gcgc-cr4r-c8xx.json index a6fbd9b8362..fbd038aad02 100644 --- a/advisories/unreviewed/2024/04/GHSA-gcgc-cr4r-c8xx/GHSA-gcgc-cr4r-c8xx.json +++ b/advisories/unreviewed/2024/04/GHSA-gcgc-cr4r-c8xx/GHSA-gcgc-cr4r-c8xx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gcgc-cr4r-c8xx", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:52Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32306" ], "details": "Tenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gmx8-9854-xjqr/GHSA-gmx8-9854-xjqr.json b/advisories/unreviewed/2024/04/GHSA-gmx8-9854-xjqr/GHSA-gmx8-9854-xjqr.json index 6a8bc5349bd..f9627947e17 100644 --- a/advisories/unreviewed/2024/04/GHSA-gmx8-9854-xjqr/GHSA-gmx8-9854-xjqr.json +++ b/advisories/unreviewed/2024/04/GHSA-gmx8-9854-xjqr/GHSA-gmx8-9854-xjqr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmx8-9854-xjqr", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:34:43Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3840" ], "details": "Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-285" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gqhg-ggfr-44wm/GHSA-gqhg-ggfr-44wm.json b/advisories/unreviewed/2024/04/GHSA-gqhg-ggfr-44wm/GHSA-gqhg-ggfr-44wm.json index 5f85651771b..1496df74ab4 100644 --- a/advisories/unreviewed/2024/04/GHSA-gqhg-ggfr-44wm/GHSA-gqhg-ggfr-44wm.json +++ b/advisories/unreviewed/2024/04/GHSA-gqhg-ggfr-44wm/GHSA-gqhg-ggfr-44wm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqhg-ggfr-44wm", - "modified": "2024-04-17T21:30:47Z", + "modified": "2024-07-03T18:35:07Z", "published": "2024-04-17T21:30:47Z", "aliases": [ "CVE-2024-30990" ], "details": "SQL Injection vulnerability in the \"Invoices\" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via \"searchdata\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gqmf-j3fp-9x2f/GHSA-gqmf-j3fp-9x2f.json b/advisories/unreviewed/2024/04/GHSA-gqmf-j3fp-9x2f/GHSA-gqmf-j3fp-9x2f.json index 68d73c92b6e..1d42d5fc2d3 100644 --- a/advisories/unreviewed/2024/04/GHSA-gqmf-j3fp-9x2f/GHSA-gqmf-j3fp-9x2f.json +++ b/advisories/unreviewed/2024/04/GHSA-gqmf-j3fp-9x2f/GHSA-gqmf-j3fp-9x2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqmf-j3fp-9x2f", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:34:44Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3843" ], "details": "Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gw9v-f3c7-qfqv/GHSA-gw9v-f3c7-qfqv.json b/advisories/unreviewed/2024/04/GHSA-gw9v-f3c7-qfqv/GHSA-gw9v-f3c7-qfqv.json index e38c3f1a294..69401418873 100644 --- a/advisories/unreviewed/2024/04/GHSA-gw9v-f3c7-qfqv/GHSA-gw9v-f3c7-qfqv.json +++ b/advisories/unreviewed/2024/04/GHSA-gw9v-f3c7-qfqv/GHSA-gw9v-f3c7-qfqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gw9v-f3c7-qfqv", - "modified": "2024-04-17T12:32:04Z", + "modified": "2024-07-03T18:34:45Z", "published": "2024-04-17T12:32:04Z", "aliases": [ "CVE-2024-26854" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix uninitialized dplls mutex usage\n\nThe pf->dplls.lock mutex is initialized too late, after its first use.\nMove it to the top of ice_dpll_init.\nNote that the \"err_exit\" error path destroys the mutex. And the mutex is\nthe last thing destroyed in ice_dpll_deinit.\nThis fixes the following warning with CONFIG_DEBUG_MUTEXES:\n\n ice 0000:10:00.0: The DDP package was successfully loaded: ICE OS Default Package version 1.3.36.0\n ice 0000:10:00.0: 252.048 Gb/s available PCIe bandwidth (16.0 GT/s PCIe x16 link)\n ice 0000:10:00.0: PTP init successful\n ------------[ cut here ]------------\n DEBUG_LOCKS_WARN_ON(lock->magic != lock)\n WARNING: CPU: 0 PID: 410 at kernel/locking/mutex.c:587 __mutex_lock+0x773/0xd40\n Modules linked in: crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic ice(+) nvme nvme_c>\n CPU: 0 PID: 410 Comm: kworker/0:4 Not tainted 6.8.0-rc5+ #3\n Hardware name: HPE ProLiant DL110 Gen10 Plus/ProLiant DL110 Gen10 Plus, BIOS U56 10/19/2023\n Workqueue: events work_for_cpu_fn\n RIP: 0010:__mutex_lock+0x773/0xd40\n Code: c0 0f 84 1d f9 ff ff 44 8b 35 0d 9c 69 01 45 85 f6 0f 85 0d f9 ff ff 48 c7 c6 12 a2 a9 85 48 c7 c7 12 f1 a>\n RSP: 0018:ff7eb1a3417a7ae0 EFLAGS: 00010286\n RAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000000\n RDX: 0000000000000002 RSI: ffffffff85ac2bff RDI: 00000000ffffffff\n RBP: ff7eb1a3417a7b80 R08: 0000000000000000 R09: 00000000ffffbfff\n R10: ff7eb1a3417a7978 R11: ff32b80f7fd2e568 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: ff32b7f02c50e0d8\n FS: 0000000000000000(0000) GS:ff32b80efe800000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000055b5852cc000 CR3: 000000003c43a004 CR4: 0000000000771ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __warn+0x84/0x170\n ? __mutex_lock+0x773/0xd40\n ? report_bug+0x1c7/0x1d0\n ? prb_read_valid+0x1b/0x30\n ? handle_bug+0x42/0x70\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? __mutex_lock+0x773/0xd40\n ? rcu_is_watching+0x11/0x50\n ? __kmalloc_node_track_caller+0x346/0x490\n ? ice_dpll_lock_status_get+0x28/0x50 [ice]\n ? __pfx_ice_dpll_lock_status_get+0x10/0x10 [ice]\n ? ice_dpll_lock_status_get+0x28/0x50 [ice]\n ice_dpll_lock_status_get+0x28/0x50 [ice]\n dpll_device_get_one+0x14f/0x2e0\n dpll_device_event_send+0x7d/0x150\n dpll_device_register+0x124/0x180\n ice_dpll_init_dpll+0x7b/0xd0 [ice]\n ice_dpll_init+0x224/0xa40 [ice]\n ? _dev_info+0x70/0x90\n ice_load+0x468/0x690 [ice]\n ice_probe+0x75b/0xa10 [ice]\n ? _raw_spin_unlock_irqrestore+0x4f/0x80\n ? process_one_work+0x1a3/0x500\n local_pci_probe+0x47/0xa0\n work_for_cpu_fn+0x17/0x30\n process_one_work+0x20d/0x500\n worker_thread+0x1df/0x3e0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x103/0x140\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n irq event stamp: 125197\n hardirqs last enabled at (125197): [] finish_task_switch.isra.0+0x12d/0x3d0\n hardirqs last disabled at (125196): [] __schedule+0xea4/0x19f0\n softirqs last enabled at (105334): [] napi_get_frags_check+0x1a/0x60\n softirqs last disabled at (105332): [] napi_get_frags_check+0x1a/0x60\n ---[ end trace 0000000000000000 ]---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json b/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json index e0d5dcd9ff6..11a6ac47f9b 100644 --- a/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json +++ b/advisories/unreviewed/2024/04/GHSA-gxh7-r3qj-jmff/GHSA-gxh7-r3qj-jmff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxh7-r3qj-jmff", - "modified": "2024-05-03T06:30:35Z", + "modified": "2024-07-03T18:34:43Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3841" ], "details": "Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h248-33jr-x3g2/GHSA-h248-33jr-x3g2.json b/advisories/unreviewed/2024/04/GHSA-h248-33jr-x3g2/GHSA-h248-33jr-x3g2.json index 07e022f6119..ea7ed0d5ba9 100644 --- a/advisories/unreviewed/2024/04/GHSA-h248-33jr-x3g2/GHSA-h248-33jr-x3g2.json +++ b/advisories/unreviewed/2024/04/GHSA-h248-33jr-x3g2/GHSA-h248-33jr-x3g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h248-33jr-x3g2", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:32Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30924" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-692" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json b/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json index 4d8bd6c55e1..39d5a79d3af 100644 --- a/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json +++ b/advisories/unreviewed/2024/04/GHSA-h3hp-g22h-899v/GHSA-h3hp-g22h-899v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3hp-g22h-899v", - "modified": "2024-04-18T18:30:41Z", + "modified": "2024-07-03T18:35:27Z", "published": "2024-04-18T18:30:41Z", "aliases": [ "CVE-2024-32326" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T17:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json b/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json index 26c0b8ddd30..ce9dd8f8f70 100644 --- a/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json +++ b/advisories/unreviewed/2024/04/GHSA-h9hg-q2g5-9w43/GHSA-h9hg-q2g5-9w43.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9hg-q2g5-9w43", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:49Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32286" ], "details": "Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hcxv-r3w2-6694/GHSA-hcxv-r3w2-6694.json b/advisories/unreviewed/2024/04/GHSA-hcxv-r3w2-6694/GHSA-hcxv-r3w2-6694.json index 6905ac3edad..9fc0ca07b2d 100644 --- a/advisories/unreviewed/2024/04/GHSA-hcxv-r3w2-6694/GHSA-hcxv-r3w2-6694.json +++ b/advisories/unreviewed/2024/04/GHSA-hcxv-r3w2-6694/GHSA-hcxv-r3w2-6694.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hcxv-r3w2-6694", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:15Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-32338" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the PAGE TITLE parameter under the Current Page module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hh22-pfjg-5xx4/GHSA-hh22-pfjg-5xx4.json b/advisories/unreviewed/2024/04/GHSA-hh22-pfjg-5xx4/GHSA-hh22-pfjg-5xx4.json index 8bce634d6cd..73d45e96651 100644 --- a/advisories/unreviewed/2024/04/GHSA-hh22-pfjg-5xx4/GHSA-hh22-pfjg-5xx4.json +++ b/advisories/unreviewed/2024/04/GHSA-hh22-pfjg-5xx4/GHSA-hh22-pfjg-5xx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hh22-pfjg-5xx4", - "modified": "2024-04-12T09:33:40Z", + "modified": "2024-07-03T18:34:21Z", "published": "2024-04-12T09:33:40Z", "aliases": [ "CVE-2024-29400" ], "details": "An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T07:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hp77-6fh4-q372/GHSA-hp77-6fh4-q372.json b/advisories/unreviewed/2024/04/GHSA-hp77-6fh4-q372/GHSA-hp77-6fh4-q372.json index ee3f5bc8b07..03c73c77190 100644 --- a/advisories/unreviewed/2024/04/GHSA-hp77-6fh4-q372/GHSA-hp77-6fh4-q372.json +++ b/advisories/unreviewed/2024/04/GHSA-hp77-6fh4-q372/GHSA-hp77-6fh4-q372.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-hprc-qr5r-m55p/GHSA-hprc-qr5r-m55p.json b/advisories/unreviewed/2024/04/GHSA-hprc-qr5r-m55p/GHSA-hprc-qr5r-m55p.json index 8013f8776d3..6d20a59eee9 100644 --- a/advisories/unreviewed/2024/04/GHSA-hprc-qr5r-m55p/GHSA-hprc-qr5r-m55p.json +++ b/advisories/unreviewed/2024/04/GHSA-hprc-qr5r-m55p/GHSA-hprc-qr5r-m55p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hprc-qr5r-m55p", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:50Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32292" ], "details": "Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json b/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json index 18f8ea62bd1..92bb7cc5b19 100644 --- a/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json +++ b/advisories/unreviewed/2024/04/GHSA-hrj8-px4x-vh25/GHSA-hrj8-px4x-vh25.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json b/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json index fa24a68b509..d3a2bb8516e 100644 --- a/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json +++ b/advisories/unreviewed/2024/04/GHSA-hv6v-2647-5j76/GHSA-hv6v-2647-5j76.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json b/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json index ae3934a37d5..83cf3ca3bc6 100644 --- a/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json +++ b/advisories/unreviewed/2024/04/GHSA-hwp9-p6mr-p438/GHSA-hwp9-p6mr-p438.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwp9-p6mr-p438", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:09Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51793" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json b/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json index 8a423a0e2c5..da058591a54 100644 --- a/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json +++ b/advisories/unreviewed/2024/04/GHSA-j3pf-jvpq-m354/GHSA-j3pf-jvpq-m354.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-j5wq-wpfj-9h9c/GHSA-j5wq-wpfj-9h9c.json b/advisories/unreviewed/2024/04/GHSA-j5wq-wpfj-9h9c/GHSA-j5wq-wpfj-9h9c.json index 067bcc667e3..dc40659ff35 100644 --- a/advisories/unreviewed/2024/04/GHSA-j5wq-wpfj-9h9c/GHSA-j5wq-wpfj-9h9c.json +++ b/advisories/unreviewed/2024/04/GHSA-j5wq-wpfj-9h9c/GHSA-j5wq-wpfj-9h9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5wq-wpfj-9h9c", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:15Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-32339" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into any of the parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json b/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json index 6a73a27ff04..32866dff40d 100644 --- a/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json +++ b/advisories/unreviewed/2024/04/GHSA-j69w-hqg4-wcw5/GHSA-j69w-hqg4-wcw5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j69w-hqg4-wcw5", - "modified": "2024-04-18T18:30:42Z", + "modified": "2024-07-03T18:35:28Z", "published": "2024-04-18T18:30:42Z", "aliases": [ "CVE-2024-32335" ], "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T17:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json b/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json index 308dcbb3d34..270805bef96 100644 --- a/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json +++ b/advisories/unreviewed/2024/04/GHSA-j87x-xq7w-hp68/GHSA-j87x-xq7w-hp68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j87x-xq7w-hp68", - "modified": "2024-04-05T21:32:43Z", + "modified": "2024-07-03T18:34:12Z", "published": "2024-04-05T21:32:43Z", "aliases": [ "CVE-2024-29740" ], "details": "In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j9pq-pgg7-c4j2/GHSA-j9pq-pgg7-c4j2.json b/advisories/unreviewed/2024/04/GHSA-j9pq-pgg7-c4j2/GHSA-j9pq-pgg7-c4j2.json index 3325ff4b73a..e28c4351690 100644 --- a/advisories/unreviewed/2024/04/GHSA-j9pq-pgg7-c4j2/GHSA-j9pq-pgg7-c4j2.json +++ b/advisories/unreviewed/2024/04/GHSA-j9pq-pgg7-c4j2/GHSA-j9pq-pgg7-c4j2.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-jc4p-rhvc-xg67/GHSA-jc4p-rhvc-xg67.json b/advisories/unreviewed/2024/04/GHSA-jc4p-rhvc-xg67/GHSA-jc4p-rhvc-xg67.json index 2e2d78afa23..20519f220a6 100644 --- a/advisories/unreviewed/2024/04/GHSA-jc4p-rhvc-xg67/GHSA-jc4p-rhvc-xg67.json +++ b/advisories/unreviewed/2024/04/GHSA-jc4p-rhvc-xg67/GHSA-jc4p-rhvc-xg67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jc4p-rhvc-xg67", - "modified": "2024-04-11T21:30:52Z", + "modified": "2024-07-03T18:34:18Z", "published": "2024-04-11T21:30:52Z", "aliases": [ "CVE-2024-22722" ], "details": "Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T20:15:33Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json b/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json index e43c146362d..78e0e50253f 100644 --- a/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json +++ b/advisories/unreviewed/2024/04/GHSA-jf9g-42gm-v87w/GHSA-jf9g-42gm-v87w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jf9g-42gm-v87w", - "modified": "2024-04-20T00:31:52Z", + "modified": "2024-07-03T18:34:16Z", "published": "2024-04-10T21:30:33Z", "aliases": [ "CVE-2024-3516" ], "details": "Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json b/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json index dd614d05778..2657f5fba1b 100644 --- a/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json +++ b/advisories/unreviewed/2024/04/GHSA-jfff-gxr9-9j6r/GHSA-jfff-gxr9-9j6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jfff-gxr9-9j6r", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:05Z", "published": "2024-04-19T18:31:14Z", "aliases": [ "CVE-2023-49501" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json b/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json index e0a97f03396..7ff2d826173 100644 --- a/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json +++ b/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhp9-93xh-vh3m", - "modified": "2024-04-19T09:30:47Z", + "modified": "2024-07-03T18:36:00Z", "published": "2024-04-19T09:30:47Z", "aliases": [ "CVE-2024-1065" ], "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T09:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jv87-hfr8-8j2r/GHSA-jv87-hfr8-8j2r.json b/advisories/unreviewed/2024/04/GHSA-jv87-hfr8-8j2r/GHSA-jv87-hfr8-8j2r.json index 84a3977e032..9f5e268d67e 100644 --- a/advisories/unreviewed/2024/04/GHSA-jv87-hfr8-8j2r/GHSA-jv87-hfr8-8j2r.json +++ b/advisories/unreviewed/2024/04/GHSA-jv87-hfr8-8j2r/GHSA-jv87-hfr8-8j2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jv87-hfr8-8j2r", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:35:03Z", "published": "2024-04-17T18:31:37Z", "aliases": [ "CVE-2024-3914" ], "details": "Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T18:15:16Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json b/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json index 1059de5fbc5..5d7a89eb87e 100644 --- a/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json +++ b/advisories/unreviewed/2024/04/GHSA-jw4m-rwmx-c8ph/GHSA-jw4m-rwmx-c8ph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jw4m-rwmx-c8ph", - "modified": "2024-04-09T15:30:36Z", + "modified": "2024-07-03T18:34:13Z", "published": "2024-04-09T15:30:36Z", "aliases": [ "CVE-2024-31544" ], "details": "A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in /classes/Master.php?f=save_record.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-09T13:15:33Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json b/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json index 178ad590e87..65bff38fad7 100644 --- a/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json +++ b/advisories/unreviewed/2024/04/GHSA-m37q-xj87-cf4v/GHSA-m37q-xj87-cf4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m37q-xj87-cf4v", - "modified": "2024-04-18T18:30:42Z", + "modified": "2024-07-03T18:35:28Z", "published": "2024-04-18T18:30:42Z", "aliases": [ "CVE-2024-32334" ], "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T17:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json b/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json index 94b3914ad18..af3295d17d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json +++ b/advisories/unreviewed/2024/04/GHSA-mr7r-xrwf-p8ph/GHSA-mr7r-xrwf-p8ph.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json index 62754cc302f..83bc06edc38 100644 --- a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json +++ b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mvc5-vcrh-v937", - "modified": "2024-04-22T12:30:33Z", + "modified": "2024-07-03T18:34:34Z", "published": "2024-04-16T18:31:36Z", "aliases": [ "CVE-2024-3861" ], "details": "If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mx2h-33cr-3q5j/GHSA-mx2h-33cr-3q5j.json b/advisories/unreviewed/2024/04/GHSA-mx2h-33cr-3q5j/GHSA-mx2h-33cr-3q5j.json index 4ed2e9ad765..8be8af26ce6 100644 --- a/advisories/unreviewed/2024/04/GHSA-mx2h-33cr-3q5j/GHSA-mx2h-33cr-3q5j.json +++ b/advisories/unreviewed/2024/04/GHSA-mx2h-33cr-3q5j/GHSA-mx2h-33cr-3q5j.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-p2cr-5w6f-32jg/GHSA-p2cr-5w6f-32jg.json b/advisories/unreviewed/2024/04/GHSA-p2cr-5w6f-32jg/GHSA-p2cr-5w6f-32jg.json index e593fff4eb7..5db579b85dc 100644 --- a/advisories/unreviewed/2024/04/GHSA-p2cr-5w6f-32jg/GHSA-p2cr-5w6f-32jg.json +++ b/advisories/unreviewed/2024/04/GHSA-p2cr-5w6f-32jg/GHSA-p2cr-5w6f-32jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2cr-5w6f-32jg", - "modified": "2024-04-15T12:30:34Z", + "modified": "2024-07-03T18:34:23Z", "published": "2024-04-15T12:30:34Z", "aliases": [ "CVE-2024-23911" ], "details": "Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T11:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json b/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json index 1fabab7e072..2f1128b42d1 100644 --- a/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json +++ b/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2g5-6h8g-6jr3", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:52Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32315" ], "details": "Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p2hm-x2gw-w2xc/GHSA-p2hm-x2gw-w2xc.json b/advisories/unreviewed/2024/04/GHSA-p2hm-x2gw-w2xc/GHSA-p2hm-x2gw-w2xc.json index d794f1c7199..0ece1962703 100644 --- a/advisories/unreviewed/2024/04/GHSA-p2hm-x2gw-w2xc/GHSA-p2hm-x2gw-w2xc.json +++ b/advisories/unreviewed/2024/04/GHSA-p2hm-x2gw-w2xc/GHSA-p2hm-x2gw-w2xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2hm-x2gw-w2xc", - "modified": "2024-04-17T15:30:42Z", + "modified": "2024-07-03T18:34:46Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-32312" ], "details": "Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the adslPwd parameter of the formWanParameterSetting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p2wx-52q9-6mgg/GHSA-p2wx-52q9-6mgg.json b/advisories/unreviewed/2024/04/GHSA-p2wx-52q9-6mgg/GHSA-p2wx-52q9-6mgg.json index a67941f7401..6d042959e4c 100644 --- a/advisories/unreviewed/2024/04/GHSA-p2wx-52q9-6mgg/GHSA-p2wx-52q9-6mgg.json +++ b/advisories/unreviewed/2024/04/GHSA-p2wx-52q9-6mgg/GHSA-p2wx-52q9-6mgg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2wx-52q9-6mgg", - "modified": "2024-04-17T21:30:48Z", + "modified": "2024-07-03T18:35:09Z", "published": "2024-04-17T21:30:48Z", "aliases": [ "CVE-2024-31040" ], "details": "Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p3j2-f5fx-mvq9/GHSA-p3j2-f5fx-mvq9.json b/advisories/unreviewed/2024/04/GHSA-p3j2-f5fx-mvq9/GHSA-p3j2-f5fx-mvq9.json index 9ec53d93834..993863c5b93 100644 --- a/advisories/unreviewed/2024/04/GHSA-p3j2-f5fx-mvq9/GHSA-p3j2-f5fx-mvq9.json +++ b/advisories/unreviewed/2024/04/GHSA-p3j2-f5fx-mvq9/GHSA-p3j2-f5fx-mvq9.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-p3xm-9632-5464/GHSA-p3xm-9632-5464.json b/advisories/unreviewed/2024/04/GHSA-p3xm-9632-5464/GHSA-p3xm-9632-5464.json index 641e4777ba6..8ab749b053d 100644 --- a/advisories/unreviewed/2024/04/GHSA-p3xm-9632-5464/GHSA-p3xm-9632-5464.json +++ b/advisories/unreviewed/2024/04/GHSA-p3xm-9632-5464/GHSA-p3xm-9632-5464.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3xm-9632-5464", - "modified": "2024-04-17T18:31:33Z", + "modified": "2024-07-03T18:34:54Z", "published": "2024-04-17T18:31:33Z", "aliases": [ "CVE-2024-32314" ], "details": "Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json b/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json index b519b65dff2..7c264eac629 100644 --- a/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json +++ b/advisories/unreviewed/2024/04/GHSA-p499-wvm3-j86w/GHSA-p499-wvm3-j86w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p499-wvm3-j86w", - "modified": "2024-04-04T15:30:34Z", + "modified": "2024-07-03T18:34:06Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-27575" ], "details": "Directory Traversal vulnerability in INOTEC Sicherheitstechnik GmbH INOTEC Sicherheitstechnik GmbH WebServer CPS220/64 V.3.3.19 allows a remote attacker to execute arbitrary code via the /etc/passwd file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T13:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json b/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json index b659a36770b..540d002b011 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json +++ b/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5p6-3j26-j8rh", - "modified": "2024-04-03T06:30:47Z", + "modified": "2024-07-03T18:34:05Z", "published": "2024-04-03T06:30:47Z", "aliases": [ "CVE-2024-31012" ], "details": "An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T04:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json index 82ec74169fc..eb3d498e4ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json +++ b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6gp-c388-p4cr", - "modified": "2024-04-24T12:30:42Z", + "modified": "2024-07-03T18:34:28Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3302" ], "details": "There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json b/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json index bd63457c6d8..0361536e38c 100644 --- a/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json +++ b/advisories/unreviewed/2024/04/GHSA-p6j5-jrmm-j3w6/GHSA-p6j5-jrmm-j3w6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p6j5-jrmm-j3w6", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-07-03T18:34:29Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3853" ], "details": "A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p777-v2c9-7gxq/GHSA-p777-v2c9-7gxq.json b/advisories/unreviewed/2024/04/GHSA-p777-v2c9-7gxq/GHSA-p777-v2c9-7gxq.json index 1e6e431a20b..53e176b7480 100644 --- a/advisories/unreviewed/2024/04/GHSA-p777-v2c9-7gxq/GHSA-p777-v2c9-7gxq.json +++ b/advisories/unreviewed/2024/04/GHSA-p777-v2c9-7gxq/GHSA-p777-v2c9-7gxq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p777-v2c9-7gxq", - "modified": "2024-04-11T03:35:00Z", + "modified": "2024-07-03T18:34:18Z", "published": "2024-04-11T03:35:00Z", "aliases": [ "CVE-2024-25572" ], "details": "Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T03:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json b/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json index c71b795b08f..02c10a1b28c 100644 --- a/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json +++ b/advisories/unreviewed/2024/04/GHSA-p7q5-2qf4-97cw/GHSA-p7q5-2qf4-97cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p7q5-2qf4-97cw", - "modified": "2024-04-19T06:30:28Z", + "modified": "2024-07-03T18:35:56Z", "published": "2024-04-19T06:30:28Z", "aliases": [ "CVE-2024-2761" ], "details": "The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T05:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pc3v-v7v4-v9h7/GHSA-pc3v-v7v4-v9h7.json b/advisories/unreviewed/2024/04/GHSA-pc3v-v7v4-v9h7/GHSA-pc3v-v7v4-v9h7.json index 59f36585338..6ed9082c6ac 100644 --- a/advisories/unreviewed/2024/04/GHSA-pc3v-v7v4-v9h7/GHSA-pc3v-v7v4-v9h7.json +++ b/advisories/unreviewed/2024/04/GHSA-pc3v-v7v4-v9h7/GHSA-pc3v-v7v4-v9h7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json index 3633eadaf25..4986c5c600e 100644 --- a/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json +++ b/advisories/unreviewed/2024/04/GHSA-pc7c-2483-8558/GHSA-pc7c-2483-8558.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc7c-2483-8558", - "modified": "2024-04-22T12:30:33Z", + "modified": "2024-07-03T18:34:29Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3852" ], "details": "GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-386" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json b/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json index ab90577dfdb..4eeec4369ac 100644 --- a/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json +++ b/advisories/unreviewed/2024/04/GHSA-pcqx-8h4p-6r69/GHSA-pcqx-8h4p-6r69.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcqx-8h4p-6r69", - "modified": "2024-04-18T21:30:31Z", + "modified": "2024-07-03T18:35:30Z", "published": "2024-04-18T21:30:31Z", "aliases": [ "CVE-2024-30922" ], "details": "SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pfjf-fvqx-mc5q/GHSA-pfjf-fvqx-mc5q.json b/advisories/unreviewed/2024/04/GHSA-pfjf-fvqx-mc5q/GHSA-pfjf-fvqx-mc5q.json index 577fb196dfc..24ce0e00d26 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfjf-fvqx-mc5q/GHSA-pfjf-fvqx-mc5q.json +++ b/advisories/unreviewed/2024/04/GHSA-pfjf-fvqx-mc5q/GHSA-pfjf-fvqx-mc5q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfjf-fvqx-mc5q", - "modified": "2024-04-17T15:30:42Z", + "modified": "2024-07-03T18:34:46Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-32313" ], "details": "Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T13:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pg6v-c8vh-5xch/GHSA-pg6v-c8vh-5xch.json b/advisories/unreviewed/2024/04/GHSA-pg6v-c8vh-5xch/GHSA-pg6v-c8vh-5xch.json index 872d1a1cca4..98d5a5a140f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pg6v-c8vh-5xch/GHSA-pg6v-c8vh-5xch.json +++ b/advisories/unreviewed/2024/04/GHSA-pg6v-c8vh-5xch/GHSA-pg6v-c8vh-5xch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pg6v-c8vh-5xch", - "modified": "2024-04-15T21:30:46Z", + "modified": "2024-07-03T18:34:25Z", "published": "2024-04-15T21:30:46Z", "aliases": [ "CVE-2024-31650" ], "details": "A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pg7h-5qx3-wjr3/GHSA-pg7h-5qx3-wjr3.json b/advisories/unreviewed/2024/04/GHSA-pg7h-5qx3-wjr3/GHSA-pg7h-5qx3-wjr3.json index 7781e3bedbd..584d3206441 100644 --- a/advisories/unreviewed/2024/04/GHSA-pg7h-5qx3-wjr3/GHSA-pg7h-5qx3-wjr3.json +++ b/advisories/unreviewed/2024/04/GHSA-pg7h-5qx3-wjr3/GHSA-pg7h-5qx3-wjr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pg7h-5qx3-wjr3", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:11Z", "published": "2024-04-17T21:30:48Z", "aliases": [ "CVE-2024-31583" ], "details": "Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T19:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json b/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json index bfcc9f1532f..1e1d3d1611e 100644 --- a/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json +++ b/advisories/unreviewed/2024/04/GHSA-ppm8-gjfw-8977/GHSA-ppm8-gjfw-8977.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppm8-gjfw-8977", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:09Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51795" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pvrj-ghv7-6684/GHSA-pvrj-ghv7-6684.json b/advisories/unreviewed/2024/04/GHSA-pvrj-ghv7-6684/GHSA-pvrj-ghv7-6684.json index 9c62f5ebd79..d9c090ca44c 100644 --- a/advisories/unreviewed/2024/04/GHSA-pvrj-ghv7-6684/GHSA-pvrj-ghv7-6684.json +++ b/advisories/unreviewed/2024/04/GHSA-pvrj-ghv7-6684/GHSA-pvrj-ghv7-6684.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-pw85-29gv-q327/GHSA-pw85-29gv-q327.json b/advisories/unreviewed/2024/04/GHSA-pw85-29gv-q327/GHSA-pw85-29gv-q327.json index 5c0a51963be..2ba1afe6cec 100644 --- a/advisories/unreviewed/2024/04/GHSA-pw85-29gv-q327/GHSA-pw85-29gv-q327.json +++ b/advisories/unreviewed/2024/04/GHSA-pw85-29gv-q327/GHSA-pw85-29gv-q327.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pw85-29gv-q327", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:50Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32290" ], "details": "Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json b/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json index fbc35fc63e4..bc9e2d95ccb 100644 --- a/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json +++ b/advisories/unreviewed/2024/04/GHSA-q2j3-5vpq-qxp4/GHSA-q2j3-5vpq-qxp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2j3-5vpq-qxp4", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:05Z", "published": "2024-04-19T18:31:14Z", "aliases": [ "CVE-2023-49502" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q2pc-5mm4-68mj/GHSA-q2pc-5mm4-68mj.json b/advisories/unreviewed/2024/04/GHSA-q2pc-5mm4-68mj/GHSA-q2pc-5mm4-68mj.json index 946161458f2..eb778b80266 100644 --- a/advisories/unreviewed/2024/04/GHSA-q2pc-5mm4-68mj/GHSA-q2pc-5mm4-68mj.json +++ b/advisories/unreviewed/2024/04/GHSA-q2pc-5mm4-68mj/GHSA-q2pc-5mm4-68mj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2pc-5mm4-68mj", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:50Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32291" ], "details": "Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json b/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json index db5dc96fa53..dcfc29cd06c 100644 --- a/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json +++ b/advisories/unreviewed/2024/04/GHSA-q3pf-hpw8-6327/GHSA-q3pf-hpw8-6327.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3pf-hpw8-6327", - "modified": "2024-04-19T18:31:15Z", + "modified": "2024-07-03T18:36:12Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2024-31552" ], "details": "CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:54Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q729-84hg-j6wm/GHSA-q729-84hg-j6wm.json b/advisories/unreviewed/2024/04/GHSA-q729-84hg-j6wm/GHSA-q729-84hg-j6wm.json index a80766c2478..13cb1373ed9 100644 --- a/advisories/unreviewed/2024/04/GHSA-q729-84hg-j6wm/GHSA-q729-84hg-j6wm.json +++ b/advisories/unreviewed/2024/04/GHSA-q729-84hg-j6wm/GHSA-q729-84hg-j6wm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q729-84hg-j6wm", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:33Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30928" ], "details": "SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json b/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json index 0634ab2b441..d6db3b642ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json +++ b/advisories/unreviewed/2024/04/GHSA-qp44-g28j-qgqp/GHSA-qp44-g28j-qgqp.json @@ -25,7 +25,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json b/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json index fd98a3ee25f..b6e0f49c1b2 100644 --- a/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json +++ b/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qq5c-v7vr-8ggg", - "modified": "2024-04-15T12:30:34Z", + "modified": "2024-07-03T18:34:23Z", "published": "2024-04-15T12:30:34Z", "aliases": [ "CVE-2024-29218" ], "details": "Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T11:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json b/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json index ceba1eca9c6..7fc9079d9a5 100644 --- a/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json +++ b/advisories/unreviewed/2024/04/GHSA-r345-8c48-x279/GHSA-r345-8c48-x279.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-r43r-4m97-hpp9/GHSA-r43r-4m97-hpp9.json b/advisories/unreviewed/2024/04/GHSA-r43r-4m97-hpp9/GHSA-r43r-4m97-hpp9.json index aaeb157a45e..108da949a8f 100644 --- a/advisories/unreviewed/2024/04/GHSA-r43r-4m97-hpp9/GHSA-r43r-4m97-hpp9.json +++ b/advisories/unreviewed/2024/04/GHSA-r43r-4m97-hpp9/GHSA-r43r-4m97-hpp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r43r-4m97-hpp9", - "modified": "2024-04-10T21:30:32Z", + "modified": "2024-07-03T18:34:14Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2024-28344" ], "details": "An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the \"back\" parameter in the URL through a double encoded URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json b/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json index 6bc0451bf42..37fcd41b701 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json +++ b/advisories/unreviewed/2024/04/GHSA-r8fc-3gvg-wxxf/GHSA-r8fc-3gvg-wxxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8fc-3gvg-wxxf", - "modified": "2024-05-03T03:30:46Z", + "modified": "2024-07-03T18:34:44Z", "published": "2024-04-17T09:30:32Z", "aliases": [ "CVE-2024-3847" ], "details": "Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-305" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T08:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json b/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json index c3f43bbbbe2..1d830fe737b 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json +++ b/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8wj-r2jc-587q", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:06Z", "published": "2024-04-19T18:31:14Z", "aliases": [ "CVE-2023-50007" ], "details": "Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via theav_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json b/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json index fdd90912a7c..0b690ab865c 100644 --- a/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json +++ b/advisories/unreviewed/2024/04/GHSA-rc4x-jw53-834q/GHSA-rc4x-jw53-834q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json b/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json index c1cb7a0e4b8..f4c89899d6a 100644 --- a/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json +++ b/advisories/unreviewed/2024/04/GHSA-rjv9-5c65-673q/GHSA-rjv9-5c65-673q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json b/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json index 271569bc5bf..af466a0ae82 100644 --- a/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json +++ b/advisories/unreviewed/2024/04/GHSA-rv7j-2mm5-9fv2/GHSA-rv7j-2mm5-9fv2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json b/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json index 1c666a33653..0e77fccd8ad 100644 --- a/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json +++ b/advisories/unreviewed/2024/04/GHSA-v26v-9938-hw55/GHSA-v26v-9938-hw55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v26v-9938-hw55", - "modified": "2024-04-19T18:31:11Z", + "modified": "2024-07-03T18:36:04Z", "published": "2024-04-19T18:31:11Z", "aliases": [ "CVE-2024-31846" ], "details": "An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T16:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json b/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json index 1f7364fd559..179fc478fc4 100644 --- a/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json +++ b/advisories/unreviewed/2024/04/GHSA-v4c8-xmpc-f835/GHSA-v4c8-xmpc-f835.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v4c8-xmpc-f835", - "modified": "2024-04-19T18:31:11Z", + "modified": "2024-07-03T18:36:02Z", "published": "2024-04-19T18:31:11Z", "aliases": [ "CVE-2024-31841" ], "details": "An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T16:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json b/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json index b1a4503142f..a0331e04df1 100644 --- a/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json +++ b/advisories/unreviewed/2024/04/GHSA-v829-2px7-7w8w/GHSA-v829-2px7-7w8w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-v86q-pm22-5w9h/GHSA-v86q-pm22-5w9h.json b/advisories/unreviewed/2024/04/GHSA-v86q-pm22-5w9h/GHSA-v86q-pm22-5w9h.json index 5839adae0f4..f9b2f6d5924 100644 --- a/advisories/unreviewed/2024/04/GHSA-v86q-pm22-5w9h/GHSA-v86q-pm22-5w9h.json +++ b/advisories/unreviewed/2024/04/GHSA-v86q-pm22-5w9h/GHSA-v86q-pm22-5w9h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v86q-pm22-5w9h", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:32Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30925" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vffh-vwhr-v5jp/GHSA-vffh-vwhr-v5jp.json b/advisories/unreviewed/2024/04/GHSA-vffh-vwhr-v5jp/GHSA-vffh-vwhr-v5jp.json index fa00613ccfe..c9dcc183a83 100644 --- a/advisories/unreviewed/2024/04/GHSA-vffh-vwhr-v5jp/GHSA-vffh-vwhr-v5jp.json +++ b/advisories/unreviewed/2024/04/GHSA-vffh-vwhr-v5jp/GHSA-vffh-vwhr-v5jp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vffh-vwhr-v5jp", - "modified": "2024-04-17T12:32:04Z", + "modified": "2024-07-03T18:34:45Z", "published": "2024-04-17T12:32:04Z", "aliases": [ "CVE-2024-26864" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix refcnt handling in __inet_hash_connect().\n\nsyzbot reported a warning in sk_nulls_del_node_init_rcu().\n\nThe commit 66b60b0c8c4a (\"dccp/tcp: Unhash sk from ehash for tb2 alloc\nfailure after check_estalblished().\") tried to fix an issue that an\nunconnected socket occupies an ehash entry when bhash2 allocation fails.\n\nIn such a case, we need to revert changes done by check_established(),\nwhich does not hold refcnt when inserting socket into ehash.\n\nSo, to revert the change, we need to __sk_nulls_add_node_rcu() instead\nof sk_nulls_add_node_rcu().\n\nOtherwise, sock_put() will cause refcnt underflow and leak the socket.\n\n[0]:\nWARNING: CPU: 0 PID: 23948 at include/net/sock.h:799 sk_nulls_del_node_init_rcu+0x166/0x1a0 include/net/sock.h:799\nModules linked in:\nCPU: 0 PID: 23948 Comm: syz-executor.2 Not tainted 6.8.0-rc6-syzkaller-00159-gc055fc00c07b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024\nRIP: 0010:sk_nulls_del_node_init_rcu+0x166/0x1a0 include/net/sock.h:799\nCode: e8 7f 71 c6 f7 83 fb 02 7c 25 e8 35 6d c6 f7 4d 85 f6 0f 95 c0 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 1b 6d c6 f7 90 <0f> 0b 90 eb b2 e8 10 6d c6 f7 4c 89 e7 be 04 00 00 00 e8 63 e7 d2\nRSP: 0018:ffffc900032d7848 EFLAGS: 00010246\nRAX: ffffffff89cd0035 RBX: 0000000000000001 RCX: 0000000000040000\nRDX: ffffc90004de1000 RSI: 000000000003ffff RDI: 0000000000040000\nRBP: 1ffff1100439ac26 R08: ffffffff89ccffe3 R09: 1ffff1100439ac28\nR10: dffffc0000000000 R11: ffffed100439ac29 R12: ffff888021cd6140\nR13: dffffc0000000000 R14: ffff88802a9bf5c0 R15: ffff888021cd6130\nFS: 00007f3b823f16c0(0000) GS:ffff8880b9400000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f3b823f0ff8 CR3: 000000004674a000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __inet_hash_connect+0x140f/0x20b0 net/ipv4/inet_hashtables.c:1139\n dccp_v6_connect+0xcb9/0x1480 net/dccp/ipv6.c:956\n __inet_stream_connect+0x262/0xf30 net/ipv4/af_inet.c:678\n inet_stream_connect+0x65/0xa0 net/ipv4/af_inet.c:749\n __sys_connect_file net/socket.c:2048 [inline]\n __sys_connect+0x2df/0x310 net/socket.c:2065\n __do_sys_connect net/socket.c:2075 [inline]\n __se_sys_connect net/socket.c:2072 [inline]\n __x64_sys_connect+0x7a/0x90 net/socket.c:2072\n do_syscall_64+0xf9/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\nRIP: 0033:0x7f3b8167dda9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f3b823f10c8 EFLAGS: 00000246 ORIG_RAX: 000000000000002a\nRAX: ffffffffffffffda RBX: 00007f3b817abf80 RCX: 00007f3b8167dda9\nRDX: 000000000000001c RSI: 0000000020000040 RDI: 0000000000000003\nRBP: 00007f3b823f1120 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001\nR13: 000000000000000b R14: 00007f3b817abf80 R15: 00007ffd3beb57b8\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json b/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json index 29ff7565eb6..0fa7666ee0e 100644 --- a/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json +++ b/advisories/unreviewed/2024/04/GHSA-vmcx-j4f5-gfcv/GHSA-vmcx-j4f5-gfcv.json @@ -41,7 +41,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-vqp5-2qc7-5hwg/GHSA-vqp5-2qc7-5hwg.json b/advisories/unreviewed/2024/04/GHSA-vqp5-2qc7-5hwg/GHSA-vqp5-2qc7-5hwg.json index 6a9ae9efd0b..159fd8f7846 100644 --- a/advisories/unreviewed/2024/04/GHSA-vqp5-2qc7-5hwg/GHSA-vqp5-2qc7-5hwg.json +++ b/advisories/unreviewed/2024/04/GHSA-vqp5-2qc7-5hwg/GHSA-vqp5-2qc7-5hwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqp5-2qc7-5hwg", - "modified": "2024-04-17T15:30:43Z", + "modified": "2024-07-03T18:34:49Z", "published": "2024-04-17T15:30:43Z", "aliases": [ "CVE-2024-32287" ], "details": "Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T14:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vrjw-w4gq-q7m6/GHSA-vrjw-w4gq-q7m6.json b/advisories/unreviewed/2024/04/GHSA-vrjw-w4gq-q7m6/GHSA-vrjw-w4gq-q7m6.json index ef91bfad577..04b7f3b20ae 100644 --- a/advisories/unreviewed/2024/04/GHSA-vrjw-w4gq-q7m6/GHSA-vrjw-w4gq-q7m6.json +++ b/advisories/unreviewed/2024/04/GHSA-vrjw-w4gq-q7m6/GHSA-vrjw-w4gq-q7m6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vrjw-w4gq-q7m6", - "modified": "2024-04-17T21:30:49Z", + "modified": "2024-07-03T18:35:15Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-32337" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ADMIN LOGIN URL parameter under the Security module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json b/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json index 433e10683a2..daf515f3ffd 100644 --- a/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json +++ b/advisories/unreviewed/2024/04/GHSA-vv98-j6p5-8hj3/GHSA-vv98-j6p5-8hj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vv98-j6p5-8hj3", - "modified": "2024-04-17T06:30:52Z", + "modified": "2024-07-03T18:34:40Z", "published": "2024-04-17T06:30:52Z", "aliases": [ "CVE-2024-2118" ], "details": "The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T05:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w22g-gw2j-fp4p/GHSA-w22g-gw2j-fp4p.json b/advisories/unreviewed/2024/04/GHSA-w22g-gw2j-fp4p/GHSA-w22g-gw2j-fp4p.json index c938eec2a5f..7c875b5d401 100644 --- a/advisories/unreviewed/2024/04/GHSA-w22g-gw2j-fp4p/GHSA-w22g-gw2j-fp4p.json +++ b/advisories/unreviewed/2024/04/GHSA-w22g-gw2j-fp4p/GHSA-w22g-gw2j-fp4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w22g-gw2j-fp4p", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:16Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32344" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under the Language section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w597-3p68-qvch/GHSA-w597-3p68-qvch.json b/advisories/unreviewed/2024/04/GHSA-w597-3p68-qvch/GHSA-w597-3p68-qvch.json index 6d3bc4a6911..065e08e0aac 100644 --- a/advisories/unreviewed/2024/04/GHSA-w597-3p68-qvch/GHSA-w597-3p68-qvch.json +++ b/advisories/unreviewed/2024/04/GHSA-w597-3p68-qvch/GHSA-w597-3p68-qvch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w597-3p68-qvch", - "modified": "2024-04-18T21:30:31Z", + "modified": "2024-07-03T18:35:29Z", "published": "2024-04-18T21:30:31Z", "aliases": [ "CVE-2024-30920" ], "details": "Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json b/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json index 4e9767152cc..ea51e1b03e0 100644 --- a/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json +++ b/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w5wq-cvfc-3r8g", - "modified": "2024-04-08T18:30:47Z", + "modified": "2024-07-03T18:34:11Z", "published": "2024-04-05T06:30:46Z", "aliases": [ "CVE-2024-2509" ], "details": "The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T05:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json b/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json index beb0e9f890c..c5f0c16c7af 100644 --- a/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json +++ b/advisories/unreviewed/2024/04/GHSA-w74q-jj94-wcp5/GHSA-w74q-jj94-wcp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w74q-jj94-wcp5", - "modified": "2024-04-18T18:30:42Z", + "modified": "2024-07-03T18:35:27Z", "published": "2024-04-18T18:30:42Z", "aliases": [ "CVE-2024-32333" ], "details": "TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-18T17:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w7jr-2c2w-7vxj/GHSA-w7jr-2c2w-7vxj.json b/advisories/unreviewed/2024/04/GHSA-w7jr-2c2w-7vxj/GHSA-w7jr-2c2w-7vxj.json index 1170dbfd432..7bdb0434f5a 100644 --- a/advisories/unreviewed/2024/04/GHSA-w7jr-2c2w-7vxj/GHSA-w7jr-2c2w-7vxj.json +++ b/advisories/unreviewed/2024/04/GHSA-w7jr-2c2w-7vxj/GHSA-w7jr-2c2w-7vxj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wq7q-x8vc-j7p4/GHSA-wq7q-x8vc-j7p4.json b/advisories/unreviewed/2024/04/GHSA-wq7q-x8vc-j7p4/GHSA-wq7q-x8vc-j7p4.json index 4da38875081..c4bce12a5ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-wq7q-x8vc-j7p4/GHSA-wq7q-x8vc-j7p4.json +++ b/advisories/unreviewed/2024/04/GHSA-wq7q-x8vc-j7p4/GHSA-wq7q-x8vc-j7p4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq7q-x8vc-j7p4", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:34Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-30938" ], "details": "SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T00:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wqhj-p438-8c8f/GHSA-wqhj-p438-8c8f.json b/advisories/unreviewed/2024/04/GHSA-wqhj-p438-8c8f/GHSA-wqhj-p438-8c8f.json index 598b5356b18..0662442477f 100644 --- a/advisories/unreviewed/2024/04/GHSA-wqhj-p438-8c8f/GHSA-wqhj-p438-8c8f.json +++ b/advisories/unreviewed/2024/04/GHSA-wqhj-p438-8c8f/GHSA-wqhj-p438-8c8f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqhj-p438-8c8f", - "modified": "2024-04-15T21:30:45Z", + "modified": "2024-07-03T18:34:24Z", "published": "2024-04-15T21:30:45Z", "aliases": [ "CVE-2024-28556" ], "details": "SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T19:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wr26-wjhr-jcwj/GHSA-wr26-wjhr-jcwj.json b/advisories/unreviewed/2024/04/GHSA-wr26-wjhr-jcwj/GHSA-wr26-wjhr-jcwj.json index 4ea084616ce..d711b953856 100644 --- a/advisories/unreviewed/2024/04/GHSA-wr26-wjhr-jcwj/GHSA-wr26-wjhr-jcwj.json +++ b/advisories/unreviewed/2024/04/GHSA-wr26-wjhr-jcwj/GHSA-wr26-wjhr-jcwj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr26-wjhr-jcwj", - "modified": "2024-04-17T18:31:36Z", + "modified": "2024-07-03T18:34:54Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-30983" ], "details": "SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-computer-detail.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T17:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json b/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json index 8cdeac8d6f5..fbcdfb68352 100644 --- a/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json +++ b/advisories/unreviewed/2024/04/GHSA-ww6m-hg6p-rm96/GHSA-ww6m-hg6p-rm96.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-x59x-2v4j-jj4c/GHSA-x59x-2v4j-jj4c.json b/advisories/unreviewed/2024/04/GHSA-x59x-2v4j-jj4c/GHSA-x59x-2v4j-jj4c.json index fa3be6a0118..c985b081af0 100644 --- a/advisories/unreviewed/2024/04/GHSA-x59x-2v4j-jj4c/GHSA-x59x-2v4j-jj4c.json +++ b/advisories/unreviewed/2024/04/GHSA-x59x-2v4j-jj4c/GHSA-x59x-2v4j-jj4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x59x-2v4j-jj4c", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:19Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32745" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the PAGE DESCRIPTION parameter under the CURRENT PAGE module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x6cj-gx36-vcxv/GHSA-x6cj-gx36-vcxv.json b/advisories/unreviewed/2024/04/GHSA-x6cj-gx36-vcxv/GHSA-x6cj-gx36-vcxv.json index 169c9610d4a..fba96dd9934 100644 --- a/advisories/unreviewed/2024/04/GHSA-x6cj-gx36-vcxv/GHSA-x6cj-gx36-vcxv.json +++ b/advisories/unreviewed/2024/04/GHSA-x6cj-gx36-vcxv/GHSA-x6cj-gx36-vcxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6cj-gx36-vcxv", - "modified": "2024-04-20T00:31:52Z", + "modified": "2024-07-03T18:34:16Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2024-3515" ], "details": "Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x8vw-8mw4-42v9/GHSA-x8vw-8mw4-42v9.json b/advisories/unreviewed/2024/04/GHSA-x8vw-8mw4-42v9/GHSA-x8vw-8mw4-42v9.json index 081c9864137..a6ccbbe15b2 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8vw-8mw4-42v9/GHSA-x8vw-8mw4-42v9.json +++ b/advisories/unreviewed/2024/04/GHSA-x8vw-8mw4-42v9/GHSA-x8vw-8mw4-42v9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8vw-8mw4-42v9", - "modified": "2024-04-19T00:30:54Z", + "modified": "2024-07-03T18:35:34Z", "published": "2024-04-19T00:30:54Z", "aliases": [ "CVE-2024-31750" ], "details": "SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T00:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json b/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json index f7e942ccb85..bf1e4a9173f 100644 --- a/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json +++ b/advisories/unreviewed/2024/04/GHSA-x9r4-wx9q-2r6r/GHSA-x9r4-wx9q-2r6r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json index 2fffe25734b..2bbec9cc87a 100644 --- a/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json +++ b/advisories/unreviewed/2024/04/GHSA-xc66-q4x2-cwqx/GHSA-xc66-q4x2-cwqx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc66-q4x2-cwqx", - "modified": "2024-04-22T12:30:33Z", + "modified": "2024-07-03T18:34:29Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3854" ], "details": "In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json b/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json index 5e96c6fa9fc..64d0d23eeff 100644 --- a/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json +++ b/advisories/unreviewed/2024/04/GHSA-xj57-m8w7-83wf/GHSA-xj57-m8w7-83wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj57-m8w7-83wf", - "modified": "2024-06-10T18:30:55Z", + "modified": "2024-07-03T18:36:07Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-51792" ], "details": "Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-19T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xrfp-xr69-8628/GHSA-xrfp-xr69-8628.json b/advisories/unreviewed/2024/04/GHSA-xrfp-xr69-8628/GHSA-xrfp-xr69-8628.json index 9e6dca4a78e..f3f3cb2e33d 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrfp-xr69-8628/GHSA-xrfp-xr69-8628.json +++ b/advisories/unreviewed/2024/04/GHSA-xrfp-xr69-8628/GHSA-xrfp-xr69-8628.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrfp-xr69-8628", - "modified": "2024-04-17T21:30:50Z", + "modified": "2024-07-03T18:35:18Z", "published": "2024-04-17T21:30:50Z", "aliases": [ "CVE-2024-32743" ], "details": "A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SITE LANGUAGE CONFIG parameter under the Security module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T21:15:09Z"