diff --git a/advisories/github-reviewed/2022/05/GHSA-qcj3-h27m-mp9x/GHSA-qcj3-h27m-mp9x.json b/advisories/github-reviewed/2022/05/GHSA-qcj3-h27m-mp9x/GHSA-qcj3-h27m-mp9x.json index 5e776039d1f..b4e31f21427 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qcj3-h27m-mp9x/GHSA-qcj3-h27m-mp9x.json +++ b/advisories/github-reviewed/2022/05/GHSA-qcj3-h27m-mp9x/GHSA-qcj3-h27m-mp9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qcj3-h27m-mp9x", - "modified": "2024-04-29T11:08:44Z", + "modified": "2024-10-07T21:32:17Z", "published": "2022-05-13T01:07:34Z", "aliases": [ "CVE-2018-16856" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -28,14 +32,11 @@ "introduced": "0" }, { - "fixed": "3.1.0" + "fixed": "2.1.0" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "< 2.1.0" - } + ] }, { "package": { @@ -77,6 +78,10 @@ { "type": "WEB", "url": "https://github.com/openstack/octavia/commits/3.1.0" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/octavia/PYSEC-2019-193.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/09/GHSA-49wm-4fp6-h59c/GHSA-49wm-4fp6-h59c.json b/advisories/github-reviewed/2022/09/GHSA-49wm-4fp6-h59c/GHSA-49wm-4fp6-h59c.json index cecce37ae0e..17c3899420e 100644 --- a/advisories/github-reviewed/2022/09/GHSA-49wm-4fp6-h59c/GHSA-49wm-4fp6-h59c.json +++ b/advisories/github-reviewed/2022/09/GHSA-49wm-4fp6-h59c/GHSA-49wm-4fp6-h59c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-49wm-4fp6-h59c", - "modified": "2022-09-23T13:58:49Z", + "modified": "2024-10-07T21:33:25Z", "published": "2022-09-22T00:00:32Z", "aliases": [ "CVE-2022-2872" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ diff --git a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json index fc2e389b583..d4f351ac741 100644 --- a/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json +++ b/advisories/github-reviewed/2024/08/GHSA-9623-mqmm-5rcf/GHSA-9623-mqmm-5rcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9623-mqmm-5rcf", - "modified": "2024-10-01T12:30:29Z", + "modified": "2024-10-07T21:33:28Z", "published": "2024-08-21T15:30:54Z", "aliases": [ "CVE-2024-7885" @@ -60,6 +60,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:7442" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7735" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:7736" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7885" diff --git a/advisories/unreviewed/2022/04/GHSA-2grp-34h8-p48c/GHSA-2grp-34h8-p48c.json b/advisories/unreviewed/2022/04/GHSA-2grp-34h8-p48c/GHSA-2grp-34h8-p48c.json index 24f06d26291..41206403692 100644 --- a/advisories/unreviewed/2022/04/GHSA-2grp-34h8-p48c/GHSA-2grp-34h8-p48c.json +++ b/advisories/unreviewed/2022/04/GHSA-2grp-34h8-p48c/GHSA-2grp-34h8-p48c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-cgq6-65fg-2fvf/GHSA-cgq6-65fg-2fvf.json b/advisories/unreviewed/2023/04/GHSA-cgq6-65fg-2fvf/GHSA-cgq6-65fg-2fvf.json index 4b7ef60ed23..6c24758e243 100644 --- a/advisories/unreviewed/2023/04/GHSA-cgq6-65fg-2fvf/GHSA-cgq6-65fg-2fvf.json +++ b/advisories/unreviewed/2023/04/GHSA-cgq6-65fg-2fvf/GHSA-cgq6-65fg-2fvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cgq6-65fg-2fvf", - "modified": "2023-04-11T18:30:28Z", + "modified": "2024-10-07T21:33:27Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-1818" diff --git a/advisories/unreviewed/2023/08/GHSA-6mpq-5wjj-48jg/GHSA-6mpq-5wjj-48jg.json b/advisories/unreviewed/2023/08/GHSA-6mpq-5wjj-48jg/GHSA-6mpq-5wjj-48jg.json index 84ce5ecb0bc..288bfa810d0 100644 --- a/advisories/unreviewed/2023/08/GHSA-6mpq-5wjj-48jg/GHSA-6mpq-5wjj-48jg.json +++ b/advisories/unreviewed/2023/08/GHSA-6mpq-5wjj-48jg/GHSA-6mpq-5wjj-48jg.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-9m48-r3w4-x35v/GHSA-9m48-r3w4-x35v.json b/advisories/unreviewed/2023/08/GHSA-9m48-r3w4-x35v/GHSA-9m48-r3w4-x35v.json index 4239927cf13..63e0a9570bc 100644 --- a/advisories/unreviewed/2023/08/GHSA-9m48-r3w4-x35v/GHSA-9m48-r3w4-x35v.json +++ b/advisories/unreviewed/2023/08/GHSA-9m48-r3w4-x35v/GHSA-9m48-r3w4-x35v.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-288" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-c5mr-x8m3-hpc9/GHSA-c5mr-x8m3-hpc9.json b/advisories/unreviewed/2023/08/GHSA-c5mr-x8m3-hpc9/GHSA-c5mr-x8m3-hpc9.json index c38062695a1..fef538fec1a 100644 --- a/advisories/unreviewed/2023/08/GHSA-c5mr-x8m3-hpc9/GHSA-c5mr-x8m3-hpc9.json +++ b/advisories/unreviewed/2023/08/GHSA-c5mr-x8m3-hpc9/GHSA-c5mr-x8m3-hpc9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-f5w2-2h32-hmg6/GHSA-f5w2-2h32-hmg6.json b/advisories/unreviewed/2023/08/GHSA-f5w2-2h32-hmg6/GHSA-f5w2-2h32-hmg6.json index b51524244bb..0ed8475ebb3 100644 --- a/advisories/unreviewed/2023/08/GHSA-f5w2-2h32-hmg6/GHSA-f5w2-2h32-hmg6.json +++ b/advisories/unreviewed/2023/08/GHSA-f5w2-2h32-hmg6/GHSA-f5w2-2h32-hmg6.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-562" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-hpr7-fpw7-jcx2/GHSA-hpr7-fpw7-jcx2.json b/advisories/unreviewed/2023/08/GHSA-hpr7-fpw7-jcx2/GHSA-hpr7-fpw7-jcx2.json index ed9d1431f05..4c8a97430d7 100644 --- a/advisories/unreviewed/2023/08/GHSA-hpr7-fpw7-jcx2/GHSA-hpr7-fpw7-jcx2.json +++ b/advisories/unreviewed/2023/08/GHSA-hpr7-fpw7-jcx2/GHSA-hpr7-fpw7-jcx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpr7-fpw7-jcx2", - "modified": "2023-11-06T06:30:26Z", + "modified": "2024-10-07T21:33:27Z", "published": "2023-08-18T15:30:23Z", "aliases": [ "CVE-2023-27576" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-jpj3-79gp-9hv5/GHSA-jpj3-79gp-9hv5.json b/advisories/unreviewed/2023/08/GHSA-jpj3-79gp-9hv5/GHSA-jpj3-79gp-9hv5.json index 5573e5c5abc..0f16ce8becd 100644 --- a/advisories/unreviewed/2023/08/GHSA-jpj3-79gp-9hv5/GHSA-jpj3-79gp-9hv5.json +++ b/advisories/unreviewed/2023/08/GHSA-jpj3-79gp-9hv5/GHSA-jpj3-79gp-9hv5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-mjgv-6qmw-8jwc/GHSA-mjgv-6qmw-8jwc.json b/advisories/unreviewed/2023/08/GHSA-mjgv-6qmw-8jwc/GHSA-mjgv-6qmw-8jwc.json index 1aec0f44d7a..08d4f2348eb 100644 --- a/advisories/unreviewed/2023/08/GHSA-mjgv-6qmw-8jwc/GHSA-mjgv-6qmw-8jwc.json +++ b/advisories/unreviewed/2023/08/GHSA-mjgv-6qmw-8jwc/GHSA-mjgv-6qmw-8jwc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-r7qv-f5p4-f3qr/GHSA-r7qv-f5p4-f3qr.json b/advisories/unreviewed/2023/08/GHSA-r7qv-f5p4-f3qr/GHSA-r7qv-f5p4-f3qr.json index 94edb64da03..f5a7758f0c9 100644 --- a/advisories/unreviewed/2023/08/GHSA-r7qv-f5p4-f3qr/GHSA-r7qv-f5p4-f3qr.json +++ b/advisories/unreviewed/2023/08/GHSA-r7qv-f5p4-f3qr/GHSA-r7qv-f5p4-f3qr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-wpv3-j7wc-292j/GHSA-wpv3-j7wc-292j.json b/advisories/unreviewed/2023/08/GHSA-wpv3-j7wc-292j/GHSA-wpv3-j7wc-292j.json index 896ec7a8e03..e352bb08a79 100644 --- a/advisories/unreviewed/2023/08/GHSA-wpv3-j7wc-292j/GHSA-wpv3-j7wc-292j.json +++ b/advisories/unreviewed/2023/08/GHSA-wpv3-j7wc-292j/GHSA-wpv3-j7wc-292j.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-w96c-3jm7-32vm/GHSA-w96c-3jm7-32vm.json b/advisories/unreviewed/2023/12/GHSA-w96c-3jm7-32vm/GHSA-w96c-3jm7-32vm.json index ecf8b4a4ddf..a6d099e0720 100644 --- a/advisories/unreviewed/2023/12/GHSA-w96c-3jm7-32vm/GHSA-w96c-3jm7-32vm.json +++ b/advisories/unreviewed/2023/12/GHSA-w96c-3jm7-32vm/GHSA-w96c-3jm7-32vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w96c-3jm7-32vm", - "modified": "2023-12-20T18:30:31Z", + "modified": "2024-10-07T21:33:28Z", "published": "2023-12-16T03:30:21Z", "aliases": [ "CVE-2021-42796" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json b/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json index 56d276f8533..950bd466364 100644 --- a/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json +++ b/advisories/unreviewed/2024/02/GHSA-gc2m-7496-w444/GHSA-gc2m-7496-w444.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gc2m-7496-w444", - "modified": "2024-02-13T18:38:23Z", + "modified": "2024-10-07T21:33:28Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2023-45207" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browser, the stored XSS payload is executed. (This has been mitigated by sanitising the JavaScript code present in a PDF document.)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-13T16:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json b/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json index 0c47471b2d6..48059e3f9db 100644 --- a/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json +++ b/advisories/unreviewed/2024/09/GHSA-5257-g4x8-28qj/GHSA-5257-g4x8-28qj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-521" + "CWE-521", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json b/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json index bb60ceecb8c..9f9baa6f13c 100644 --- a/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json +++ b/advisories/unreviewed/2024/09/GHSA-pf8r-hfj4-5hrm/GHSA-pf8r-hfj4-5hrm.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-345", "CWE-353" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json b/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json index de7c483f221..a93f6383934 100644 --- a/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json +++ b/advisories/unreviewed/2024/09/GHSA-vrv4-mmpj-7phv/GHSA-vrv4-mmpj-7phv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json b/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json index 09280b12a9b..f99186ee91d 100644 --- a/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json +++ b/advisories/unreviewed/2024/09/GHSA-wq4q-895p-v538/GHSA-wq4q-895p-v538.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json b/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json new file mode 100644 index 00000000000..77e202fe4ef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-32jw-rrh7-q59g/GHSA-32jw-rrh7-q59g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32jw-rrh7-q59g", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:31Z", + "aliases": [ + "CVE-2024-47972" + ], + "details": "Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47972" + }, + { + "type": "WEB", + "url": "https://https://www.solidigm.com/support-page/support-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3p98-cw2j-96xf/GHSA-3p98-cw2j-96xf.json b/advisories/unreviewed/2024/10/GHSA-3p98-cw2j-96xf/GHSA-3p98-cw2j-96xf.json index 546922b4a56..f368002cfd7 100644 --- a/advisories/unreviewed/2024/10/GHSA-3p98-cw2j-96xf/GHSA-3p98-cw2j-96xf.json +++ b/advisories/unreviewed/2024/10/GHSA-3p98-cw2j-96xf/GHSA-3p98-cw2j-96xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p98-cw2j-96xf", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41515" ], "details": "A reflected cross-site scripting (XSS) vulnerability in \"ccHandlerResource.ashx\" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the \"res_url\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-438g-rq2f-384h/GHSA-438g-rq2f-384h.json b/advisories/unreviewed/2024/10/GHSA-438g-rq2f-384h/GHSA-438g-rq2f-384h.json index ddae9c6581c..740dab77ba2 100644 --- a/advisories/unreviewed/2024/10/GHSA-438g-rq2f-384h/GHSA-438g-rq2f-384h.json +++ b/advisories/unreviewed/2024/10/GHSA-438g-rq2f-384h/GHSA-438g-rq2f-384h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-438g-rq2f-384h", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20101" ], "details": "In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json b/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json index b1c158521e8..d36c731cace 100644 --- a/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json +++ b/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4q89-84pm-r2p6", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20094" ], "details": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -28,7 +31,7 @@ "CWE-20", "CWE-617" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json b/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json new file mode 100644 index 00000000000..740f2c03f98 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rj9-473r-rjfw", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:31Z", + "aliases": [ + "CVE-2024-47971" + ], + "details": "Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47971" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.htmlhttps:" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json b/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json index 5f7997e86cd..0e16ebea999 100644 --- a/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json +++ b/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52p8-m5r2-c245", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-46077" ], "details": "itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T19:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5gx5-6w46-474p/GHSA-5gx5-6w46-474p.json b/advisories/unreviewed/2024/10/GHSA-5gx5-6w46-474p/GHSA-5gx5-6w46-474p.json index dd9364b5946..10c90cd1485 100644 --- a/advisories/unreviewed/2024/10/GHSA-5gx5-6w46-474p/GHSA-5gx5-6w46-474p.json +++ b/advisories/unreviewed/2024/10/GHSA-5gx5-6w46-474p/GHSA-5gx5-6w46-474p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5gx5-6w46-474p", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20098" ], "details": "In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json new file mode 100644 index 00000000000..29380c8157c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p85-p472-x7wv", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:31Z", + "aliases": [ + "CVE-2024-47967" + ], + "details": "Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47967" + }, + { + "type": "WEB", + "url": "https://https://www.solidigm.com/support-page/support-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json b/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json index 7784f684eed..172eec937cc 100644 --- a/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json +++ b/advisories/unreviewed/2024/10/GHSA-5qpr-f47p-f6ch/GHSA-5qpr-f47p-f6ch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qpr-f47p-f6ch", - "modified": "2024-10-03T21:31:04Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-03T21:31:04Z", "aliases": [ "CVE-2024-41588" ], "details": "The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5qw6-g66j-jc2c/GHSA-5qw6-g66j-jc2c.json b/advisories/unreviewed/2024/10/GHSA-5qw6-g66j-jc2c/GHSA-5qw6-g66j-jc2c.json index 920110a73d3..bb31c9130e2 100644 --- a/advisories/unreviewed/2024/10/GHSA-5qw6-g66j-jc2c/GHSA-5qw6-g66j-jc2c.json +++ b/advisories/unreviewed/2024/10/GHSA-5qw6-g66j-jc2c/GHSA-5qw6-g66j-jc2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qw6-g66j-jc2c", - "modified": "2024-10-02T12:30:32Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-02T12:30:32Z", "aliases": [ "CVE-2024-8282" diff --git a/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json b/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json index 8776ebfdf40..387ea1c3082 100644 --- a/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json +++ b/advisories/unreviewed/2024/10/GHSA-5wwp-5xg3-xwh6/GHSA-5wwp-5xg3-xwh6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5wwp-5xg3-xwh6", - "modified": "2024-10-01T21:31:34Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-31835" ], "details": "Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T19:15:07Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json b/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json index 09b704bd1ef..bec85d95eb2 100644 --- a/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json +++ b/advisories/unreviewed/2024/10/GHSA-6hr6-rx9m-cchc/GHSA-6hr6-rx9m-cchc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6hr6-rx9m-cchc", - "modified": "2024-10-07T18:31:09Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:09Z", "aliases": [ "CVE-2024-42831" ], "details": "A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T18:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-76q6-3r42-2mj6/GHSA-76q6-3r42-2mj6.json b/advisories/unreviewed/2024/10/GHSA-76q6-3r42-2mj6/GHSA-76q6-3r42-2mj6.json index a989a9c1a5e..2ee4f3e2122 100644 --- a/advisories/unreviewed/2024/10/GHSA-76q6-3r42-2mj6/GHSA-76q6-3r42-2mj6.json +++ b/advisories/unreviewed/2024/10/GHSA-76q6-3r42-2mj6/GHSA-76q6-3r42-2mj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76q6-3r42-2mj6", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20090" ], "details": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1703.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json b/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json index 4e45abee699..db00ada7e65 100644 --- a/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json +++ b/advisories/unreviewed/2024/10/GHSA-82m4-8qr7-3gp9/GHSA-82m4-8qr7-3gp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82m4-8qr7-3gp9", - "modified": "2024-10-07T18:31:08Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:08Z", "aliases": [ "CVE-2024-46041" ], "details": "IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-294" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T16:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json b/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json index 41efe964507..cf08478275e 100644 --- a/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json +++ b/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-85hj-g8gj-8mxh", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2023-26771" ], "details": "Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json b/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json index 1fe1eeace84..0f95f0b9dba 100644 --- a/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json +++ b/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json b/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json index 5fdd1097007..b6d0cdf47a5 100644 --- a/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json +++ b/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cpm-p3f3-45f7", - "modified": "2024-10-04T21:31:30Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:30Z", "aliases": [ "CVE-2024-37868" ], "details": "File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the \"sendreply.php\" file, and the uploaded file was received using the \"$- FILES\" variable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T21:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8rfp-v855-gr3w/GHSA-8rfp-v855-gr3w.json b/advisories/unreviewed/2024/10/GHSA-8rfp-v855-gr3w/GHSA-8rfp-v855-gr3w.json new file mode 100644 index 00000000000..6a15e904528 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8rfp-v855-gr3w/GHSA-8rfp-v855-gr3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rfp-v855-gr3w", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-47556" + ], + "details": "Pre-Auth RCE via Path Traversal", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47556" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2024/10/Xerox-Security-Bulletin-XRX24-014-for-Xerox%C2%AE-FreeFlow%C2%AE-Core-v7.0-.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json b/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json index d8f5252eddf..b5a22075246 100644 --- a/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json +++ b/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wx5-f2gv-24cc", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41512" ], "details": "A SQL Injection vulnerability in \"ccHandler.aspx\" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the \"bomid\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json b/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json index b1d00283448..26ba08554fa 100644 --- a/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json +++ b/advisories/unreviewed/2024/10/GHSA-9wcc-fp9g-mcjc/GHSA-9wcc-fp9g-mcjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9wcc-fp9g-mcjc", - "modified": "2024-10-07T18:31:09Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:09Z", "aliases": [ "CVE-2024-44674" ], "details": "D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T18:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json b/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json index e7cbdd42093..8deaf41c140 100644 --- a/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json +++ b/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c49j-87c4-mmr5", - "modified": "2024-10-04T21:31:30Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:30Z", "aliases": [ "CVE-2024-47910" ], "details": "An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T21:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json b/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json index 00a61b877d5..edb840ed3a2 100644 --- a/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json +++ b/advisories/unreviewed/2024/10/GHSA-f2c3-h6fh-5x7q/GHSA-f2c3-h6fh-5x7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2c3-h6fh-5x7q", - "modified": "2024-10-07T18:31:09Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:09Z", "aliases": [ "CVE-2024-46076" ], "details": "RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T18:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json b/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json index 08ba79e5849..c48d5f27fa0 100644 --- a/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json +++ b/advisories/unreviewed/2024/10/GHSA-f7vv-q49x-rvww/GHSA-f7vv-q49x-rvww.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1391" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-frrh-j3wr-gprp/GHSA-frrh-j3wr-gprp.json b/advisories/unreviewed/2024/10/GHSA-frrh-j3wr-gprp/GHSA-frrh-j3wr-gprp.json new file mode 100644 index 00000000000..b607ee00ca2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-frrh-j3wr-gprp/GHSA-frrh-j3wr-gprp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frrh-j3wr-gprp", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-44068" + ], + "details": "An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44068" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates" + }, + { + "type": "WEB", + "url": "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-44068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g4jv-rpgh-595r/GHSA-g4jv-rpgh-595r.json b/advisories/unreviewed/2024/10/GHSA-g4jv-rpgh-595r/GHSA-g4jv-rpgh-595r.json index c90650f1920..44096c806cf 100644 --- a/advisories/unreviewed/2024/10/GHSA-g4jv-rpgh-595r/GHSA-g4jv-rpgh-595r.json +++ b/advisories/unreviewed/2024/10/GHSA-g4jv-rpgh-595r/GHSA-g4jv-rpgh-595r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g4jv-rpgh-595r", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20100" ], "details": "In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json b/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json index eff29241853..b4ac15bb4a6 100644 --- a/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json +++ b/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv59-h7rc-cxvr", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2023-26770" ], "details": "TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T19:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json b/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json index 2da406c17a8..9f0b40b424c 100644 --- a/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json +++ b/advisories/unreviewed/2024/10/GHSA-gx28-329m-22gw/GHSA-gx28-329m-22gw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gx28-329m-22gw", - "modified": "2024-10-03T21:31:04Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-03T21:31:04Z", "aliases": [ "CVE-2024-41590" ], "details": "Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hj4f-v7wh-wv79/GHSA-hj4f-v7wh-wv79.json b/advisories/unreviewed/2024/10/GHSA-hj4f-v7wh-wv79/GHSA-hj4f-v7wh-wv79.json index 06c9626c087..6b53abe5f5f 100644 --- a/advisories/unreviewed/2024/10/GHSA-hj4f-v7wh-wv79/GHSA-hj4f-v7wh-wv79.json +++ b/advisories/unreviewed/2024/10/GHSA-hj4f-v7wh-wv79/GHSA-hj4f-v7wh-wv79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hj4f-v7wh-wv79", - "modified": "2024-10-04T18:31:10Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-46409" ], "details": "A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-hp5q-qr77-457v/GHSA-hp5q-qr77-457v.json b/advisories/unreviewed/2024/10/GHSA-hp5q-qr77-457v/GHSA-hp5q-qr77-457v.json index 2c40e00fa7b..4fbf8190773 100644 --- a/advisories/unreviewed/2024/10/GHSA-hp5q-qr77-457v/GHSA-hp5q-qr77-457v.json +++ b/advisories/unreviewed/2024/10/GHSA-hp5q-qr77-457v/GHSA-hp5q-qr77-457v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp5q-qr77-457v", - "modified": "2024-10-02T12:30:32Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-02T12:30:32Z", "aliases": [ "CVE-2024-8505" @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-87" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json b/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json index 292d4a543f5..4466082d31a 100644 --- a/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json +++ b/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6px-w88f-j869", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41514" ], "details": "A reflected cross-site scripting (XSS) vulnerability in \"PrevPgGroup.aspx\" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the \"wer\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json new file mode 100644 index 00000000000..7ada2dd68e7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgmx-4v96-mgr5", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:31Z", + "aliases": [ + "CVE-2024-47974" + ], + "details": "Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47974" + }, + { + "type": "WEB", + "url": "https://https://www.solidigm.com/support-page/support-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json b/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json index fa67cf388f9..3ebd95f7797 100644 --- a/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json +++ b/advisories/unreviewed/2024/10/GHSA-jhrj-jf6x-vjjx/GHSA-jhrj-jf6x-vjjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhrj-jf6x-vjjx", - "modified": "2024-10-03T21:31:04Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-03T21:31:04Z", "aliases": [ "CVE-2024-41585" ], "details": "DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T19:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json b/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json index 347a61ebd59..a2b2071d1da 100644 --- a/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json +++ b/advisories/unreviewed/2024/10/GHSA-jp3v-f34f-92px/GHSA-jp3v-f34f-92px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jp3v-f34f-92px", - "modified": "2024-10-07T18:31:09Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:09Z", "aliases": [ "CVE-2024-46300" ], "details": "itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T17:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-m58m-2q43-q4v2/GHSA-m58m-2q43-q4v2.json b/advisories/unreviewed/2024/10/GHSA-m58m-2q43-q4v2/GHSA-m58m-2q43-q4v2.json new file mode 100644 index 00000000000..b5da869bef9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m58m-2q43-q4v2/GHSA-m58m-2q43-q4v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m58m-2q43-q4v2", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:31Z", + "aliases": [ + "CVE-2024-47973" + ], + "details": "In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47973" + }, + { + "type": "WEB", + "url": "https://www.solidigm.com/support-page/support-security.htmlhttps:" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m73v-86ff-ghch/GHSA-m73v-86ff-ghch.json b/advisories/unreviewed/2024/10/GHSA-m73v-86ff-ghch/GHSA-m73v-86ff-ghch.json new file mode 100644 index 00000000000..d3f73cfb8ac --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m73v-86ff-ghch/GHSA-m73v-86ff-ghch.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m73v-86ff-ghch", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:31Z", + "aliases": [ + "CVE-2024-45919" + ], + "details": "A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflows leading to unauthorized access to sensitive information or approval of fraudulent requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45919" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ipxsec/28afaf965389283a68433c7afd54d17a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json b/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json index 472f5b7c74b..76b72a3649a 100644 --- a/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json +++ b/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjg9-2fc5-7g27", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:29Z", "aliases": [ "CVE-2024-46078" ], "details": "itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T19:15:16Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mqv7-vh3x-r5qv/GHSA-mqv7-vh3x-r5qv.json b/advisories/unreviewed/2024/10/GHSA-mqv7-vh3x-r5qv/GHSA-mqv7-vh3x-r5qv.json index bb8f3e23597..d5ae7cf2afa 100644 --- a/advisories/unreviewed/2024/10/GHSA-mqv7-vh3x-r5qv/GHSA-mqv7-vh3x-r5qv.json +++ b/advisories/unreviewed/2024/10/GHSA-mqv7-vh3x-r5qv/GHSA-mqv7-vh3x-r5qv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqv7-vh3x-r5qv", - "modified": "2024-10-04T18:31:10Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-46486" ], "details": "TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T17:15:17Z" diff --git a/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json b/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json index 054442d8abf..af44f9f50c4 100644 --- a/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json +++ b/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mvx6-xfx7-r23g", - "modified": "2024-10-07T15:31:38Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41511" ], "details": "A Path Traversal (Local File Inclusion) vulnerability in \"BinaryFileRedirector.ashx\" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the \"path\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pmxr-vg36-rjqq/GHSA-pmxr-vg36-rjqq.json b/advisories/unreviewed/2024/10/GHSA-pmxr-vg36-rjqq/GHSA-pmxr-vg36-rjqq.json index 2a3de5e2ba3..52473958ffb 100644 --- a/advisories/unreviewed/2024/10/GHSA-pmxr-vg36-rjqq/GHSA-pmxr-vg36-rjqq.json +++ b/advisories/unreviewed/2024/10/GHSA-pmxr-vg36-rjqq/GHSA-pmxr-vg36-rjqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmxr-vg36-rjqq", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20103" ], "details": "In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q2rv-rxjh-hjrw/GHSA-q2rv-rxjh-hjrw.json b/advisories/unreviewed/2024/10/GHSA-q2rv-rxjh-hjrw/GHSA-q2rv-rxjh-hjrw.json new file mode 100644 index 00000000000..a54aae51648 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q2rv-rxjh-hjrw/GHSA-q2rv-rxjh-hjrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2rv-rxjh-hjrw", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-47559" + ], + "details": "Authenticated RCE via Path Traversal", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47559" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2024/10/Xerox-Security-Bulletin-XRX24-014-for-Xerox%C2%AE-FreeFlow%C2%AE-Core-v7.0-.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json b/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json new file mode 100644 index 00000000000..b59898109bc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8xm-x824-w6gf", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-45894" + ], + "details": "BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45894" + }, + { + "type": "WEB", + "url": "https://github.com/source-trace/bluecms/issues/1" + }, + { + "type": "WEB", + "url": "https://gist.github.com/yihanjinchangtai/215ea4bf71edb0ac9df33b221b63a3a9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json b/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json new file mode 100644 index 00000000000..55dcaae8809 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qf67-47q7-2f84/GHSA-qf67-47q7-2f84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf67-47q7-2f84", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-47975" + ], + "details": "Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47975" + }, + { + "type": "WEB", + "url": "https://https://www.solidigm.com/support-page/support-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json b/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json index fa86b08098d..b8587e99f6b 100644 --- a/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json +++ b/advisories/unreviewed/2024/10/GHSA-qw9m-35wc-m4gj/GHSA-qw9m-35wc-m4gj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw9m-35wc-m4gj", - "modified": "2024-10-07T18:31:09Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:09Z", "aliases": [ "CVE-2024-46278" ], "details": "Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T16:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json b/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json index 57cafbc31fc..1122ac3d444 100644 --- a/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json +++ b/advisories/unreviewed/2024/10/GHSA-qxgf-2m78-27m8/GHSA-qxgf-2m78-27m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxgf-2m78-27m8", - "modified": "2024-10-03T21:31:05Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-03T21:31:05Z", "aliases": [ "CVE-2024-46658" ], "details": "Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-03T21:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rw58-478h-633w/GHSA-rw58-478h-633w.json b/advisories/unreviewed/2024/10/GHSA-rw58-478h-633w/GHSA-rw58-478h-633w.json index bc928d99d5a..d772831405c 100644 --- a/advisories/unreviewed/2024/10/GHSA-rw58-478h-633w/GHSA-rw58-478h-633w.json +++ b/advisories/unreviewed/2024/10/GHSA-rw58-478h-633w/GHSA-rw58-478h-633w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rw58-478h-633w", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20092" ], "details": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1700.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json b/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json index 69f7efff763..54a14070452 100644 --- a/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json +++ b/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rwh5-jx2j-64h2", - "modified": "2024-10-04T21:31:29Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41513" ], "details": "A reflected cross-site scripting (XSS) vulnerability in \"Artikel.aspx\" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the \"searchindex\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json b/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json index 542244826b5..e26cb226283 100644 --- a/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json +++ b/advisories/unreviewed/2024/10/GHSA-v5jv-g2mh-7rmh/GHSA-v5jv-g2mh-7rmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5jv-g2mh-7rmh", - "modified": "2024-10-01T21:31:34Z", + "modified": "2024-10-07T21:33:29Z", "published": "2024-10-01T21:31:34Z", "aliases": [ "CVE-2024-45999" ], "details": "A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v6p5-66x7-2x3r/GHSA-v6p5-66x7-2x3r.json b/advisories/unreviewed/2024/10/GHSA-v6p5-66x7-2x3r/GHSA-v6p5-66x7-2x3r.json index c10fac45404..764f039a4f3 100644 --- a/advisories/unreviewed/2024/10/GHSA-v6p5-66x7-2x3r/GHSA-v6p5-66x7-2x3r.json +++ b/advisories/unreviewed/2024/10/GHSA-v6p5-66x7-2x3r/GHSA-v6p5-66x7-2x3r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v6p5-66x7-2x3r", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41516" ], "details": "A Reflected cross-site scripting (XSS) vulnerability in \"ccHandler.aspx\" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the \"bomid\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T18:15:08Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json b/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json index 964cfb6d08b..a01ebea0ed4 100644 --- a/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json +++ b/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf2m-6wph-fchf", - "modified": "2024-10-04T21:31:30Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-04T21:31:30Z", "aliases": [ "CVE-2024-37869" ], "details": "File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the \"poster.php\" file, and the uploaded file was received using the \"$- FILES\" variable", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-04T21:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w54h-mv2w-5x75/GHSA-w54h-mv2w-5x75.json b/advisories/unreviewed/2024/10/GHSA-w54h-mv2w-5x75/GHSA-w54h-mv2w-5x75.json index 84a17581014..315e51a5978 100644 --- a/advisories/unreviewed/2024/10/GHSA-w54h-mv2w-5x75/GHSA-w54h-mv2w-5x75.json +++ b/advisories/unreviewed/2024/10/GHSA-w54h-mv2w-5x75/GHSA-w54h-mv2w-5x75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w54h-mv2w-5x75", - "modified": "2024-10-07T03:30:31Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T03:30:31Z", "aliases": [ "CVE-2024-20099" ], "details": "In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T03:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-w844-jc94-9fpw/GHSA-w844-jc94-9fpw.json b/advisories/unreviewed/2024/10/GHSA-w844-jc94-9fpw/GHSA-w844-jc94-9fpw.json new file mode 100644 index 00000000000..aa4679f3856 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w844-jc94-9fpw/GHSA-w844-jc94-9fpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w844-jc94-9fpw", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-47557" + ], + "details": "Pre-Auth RCE via Path Traversal", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47557" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2024/10/Xerox-Security-Bulletin-XRX24-014-for-Xerox%C2%AE-FreeFlow%C2%AE-Core-v7.0-.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x834-53jc-rjr9/GHSA-x834-53jc-rjr9.json b/advisories/unreviewed/2024/10/GHSA-x834-53jc-rjr9/GHSA-x834-53jc-rjr9.json new file mode 100644 index 00000000000..675d7ce3448 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x834-53jc-rjr9/GHSA-x834-53jc-rjr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x834-53jc-rjr9", + "modified": "2024-10-07T21:33:31Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-47976" + ], + "details": "Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47976" + }, + { + "type": "WEB", + "url": "https://https://www.solidigm.com/support-page/support-security.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xcfw-562c-6qr6/GHSA-xcfw-562c-6qr6.json b/advisories/unreviewed/2024/10/GHSA-xcfw-562c-6qr6/GHSA-xcfw-562c-6qr6.json new file mode 100644 index 00000000000..fb7264b67ff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xcfw-562c-6qr6/GHSA-xcfw-562c-6qr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcfw-562c-6qr6", + "modified": "2024-10-07T21:33:30Z", + "published": "2024-10-07T21:33:30Z", + "aliases": [ + "CVE-2024-47558" + ], + "details": "Authenticated RCE via Path Traversal", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47558" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2024/10/Xerox-Security-Bulletin-XRX24-014-for-Xerox%C2%AE-FreeFlow%C2%AE-Core-v7.0-.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json b/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json index b5865be49e5..c96490bd09e 100644 --- a/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json +++ b/advisories/unreviewed/2024/10/GHSA-xq72-m3h5-wf3q/GHSA-xq72-m3h5-wf3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq72-m3h5-wf3q", - "modified": "2024-10-07T18:31:09Z", + "modified": "2024-10-07T21:33:30Z", "published": "2024-10-07T18:31:09Z", "aliases": [ "CVE-2024-46446" ], "details": "Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T16:15:05Z"