diff --git a/advisories/unreviewed/2022/05/GHSA-xqgh-qj2v-fjfx/GHSA-xqgh-qj2v-fjfx.json b/advisories/unreviewed/2022/05/GHSA-xqgh-qj2v-fjfx/GHSA-xqgh-qj2v-fjfx.json index 4a20ac9e085..87d468b18c9 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqgh-qj2v-fjfx/GHSA-xqgh-qj2v-fjfx.json +++ b/advisories/unreviewed/2022/05/GHSA-xqgh-qj2v-fjfx/GHSA-xqgh-qj2v-fjfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xqgh-qj2v-fjfx", - "modified": "2022-05-13T01:50:04Z", + "modified": "2024-12-19T03:30:40Z", "published": "2022-05-13T01:50:04Z", "aliases": [ "CVE-2018-14933" diff --git a/advisories/unreviewed/2024/12/GHSA-3hvf-qx27-92j4/GHSA-3hvf-qx27-92j4.json b/advisories/unreviewed/2024/12/GHSA-3hvf-qx27-92j4/GHSA-3hvf-qx27-92j4.json new file mode 100644 index 00000000000..1e066a130f5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3hvf-qx27-92j4/GHSA-3hvf-qx27-92j4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hvf-qx27-92j4", + "modified": "2024-12-19T03:30:42Z", + "published": "2024-12-19T03:30:42Z", + "aliases": [ + "CVE-2024-35141" + ], + "details": "IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35141" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7155356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3xqq-74gp-f73g/GHSA-3xqq-74gp-f73g.json b/advisories/unreviewed/2024/12/GHSA-3xqq-74gp-f73g/GHSA-3xqq-74gp-f73g.json new file mode 100644 index 00000000000..8b9e823877d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3xqq-74gp-f73g/GHSA-3xqq-74gp-f73g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xqq-74gp-f73g", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2023-23354" + ], + "details": "A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQuLog Center 1.5.0.738 ( 2023/03/06 ) and later\nQuLog Center 1.4.1.691 ( 2023/03/01 ) and later\nQuLog Center 1.3.1.645 ( 2023/02/22 ) and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23354" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5w8r-9w4r-m8w8/GHSA-5w8r-9w4r-m8w8.json b/advisories/unreviewed/2024/12/GHSA-5w8r-9w4r-m8w8/GHSA-5w8r-9w4r-m8w8.json new file mode 100644 index 00000000000..f6edea3241e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5w8r-9w4r-m8w8/GHSA-5w8r-9w4r-m8w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w8r-9w4r-m8w8", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2022-27595" + ], + "details": "An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands.\n\nWe have already fixed the vulnerability in the following versions:\nQVPN Windows 2.0.0.1316 and later\nQVPN Windows 2.0.0.1310 and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27595" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77mp-jg87-qc6g/GHSA-77mp-jg87-qc6g.json b/advisories/unreviewed/2024/12/GHSA-77mp-jg87-qc6g/GHSA-77mp-jg87-qc6g.json new file mode 100644 index 00000000000..c8f0d3623d5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77mp-jg87-qc6g/GHSA-77mp-jg87-qc6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77mp-jg87-qc6g", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2023-23357" + ], + "details": "A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data.\n\nWe have already fixed the vulnerability in the following versions:\nQuLog Center 1.5.0.738 ( 2023/03/06 ) and later\nQuLog Center 1.4.1.691 ( 2023/03/01 ) and later\nQuLog Center 1.3.1.645 ( 2023/02/22 ) and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23357" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-16" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7q2m-5cgc-3v5r/GHSA-7q2m-5cgc-3v5r.json b/advisories/unreviewed/2024/12/GHSA-7q2m-5cgc-3v5r/GHSA-7q2m-5cgc-3v5r.json new file mode 100644 index 00000000000..637a03568cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7q2m-5cgc-3v5r/GHSA-7q2m-5cgc-3v5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q2m-5cgc-3v5r", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2023-23356" + ], + "details": "A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands.\n\nWe have already fixed the vulnerability in the following versions:\nQuFirewall 2.3.3 ( 2023/03/27 ) and later\n and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23356" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-14" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c6cm-8p8j-4fm3/GHSA-c6cm-8p8j-4fm3.json b/advisories/unreviewed/2024/12/GHSA-c6cm-8p8j-4fm3/GHSA-c6cm-8p8j-4fm3.json new file mode 100644 index 00000000000..b6b2c1c21a2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c6cm-8p8j-4fm3/GHSA-c6cm-8p8j-4fm3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6cm-8p8j-4fm3", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2024-10548" + ], + "details": "The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the hashed passwords of project owners (e.g. adminstrators).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10548" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3206717/wedevs-project-manager/tags/2.6.16/src/Task_List/Controllers/Task_List_Controller.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a21b7c40-2090-4262-9105-346db2325612?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gxhj-h2vr-cfxw/GHSA-gxhj-h2vr-cfxw.json b/advisories/unreviewed/2024/12/GHSA-gxhj-h2vr-cfxw/GHSA-gxhj-h2vr-cfxw.json new file mode 100644 index 00000000000..6b290e3f543 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gxhj-h2vr-cfxw/GHSA-gxhj-h2vr-cfxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxhj-h2vr-cfxw", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2022-27600" + ], + "details": "An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack.\n\nWe have already fixed the vulnerability in the following versions:\nQTS 5.0.1.2277 and later\nQTS 4.5.4.2280 build 20230112 and later\nQuTS hero h5.0.1.2277 build 20230112 and later\nQuTS hero h4.5.4.2374 build 20230417 and later\nQuTScloud c5.0.1.2374 and later", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27600" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qcgv-qhww-jvg4/GHSA-qcgv-qhww-jvg4.json b/advisories/unreviewed/2024/12/GHSA-qcgv-qhww-jvg4/GHSA-qcgv-qhww-jvg4.json new file mode 100644 index 00000000000..96f9e159c63 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qcgv-qhww-jvg4/GHSA-qcgv-qhww-jvg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcgv-qhww-jvg4", + "modified": "2024-12-19T03:30:40Z", + "published": "2024-12-19T03:30:40Z", + "aliases": [ + "CVE-2021-39081" + ], + "details": "IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39081" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6555140" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T01:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r56x-jv68-vpm6/GHSA-r56x-jv68-vpm6.json b/advisories/unreviewed/2024/12/GHSA-r56x-jv68-vpm6/GHSA-r56x-jv68-vpm6.json new file mode 100644 index 00000000000..e0e6928dd96 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r56x-jv68-vpm6/GHSA-r56x-jv68-vpm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r56x-jv68-vpm6", + "modified": "2024-12-19T03:30:42Z", + "published": "2024-12-19T03:30:42Z", + "aliases": [ + "CVE-2024-51532" + ], + "details": "Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51532" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-ie/000250483/dsa-2024-462-dell-powerstore-t-security-update-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rghv-2x52-r3g8/GHSA-rghv-2x52-r3g8.json b/advisories/unreviewed/2024/12/GHSA-rghv-2x52-r3g8/GHSA-rghv-2x52-r3g8.json new file mode 100644 index 00000000000..2f1791a8a6e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rghv-2x52-r3g8/GHSA-rghv-2x52-r3g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rghv-2x52-r3g8", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2023-30443" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30443" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rrv8-h9v7-3gp2/GHSA-rrv8-h9v7-3gp2.json b/advisories/unreviewed/2024/12/GHSA-rrv8-h9v7-3gp2/GHSA-rrv8-h9v7-3gp2.json new file mode 100644 index 00000000000..1e50e5f5981 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rrv8-h9v7-3gp2/GHSA-rrv8-h9v7-3gp2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrv8-h9v7-3gp2", + "modified": "2024-12-19T03:30:41Z", + "published": "2024-12-19T03:30:41Z", + "aliases": [ + "CVE-2024-12121" + ], + "details": "The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12121" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3207590/broken-link-finder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa52034e-3d11-4be5-ab8b-8f7256be2a3e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T02:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v885-gqcv-cj29/GHSA-v885-gqcv-cj29.json b/advisories/unreviewed/2024/12/GHSA-v885-gqcv-cj29/GHSA-v885-gqcv-cj29.json new file mode 100644 index 00000000000..1c7893e5376 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v885-gqcv-cj29/GHSA-v885-gqcv-cj29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v885-gqcv-cj29", + "modified": "2024-12-19T03:30:40Z", + "published": "2024-12-19T03:30:40Z", + "aliases": [ + "CVE-2022-33954" + ], + "details": "IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33954" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6608458" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-19T01:15:06Z" + } +} \ No newline at end of file