diff --git a/advisories/unreviewed/2024/05/GHSA-2rmm-hwr3-75xq/GHSA-2rmm-hwr3-75xq.json b/advisories/unreviewed/2024/05/GHSA-2rmm-hwr3-75xq/GHSA-2rmm-hwr3-75xq.json new file mode 100644 index 00000000000..0c9f825fa63 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2rmm-hwr3-75xq/GHSA-2rmm-hwr3-75xq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rmm-hwr3-75xq", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4583" + ], + "details": "A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the component Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-263305 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4583" + }, + { + "type": "WEB", + "url": "https://file.notion.so/f/f/3f67e7ef-2ba8-446a-9721-f87d0baa1695/193e9734-f9eb-44b0-bd85-92263d0e84ec/get_password_submit.py?id=8fd5a7e0-bc2d-4ef8-9037-d3c1b68a6be1&table=block&spaceId=3f67e7ef-2ba8-446a-9721-f87d0baa1695&expirationTimestamp=1715148000000&" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Unauthorized-Credential-Exposure-in-Faraday-Technology-Grain-Media-GM828x-GM8181-DVR-Devices-6a501c33e5d44beab7148074d2214b8f?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263305" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263305" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.324403" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-2xjr-fp46-9fhh/GHSA-2xjr-fp46-9fhh.json b/advisories/unreviewed/2024/05/GHSA-2xjr-fp46-9fhh/GHSA-2xjr-fp46-9fhh.json new file mode 100644 index 00000000000..5ae4ee7ec08 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2xjr-fp46-9fhh/GHSA-2xjr-fp46-9fhh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xjr-fp46-9fhh", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4537" + ], + "details": "IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4537" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janto-ticketing-software" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6hpj-m38r-374m/GHSA-6hpj-m38r-374m.json b/advisories/unreviewed/2024/05/GHSA-6hpj-m38r-374m/GHSA-6hpj-m38r-374m.json new file mode 100644 index 00000000000..83e2b50b804 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6hpj-m38r-374m/GHSA-6hpj-m38r-374m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hpj-m38r-374m", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4599" + ], + "details": "Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a long string directly and continuously over the UDP protocol.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4599" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/denial-service-vulnerability-lan-messenger" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9x6g-pjcq-f3j2/GHSA-9x6g-pjcq-f3j2.json b/advisories/unreviewed/2024/05/GHSA-9x6g-pjcq-f3j2/GHSA-9x6g-pjcq-f3j2.json new file mode 100644 index 00000000000..88b292f9689 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9x6g-pjcq-f3j2/GHSA-9x6g-pjcq-f3j2.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x6g-pjcq-f3j2", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4585" + ], + "details": "A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263307. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4585" + }, + { + "type": "WEB", + "url": "https://github.com/Hckwzh/cms/blob/main/16.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.324953" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f76v-4xxj-grpm/GHSA-f76v-4xxj-grpm.json b/advisories/unreviewed/2024/05/GHSA-f76v-4xxj-grpm/GHSA-f76v-4xxj-grpm.json new file mode 100644 index 00000000000..e66d1d4f0a6 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f76v-4xxj-grpm/GHSA-f76v-4xxj-grpm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f76v-4xxj-grpm", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2023-6810" + ], + "details": "The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with author access and above, to retrieve the plugin's configured API keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6810" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3081436/clickcease-click-fraud-protection/trunk/classes/routes.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5d572cac-b8e3-4c52-9b35-80fe5ee9e900?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json b/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json index 2646b9f3019..57fd174654b 100644 --- a/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json +++ b/advisories/unreviewed/2024/05/GHSA-m6xf-rg25-42wc/GHSA-m6xf-rg25-42wc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6xf-rg25-42wc", - "modified": "2024-05-06T21:30:37Z", + "modified": "2024-05-07T12:30:50Z", "published": "2024-05-03T21:30:30Z", "aliases": [ "CVE-2024-34455" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/05/06/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/05/07/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-pv2p-xrw4-77m7/GHSA-pv2p-xrw4-77m7.json b/advisories/unreviewed/2024/05/GHSA-pv2p-xrw4-77m7/GHSA-pv2p-xrw4-77m7.json new file mode 100644 index 00000000000..04c6afeb6a8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pv2p-xrw4-77m7/GHSA-pv2p-xrw4-77m7.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv2p-xrw4-77m7", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4582" + ], + "details": "A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP Service. The manipulation of the argument ntp_srv leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-263304.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4582" + }, + { + "type": "WEB", + "url": "https://file.notion.so/f/f/3f67e7ef-2ba8-446a-9721-f87d0baa1695/fa61d774-823d-4516-8ff3-73c310ff7801/command_injection_submit.py?id=6d18aced-daaa-4e52-a0e8-9d1c5e00acee&table=block&spaceId=3f67e7ef-2ba8-446a-9721-f87d0baa1695&expirationTimestamp=171514800" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Command-Injection-in-Faraday-Technology-GM828x-GM8181-DVR-1bc02d17ee5540a08273da2850e809c4?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263304" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263304" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.324393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q8h9-wf3c-q2j4/GHSA-q8h9-wf3c-q2j4.json b/advisories/unreviewed/2024/05/GHSA-q8h9-wf3c-q2j4/GHSA-q8h9-wf3c-q2j4.json new file mode 100644 index 00000000000..aae79a163c0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q8h9-wf3c-q2j4/GHSA-q8h9-wf3c-q2j4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8h9-wf3c-q2j4", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4584" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Faraday GM8181 and GM828x up to 20240429. Affected by this issue is some unknown functionality of the file /command_port.ini. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263306 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4584" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Information-Disclosure-in-Faraday-Technology-Grain-Media-GM828x-GM8181-DVR-via-Unauthenticated-Acc-3d184791c8d7405ba9d6a49e7a5bd918?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.263306" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.263306" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.324404" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qc4p-7g72-jqrq/GHSA-qc4p-7g72-jqrq.json b/advisories/unreviewed/2024/05/GHSA-qc4p-7g72-jqrq/GHSA-qc4p-7g72-jqrq.json index d334e04b07a..72382adbba5 100644 --- a/advisories/unreviewed/2024/05/GHSA-qc4p-7g72-jqrq/GHSA-qc4p-7g72-jqrq.json +++ b/advisories/unreviewed/2024/05/GHSA-qc4p-7g72-jqrq/GHSA-qc4p-7g72-jqrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc4p-7g72-jqrq", - "modified": "2024-05-01T18:30:40Z", + "modified": "2024-05-07T12:30:50Z", "published": "2024-05-01T18:30:40Z", "aliases": [ "CVE-2023-40533" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1902" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/05/07/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-rc5f-cjwc-8xx6/GHSA-rc5f-cjwc-8xx6.json b/advisories/unreviewed/2024/05/GHSA-rc5f-cjwc-8xx6/GHSA-rc5f-cjwc-8xx6.json new file mode 100644 index 00000000000..3dfb841b821 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rc5f-cjwc-8xx6/GHSA-rc5f-cjwc-8xx6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc5f-cjwc-8xx6", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4538" + ], + "details": "IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket by creating a specific request with the ticket reference ID, leading to the exposure of sensitive user data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4538" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janto-ticketing-software" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rqfw-w5rj-x59c/GHSA-rqfw-w5rj-x59c.json b/advisories/unreviewed/2024/05/GHSA-rqfw-w5rj-x59c/GHSA-rqfw-w5rj-x59c.json new file mode 100644 index 00000000000..eb9ac546fc3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rqfw-w5rj-x59c/GHSA-rqfw-w5rj-x59c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqfw-w5rj-x59c", + "modified": "2024-05-07T12:30:51Z", + "published": "2024-05-07T12:30:51Z", + "aliases": [ + "CVE-2024-4601" + ], + "details": "An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perform a brute force attack on the application and recover a valid session, because the application uses a five-digit integer value.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4601" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-socomec-net-vision" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v9pp-qqfq-3qvw/GHSA-v9pp-qqfq-3qvw.json b/advisories/unreviewed/2024/05/GHSA-v9pp-qqfq-3qvw/GHSA-v9pp-qqfq-3qvw.json new file mode 100644 index 00000000000..961f35239bb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v9pp-qqfq-3qvw/GHSA-v9pp-qqfq-3qvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9pp-qqfq-3qvw", + "modified": "2024-05-07T12:30:50Z", + "published": "2024-05-07T12:30:50Z", + "aliases": [ + "CVE-2024-4600" + ], + "details": "Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users into performing critical actions, such as adding and updating accounts, due to lack of proper sanitisation of the ‘set_param.cgi’ file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4600" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-socomec-net-vision" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-07T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w78j-vw2g-233v/GHSA-w78j-vw2g-233v.json b/advisories/unreviewed/2024/05/GHSA-w78j-vw2g-233v/GHSA-w78j-vw2g-233v.json index 7181c925d32..8567ddc7faa 100644 --- a/advisories/unreviewed/2024/05/GHSA-w78j-vw2g-233v/GHSA-w78j-vw2g-233v.json +++ b/advisories/unreviewed/2024/05/GHSA-w78j-vw2g-233v/GHSA-w78j-vw2g-233v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w78j-vw2g-233v", - "modified": "2024-05-01T18:30:41Z", + "modified": "2024-05-07T12:30:50Z", "published": "2024-05-01T18:30:41Z", "aliases": [ "CVE-2023-49606" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/05/07/1" } ], "database_specific": {