From d91a27b047db2458ff9db69786a03baa650414de Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 26 Aug 2024 18:34:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cp56-rpr6-7673.json | 2 +- .../GHSA-pcv9-72q8-27vc.json | 2 +- .../GHSA-48j9-xh9v-wh6m.json | 11 ++-- .../GHSA-5hxp-xf5x-xjxf.json | 11 ++-- .../GHSA-6w8c-45mh-9rvm.json | 9 ++- .../GHSA-g759-2x5w-f89c.json | 3 +- .../GHSA-pq76-qjgj-qv82.json | 9 ++- .../GHSA-2cq3-gjjm-48mc.json | 11 ++-- .../GHSA-3xh7-vf3h-529r.json | 11 ++-- .../GHSA-438q-mx46-fpm4.json | 11 ++-- .../GHSA-5r6q-rqqp-8fc4.json | 11 ++-- .../GHSA-6cqh-4xr5-c65x.json | 11 ++-- .../GHSA-7hgq-9c4p-6wjc.json | 9 ++- .../GHSA-92j5-pvp2-25px.json | 9 ++- .../GHSA-98v3-6phw-46hc.json | 11 ++-- .../GHSA-9vq4-5j8m-hmv2.json | 11 ++-- .../GHSA-chrr-r69v-42vf.json | 9 ++- .../GHSA-h62x-f726-fw3q.json | 9 ++- .../GHSA-mrc8-vchm-35qc.json | 11 ++-- .../GHSA-rfmj-78j3-h4xf.json | 9 ++- .../GHSA-vj45-573c-w3cr.json | 11 ++-- .../GHSA-jhv7-rhr9-5c2j.json | 11 ++-- .../GHSA-264r-p5m9-6v8c.json | 9 ++- .../GHSA-7cvp-jg2x-qvqg.json | 9 ++- .../GHSA-8g2f-8jp6-pr2w.json | 3 +- .../GHSA-98g4-wc2v-qqh4.json | 11 ++-- .../GHSA-22xm-w7r2-834q.json | 39 ++++++++++++ .../GHSA-2wr3-xjqg-6q48.json | 11 ++-- .../GHSA-3g58-rjqp-pmgh.json | 39 ++++++++++++ .../GHSA-3xww-gg44-m2qc.json | 6 +- .../GHSA-553w-hm5g-6ccq.json | 2 +- .../GHSA-5fp3-g9fp-wmqm.json | 2 +- .../GHSA-5mgq-44p6-x2pr.json | 11 ++-- .../GHSA-5vrp-5g78-5924.json | 35 +++++++++++ .../GHSA-67w9-6p7h-rc7m.json | 43 +++++++++++++ .../GHSA-736q-w2cq-gpwv.json | 11 ++-- .../GHSA-7q36-59qh-gqjv.json | 39 ++++++++++++ .../GHSA-7v24-gjqv-fwg7.json | 2 +- .../GHSA-7wc7-j82h-f9pw.json | 11 ++-- .../GHSA-8797-vvp8-wj9v.json | 35 +++++++++++ .../GHSA-8qmg-cpxv-gv43.json | 58 +++++++++++++++++ .../GHSA-94jf-fffp-948f.json | 2 +- .../GHSA-9fhr-488x-fp7h.json | 38 ++++++++++++ .../GHSA-9m3h-9ppv-fmgc.json | 38 ++++++++++++ .../GHSA-9w4j-f548-f8jj.json | 38 ++++++++++++ .../GHSA-f486-3qch-c5jm.json | 38 ++++++++++++ .../GHSA-ff7x-jjpw-6gvh.json | 58 +++++++++++++++++ .../GHSA-fg93-gp73-8497.json | 39 ++++++++++++ .../GHSA-fmrv-g3hm-j6pp.json | 11 ++-- .../GHSA-g24f-94pq-jr67.json | 3 +- .../GHSA-gj2j-3p2j-pmwr.json | 35 +++++++++++ .../GHSA-grqx-r2q2-j425.json | 39 ++++++++++++ .../GHSA-h964-f4gx-gw3x.json | 11 ++-- .../GHSA-hmrp-qqm4-qjf7.json | 35 +++++++++++ .../GHSA-j5jg-j64j-c6rq.json | 9 ++- .../GHSA-m56p-h3j2-3v46.json | 38 ++++++++++++ .../GHSA-mhrr-6g42-v5rq.json | 58 +++++++++++++++++ .../GHSA-p2hh-36mx-vq2f.json | 2 +- .../GHSA-p75j-9r7c-8qmf.json | 58 +++++++++++++++++ .../GHSA-pg9r-4fxg-8jcv.json | 39 ++++++++++++ .../GHSA-pr2m-hg7m-28mp.json | 11 ++-- .../GHSA-pw2q-78xx-rv8j.json | 47 ++++++++++++++ .../GHSA-q9rp-4m44-qjc7.json | 11 ++-- .../GHSA-qxhc-f89g-j37j.json | 38 ++++++++++++ .../GHSA-rcmr-c4gr-768m.json | 42 +++++++++++++ .../GHSA-rp5g-xj9f-ghvw.json | 35 +++++++++++ .../GHSA-v3c5-gq46-x5cm.json | 39 ++++++++++++ .../GHSA-v5f5-778p-qh56.json | 11 ++-- .../GHSA-vhvg-rmxw-qrqr.json | 35 +++++++++++ .../GHSA-vq8h-2x8r-w2fj.json | 62 +++++++++++++++++++ .../GHSA-w48h-jh8w-wm43.json | 43 +++++++++++++ .../GHSA-wp3m-rhjq-59fj.json | 9 ++- .../GHSA-x7fm-xq4g-7h9j.json | 11 ++-- 73 files changed, 1426 insertions(+), 135 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-22xm-w7r2-834q/GHSA-22xm-w7r2-834q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json create mode 100644 advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8qmg-cpxv-gv43/GHSA-8qmg-cpxv-gv43.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9fhr-488x-fp7h/GHSA-9fhr-488x-fp7h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9m3h-9ppv-fmgc/GHSA-9m3h-9ppv-fmgc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9w4j-f548-f8jj/GHSA-9w4j-f548-f8jj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f486-3qch-c5jm/GHSA-f486-3qch-c5jm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ff7x-jjpw-6gvh/GHSA-ff7x-jjpw-6gvh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-grqx-r2q2-j425/GHSA-grqx-r2q2-j425.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m56p-h3j2-3v46/GHSA-m56p-h3j2-3v46.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mhrr-6g42-v5rq/GHSA-mhrr-6g42-v5rq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p75j-9r7c-8qmf/GHSA-p75j-9r7c-8qmf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pg9r-4fxg-8jcv/GHSA-pg9r-4fxg-8jcv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qxhc-f89g-j37j/GHSA-qxhc-f89g-j37j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rp5g-xj9f-ghvw/GHSA-rp5g-xj9f-ghvw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vq8h-2x8r-w2fj/GHSA-vq8h-2x8r-w2fj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json diff --git a/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json b/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json index 06d2926f000..db8d5cfbea9 100644 --- a/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json +++ b/advisories/unreviewed/2023/08/GHSA-cp56-rpr6-7673/GHSA-cp56-rpr6-7673.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cp56-rpr6-7673", - "modified": "2023-11-29T15:30:20Z", + "modified": "2024-08-26T18:33:31Z", "published": "2023-08-14T03:30:32Z", "aliases": [ "CVE-2023-40283" diff --git a/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json b/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json index b4ced1e6ef6..4200fc71e99 100644 --- a/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json +++ b/advisories/unreviewed/2023/08/GHSA-pcv9-72q8-27vc/GHSA-pcv9-72q8-27vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcv9-72q8-27vc", - "modified": "2023-11-21T18:30:25Z", + "modified": "2024-08-26T18:33:31Z", "published": "2023-08-07T15:30:27Z", "aliases": [ "CVE-2023-4147" diff --git a/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json b/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json index 8f6fd922020..6bb76798150 100644 --- a/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json +++ b/advisories/unreviewed/2024/02/GHSA-48j9-xh9v-wh6m/GHSA-48j9-xh9v-wh6m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48j9-xh9v-wh6m", - "modified": "2024-02-21T09:31:00Z", + "modified": "2024-08-26T18:33:31Z", "published": "2024-02-21T09:31:00Z", "aliases": [ "CVE-2023-42848" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. Processing a maliciously crafted image may lead to heap corruption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:49Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5hxp-xf5x-xjxf/GHSA-5hxp-xf5x-xjxf.json b/advisories/unreviewed/2024/02/GHSA-5hxp-xf5x-xjxf/GHSA-5hxp-xf5x-xjxf.json index fde866ba4be..d54f4c63ae3 100644 --- a/advisories/unreviewed/2024/02/GHSA-5hxp-xf5x-xjxf/GHSA-5hxp-xf5x-xjxf.json +++ b/advisories/unreviewed/2024/02/GHSA-5hxp-xf5x-xjxf/GHSA-5hxp-xf5x-xjxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hxp-xf5x-xjxf", - "modified": "2024-02-21T00:31:31Z", + "modified": "2024-08-26T18:33:31Z", "published": "2024-02-21T00:31:31Z", "aliases": [ "CVE-2023-47422" ], "details": "An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T22:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json b/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json index c9abfa852cd..0541d6988bc 100644 --- a/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json +++ b/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6w8c-45mh-9rvm", - "modified": "2024-02-16T03:30:51Z", + "modified": "2024-08-26T18:33:31Z", "published": "2024-02-16T03:30:51Z", "aliases": [ "CVE-2024-0041" ], "details": "In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:51Z" diff --git a/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json b/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json index df48e72f046..38d2d0fa140 100644 --- a/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json +++ b/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-203" + "CWE-203", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pq76-qjgj-qv82/GHSA-pq76-qjgj-qv82.json b/advisories/unreviewed/2024/02/GHSA-pq76-qjgj-qv82/GHSA-pq76-qjgj-qv82.json index 1e6b4887903..2316d1cb734 100644 --- a/advisories/unreviewed/2024/02/GHSA-pq76-qjgj-qv82/GHSA-pq76-qjgj-qv82.json +++ b/advisories/unreviewed/2024/02/GHSA-pq76-qjgj-qv82/GHSA-pq76-qjgj-qv82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq76-qjgj-qv82", - "modified": "2024-02-21T12:32:03Z", + "modified": "2024-08-26T18:33:31Z", "published": "2024-02-21T12:32:03Z", "aliases": [ "CVE-2023-7235" ], "details": "The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T11:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2cq3-gjjm-48mc/GHSA-2cq3-gjjm-48mc.json b/advisories/unreviewed/2024/03/GHSA-2cq3-gjjm-48mc/GHSA-2cq3-gjjm-48mc.json index 8c1d67784b3..389fdeeb80c 100644 --- a/advisories/unreviewed/2024/03/GHSA-2cq3-gjjm-48mc/GHSA-2cq3-gjjm-48mc.json +++ b/advisories/unreviewed/2024/03/GHSA-2cq3-gjjm-48mc/GHSA-2cq3-gjjm-48mc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2cq3-gjjm-48mc", - "modified": "2024-03-13T18:31:35Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-28678" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_description_main.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T16:15:30Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3xh7-vf3h-529r/GHSA-3xh7-vf3h-529r.json b/advisories/unreviewed/2024/03/GHSA-3xh7-vf3h-529r/GHSA-3xh7-vf3h-529r.json index 5fce3aff512..d553327d876 100644 --- a/advisories/unreviewed/2024/03/GHSA-3xh7-vf3h-529r/GHSA-3xh7-vf3h-529r.json +++ b/advisories/unreviewed/2024/03/GHSA-3xh7-vf3h-529r/GHSA-3xh7-vf3h-529r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3xh7-vf3h-529r", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27205" ], "details": "In tbd of tbd, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-438q-mx46-fpm4/GHSA-438q-mx46-fpm4.json b/advisories/unreviewed/2024/03/GHSA-438q-mx46-fpm4/GHSA-438q-mx46-fpm4.json index 856f2040cb3..442b0c2fb14 100644 --- a/advisories/unreviewed/2024/03/GHSA-438q-mx46-fpm4/GHSA-438q-mx46-fpm4.json +++ b/advisories/unreviewed/2024/03/GHSA-438q-mx46-fpm4/GHSA-438q-mx46-fpm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-438q-mx46-fpm4", - "modified": "2024-03-11T21:31:26Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-11T21:31:26Z", "aliases": [ "CVE-2024-27220" ], "details": "In lpm_req_handler of TBD, there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5r6q-rqqp-8fc4/GHSA-5r6q-rqqp-8fc4.json b/advisories/unreviewed/2024/03/GHSA-5r6q-rqqp-8fc4/GHSA-5r6q-rqqp-8fc4.json index 89e92e1ff35..e5e7befcbda 100644 --- a/advisories/unreviewed/2024/03/GHSA-5r6q-rqqp-8fc4/GHSA-5r6q-rqqp-8fc4.json +++ b/advisories/unreviewed/2024/03/GHSA-5r6q-rqqp-8fc4/GHSA-5r6q-rqqp-8fc4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5r6q-rqqp-8fc4", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-12T21:31:00Z", "aliases": [ "CVE-2024-23300" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T21:15:58Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6cqh-4xr5-c65x/GHSA-6cqh-4xr5-c65x.json b/advisories/unreviewed/2024/03/GHSA-6cqh-4xr5-c65x/GHSA-6cqh-4xr5-c65x.json index 9204253f043..6031c3c9ed5 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cqh-4xr5-c65x/GHSA-6cqh-4xr5-c65x.json +++ b/advisories/unreviewed/2024/03/GHSA-6cqh-4xr5-c65x/GHSA-6cqh-4xr5-c65x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6cqh-4xr5-c65x", - "modified": "2024-03-25T15:30:40Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-25T15:30:40Z", "aliases": [ "CVE-2024-28435" ], "details": "The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T14:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json b/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json index 181f826c56f..b896c3b0c06 100644 --- a/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json +++ b/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7hgq-9c4p-6wjc", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23294" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-92j5-pvp2-25px/GHSA-92j5-pvp2-25px.json b/advisories/unreviewed/2024/03/GHSA-92j5-pvp2-25px/GHSA-92j5-pvp2-25px.json index d818ec8794d..38201320cd8 100644 --- a/advisories/unreviewed/2024/03/GHSA-92j5-pvp2-25px/GHSA-92j5-pvp2-25px.json +++ b/advisories/unreviewed/2024/03/GHSA-92j5-pvp2-25px/GHSA-92j5-pvp2-25px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92j5-pvp2-25px", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-08T03:31:24Z", "aliases": [ "CVE-2024-23247" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-98v3-6phw-46hc/GHSA-98v3-6phw-46hc.json b/advisories/unreviewed/2024/03/GHSA-98v3-6phw-46hc/GHSA-98v3-6phw-46hc.json index 2a8b347984d..0444610e24b 100644 --- a/advisories/unreviewed/2024/03/GHSA-98v3-6phw-46hc/GHSA-98v3-6phw-46hc.json +++ b/advisories/unreviewed/2024/03/GHSA-98v3-6phw-46hc/GHSA-98v3-6phw-46hc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-98v3-6phw-46hc", - "modified": "2024-03-09T06:30:41Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-09T06:30:41Z", "aliases": [ "CVE-2023-50015" ], "details": "An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-250" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-09T05:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9vq4-5j8m-hmv2/GHSA-9vq4-5j8m-hmv2.json b/advisories/unreviewed/2024/03/GHSA-9vq4-5j8m-hmv2/GHSA-9vq4-5j8m-hmv2.json index c784e550557..74f97cef6f8 100644 --- a/advisories/unreviewed/2024/03/GHSA-9vq4-5j8m-hmv2/GHSA-9vq4-5j8m-hmv2.json +++ b/advisories/unreviewed/2024/03/GHSA-9vq4-5j8m-hmv2/GHSA-9vq4-5j8m-hmv2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9vq4-5j8m-hmv2", - "modified": "2024-03-11T21:31:25Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-11T21:31:25Z", "aliases": [ "CVE-2024-25985" ], "details": "In bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json b/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json index 0515f5771ac..dbb159198aa 100644 --- a/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json +++ b/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-chrr-r69v-42vf", - "modified": "2024-03-14T21:30:51Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-14T21:30:51Z", "aliases": [ "CVE-2023-42938" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-14T19:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-h62x-f726-fw3q/GHSA-h62x-f726-fw3q.json b/advisories/unreviewed/2024/03/GHSA-h62x-f726-fw3q/GHSA-h62x-f726-fw3q.json index 85b7b25ffd2..b914901f262 100644 --- a/advisories/unreviewed/2024/03/GHSA-h62x-f726-fw3q/GHSA-h62x-f726-fw3q.json +++ b/advisories/unreviewed/2024/03/GHSA-h62x-f726-fw3q/GHSA-h62x-f726-fw3q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h62x-f726-fw3q", - "modified": "2024-03-15T18:30:38Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-15T18:30:38Z", "aliases": [ "CVE-2023-7009" ], "details": "Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passed to the lock. These malicious commands, less then 16 bytes in length, will be processed by the lock as if they were encrypted communications. This can be further exploited by an attacker to compromise the lock's integrity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T17:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mrc8-vchm-35qc/GHSA-mrc8-vchm-35qc.json b/advisories/unreviewed/2024/03/GHSA-mrc8-vchm-35qc/GHSA-mrc8-vchm-35qc.json index 2c1048f7d91..60cd61b85f4 100644 --- a/advisories/unreviewed/2024/03/GHSA-mrc8-vchm-35qc/GHSA-mrc8-vchm-35qc.json +++ b/advisories/unreviewed/2024/03/GHSA-mrc8-vchm-35qc/GHSA-mrc8-vchm-35qc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrc8-vchm-35qc", - "modified": "2024-03-15T18:30:37Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-15T18:30:37Z", "aliases": [ "CVE-2023-7004" ], "details": "The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device that spoofs the MAC address of a lock, which compromises the legitimate locks integrity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-940" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T17:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-rfmj-78j3-h4xf/GHSA-rfmj-78j3-h4xf.json b/advisories/unreviewed/2024/03/GHSA-rfmj-78j3-h4xf/GHSA-rfmj-78j3-h4xf.json index c995c50705f..3338cfeea21 100644 --- a/advisories/unreviewed/2024/03/GHSA-rfmj-78j3-h4xf/GHSA-rfmj-78j3-h4xf.json +++ b/advisories/unreviewed/2024/03/GHSA-rfmj-78j3-h4xf/GHSA-rfmj-78j3-h4xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfmj-78j3-h4xf", - "modified": "2024-03-05T21:30:25Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-05T21:30:25Z", "aliases": [ "CVE-2024-2055" ], "details": "The \"Rich Filemanager\" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-288" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T20:16:01Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vj45-573c-w3cr/GHSA-vj45-573c-w3cr.json b/advisories/unreviewed/2024/03/GHSA-vj45-573c-w3cr/GHSA-vj45-573c-w3cr.json index a2043519b4a..9d0f970f995 100644 --- a/advisories/unreviewed/2024/03/GHSA-vj45-573c-w3cr/GHSA-vj45-573c-w3cr.json +++ b/advisories/unreviewed/2024/03/GHSA-vj45-573c-w3cr/GHSA-vj45-573c-w3cr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj45-573c-w3cr", - "modified": "2024-03-07T03:30:40Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2023-51281" ], "details": "Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, \"lastname\", \"middlename\", \"contact\" and address parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T01:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json b/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json index d1273200151..f230afdbae2 100644 --- a/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json +++ b/advisories/unreviewed/2024/04/GHSA-jhv7-rhr9-5c2j/GHSA-jhv7-rhr9-5c2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhv7-rhr9-5c2j", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52545" ], "details": "Vulnerability of undefined permissions in the Calendar app.\nImpact: Successful exploitation of this vulnerability will affect availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-264r-p5m9-6v8c/GHSA-264r-p5m9-6v8c.json b/advisories/unreviewed/2024/07/GHSA-264r-p5m9-6v8c/GHSA-264r-p5m9-6v8c.json index dd194661542..8a0cb963865 100644 --- a/advisories/unreviewed/2024/07/GHSA-264r-p5m9-6v8c/GHSA-264r-p5m9-6v8c.json +++ b/advisories/unreviewed/2024/07/GHSA-264r-p5m9-6v8c/GHSA-264r-p5m9-6v8c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-264r-p5m9-6v8c", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40787" ], "details": "This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7cvp-jg2x-qvqg/GHSA-7cvp-jg2x-qvqg.json b/advisories/unreviewed/2024/07/GHSA-7cvp-jg2x-qvqg/GHSA-7cvp-jg2x-qvqg.json index 984f5bd681a..ad746fd8997 100644 --- a/advisories/unreviewed/2024/07/GHSA-7cvp-jg2x-qvqg/GHSA-7cvp-jg2x-qvqg.json +++ b/advisories/unreviewed/2024/07/GHSA-7cvp-jg2x-qvqg/GHSA-7cvp-jg2x-qvqg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7cvp-jg2x-qvqg", - "modified": "2024-07-25T18:32:36Z", + "modified": "2024-08-26T18:33:32Z", "published": "2024-07-25T18:32:36Z", "aliases": [ "CVE-2024-7007" ], "details": "Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8g2f-8jp6-pr2w/GHSA-8g2f-8jp6-pr2w.json b/advisories/unreviewed/2024/07/GHSA-8g2f-8jp6-pr2w/GHSA-8g2f-8jp6-pr2w.json index 068bf6a560e..f3865a9271b 100644 --- a/advisories/unreviewed/2024/07/GHSA-8g2f-8jp6-pr2w/GHSA-8g2f-8jp6-pr2w.json +++ b/advisories/unreviewed/2024/07/GHSA-8g2f-8jp6-pr2w/GHSA-8g2f-8jp6-pr2w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-113" + "CWE-113", + "CWE-74" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-98g4-wc2v-qqh4/GHSA-98g4-wc2v-qqh4.json b/advisories/unreviewed/2024/07/GHSA-98g4-wc2v-qqh4/GHSA-98g4-wc2v-qqh4.json index 77c759d1be5..de2d3f14690 100644 --- a/advisories/unreviewed/2024/07/GHSA-98g4-wc2v-qqh4/GHSA-98g4-wc2v-qqh4.json +++ b/advisories/unreviewed/2024/07/GHSA-98g4-wc2v-qqh4/GHSA-98g4-wc2v-qqh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-98g4-wc2v-qqh4", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-07-30T00:34:27Z", "aliases": [ "CVE-2024-40788" ], "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. A local attacker may be able to cause unexpected system shutdown.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -85,9 +88,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-22xm-w7r2-834q/GHSA-22xm-w7r2-834q.json b/advisories/unreviewed/2024/08/GHSA-22xm-w7r2-834q/GHSA-22xm-w7r2-834q.json new file mode 100644 index 00000000000..291be7ea20a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-22xm-w7r2-834q/GHSA-22xm-w7r2-834q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22xm-w7r2-834q", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-42816" + ], + "details": "A cross-site scripting (XSS) vulnerability in the Create Product function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42816" + }, + { + "type": "WEB", + "url": "https://github.com/fastapi-admin/fastapi-admin/issues/172" + }, + { + "type": "WEB", + "url": "https://fastapi-admin-pro.long2ice.io/admin/login" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2wr3-xjqg-6q48/GHSA-2wr3-xjqg-6q48.json b/advisories/unreviewed/2024/08/GHSA-2wr3-xjqg-6q48/GHSA-2wr3-xjqg-6q48.json index 44da7b344b4..c81d5d0ff8a 100644 --- a/advisories/unreviewed/2024/08/GHSA-2wr3-xjqg-6q48/GHSA-2wr3-xjqg-6q48.json +++ b/advisories/unreviewed/2024/08/GHSA-2wr3-xjqg-6q48/GHSA-2wr3-xjqg-6q48.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2wr3-xjqg-6q48", - "modified": "2024-08-25T00:30:31Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-25T00:30:31Z", "aliases": [ "CVE-2024-45235" ], "details": "An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key Identifier extension that lacks the keyIdentifier field. Fort references this pointer without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-24T23:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json b/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json new file mode 100644 index 00000000000..cc7ecd67ba9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3g58-rjqp-pmgh/GHSA-3g58-rjqp-pmgh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g58-rjqp-pmgh", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-45265" + ], + "details": "A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45265" + }, + { + "type": "WEB", + "url": "https://github.com/TheHermione/CVE-2024-45265" + }, + { + "type": "WEB", + "url": "https://skyss.ru" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json b/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json index 208eb3cef36..97f3773e173 100644 --- a/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json +++ b/advisories/unreviewed/2024/08/GHSA-3xww-gg44-m2qc/GHSA-3xww-gg44-m2qc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xww-gg44-m2qc", - "modified": "2024-08-23T18:33:01Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-23T18:33:01Z", "aliases": [ "CVE-2024-42756" @@ -18,6 +18,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42756" }, + { + "type": "WEB", + "url": "https://github.com/Nop3z/CVE/blob/main/Netgear/Netgear%20DGN1000%20RCE/Netgear%20DGN1000%20RCE.md" + }, { "type": "WEB", "url": "https://www.netgear.com/about/security" diff --git a/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json b/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json index 34c151cef5e..fc2a97f2bb1 100644 --- a/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json +++ b/advisories/unreviewed/2024/08/GHSA-553w-hm5g-6ccq/GHSA-553w-hm5g-6ccq.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5fp3-g9fp-wmqm/GHSA-5fp3-g9fp-wmqm.json b/advisories/unreviewed/2024/08/GHSA-5fp3-g9fp-wmqm/GHSA-5fp3-g9fp-wmqm.json index f0b3856a178..3724f273512 100644 --- a/advisories/unreviewed/2024/08/GHSA-5fp3-g9fp-wmqm/GHSA-5fp3-g9fp-wmqm.json +++ b/advisories/unreviewed/2024/08/GHSA-5fp3-g9fp-wmqm/GHSA-5fp3-g9fp-wmqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5fp3-g9fp-wmqm", - "modified": "2024-08-20T03:32:24Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-20T03:32:24Z", "aliases": [ "CVE-2024-5941" diff --git a/advisories/unreviewed/2024/08/GHSA-5mgq-44p6-x2pr/GHSA-5mgq-44p6-x2pr.json b/advisories/unreviewed/2024/08/GHSA-5mgq-44p6-x2pr/GHSA-5mgq-44p6-x2pr.json index dca08c2aadd..b2d7c2719e6 100644 --- a/advisories/unreviewed/2024/08/GHSA-5mgq-44p6-x2pr/GHSA-5mgq-44p6-x2pr.json +++ b/advisories/unreviewed/2024/08/GHSA-5mgq-44p6-x2pr/GHSA-5mgq-44p6-x2pr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mgq-44p6-x2pr", - "modified": "2024-08-25T00:30:32Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-25T00:30:32Z", "aliases": [ "CVE-2024-45238" ], "details": "An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the pointer. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-24T23:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json b/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json new file mode 100644 index 00000000000..660ae43a7c8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5vrp-5g78-5924/GHSA-5vrp-5g78-5924.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vrp-5g78-5924", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44555" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44555" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-setIptvInfo-5aee8fa8b7754d319ee35027d3628f2e?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json b/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json new file mode 100644 index 00000000000..97ff23b0cfe --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-67w9-6p7h-rc7m/GHSA-67w9-6p7h-rc7m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67w9-6p7h-rc7m", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-41285" + ], + "details": "A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41285" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Giles-one/834b2becd7abebc3cabea0484301d149" + }, + { + "type": "WEB", + "url": "https://github.com/Giles-one/FW300RouterCrack" + }, + { + "type": "WEB", + "url": "https://www.fastcom.com.cn/product-8.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json b/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json index df5f0c124f7..f6050ff2680 100644 --- a/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json +++ b/advisories/unreviewed/2024/08/GHSA-736q-w2cq-gpwv/GHSA-736q-w2cq-gpwv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-736q-w2cq-gpwv", - "modified": "2024-08-26T15:31:15Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-26T15:31:15Z", "aliases": [ "CVE-2024-42787" ], "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/music/ajax.php?action=save_playlist\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via \"title\" & \"description\" parameter fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T15:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json b/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json new file mode 100644 index 00000000000..7f38750d847 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7q36-59qh-gqjv/GHSA-7q36-59qh-gqjv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q36-59qh-gqjv", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-42791" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42791" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/CSRF%20-%20Delete%20Genre.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json b/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json index e9541685023..2b13796587c 100644 --- a/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json +++ b/advisories/unreviewed/2024/08/GHSA-7v24-gjqv-fwg7/GHSA-7v24-gjqv-fwg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v24-gjqv-fwg7", - "modified": "2024-08-23T18:33:00Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-39717" diff --git a/advisories/unreviewed/2024/08/GHSA-7wc7-j82h-f9pw/GHSA-7wc7-j82h-f9pw.json b/advisories/unreviewed/2024/08/GHSA-7wc7-j82h-f9pw/GHSA-7wc7-j82h-f9pw.json index cbf55f18a5a..74561ee62c4 100644 --- a/advisories/unreviewed/2024/08/GHSA-7wc7-j82h-f9pw/GHSA-7wc7-j82h-f9pw.json +++ b/advisories/unreviewed/2024/08/GHSA-7wc7-j82h-f9pw/GHSA-7wc7-j82h-f9pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7wc7-j82h-f9pw", - "modified": "2024-08-26T12:31:20Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-26T12:31:20Z", "aliases": [ "CVE-2024-44565" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T12:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json b/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json new file mode 100644 index 00000000000..60720427759 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8797-vvp8-wj9v/GHSA-8797-vvp8-wj9v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8797-vvp8-wj9v", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44552" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44552" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formGetIptv-74cd0418924247729bae905996ae8902?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8qmg-cpxv-gv43/GHSA-8qmg-cpxv-gv43.json b/advisories/unreviewed/2024/08/GHSA-8qmg-cpxv-gv43/GHSA-8qmg-cpxv-gv43.json new file mode 100644 index 00000000000..ea7290adecb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8qmg-cpxv-gv43/GHSA-8qmg-cpxv-gv43.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qmg-cpxv-gv43", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-8171" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file staffcatedit.php. The manipulation of the argument title leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8171" + }, + { + "type": "WEB", + "url": "https://github.com/t4rrega/cve/issues/6" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275770" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275770" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397720" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-94jf-fffp-948f/GHSA-94jf-fffp-948f.json b/advisories/unreviewed/2024/08/GHSA-94jf-fffp-948f/GHSA-94jf-fffp-948f.json index b3c95b5c4fc..6f7b1708e40 100644 --- a/advisories/unreviewed/2024/08/GHSA-94jf-fffp-948f/GHSA-94jf-fffp-948f.json +++ b/advisories/unreviewed/2024/08/GHSA-94jf-fffp-948f/GHSA-94jf-fffp-948f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-94jf-fffp-948f", - "modified": "2024-08-20T03:32:24Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-20T03:32:24Z", "aliases": [ "CVE-2024-5940" diff --git a/advisories/unreviewed/2024/08/GHSA-9fhr-488x-fp7h/GHSA-9fhr-488x-fp7h.json b/advisories/unreviewed/2024/08/GHSA-9fhr-488x-fp7h/GHSA-9fhr-488x-fp7h.json new file mode 100644 index 00000000000..4de8e55c81f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9fhr-488x-fp7h/GHSA-9fhr-488x-fp7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fhr-488x-fp7h", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44553" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44553" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formGetIptv-74cd0418924247729bae905996ae8902?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9m3h-9ppv-fmgc/GHSA-9m3h-9ppv-fmgc.json b/advisories/unreviewed/2024/08/GHSA-9m3h-9ppv-fmgc/GHSA-9m3h-9ppv-fmgc.json new file mode 100644 index 00000000000..a577582c579 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9m3h-9ppv-fmgc/GHSA-9m3h-9ppv-fmgc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m3h-9ppv-fmgc", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-43289" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-forum-plugin-2-3-4-unauthenticated-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9w4j-f548-f8jj/GHSA-9w4j-f548-f8jj.json b/advisories/unreviewed/2024/08/GHSA-9w4j-f548-f8jj/GHSA-9w4j-f548-f8jj.json new file mode 100644 index 00000000000..cbf08cde530 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9w4j-f548-f8jj/GHSA-9w4j-f548-f8jj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w4j-f548-f8jj", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-43319" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43319" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/html5-video-player/wordpress-html5-video-player-plugin-2-5-31-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f486-3qch-c5jm/GHSA-f486-3qch-c5jm.json b/advisories/unreviewed/2024/08/GHSA-f486-3qch-c5jm/GHSA-f486-3qch-c5jm.json new file mode 100644 index 00000000000..9d04f2feca4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f486-3qch-c5jm/GHSA-f486-3qch-c5jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f486-3qch-c5jm", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-43967" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43967" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-testimonial-widget/wordpress-wp-testimonial-widget-plugin-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ff7x-jjpw-6gvh/GHSA-ff7x-jjpw-6gvh.json b/advisories/unreviewed/2024/08/GHSA-ff7x-jjpw-6gvh/GHSA-ff7x-jjpw-6gvh.json new file mode 100644 index 00000000000..211af2da7db --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ff7x-jjpw-6gvh/GHSA-ff7x-jjpw-6gvh.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff7x-jjpw-6gvh", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-8170" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects an unknown part of the file /endpoint/add-folder.php. The manipulation of the argument folder leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8170" + }, + { + "type": "WEB", + "url": "https://github.com/jadu101/CVE/blob/main/SourceCodester_Zipped_Folder_Manager_App_File_Upload.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275769" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275769" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397719" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json b/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json new file mode 100644 index 00000000000..daf11f1c484 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fg93-gp73-8497/GHSA-fg93-gp73-8497.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg93-gp73-8497", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-42788" + ], + "details": "A Stored Cross Site Scripting (XSS) vulnerability was found in \"/music/ajax.php?action=save_music\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via \"title\" & \"artist\" parameter fields.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42788" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Stored%20XSS%20-%20Add%20New%20Music%20List.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fmrv-g3hm-j6pp/GHSA-fmrv-g3hm-j6pp.json b/advisories/unreviewed/2024/08/GHSA-fmrv-g3hm-j6pp/GHSA-fmrv-g3hm-j6pp.json index c861fe035e1..93445d5acc5 100644 --- a/advisories/unreviewed/2024/08/GHSA-fmrv-g3hm-j6pp/GHSA-fmrv-g3hm-j6pp.json +++ b/advisories/unreviewed/2024/08/GHSA-fmrv-g3hm-j6pp/GHSA-fmrv-g3hm-j6pp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fmrv-g3hm-j6pp", - "modified": "2024-08-22T21:31:29Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-22T21:31:29Z", "aliases": [ "CVE-2024-42599" ], "details": "SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json b/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json index 2ab8ec4c590..8ccc5b49e18 100644 --- a/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json +++ b/advisories/unreviewed/2024/08/GHSA-g24f-94pq-jr67/GHSA-g24f-94pq-jr67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g24f-94pq-jr67", - "modified": "2024-08-26T09:30:44Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-26T09:30:44Z", "aliases": [ "CVE-2024-43442" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-790" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json b/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json new file mode 100644 index 00000000000..f5044d2ecc1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gj2j-3p2j-pmwr/GHSA-gj2j-3p2j-pmwr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj2j-3p2j-pmwr", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44549" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44549" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formGetIptv-74cd0418924247729bae905996ae8902?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-grqx-r2q2-j425/GHSA-grqx-r2q2-j425.json b/advisories/unreviewed/2024/08/GHSA-grqx-r2q2-j425/GHSA-grqx-r2q2-j425.json new file mode 100644 index 00000000000..098ac5415b2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-grqx-r2q2-j425/GHSA-grqx-r2q2-j425.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grqx-r2q2-j425", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-42818" + ], + "details": "A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42818" + }, + { + "type": "WEB", + "url": "https://github.com/fastapi-admin/fastapi-admin/issues/172" + }, + { + "type": "WEB", + "url": "https://fastapi-admin-pro.long2ice.io/admin/login" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h964-f4gx-gw3x/GHSA-h964-f4gx-gw3x.json b/advisories/unreviewed/2024/08/GHSA-h964-f4gx-gw3x/GHSA-h964-f4gx-gw3x.json index 8996e391f73..088f423a791 100644 --- a/advisories/unreviewed/2024/08/GHSA-h964-f4gx-gw3x/GHSA-h964-f4gx-gw3x.json +++ b/advisories/unreviewed/2024/08/GHSA-h964-f4gx-gw3x/GHSA-h964-f4gx-gw3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h964-f4gx-gw3x", - "modified": "2024-08-26T06:30:46Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-26T06:30:46Z", "aliases": [ "CVE-2024-41996" ], "details": "Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json b/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json new file mode 100644 index 00000000000..ad3ad48589e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hmrp-qqm4-qjf7/GHSA-hmrp-qqm4-qjf7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmrp-qqm4-qjf7", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44557" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44557" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-setIptvInfo-5aee8fa8b7754d319ee35027d3628f2e?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json b/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json index 4b5c91a3d1f..e6ec8c45635 100644 --- a/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json +++ b/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5jg-j64j-c6rq", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42662" ], "details": "An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T15:15:23Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m56p-h3j2-3v46/GHSA-m56p-h3j2-3v46.json b/advisories/unreviewed/2024/08/GHSA-m56p-h3j2-3v46/GHSA-m56p-h3j2-3v46.json new file mode 100644 index 00000000000..a6a2b375994 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m56p-h3j2-3v46/GHSA-m56p-h3j2-3v46.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m56p-h3j2-3v46", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44550" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44550" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formGetIptv-74cd0418924247729bae905996ae8902?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mhrr-6g42-v5rq/GHSA-mhrr-6g42-v5rq.json b/advisories/unreviewed/2024/08/GHSA-mhrr-6g42-v5rq/GHSA-mhrr-6g42-v5rq.json new file mode 100644 index 00000000000..c0630a98d74 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mhrr-6g42-v5rq/GHSA-mhrr-6g42-v5rq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhrr-6g42-v5rq", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-8173" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file /login.php of the component Login Page. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8173" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/prankfulin/cve/blob/main/sql1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275772" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275772" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397882" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p2hh-36mx-vq2f/GHSA-p2hh-36mx-vq2f.json b/advisories/unreviewed/2024/08/GHSA-p2hh-36mx-vq2f/GHSA-p2hh-36mx-vq2f.json index e305b866797..45756ddc1ba 100644 --- a/advisories/unreviewed/2024/08/GHSA-p2hh-36mx-vq2f/GHSA-p2hh-36mx-vq2f.json +++ b/advisories/unreviewed/2024/08/GHSA-p2hh-36mx-vq2f/GHSA-p2hh-36mx-vq2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p2hh-36mx-vq2f", - "modified": "2024-08-20T03:32:24Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-20T03:32:24Z", "aliases": [ "CVE-2024-5939" diff --git a/advisories/unreviewed/2024/08/GHSA-p75j-9r7c-8qmf/GHSA-p75j-9r7c-8qmf.json b/advisories/unreviewed/2024/08/GHSA-p75j-9r7c-8qmf/GHSA-p75j-9r7c-8qmf.json new file mode 100644 index 00000000000..b85e0521b70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p75j-9r7c-8qmf/GHSA-p75j-9r7c-8qmf.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p75j-9r7c-8qmf", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-8174" + ], + "details": "A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login.php of the component Login Page. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8174" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/prankfulin/cve/blob/main/xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275773" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275773" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397883" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pg9r-4fxg-8jcv/GHSA-pg9r-4fxg-8jcv.json b/advisories/unreviewed/2024/08/GHSA-pg9r-4fxg-8jcv/GHSA-pg9r-4fxg-8jcv.json new file mode 100644 index 00000000000..38c45a1cd20 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pg9r-4fxg-8jcv/GHSA-pg9r-4fxg-8jcv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg9r-4fxg-8jcv", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-42790" + ], + "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in \"/music/index.php?page=test\" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the \"page\" parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42790" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/Reflected%20XSS%20-%20index.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json b/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json index 8c62e86e85d..6cf0cfabcc0 100644 --- a/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json +++ b/advisories/unreviewed/2024/08/GHSA-pr2m-hg7m-28mp/GHSA-pr2m-hg7m-28mp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pr2m-hg7m-28mp", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-42914" ], "details": "A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T19:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json b/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json new file mode 100644 index 00000000000..25cafb9d56b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pw2q-78xx-rv8j/GHSA-pw2q-78xx-rv8j.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw2q-78xx-rv8j", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-34087" + ], + "details": "An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34087" + }, + { + "type": "WEB", + "url": "https://groups.io/g/bpq32" + }, + { + "type": "WEB", + "url": "https://themodernham.com/bbs-hacking-discovering-rce-within-bpq32-seh-based-buffer-overflow" + }, + { + "type": "WEB", + "url": "https://www.cantab.net/users/john.wiseman/Documents" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/%40ModernHam" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json b/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json index 7947f03f4a3..470f9843c7b 100644 --- a/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json +++ b/advisories/unreviewed/2024/08/GHSA-q9rp-4m44-qjc7/GHSA-q9rp-4m44-qjc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9rp-4m44-qjc7", - "modified": "2024-08-21T18:31:27Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-21T18:31:27Z", "aliases": [ "CVE-2024-39344" ], "details": "An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be compromised. With the default settings when installed for all users, the object can be accessible and (via its fields) could disclose some keys. These disclosed components can be combined to create a valid session via the Docusign API. This will generally lead to a complete compromise of the Docusign account because the session is for an administrator service account and may have permission to re-authenticate as specific users with the same authorization flow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T16:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qxhc-f89g-j37j/GHSA-qxhc-f89g-j37j.json b/advisories/unreviewed/2024/08/GHSA-qxhc-f89g-j37j/GHSA-qxhc-f89g-j37j.json new file mode 100644 index 00000000000..338bfbb633b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qxhc-f89g-j37j/GHSA-qxhc-f89g-j37j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxhc-f89g-j37j", + "modified": "2024-08-26T18:33:33Z", + "published": "2024-08-26T18:33:33Z", + "aliases": [ + "CVE-2024-43283" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 23.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-23-1-2-unauthenticated-comment-userid-and-ip-address-disclosure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json b/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json new file mode 100644 index 00000000000..047216c3cff --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rcmr-c4gr-768m/GHSA-rcmr-c4gr-768m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcmr-c4gr-768m", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-7401" + ], + "details": "Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customer’s tenant and impersonate a user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7401" + }, + { + "type": "WEB", + "url": "https://docs.netskope.com/en/secure-enrollment" + }, + { + "type": "WEB", + "url": "https://www.netskope.com/company/security-compliance-and-assurance/security-advisories-and-disclosures/netskope-security-advisory-nskpsa-2024-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rp5g-xj9f-ghvw/GHSA-rp5g-xj9f-ghvw.json b/advisories/unreviewed/2024/08/GHSA-rp5g-xj9f-ghvw/GHSA-rp5g-xj9f-ghvw.json new file mode 100644 index 00000000000..d220d9c0414 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rp5g-xj9f-ghvw/GHSA-rp5g-xj9f-ghvw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp5g-xj9f-ghvw", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-44551" + ], + "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44551" + }, + { + "type": "WEB", + "url": "https://detailed-stetson-767.notion.site/Tenda-AX1806-Buffer-Overflow-in-formGetIptv-74cd0418924247729bae905996ae8902?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json b/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json new file mode 100644 index 00000000000..56460f943e1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v3c5-gq46-x5cm/GHSA-v3c5-gq46-x5cm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3c5-gq46-x5cm", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-42792" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42792" + }, + { + "type": "WEB", + "url": "https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Music%20Management%20System%20v1.0/CSRF%20-%20Delete%20Playlist.pdf" + }, + { + "type": "WEB", + "url": "https://www.kashipara.com/project/php/12978/music-management-system-in-php-php-project-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json b/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json index 9ecc9aa5852..54768af8533 100644 --- a/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json +++ b/advisories/unreviewed/2024/08/GHSA-v5f5-778p-qh56/GHSA-v5f5-778p-qh56.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5f5-778p-qh56", - "modified": "2024-08-26T09:30:44Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-26T09:30:44Z", "aliases": [ "CVE-2024-45241" ], "details": "A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-26T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json b/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json new file mode 100644 index 00000000000..2fded0138f4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vhvg-rmxw-qrqr/GHSA-vhvg-rmxw-qrqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhvg-rmxw-qrqr", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-42913" + ], + "details": "RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42913" + }, + { + "type": "WEB", + "url": "https://github.com/yangzongzhuan/RuoYi" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vq8h-2x8r-w2fj/GHSA-vq8h-2x8r-w2fj.json b/advisories/unreviewed/2024/08/GHSA-vq8h-2x8r-w2fj/GHSA-vq8h-2x8r-w2fj.json new file mode 100644 index 00000000000..73a38c557bb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vq8h-2x8r-w2fj/GHSA-vq8h-2x8r-w2fj.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq8h-2x8r-w2fj", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-8172" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. This issue affects some unknown processing of the file /endpoint/delete-student.php. The manipulation of the argument student/attendance leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8172" + }, + { + "type": "WEB", + "url": "https://github.com/jadu101/CVE/blob/main/SourceCodester_QR_Code_Attendance_System_delete_attendance_XSS.md" + }, + { + "type": "WEB", + "url": "https://github.com/jadu101/CVE/blob/main/SourceCodester_QR_Code_Attendance_System_delete_student_XSS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275771" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275771" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.397724" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json b/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json new file mode 100644 index 00000000000..0613790ddf7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w48h-jh8w-wm43/GHSA-w48h-jh8w-wm43.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w48h-jh8w-wm43", + "modified": "2024-08-26T18:33:34Z", + "published": "2024-08-26T18:33:34Z", + "aliases": [ + "CVE-2024-41444" + ], + "details": "SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41444" + }, + { + "type": "WEB", + "url": "https://gist.github.com/looppppp/fa328c81ce19c1097d10f95c763d0d50" + }, + { + "type": "WEB", + "url": "https://github.com/seacms-net/CMS" + }, + { + "type": "WEB", + "url": "https://www.seacms.net/p-549" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-26T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wp3m-rhjq-59fj/GHSA-wp3m-rhjq-59fj.json b/advisories/unreviewed/2024/08/GHSA-wp3m-rhjq-59fj/GHSA-wp3m-rhjq-59fj.json index 7a49db52f99..17f5ef92d5d 100644 --- a/advisories/unreviewed/2024/08/GHSA-wp3m-rhjq-59fj/GHSA-wp3m-rhjq-59fj.json +++ b/advisories/unreviewed/2024/08/GHSA-wp3m-rhjq-59fj/GHSA-wp3m-rhjq-59fj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wp3m-rhjq-59fj", - "modified": "2024-08-23T06:30:44Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-23T06:30:44Z", "aliases": [ "CVE-2024-6715" ], "details": "The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-23T06:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json b/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json index b0f2780c424..984f38a470a 100644 --- a/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json +++ b/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7fm-xq4g-7h9j", - "modified": "2024-08-22T15:31:19Z", + "modified": "2024-08-26T18:33:33Z", "published": "2024-08-22T15:31:19Z", "aliases": [ "CVE-2024-36444" ], "details": "cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T15:15:16Z"