diff --git a/advisories/unreviewed/2022/02/GHSA-h9cr-qjg3-wh75/GHSA-h9cr-qjg3-wh75.json b/advisories/unreviewed/2022/02/GHSA-h9cr-qjg3-wh75/GHSA-h9cr-qjg3-wh75.json index 8bf6a676801..120db973199 100644 --- a/advisories/unreviewed/2022/02/GHSA-h9cr-qjg3-wh75/GHSA-h9cr-qjg3-wh75.json +++ b/advisories/unreviewed/2022/02/GHSA-h9cr-qjg3-wh75/GHSA-h9cr-qjg3-wh75.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h9cr-qjg3-wh75", - "modified": "2022-09-20T00:00:32Z", + "modified": "2024-10-15T18:30:48Z", "published": "2022-02-10T00:01:11Z", "aliases": [ "CVE-2022-23096" diff --git a/advisories/unreviewed/2022/05/GHSA-3j45-2pqx-6qf3/GHSA-3j45-2pqx-6qf3.json b/advisories/unreviewed/2022/05/GHSA-3j45-2pqx-6qf3/GHSA-3j45-2pqx-6qf3.json index ffab089e9d6..d9dad34b2b2 100644 --- a/advisories/unreviewed/2022/05/GHSA-3j45-2pqx-6qf3/GHSA-3j45-2pqx-6qf3.json +++ b/advisories/unreviewed/2022/05/GHSA-3j45-2pqx-6qf3/GHSA-3j45-2pqx-6qf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j45-2pqx-6qf3", - "modified": "2022-05-17T00:45:23Z", + "modified": "2024-10-15T18:30:48Z", "published": "2022-05-17T00:45:23Z", "aliases": [ "CVE-2008-5180" ], "details": "Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8pgm-3m7v-29vc/GHSA-8pgm-3m7v-29vc.json b/advisories/unreviewed/2022/05/GHSA-8pgm-3m7v-29vc/GHSA-8pgm-3m7v-29vc.json index 3666ebb704a..7082c0362d5 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pgm-3m7v-29vc/GHSA-8pgm-3m7v-29vc.json +++ b/advisories/unreviewed/2022/05/GHSA-8pgm-3m7v-29vc/GHSA-8pgm-3m7v-29vc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8pgm-3m7v-29vc", - "modified": "2022-05-01T23:36:26Z", + "modified": "2024-10-15T18:30:48Z", "published": "2022-05-01T23:36:26Z", "aliases": [ "CVE-2008-1083" ], "details": "Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka \"GDI Heap Overflow Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -101,7 +104,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-190" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-cg3g-c98g-38cg/GHSA-cg3g-c98g-38cg.json b/advisories/unreviewed/2022/05/GHSA-cg3g-c98g-38cg/GHSA-cg3g-c98g-38cg.json index 657f3368f5d..29331170901 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg3g-c98g-38cg/GHSA-cg3g-c98g-38cg.json +++ b/advisories/unreviewed/2022/05/GHSA-cg3g-c98g-38cg/GHSA-cg3g-c98g-38cg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg3g-c98g-38cg", - "modified": "2024-01-13T00:30:24Z", + "modified": "2024-10-15T18:30:48Z", "published": "2022-05-01T18:17:21Z", "aliases": [ "CVE-2007-3798" diff --git a/advisories/unreviewed/2022/05/GHSA-q664-wc5h-3vj4/GHSA-q664-wc5h-3vj4.json b/advisories/unreviewed/2022/05/GHSA-q664-wc5h-3vj4/GHSA-q664-wc5h-3vj4.json index bdb603f7df4..85682088ba4 100644 --- a/advisories/unreviewed/2022/05/GHSA-q664-wc5h-3vj4/GHSA-q664-wc5h-3vj4.json +++ b/advisories/unreviewed/2022/05/GHSA-q664-wc5h-3vj4/GHSA-q664-wc5h-3vj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q664-wc5h-3vj4", - "modified": "2022-05-14T01:31:28Z", + "modified": "2024-10-15T18:30:48Z", "published": "2022-05-14T01:31:28Z", "aliases": [ "CVE-2008-4835" ], "details": "SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified \"fields inside the SMB packets\" in an NT Trans2 request, related to \"insufficiently validating the buffer size,\" aka \"SMB Validation Remote Code Execution Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-w7r5-8qrv-2w63/GHSA-w7r5-8qrv-2w63.json b/advisories/unreviewed/2022/05/GHSA-w7r5-8qrv-2w63/GHSA-w7r5-8qrv-2w63.json index cf0c1d5f20b..a1c9c024e52 100644 --- a/advisories/unreviewed/2022/05/GHSA-w7r5-8qrv-2w63/GHSA-w7r5-8qrv-2w63.json +++ b/advisories/unreviewed/2022/05/GHSA-w7r5-8qrv-2w63/GHSA-w7r5-8qrv-2w63.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w7r5-8qrv-2w63", - "modified": "2022-05-02T00:06:18Z", + "modified": "2024-10-15T18:30:48Z", "published": "2022-05-02T00:06:18Z", "aliases": [ "CVE-2008-4036" ], "details": "Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a \"memory allocation mapping error,\" aka \"Virtual Address Descriptor Elevation of Privilege Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -61,7 +64,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json b/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json index 9e89d364344..abfee9ea013 100644 --- a/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json +++ b/advisories/unreviewed/2024/10/GHSA-3jr7-qfmv-8m22/GHSA-3jr7-qfmv-8m22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3jr7-qfmv-8m22", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48798" ], "details": "An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3qfw-5g24-8pmq/GHSA-3qfw-5g24-8pmq.json b/advisories/unreviewed/2024/10/GHSA-3qfw-5g24-8pmq/GHSA-3qfw-5g24-8pmq.json index 19b26c3b222..576f80606c1 100644 --- a/advisories/unreviewed/2024/10/GHSA-3qfw-5g24-8pmq/GHSA-3qfw-5g24-8pmq.json +++ b/advisories/unreviewed/2024/10/GHSA-3qfw-5g24-8pmq/GHSA-3qfw-5g24-8pmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3qfw-5g24-8pmq", - "modified": "2024-10-15T12:30:36Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T12:30:36Z", "aliases": [ "CVE-2024-47945" ], "details": "The devices are vulnerable to session hijacking due to insufficient \nentropy in its session ID generation algorithm. The session IDs are \npredictable, with only 32,768 possible values per user, which allows \nattackers to pre-generate valid session IDs, leading to unauthorized \naccess to user sessions. This is not only due to the use of an \n(insecure) rand() function call but also because of missing \ninitialization via srand(). As a result only the PIDs are effectively \nused as seed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-340" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T10:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-4377-w6r6-fpff/GHSA-4377-w6r6-fpff.json b/advisories/unreviewed/2024/10/GHSA-4377-w6r6-fpff/GHSA-4377-w6r6-fpff.json new file mode 100644 index 00000000000..89c59eec48d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4377-w6r6-fpff/GHSA-4377-w6r6-fpff.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4377-w6r6-fpff", + "modified": "2024-10-15T18:30:50Z", + "published": "2024-10-15T18:30:50Z", + "aliases": [ + "CVE-2024-48622" + ], + "details": "A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48622" + }, + { + "type": "WEB", + "url": "https://github.com/domainmod/domainmod/issues/174" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json b/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json index f49f80cf053..825d8376720 100644 --- a/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json +++ b/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-55qg-f678-jcg9", - "modified": "2024-10-15T15:30:54Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T15:30:54Z", "aliases": [ "CVE-2024-48278" ], "details": "Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T13:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-58qp-x69c-wv98/GHSA-58qp-x69c-wv98.json b/advisories/unreviewed/2024/10/GHSA-58qp-x69c-wv98/GHSA-58qp-x69c-wv98.json index d54ce2ff971..1798ef40a59 100644 --- a/advisories/unreviewed/2024/10/GHSA-58qp-x69c-wv98/GHSA-58qp-x69c-wv98.json +++ b/advisories/unreviewed/2024/10/GHSA-58qp-x69c-wv98/GHSA-58qp-x69c-wv98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58qp-x69c-wv98", - "modified": "2024-10-09T15:32:20Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-09T15:32:20Z", "aliases": [ "CVE-2024-47661" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid overflow from uint32_t to uint8_t\n\n[WHAT & HOW]\ndmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned\n0xFFFF. Fix it by changing it to uint8_t with value of 0xFF.\n\nThis fixes 2 INTEGER_OVERFLOW issues reported by Coverity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T15:15:15Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json b/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json index c6c2757ce42..a7840c216b7 100644 --- a/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json +++ b/advisories/unreviewed/2024/10/GHSA-5g3x-vvf6-gwg2/GHSA-5g3x-vvf6-gwg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5g3x-vvf6-gwg2", - "modified": "2024-10-14T18:30:25Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:25Z", "aliases": [ "CVE-2024-48150" ], "details": "D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T16:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5j4c-8p2g-v4jx/GHSA-5j4c-8p2g-v4jx.json b/advisories/unreviewed/2024/10/GHSA-5j4c-8p2g-v4jx/GHSA-5j4c-8p2g-v4jx.json new file mode 100644 index 00000000000..4bc1a6faee5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5j4c-8p2g-v4jx/GHSA-5j4c-8p2g-v4jx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j4c-8p2g-v4jx", + "modified": "2024-10-15T18:30:50Z", + "published": "2024-10-15T18:30:50Z", + "aliases": [ + "CVE-2024-9506" + ], + "details": "Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9506" + }, + { + "type": "WEB", + "url": "https://www.herodevs.com/vulnerability-directory/cve-2024-9506" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6p2j-228c-wmvm/GHSA-6p2j-228c-wmvm.json b/advisories/unreviewed/2024/10/GHSA-6p2j-228c-wmvm/GHSA-6p2j-228c-wmvm.json index 4e9b413826f..5f988db177b 100644 --- a/advisories/unreviewed/2024/10/GHSA-6p2j-228c-wmvm/GHSA-6p2j-228c-wmvm.json +++ b/advisories/unreviewed/2024/10/GHSA-6p2j-228c-wmvm/GHSA-6p2j-228c-wmvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6p2j-228c-wmvm", - "modified": "2024-10-14T21:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T21:30:26Z", "aliases": [ "CVE-2023-48082" ], "details": "Nagios XI before 5.11.3 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T19:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json b/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json index 18f7f670809..9fafda6db88 100644 --- a/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json +++ b/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6rfh-8xcw-f6f2", - "modified": "2024-10-15T15:30:55Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T15:30:55Z", "aliases": [ "CVE-2024-48282" ], "details": "A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T13:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json b/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json index 0e085f375de..986955f32e9 100644 --- a/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json +++ b/advisories/unreviewed/2024/10/GHSA-72c9-vcqr-cxj8/GHSA-72c9-vcqr-cxj8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72c9-vcqr-cxj8", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48797" ], "details": "An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json b/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json index f20cf517ca9..a2753cf36e0 100644 --- a/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json +++ b/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75jw-84pf-jxc9", - "modified": "2024-10-15T15:30:54Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T15:30:54Z", "aliases": [ "CVE-2024-48280" ], "details": "A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T13:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-7892-3f52-8277/GHSA-7892-3f52-8277.json b/advisories/unreviewed/2024/10/GHSA-7892-3f52-8277/GHSA-7892-3f52-8277.json index e5df00b2df2..ddd5f4115c2 100644 --- a/advisories/unreviewed/2024/10/GHSA-7892-3f52-8277/GHSA-7892-3f52-8277.json +++ b/advisories/unreviewed/2024/10/GHSA-7892-3f52-8277/GHSA-7892-3f52-8277.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-7rc4-v56c-j5pm/GHSA-7rc4-v56c-j5pm.json b/advisories/unreviewed/2024/10/GHSA-7rc4-v56c-j5pm/GHSA-7rc4-v56c-j5pm.json index 87b04b3f9f6..f2c16614238 100644 --- a/advisories/unreviewed/2024/10/GHSA-7rc4-v56c-j5pm/GHSA-7rc4-v56c-j5pm.json +++ b/advisories/unreviewed/2024/10/GHSA-7rc4-v56c-j5pm/GHSA-7rc4-v56c-j5pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rc4-v56c-j5pm", - "modified": "2024-10-14T21:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T21:30:26Z", "aliases": [ "CVE-2024-48822" ], "details": "Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8f5f-8xpp-8qfr/GHSA-8f5f-8xpp-8qfr.json b/advisories/unreviewed/2024/10/GHSA-8f5f-8xpp-8qfr/GHSA-8f5f-8xpp-8qfr.json index 6cb95b623ba..2bc6e88f819 100644 --- a/advisories/unreviewed/2024/10/GHSA-8f5f-8xpp-8qfr/GHSA-8f5f-8xpp-8qfr.json +++ b/advisories/unreviewed/2024/10/GHSA-8f5f-8xpp-8qfr/GHSA-8f5f-8xpp-8qfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8f5f-8xpp-8qfr", - "modified": "2024-10-14T21:30:27Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T21:30:26Z", "aliases": [ "CVE-2024-48821" ], "details": "Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json b/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json index c2133acedeb..7e7afffb748 100644 --- a/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json +++ b/advisories/unreviewed/2024/10/GHSA-8ppq-7m96-536p/GHSA-8ppq-7m96-536p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8ppq-7m96-536p", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48799" ], "details": "An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json b/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json index 558606bea37..6fa0c72fb8f 100644 --- a/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json +++ b/advisories/unreviewed/2024/10/GHSA-96gx-8f8g-cr5v/GHSA-96gx-8f8g-cr5v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96gx-8f8g-cr5v", - "modified": "2024-10-14T15:30:45Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T15:30:45Z", "aliases": [ "CVE-2024-48120" ], "details": "X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the \"Opportunities\" module. An attacker can inject malicious JavaScript code into the \"Name\" field when creating a list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T14:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json b/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json index 51f17e69177..f785409ec34 100644 --- a/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json +++ b/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-994f-pcw4-m52m", - "modified": "2024-10-15T15:30:55Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T15:30:55Z", "aliases": [ "CVE-2024-48283" ], "details": "Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T13:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-9p8q-67pf-fh5x/GHSA-9p8q-67pf-fh5x.json b/advisories/unreviewed/2024/10/GHSA-9p8q-67pf-fh5x/GHSA-9p8q-67pf-fh5x.json index 00d844a1354..d990dcc2460 100644 --- a/advisories/unreviewed/2024/10/GHSA-9p8q-67pf-fh5x/GHSA-9p8q-67pf-fh5x.json +++ b/advisories/unreviewed/2024/10/GHSA-9p8q-67pf-fh5x/GHSA-9p8q-67pf-fh5x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9p8q-67pf-fh5x", - "modified": "2024-10-12T00:30:47Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-12T00:30:47Z", "aliases": [ "CVE-2024-45754" ], "details": "An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T22:15:04Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json b/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json index f1611816892..0db81e69892 100644 --- a/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json +++ b/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fj8g-7f3j-g879", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48791" ], "details": "An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json b/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json index bdc7fe8ce65..179ffd95e19 100644 --- a/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json +++ b/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqcp-xv9m-hcq2", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-46535" ], "details": "Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json b/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json index 26e1ab12d97..aabd1fd03d4 100644 --- a/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json +++ b/advisories/unreviewed/2024/10/GHSA-g6f3-67v4-98vv/GHSA-g6f3-67v4-98vv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6f3-67v4-98vv", - "modified": "2024-10-11T21:31:34Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-11T21:31:34Z", "aliases": [ "CVE-2024-48770" ], "details": "An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T20:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json b/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json index dbd555db4aa..cfb6b4a2761 100644 --- a/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json +++ b/advisories/unreviewed/2024/10/GHSA-g76c-5vhc-hqmg/GHSA-g76c-5vhc-hqmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g76c-5vhc-hqmg", - "modified": "2024-10-01T18:31:19Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-01T18:31:19Z", "aliases": [ "CVE-2024-9399" ], "details": "A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-01T16:15:10Z" diff --git a/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json b/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json new file mode 100644 index 00000000000..8347320d55d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h83f-w3v7-qh8v/GHSA-h83f-w3v7-qh8v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h83f-w3v7-qh8v", + "modified": "2024-10-15T18:30:50Z", + "published": "2024-10-15T18:30:50Z", + "aliases": [ + "CVE-2024-48624" + ], + "details": "In segments\\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48624" + }, + { + "type": "WEB", + "url": "https://github.com/domainmod/domainmod/issues/175" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hc3v-29cg-jc2x/GHSA-hc3v-29cg-jc2x.json b/advisories/unreviewed/2024/10/GHSA-hc3v-29cg-jc2x/GHSA-hc3v-29cg-jc2x.json index 6fe3280dd86..4a8b58feb04 100644 --- a/advisories/unreviewed/2024/10/GHSA-hc3v-29cg-jc2x/GHSA-hc3v-29cg-jc2x.json +++ b/advisories/unreviewed/2024/10/GHSA-hc3v-29cg-jc2x/GHSA-hc3v-29cg-jc2x.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json b/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json index ea8494c9570..c05dce40c4c 100644 --- a/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json +++ b/advisories/unreviewed/2024/10/GHSA-j9m2-gxgg-6g4q/GHSA-j9m2-gxgg-6g4q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9m2-gxgg-6g4q", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48796" ], "details": "An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jfq3-w7wv-4v3g/GHSA-jfq3-w7wv-4v3g.json b/advisories/unreviewed/2024/10/GHSA-jfq3-w7wv-4v3g/GHSA-jfq3-w7wv-4v3g.json new file mode 100644 index 00000000000..01e2013e7fa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jfq3-w7wv-4v3g/GHSA-jfq3-w7wv-4v3g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfq3-w7wv-4v3g", + "modified": "2024-10-15T18:30:50Z", + "published": "2024-10-15T18:30:50Z", + "aliases": [ + "CVE-2024-48623" + ], + "details": "In queue\\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48623" + }, + { + "type": "WEB", + "url": "https://github.com/domainmod/domainmod/issues/176" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json b/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json index 7b01eaf0419..8e5b3cf7cd7 100644 --- a/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json +++ b/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m36f-v9qc-f9h5", - "modified": "2024-10-15T15:30:53Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T09:30:31Z", "aliases": [ "CVE-2024-47944" diff --git a/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json b/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json index eb1ffcef7a8..da2992ef57d 100644 --- a/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json +++ b/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m8vr-gvfq-cv5f", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48789" ], "details": "An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-p24w-fv79-9hfm/GHSA-p24w-fv79-9hfm.json b/advisories/unreviewed/2024/10/GHSA-p24w-fv79-9hfm/GHSA-p24w-fv79-9hfm.json index 11fd6957400..015fdbf56eb 100644 --- a/advisories/unreviewed/2024/10/GHSA-p24w-fv79-9hfm/GHSA-p24w-fv79-9hfm.json +++ b/advisories/unreviewed/2024/10/GHSA-p24w-fv79-9hfm/GHSA-p24w-fv79-9hfm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p24w-fv79-9hfm", - "modified": "2024-10-09T18:31:44Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-09T18:31:44Z", "aliases": [ "CVE-2024-9471" ], "details": "A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with \"Virtual system administrator (read-only)\" access could use an XML API key of a \"Virtual system administrator\" to perform write operations on the virtual system configuration even though they should be limited to read-only operations.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:L/U:Green" diff --git a/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json b/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json index 1eddda4b945..efcd0d3fc89 100644 --- a/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json +++ b/advisories/unreviewed/2024/10/GHSA-p26r-gfgc-c47h/GHSA-p26r-gfgc-c47h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p26r-gfgc-c47h", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-46528" ], "details": "An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere v3.4.1 and v4.1.1 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T18:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pqjf-jm5p-23mq/GHSA-pqjf-jm5p-23mq.json b/advisories/unreviewed/2024/10/GHSA-pqjf-jm5p-23mq/GHSA-pqjf-jm5p-23mq.json index 514218a28c3..c0efc44799c 100644 --- a/advisories/unreviewed/2024/10/GHSA-pqjf-jm5p-23mq/GHSA-pqjf-jm5p-23mq.json +++ b/advisories/unreviewed/2024/10/GHSA-pqjf-jm5p-23mq/GHSA-pqjf-jm5p-23mq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqjf-jm5p-23mq", - "modified": "2024-10-14T21:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T21:30:26Z", "aliases": [ "CVE-2024-48823" ], "details": "Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json b/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json index 22ed1cafe15..8f67fe12caf 100644 --- a/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json +++ b/advisories/unreviewed/2024/10/GHSA-qg2h-xcfx-85gx/GHSA-qg2h-xcfx-85gx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qg2h-xcfx-85gx", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48168" ], "details": "A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T17:15:13Z" diff --git a/advisories/unreviewed/2024/10/GHSA-r35v-jh35-pg4q/GHSA-r35v-jh35-pg4q.json b/advisories/unreviewed/2024/10/GHSA-r35v-jh35-pg4q/GHSA-r35v-jh35-pg4q.json index 0cd7c30045b..8c3e76c8b83 100644 --- a/advisories/unreviewed/2024/10/GHSA-r35v-jh35-pg4q/GHSA-r35v-jh35-pg4q.json +++ b/advisories/unreviewed/2024/10/GHSA-r35v-jh35-pg4q/GHSA-r35v-jh35-pg4q.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r35v-jh35-pg4q", - "modified": "2024-10-09T18:31:43Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9469" ], "details": "A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/10/GHSA-rf37-fc6x-6cp2/GHSA-rf37-fc6x-6cp2.json b/advisories/unreviewed/2024/10/GHSA-rf37-fc6x-6cp2/GHSA-rf37-fc6x-6cp2.json new file mode 100644 index 00000000000..619d0c237e9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rf37-fc6x-6cp2/GHSA-rf37-fc6x-6cp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf37-fc6x-6cp2", + "modified": "2024-10-15T18:30:50Z", + "published": "2024-10-15T18:30:50Z", + "aliases": [ + "CVE-2024-5749" + ], + "details": "Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5749" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11428772-11428805-16/hpsbpi03979" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json b/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json index 90fd4501008..65245091da5 100644 --- a/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json +++ b/advisories/unreviewed/2024/10/GHSA-rg9v-8hp2-6q4g/GHSA-rg9v-8hp2-6q4g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rg9v-8hp2-6q4g", - "modified": "2024-10-14T18:30:26Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T18:30:26Z", "aliases": [ "CVE-2024-48792" ], "details": "An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T18:15:05Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json b/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json index bd2a9680062..dc093bb1c10 100644 --- a/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json +++ b/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v77g-99m4-2vmq", - "modified": "2024-10-14T21:30:27Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T21:30:27Z", "aliases": [ "CVE-2024-48824" ], "details": "An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive information via the Racine & FileName parameters in the download-file.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T21:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json b/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json index f4248225ce8..ed13a0dcc50 100644 --- a/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json +++ b/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vgrm-w974-j729", - "modified": "2024-10-15T15:30:54Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-15T15:30:54Z", "aliases": [ "CVE-2024-48279" ], "details": "A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T13:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json new file mode 100644 index 00000000000..2f0a7fe6a1a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wq2p-5pc6-wpgf/GHSA-wq2p-5pc6-wpgf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq2p-5pc6-wpgf", + "modified": "2024-10-15T18:30:50Z", + "published": "2024-10-15T18:30:50Z", + "aliases": [ + "CVE-2024-9676" + ], + "details": "A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9676" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9676" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317467" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T16:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wxp4-9485-gpcm/GHSA-wxp4-9485-gpcm.json b/advisories/unreviewed/2024/10/GHSA-wxp4-9485-gpcm/GHSA-wxp4-9485-gpcm.json index 8e5d87ace09..14ce33ea4c4 100644 --- a/advisories/unreviewed/2024/10/GHSA-wxp4-9485-gpcm/GHSA-wxp4-9485-gpcm.json +++ b/advisories/unreviewed/2024/10/GHSA-wxp4-9485-gpcm/GHSA-wxp4-9485-gpcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wxp4-9485-gpcm", - "modified": "2024-10-14T09:30:53Z", + "modified": "2024-10-15T18:30:49Z", "published": "2024-10-14T09:30:53Z", "aliases": [ "CVE-2024-43701" ], "details": "Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-14T09:15:04Z"