diff --git a/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json b/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json index cb7cb0ca09b..5d0f69484da 100644 --- a/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json +++ b/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-6gr5-f9v8-mmjp/GHSA-6gr5-f9v8-mmjp.json b/advisories/unreviewed/2023/11/GHSA-6gr5-f9v8-mmjp/GHSA-6gr5-f9v8-mmjp.json index 67a87ffc1a2..9f22362c5b1 100644 --- a/advisories/unreviewed/2023/11/GHSA-6gr5-f9v8-mmjp/GHSA-6gr5-f9v8-mmjp.json +++ b/advisories/unreviewed/2023/11/GHSA-6gr5-f9v8-mmjp/GHSA-6gr5-f9v8-mmjp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6gr5-f9v8-mmjp", - "modified": "2023-11-15T18:30:21Z", + "modified": "2024-09-04T18:30:47Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46764" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-15" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-gvr7-26fw-gx28/GHSA-gvr7-26fw-gx28.json b/advisories/unreviewed/2023/11/GHSA-gvr7-26fw-gx28/GHSA-gvr7-26fw-gx28.json index fd099b277ae..c4a43251b63 100644 --- a/advisories/unreviewed/2023/11/GHSA-gvr7-26fw-gx28/GHSA-gvr7-26fw-gx28.json +++ b/advisories/unreviewed/2023/11/GHSA-gvr7-26fw-gx28/GHSA-gvr7-26fw-gx28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvr7-26fw-gx28", - "modified": "2023-11-15T18:30:21Z", + "modified": "2024-09-04T18:30:48Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46757" diff --git a/advisories/unreviewed/2023/11/GHSA-gx9g-7w8c-qc7m/GHSA-gx9g-7w8c-qc7m.json b/advisories/unreviewed/2023/11/GHSA-gx9g-7w8c-qc7m/GHSA-gx9g-7w8c-qc7m.json index a020843c26a..e6153af2155 100644 --- a/advisories/unreviewed/2023/11/GHSA-gx9g-7w8c-qc7m/GHSA-gx9g-7w8c-qc7m.json +++ b/advisories/unreviewed/2023/11/GHSA-gx9g-7w8c-qc7m/GHSA-gx9g-7w8c-qc7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx9g-7w8c-qc7m", - "modified": "2023-11-15T18:30:21Z", + "modified": "2024-09-04T18:30:47Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46756" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-hw72-pm43-7c85/GHSA-hw72-pm43-7c85.json b/advisories/unreviewed/2023/11/GHSA-hw72-pm43-7c85/GHSA-hw72-pm43-7c85.json index 5d1d5ea789d..05932c8e8eb 100644 --- a/advisories/unreviewed/2023/11/GHSA-hw72-pm43-7c85/GHSA-hw72-pm43-7c85.json +++ b/advisories/unreviewed/2023/11/GHSA-hw72-pm43-7c85/GHSA-hw72-pm43-7c85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw72-pm43-7c85", - "modified": "2023-11-15T18:30:21Z", + "modified": "2024-09-04T18:30:48Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46759" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-jvfm-76h2-rwxq/GHSA-jvfm-76h2-rwxq.json b/advisories/unreviewed/2023/11/GHSA-jvfm-76h2-rwxq/GHSA-jvfm-76h2-rwxq.json index 2e489da3908..3cb04225841 100644 --- a/advisories/unreviewed/2023/11/GHSA-jvfm-76h2-rwxq/GHSA-jvfm-76h2-rwxq.json +++ b/advisories/unreviewed/2023/11/GHSA-jvfm-76h2-rwxq/GHSA-jvfm-76h2-rwxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvfm-76h2-rwxq", - "modified": "2023-11-15T18:30:21Z", + "modified": "2024-09-04T18:30:47Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46763" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-w6v8-c5v8-cqhh/GHSA-w6v8-c5v8-cqhh.json b/advisories/unreviewed/2023/11/GHSA-w6v8-c5v8-cqhh/GHSA-w6v8-c5v8-cqhh.json index dc1a6fd1d99..7f5313facaf 100644 --- a/advisories/unreviewed/2023/11/GHSA-w6v8-c5v8-cqhh/GHSA-w6v8-c5v8-cqhh.json +++ b/advisories/unreviewed/2023/11/GHSA-w6v8-c5v8-cqhh/GHSA-w6v8-c5v8-cqhh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6v8-c5v8-cqhh", - "modified": "2023-11-15T18:30:21Z", + "modified": "2024-09-04T18:30:48Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46758" diff --git a/advisories/unreviewed/2024/02/GHSA-8p8h-w59q-xf45/GHSA-8p8h-w59q-xf45.json b/advisories/unreviewed/2024/02/GHSA-8p8h-w59q-xf45/GHSA-8p8h-w59q-xf45.json index 0ad147a3fab..f6e50cc2527 100644 --- a/advisories/unreviewed/2024/02/GHSA-8p8h-w59q-xf45/GHSA-8p8h-w59q-xf45.json +++ b/advisories/unreviewed/2024/02/GHSA-8p8h-w59q-xf45/GHSA-8p8h-w59q-xf45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8p8h-w59q-xf45", - "modified": "2024-02-21T00:31:31Z", + "modified": "2024-09-04T18:30:48Z", "published": "2024-02-21T00:31:31Z", "aliases": [ "CVE-2024-23758" ], "details": "An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T23:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json b/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json index 6db5aeb6219..1060b6a771d 100644 --- a/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json +++ b/advisories/unreviewed/2024/02/GHSA-j9jp-j2w9-gw9c/GHSA-j9jp-j2w9-gw9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9jp-j2w9-gw9c", - "modified": "2024-02-19T03:30:24Z", + "modified": "2024-09-04T18:30:48Z", "published": "2024-02-19T03:30:24Z", "aliases": [ "CVE-2020-36774" ], "details": "plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-664" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-19T02:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json b/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json index 95772abb7d7..c8adef61605 100644 --- a/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json +++ b/advisories/unreviewed/2024/03/GHSA-3cp6-m65f-qhcw/GHSA-3cp6-m65f-qhcw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cp6-m65f-qhcw", - "modified": "2024-03-29T15:30:32Z", + "modified": "2024-09-04T18:30:49Z", "published": "2024-03-29T15:30:32Z", "aliases": [ "CVE-2024-27619" ], "details": "Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to ram causing buffer overflow if file or files uploaded are greater than available ram. Ftp server allows change of directory to root which is one level up than root of usb flash directory. During upload ram is getting filled and causing system resource exhaustion (no free memory) which causes system to crash and reboot.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T15:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4gxp-6chj-c99r/GHSA-4gxp-6chj-c99r.json b/advisories/unreviewed/2024/03/GHSA-4gxp-6chj-c99r/GHSA-4gxp-6chj-c99r.json index 328d3f78fce..454e092f823 100644 --- a/advisories/unreviewed/2024/03/GHSA-4gxp-6chj-c99r/GHSA-4gxp-6chj-c99r.json +++ b/advisories/unreviewed/2024/03/GHSA-4gxp-6chj-c99r/GHSA-4gxp-6chj-c99r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4gxp-6chj-c99r", - "modified": "2024-03-27T06:30:31Z", + "modified": "2024-09-04T18:30:48Z", "published": "2024-03-27T06:30:31Z", "aliases": [ "CVE-2023-45931" ], "details": "Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T04:15:11Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json b/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json index 583fe3341f2..a3717f158db 100644 --- a/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json +++ b/advisories/unreviewed/2024/03/GHSA-gmxf-67jf-rrf4/GHSA-gmxf-67jf-rrf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmxf-67jf-rrf4", - "modified": "2024-07-26T21:31:15Z", + "modified": "2024-09-04T18:30:48Z", "published": "2024-03-26T12:31:28Z", "aliases": [ "CVE-2024-28093" ], "details": "The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1392" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T12:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jjf4-959w-f545/GHSA-jjf4-959w-f545.json b/advisories/unreviewed/2024/03/GHSA-jjf4-959w-f545/GHSA-jjf4-959w-f545.json index a3235c5f183..ea83037d2ae 100644 --- a/advisories/unreviewed/2024/03/GHSA-jjf4-959w-f545/GHSA-jjf4-959w-f545.json +++ b/advisories/unreviewed/2024/03/GHSA-jjf4-959w-f545/GHSA-jjf4-959w-f545.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjf4-959w-f545", - "modified": "2024-03-28T00:31:37Z", + "modified": "2024-09-04T18:30:48Z", "published": "2024-03-28T00:31:37Z", "aliases": [ "CVE-2023-47438" ], "details": "SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T22:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3p62-2p5c-mgqj/GHSA-3p62-2p5c-mgqj.json b/advisories/unreviewed/2024/04/GHSA-3p62-2p5c-mgqj/GHSA-3p62-2p5c-mgqj.json index bb226fbf120..1127ee0189f 100644 --- a/advisories/unreviewed/2024/04/GHSA-3p62-2p5c-mgqj/GHSA-3p62-2p5c-mgqj.json +++ b/advisories/unreviewed/2024/04/GHSA-3p62-2p5c-mgqj/GHSA-3p62-2p5c-mgqj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p62-2p5c-mgqj", - "modified": "2024-04-02T18:31:18Z", + "modified": "2024-09-04T18:30:49Z", "published": "2024-04-02T18:31:18Z", "aliases": [ "CVE-2024-30806" ], "details": "An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T18:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mxqc-99q2-7w6p/GHSA-mxqc-99q2-7w6p.json b/advisories/unreviewed/2024/04/GHSA-mxqc-99q2-7w6p/GHSA-mxqc-99q2-7w6p.json index cf68e86e821..1fa5d32d32c 100644 --- a/advisories/unreviewed/2024/04/GHSA-mxqc-99q2-7w6p/GHSA-mxqc-99q2-7w6p.json +++ b/advisories/unreviewed/2024/04/GHSA-mxqc-99q2-7w6p/GHSA-mxqc-99q2-7w6p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mxqc-99q2-7w6p", - "modified": "2024-04-01T21:30:47Z", + "modified": "2024-09-04T18:30:49Z", "published": "2024-04-01T21:30:47Z", "aliases": [ "CVE-2024-29433" ], "details": "A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T20:15:14Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wq73-4j39-6948/GHSA-wq73-4j39-6948.json b/advisories/unreviewed/2024/04/GHSA-wq73-4j39-6948/GHSA-wq73-4j39-6948.json index 4a175d2e120..2f3e818acaf 100644 --- a/advisories/unreviewed/2024/04/GHSA-wq73-4j39-6948/GHSA-wq73-4j39-6948.json +++ b/advisories/unreviewed/2024/04/GHSA-wq73-4j39-6948/GHSA-wq73-4j39-6948.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wq73-4j39-6948", - "modified": "2024-04-02T15:30:37Z", + "modified": "2024-09-04T18:30:49Z", "published": "2024-04-02T15:30:37Z", "aliases": [ "CVE-2024-30965" ], "details": "DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T14:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3g7g-8ghp-wcmp/GHSA-3g7g-8ghp-wcmp.json b/advisories/unreviewed/2024/08/GHSA-3g7g-8ghp-wcmp/GHSA-3g7g-8ghp-wcmp.json index 2d9619b4c9a..067e66fd6ce 100644 --- a/advisories/unreviewed/2024/08/GHSA-3g7g-8ghp-wcmp/GHSA-3g7g-8ghp-wcmp.json +++ b/advisories/unreviewed/2024/08/GHSA-3g7g-8ghp-wcmp/GHSA-3g7g-8ghp-wcmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3g7g-8ghp-wcmp", - "modified": "2024-08-31T00:31:04Z", + "modified": "2024-09-04T18:30:50Z", "published": "2024-08-31T00:31:04Z", "aliases": [ "CVE-2024-44682" ], "details": "ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9v3w-2474-chq6/GHSA-9v3w-2474-chq6.json b/advisories/unreviewed/2024/08/GHSA-9v3w-2474-chq6/GHSA-9v3w-2474-chq6.json index 7c9e46442a3..c77006e4325 100644 --- a/advisories/unreviewed/2024/08/GHSA-9v3w-2474-chq6/GHSA-9v3w-2474-chq6.json +++ b/advisories/unreviewed/2024/08/GHSA-9v3w-2474-chq6/GHSA-9v3w-2474-chq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9v3w-2474-chq6", - "modified": "2024-08-29T21:31:04Z", + "modified": "2024-09-04T18:30:50Z", "published": "2024-08-29T21:31:04Z", "aliases": [ "CVE-2024-41349" ], "details": "unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T21:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cq7c-c9r8-c439/GHSA-cq7c-c9r8-c439.json b/advisories/unreviewed/2024/08/GHSA-cq7c-c9r8-c439/GHSA-cq7c-c9r8-c439.json index 650203f700e..05ce3b53507 100644 --- a/advisories/unreviewed/2024/08/GHSA-cq7c-c9r8-c439/GHSA-cq7c-c9r8-c439.json +++ b/advisories/unreviewed/2024/08/GHSA-cq7c-c9r8-c439/GHSA-cq7c-c9r8-c439.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq7c-c9r8-c439", - "modified": "2024-08-31T00:31:05Z", + "modified": "2024-09-04T18:30:50Z", "published": "2024-08-31T00:31:05Z", "aliases": [ "CVE-2024-44683" ], "details": "Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T22:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json b/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json index 0e31caf5179..4cb0d813d64 100644 --- a/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json +++ b/advisories/unreviewed/2024/08/GHSA-hmvm-6w7r-q9wr/GHSA-hmvm-6w7r-q9wr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmvm-6w7r-q9wr", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-09-04T18:30:49Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41358" ], "details": "phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\\admin\\import-export\\import-load-data.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json b/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json index a17862ec672..4c4f8d26cca 100644 --- a/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json +++ b/advisories/unreviewed/2024/08/GHSA-m9cp-9vc4-2wpg/GHSA-m9cp-9vc4-2wpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9cp-9vc4-2wpg", - "modified": "2024-08-28T18:31:55Z", + "modified": "2024-09-04T18:30:49Z", "published": "2024-08-28T18:31:55Z", "aliases": [ "CVE-2024-7744" diff --git a/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json b/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json index 34b46ed2631..0309be5a562 100644 --- a/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json +++ b/advisories/unreviewed/2024/08/GHSA-v85v-4g2g-qmj9/GHSA-v85v-4g2g-qmj9.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-290" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-vvg9-rfgg-p242/GHSA-vvg9-rfgg-p242.json b/advisories/unreviewed/2024/08/GHSA-vvg9-rfgg-p242/GHSA-vvg9-rfgg-p242.json index ee6ec7e05fc..032a3827c12 100644 --- a/advisories/unreviewed/2024/08/GHSA-vvg9-rfgg-p242/GHSA-vvg9-rfgg-p242.json +++ b/advisories/unreviewed/2024/08/GHSA-vvg9-rfgg-p242/GHSA-vvg9-rfgg-p242.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvg9-rfgg-p242", - "modified": "2024-08-31T00:31:05Z", + "modified": "2024-09-04T18:30:50Z", "published": "2024-08-31T00:31:05Z", "aliases": [ "CVE-2024-44684" ], "details": "TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the \"Title,\" \"Images,\" and \"Content\" fields.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T22:15:06Z" diff --git a/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json b/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json new file mode 100644 index 00000000000..c0351402ea2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2vgj-5cmq-q6q3/GHSA-2vgj-5cmq-q6q3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vgj-5cmq-q6q3", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-20497" + ], + "details": "A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system.\n\nThis vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to intercept calls that are destined for a particular phone number or to make phone calls and have that phone number appear on the caller ID. To successfully exploit this vulnerability, the attacker must be an MRA user on an affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20497" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-auth-kdFrcZ2j" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-35gh-gpw3-mx2q/GHSA-35gh-gpw3-mx2q.json b/advisories/unreviewed/2024/09/GHSA-35gh-gpw3-mx2q/GHSA-35gh-gpw3-mx2q.json new file mode 100644 index 00000000000..0c35e6dfbde --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-35gh-gpw3-mx2q/GHSA-35gh-gpw3-mx2q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35gh-gpw3-mx2q", + "modified": "2024-09-04T18:30:57Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-45074" + ], + "details": "IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45074" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-39jm-vmh3-fp62/GHSA-39jm-vmh3-fp62.json b/advisories/unreviewed/2024/09/GHSA-39jm-vmh3-fp62/GHSA-39jm-vmh3-fp62.json new file mode 100644 index 00000000000..ad87077edff --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-39jm-vmh3-fp62/GHSA-39jm-vmh3-fp62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39jm-vmh3-fp62", + "modified": "2024-09-04T18:30:57Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-44818" + ], + "details": "Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44818" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-44818%20ZZCMS2023%E5%8F%8D%E5%B0%84%E5%9E%8BXSS3.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-475p-8r27-f6vh/GHSA-475p-8r27-f6vh.json b/advisories/unreviewed/2024/09/GHSA-475p-8r27-f6vh/GHSA-475p-8r27-f6vh.json new file mode 100644 index 00000000000..3398f225f0c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-475p-8r27-f6vh/GHSA-475p-8r27-f6vh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-475p-8r27-f6vh", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-45075" + ], + "details": "IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45075" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-308" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json b/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json new file mode 100644 index 00000000000..630dd7665d1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-67q3-cfc5-wcpq/GHSA-67q3-cfc5-wcpq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67q3-cfc5-wcpq", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-44859" + ], + "details": "Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44859" + }, + { + "type": "WEB", + "url": "https://github.com/Ha0-Y/IoT/blob/main/tenda-F1201/WrlExtraGet.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json b/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json new file mode 100644 index 00000000000..4d8843b4275 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6g49-7hrc-9j92/GHSA-6g49-7hrc-9j92.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g49-7hrc-9j92", + "modified": "2024-09-04T18:30:57Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-44821" + ], + "details": "ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly submitting the same incorrect captcha response, allowing them to capture the correct captcha value through error messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44821" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-44821%20ZZCMS2023%20%E9%AA%8C%E8%AF%81%E7%A0%81%E5%A4%8D%E7%94%A8%E9%80%BB%E8%BE%91%E6%BC%8F%E6%B4%9E.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6mq8-52vx-mwcm/GHSA-6mq8-52vx-mwcm.json b/advisories/unreviewed/2024/09/GHSA-6mq8-52vx-mwcm/GHSA-6mq8-52vx-mwcm.json index 057255a7216..787dbbebea6 100644 --- a/advisories/unreviewed/2024/09/GHSA-6mq8-52vx-mwcm/GHSA-6mq8-52vx-mwcm.json +++ b/advisories/unreviewed/2024/09/GHSA-6mq8-52vx-mwcm/GHSA-6mq8-52vx-mwcm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mq8-52vx-mwcm", - "modified": "2024-09-02T06:30:49Z", + "modified": "2024-09-04T18:30:51Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-7871" ], "details": "SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-6q4m-8cmc-2222/GHSA-6q4m-8cmc-2222.json b/advisories/unreviewed/2024/09/GHSA-6q4m-8cmc-2222/GHSA-6q4m-8cmc-2222.json index 69ea7cd47bf..f1ba633ce16 100644 --- a/advisories/unreviewed/2024/09/GHSA-6q4m-8cmc-2222/GHSA-6q4m-8cmc-2222.json +++ b/advisories/unreviewed/2024/09/GHSA-6q4m-8cmc-2222/GHSA-6q4m-8cmc-2222.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json b/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json new file mode 100644 index 00000000000..206a1c446e4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8c2m-6m99-9w9r/GHSA-8c2m-6m99-9w9r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c2m-6m99-9w9r", + "modified": "2024-09-04T18:30:57Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-44817" + ], + "details": "SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44817" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-44817%20ZZCMS2023SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9478-fw83-f763/GHSA-9478-fw83-f763.json b/advisories/unreviewed/2024/09/GHSA-9478-fw83-f763/GHSA-9478-fw83-f763.json index ee052172cc2..70587d92574 100644 --- a/advisories/unreviewed/2024/09/GHSA-9478-fw83-f763/GHSA-9478-fw83-f763.json +++ b/advisories/unreviewed/2024/09/GHSA-9478-fw83-f763/GHSA-9478-fw83-f763.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-987f-mx6v-8j5v/GHSA-987f-mx6v-8j5v.json b/advisories/unreviewed/2024/09/GHSA-987f-mx6v-8j5v/GHSA-987f-mx6v-8j5v.json index c8128482f03..87f6a417657 100644 --- a/advisories/unreviewed/2024/09/GHSA-987f-mx6v-8j5v/GHSA-987f-mx6v-8j5v.json +++ b/advisories/unreviewed/2024/09/GHSA-987f-mx6v-8j5v/GHSA-987f-mx6v-8j5v.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json b/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json new file mode 100644 index 00000000000..21a440e2b6b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cx6w-h9jj-x2vr/GHSA-cx6w-h9jj-x2vr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx6w-h9jj-x2vr", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-20503" + ], + "details": "A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system.\n\nThis vulnerability is due to improper storage of an unencrypted registry key. A low-privileged attacker could exploit this vulnerability by viewing or querying the registry key on the affected system. A successful exploit could allow the attacker to view sensitive information in cleartext.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20503" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-epic-info-sdLv6h8y" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json b/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json index 3254089ffc7..bc2bf3ff04f 100644 --- a/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json +++ b/advisories/unreviewed/2024/09/GHSA-f5v6-6qcg-mrg8/GHSA-f5v6-6qcg-mrg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5v6-6qcg-mrg8", - "modified": "2024-09-04T06:30:41Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-6889" ], "details": "The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T06:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-g3fw-hx3v-rvcr/GHSA-g3fw-hx3v-rvcr.json b/advisories/unreviewed/2024/09/GHSA-g3fw-hx3v-rvcr/GHSA-g3fw-hx3v-rvcr.json new file mode 100644 index 00000000000..fbc8ac5136c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g3fw-hx3v-rvcr/GHSA-g3fw-hx3v-rvcr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3fw-hx3v-rvcr", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-20469" + ], + "details": "A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrator privileges on an affected device.\n\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20469" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-6kn9tSxm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g3gh-jc9x-f7g5/GHSA-g3gh-jc9x-f7g5.json b/advisories/unreviewed/2024/09/GHSA-g3gh-jc9x-f7g5/GHSA-g3gh-jc9x-f7g5.json index 06717a299bd..d6e85c11eb5 100644 --- a/advisories/unreviewed/2024/09/GHSA-g3gh-jc9x-f7g5/GHSA-g3gh-jc9x-f7g5.json +++ b/advisories/unreviewed/2024/09/GHSA-g3gh-jc9x-f7g5/GHSA-g3gh-jc9x-f7g5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-g766-256g-wqp4/GHSA-g766-256g-wqp4.json b/advisories/unreviewed/2024/09/GHSA-g766-256g-wqp4/GHSA-g766-256g-wqp4.json index bfa12884e2a..d62adcabf37 100644 --- a/advisories/unreviewed/2024/09/GHSA-g766-256g-wqp4/GHSA-g766-256g-wqp4.json +++ b/advisories/unreviewed/2024/09/GHSA-g766-256g-wqp4/GHSA-g766-256g-wqp4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-g76f-gjfx-4rpr/GHSA-g76f-gjfx-4rpr.json b/advisories/unreviewed/2024/09/GHSA-g76f-gjfx-4rpr/GHSA-g76f-gjfx-4rpr.json new file mode 100644 index 00000000000..badf1ef918c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g76f-gjfx-4rpr/GHSA-g76f-gjfx-4rpr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g76f-gjfx-4rpr", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-8391" + ], + "details": "In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). \n\n\n\n\nThis is fixed in the 4.5.10 version. \n\n\n\n\nNote this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8391" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-vertx/vertx-grpc/issues/113" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/31" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g9j7-w55p-jq3w/GHSA-g9j7-w55p-jq3w.json b/advisories/unreviewed/2024/09/GHSA-g9j7-w55p-jq3w/GHSA-g9j7-w55p-jq3w.json new file mode 100644 index 00000000000..b7d7ac36f59 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g9j7-w55p-jq3w/GHSA-g9j7-w55p-jq3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9j7-w55p-jq3w", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-20440" + ], + "details": "A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.\n\nThis vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20440" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json b/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json index 36bece813a1..06535f1720e 100644 --- a/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json +++ b/advisories/unreviewed/2024/09/GHSA-gmvf-rv8w-2hrh/GHSA-gmvf-rv8w-2hrh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gmvf-rv8w-2hrh", - "modified": "2024-09-04T15:30:35Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T15:30:35Z", "aliases": [ "CVE-2024-45506" ], "details": "HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T15:15:14Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json b/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json index b76f129b41e..c307198c7e1 100644 --- a/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json +++ b/advisories/unreviewed/2024/09/GHSA-gp3v-m4q9-3v8h/GHSA-gp3v-m4q9-3v8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gp3v-m4q9-3v8h", - "modified": "2024-09-04T15:30:35Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T15:30:35Z", "aliases": [ "CVE-2024-7012" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7012" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6335" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6336" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6337" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7012" diff --git a/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json b/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json new file mode 100644 index 00000000000..68c28bb18f9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hph4-74mx-4369/GHSA-hph4-74mx-4369.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hph4-74mx-4369", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-45174" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web interface are vulnerable to SQL injection attacks. This kind of attack allows an authenticated user to execute arbitrary SQL commands in the context of the corresponding MySQL database.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45174" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-023.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json b/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json index 19477a29f7c..72ed25d331e 100644 --- a/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json +++ b/advisories/unreviewed/2024/09/GHSA-j755-mmjr-g7rh/GHSA-j755-mmjr-g7rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j755-mmjr-g7rh", - "modified": "2024-09-03T15:30:46Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-03T15:30:46Z", "aliases": [ "CVE-2024-8388" ], "details": "Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after the fix for CVE-2023-6870 in Firefox 121. This could lead to spoofing the browser UI if the sudden appearance of the prompt distracted the user from noticing the visual transition happening behind the prompt. These notifications now use the Android Toast feature. \n*This bug only affects Firefox on Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 130.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T13:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json b/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json index 46230c2a27c..0ffac32db06 100644 --- a/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json +++ b/advisories/unreviewed/2024/09/GHSA-jwxp-gwr3-g9q3/GHSA-jwxp-gwr3-g9q3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwxp-gwr3-g9q3", - "modified": "2024-09-04T06:30:41Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-7786" ], "details": "The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T06:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m294-4vh4-9qwg/GHSA-m294-4vh4-9qwg.json b/advisories/unreviewed/2024/09/GHSA-m294-4vh4-9qwg/GHSA-m294-4vh4-9qwg.json index e0e5c3176ad..ebff392c3ad 100644 --- a/advisories/unreviewed/2024/09/GHSA-m294-4vh4-9qwg/GHSA-m294-4vh4-9qwg.json +++ b/advisories/unreviewed/2024/09/GHSA-m294-4vh4-9qwg/GHSA-m294-4vh4-9qwg.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json b/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json new file mode 100644 index 00000000000..15da548c13e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mcxm-8hr3-frmx/GHSA-mcxm-8hr3-frmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcxm-8hr3-frmx", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-20439" + ], + "details": "A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential.\n\nThis vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to log in to the affected system. A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20439" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mfmc-fmc9-6ph8/GHSA-mfmc-fmc9-6ph8.json b/advisories/unreviewed/2024/09/GHSA-mfmc-fmc9-6ph8/GHSA-mfmc-fmc9-6ph8.json index d74c5021266..7993b5c12fd 100644 --- a/advisories/unreviewed/2024/09/GHSA-mfmc-fmc9-6ph8/GHSA-mfmc-fmc9-6ph8.json +++ b/advisories/unreviewed/2024/09/GHSA-mfmc-fmc9-6ph8/GHSA-mfmc-fmc9-6ph8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-562" + "CWE-562", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json b/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json new file mode 100644 index 00000000000..a1187954898 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mq6r-xpp8-hm92/GHSA-mq6r-xpp8-hm92.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq6r-xpp8-hm92", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-45170" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of the C-MOR web interface. It was found out that different functions are only available to administrative users. However, access those functions is restricted via the web application user interface and not checked on the server side. Thus, by sending corresponding HTTP requests to the web server of the C-MOR web interface, low privileged users can also use administrative functionality, for instance downloading backup files or changing configuration settings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45170" + }, + { + "type": "WEB", + "url": "https://www-syss-de.translate.goog/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en-US&_x_tr_pto=wapp" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-024.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json b/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json index b6650a885f5..b8d55d87e9a 100644 --- a/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json +++ b/advisories/unreviewed/2024/09/GHSA-p34f-6xg6-mcrp/GHSA-p34f-6xg6-mcrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p34f-6xg6-mcrp", - "modified": "2024-09-03T15:30:46Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-03T15:30:46Z", "aliases": [ "CVE-2024-8386" ], "details": "If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130 and Firefox ESR < 128.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-03T13:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json b/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json new file mode 100644 index 00000000000..ee5ec2cbdbd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p6qw-qg3w-mhxx/GHSA-p6qw-qg3w-mhxx.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6qw-qg3w-mhxx", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-8417" + ], + "details": "A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/educloud/videobind.html. The manipulation leads to inclusion of sensitive information in source code. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.6 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8417" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276496" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276496" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.402376" + }, + { + "type": "WEB", + "url": "https://wiki.shikangsi.com/post/share/d31fefa1-ca08-48d7-a671-727d63bfaf65" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-540" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p756-mqpr-v8g9/GHSA-p756-mqpr-v8g9.json b/advisories/unreviewed/2024/09/GHSA-p756-mqpr-v8g9/GHSA-p756-mqpr-v8g9.json new file mode 100644 index 00000000000..d9fa204c50e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p756-mqpr-v8g9/GHSA-p756-mqpr-v8g9.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p756-mqpr-v8g9", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-8416" + ], + "details": "A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. This affects an unknown part of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8416" + }, + { + "type": "WEB", + "url": "https://github.com/SherlockMA0/cve/blob/main/sql2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.402369" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pfvx-h79p-j2mp/GHSA-pfvx-h79p-j2mp.json b/advisories/unreviewed/2024/09/GHSA-pfvx-h79p-j2mp/GHSA-pfvx-h79p-j2mp.json index 800f76c907c..fb0849ddf77 100644 --- a/advisories/unreviewed/2024/09/GHSA-pfvx-h79p-j2mp/GHSA-pfvx-h79p-j2mp.json +++ b/advisories/unreviewed/2024/09/GHSA-pfvx-h79p-j2mp/GHSA-pfvx-h79p-j2mp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json b/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json index 3709cfa31ae..b353490266d 100644 --- a/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json +++ b/advisories/unreviewed/2024/09/GHSA-pm7g-mpjq-33gr/GHSA-pm7g-mpjq-33gr.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json b/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json index fcb1ea5346f..e7c88bfeec2 100644 --- a/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json +++ b/advisories/unreviewed/2024/09/GHSA-pmjc-mxf4-8qwx/GHSA-pmjc-mxf4-8qwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmjc-mxf4-8qwx", - "modified": "2024-09-04T15:30:35Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T15:30:35Z", "aliases": [ "CVE-2024-7923" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7923" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6335" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6336" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6337" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7923" diff --git a/advisories/unreviewed/2024/09/GHSA-pwp5-q92q-2hmm/GHSA-pwp5-q92q-2hmm.json b/advisories/unreviewed/2024/09/GHSA-pwp5-q92q-2hmm/GHSA-pwp5-q92q-2hmm.json new file mode 100644 index 00000000000..61ae6e5e1fa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pwp5-q92q-2hmm/GHSA-pwp5-q92q-2hmm.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwp5-q92q-2hmm", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-8412" + ], + "details": "A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comments/views.py. The manipulation of the argument next leads to open redirect. It is possible to launch the attack remotely. The name of the patch is ebd1c2cba59cbac198bf2fd5a10565994d4f02cb. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8412" + }, + { + "type": "WEB", + "url": "https://github.com/LinuxOSsk/Shakal-NG/issues/202" + }, + { + "type": "WEB", + "url": "https://github.com/LinuxOSsk/Shakal-NG/issues/202#issuecomment-2325187434" + }, + { + "type": "WEB", + "url": "https://github.com/LinuxOSsk/Shakal-NG/commit/ebd1c2cba59cbac198bf2fd5a10565994d4f02cb" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.400792" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json b/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json index 374957df4d7..e1a2c013dc5 100644 --- a/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json +++ b/advisories/unreviewed/2024/09/GHSA-q3xw-vphm-88j4/GHSA-q3xw-vphm-88j4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q3xw-vphm-88j4", - "modified": "2024-09-04T06:30:41Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-6888" ], "details": "The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T06:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json b/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json new file mode 100644 index 00000000000..f98219158c6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-q4cc-q982-86m8/GHSA-q4cc-q982-86m8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4cc-q982-86m8", + "modified": "2024-09-04T18:30:57Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-44808" + ], + "details": "An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44808" + }, + { + "type": "WEB", + "url": "https://github.com/Vypor/Vypors-Attack-API-System" + }, + { + "type": "WEB", + "url": "https://jacobmasse.medium.com/cve-2024-44808-remote-command-execution-in-vypor-ddos-attack-api-1ed073725595" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r5wp-3hxw-g22v/GHSA-r5wp-3hxw-g22v.json b/advisories/unreviewed/2024/09/GHSA-r5wp-3hxw-g22v/GHSA-r5wp-3hxw-g22v.json index c2506684884..61652397e47 100644 --- a/advisories/unreviewed/2024/09/GHSA-r5wp-3hxw-g22v/GHSA-r5wp-3hxw-g22v.json +++ b/advisories/unreviewed/2024/09/GHSA-r5wp-3hxw-g22v/GHSA-r5wp-3hxw-g22v.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-rcrr-hgw3-crch/GHSA-rcrr-hgw3-crch.json b/advisories/unreviewed/2024/09/GHSA-rcrr-hgw3-crch/GHSA-rcrr-hgw3-crch.json index 52f20539a2a..3a1aaeb350c 100644 --- a/advisories/unreviewed/2024/09/GHSA-rcrr-hgw3-crch/GHSA-rcrr-hgw3-crch.json +++ b/advisories/unreviewed/2024/09/GHSA-rcrr-hgw3-crch/GHSA-rcrr-hgw3-crch.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-v5p2-949x-45f5/GHSA-v5p2-949x-45f5.json b/advisories/unreviewed/2024/09/GHSA-v5p2-949x-45f5/GHSA-v5p2-949x-45f5.json index 4c8018998a7..44048e56cf8 100644 --- a/advisories/unreviewed/2024/09/GHSA-v5p2-949x-45f5/GHSA-v5p2-949x-45f5.json +++ b/advisories/unreviewed/2024/09/GHSA-v5p2-949x-45f5/GHSA-v5p2-949x-45f5.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-vghc-48hc-4pr8/GHSA-vghc-48hc-4pr8.json b/advisories/unreviewed/2024/09/GHSA-vghc-48hc-4pr8/GHSA-vghc-48hc-4pr8.json index 0753b0ae6e9..7d677656fb9 100644 --- a/advisories/unreviewed/2024/09/GHSA-vghc-48hc-4pr8/GHSA-vghc-48hc-4pr8.json +++ b/advisories/unreviewed/2024/09/GHSA-vghc-48hc-4pr8/GHSA-vghc-48hc-4pr8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-822" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json b/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json index f6fcfab00d7..b2bf09124a6 100644 --- a/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json +++ b/advisories/unreviewed/2024/09/GHSA-vjjf-x2fh-7rqj/GHSA-vjjf-x2fh-7rqj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vjjf-x2fh-7rqj", - "modified": "2024-09-04T06:30:41Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-6926" ], "details": "The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T06:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-w8w4-463p-8pg7/GHSA-w8w4-463p-8pg7.json b/advisories/unreviewed/2024/09/GHSA-w8w4-463p-8pg7/GHSA-w8w4-463p-8pg7.json index fef49238e2c..8a944098178 100644 --- a/advisories/unreviewed/2024/09/GHSA-w8w4-463p-8pg7/GHSA-w8w4-463p-8pg7.json +++ b/advisories/unreviewed/2024/09/GHSA-w8w4-463p-8pg7/GHSA-w8w4-463p-8pg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8w4-463p-8pg7", - "modified": "2024-09-04T09:30:45Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T09:30:45Z", "aliases": [ "CVE-2024-45507" ], "details": "Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: before 18.12.16.\n\nUsers are recommended to upgrade to version 18.12.16, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T09:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json b/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json new file mode 100644 index 00000000000..fe3bf0feed7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wvf7-c4v8-cmj9/GHSA-wvf7-c4v8-cmj9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvf7-c4v8-cmj9", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-45177" + ], + "details": "An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent cross-site scripting (XSS) attacks. It was found out that the camera configuration is vulnerable to a persistent cross-site scripting attack due to insufficient user input validation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45177" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-021.txt" + }, + { + "type": "WEB", + "url": "https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T18:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json b/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json index c1cfb0b4122..524c4721488 100644 --- a/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json +++ b/advisories/unreviewed/2024/09/GHSA-wwjw-jqq2-7xjv/GHSA-wwjw-jqq2-7xjv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwjw-jqq2-7xjv", - "modified": "2024-09-04T06:30:41Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-6020" ], "details": "The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T06:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wwxq-g564-5hhr/GHSA-wwxq-g564-5hhr.json b/advisories/unreviewed/2024/09/GHSA-wwxq-g564-5hhr/GHSA-wwxq-g564-5hhr.json new file mode 100644 index 00000000000..5b48e49cad7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wwxq-g564-5hhr/GHSA-wwxq-g564-5hhr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwxq-g564-5hhr", + "modified": "2024-09-04T18:30:57Z", + "published": "2024-09-04T18:30:57Z", + "aliases": [ + "CVE-2024-45076" + ], + "details": "IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45076" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7167245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json b/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json index a283068a4e6..b4a017bb707 100644 --- a/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json +++ b/advisories/unreviewed/2024/09/GHSA-x3f6-2323-r899/GHSA-x3f6-2323-r899.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x3f6-2323-r899", - "modified": "2024-09-04T06:30:41Z", + "modified": "2024-09-04T18:30:57Z", "published": "2024-09-04T06:30:41Z", "aliases": [ "CVE-2024-6722" ], "details": "The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-04T06:15:17Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xr2r-hj4r-gw3q/GHSA-xr2r-hj4r-gw3q.json b/advisories/unreviewed/2024/09/GHSA-xr2r-hj4r-gw3q/GHSA-xr2r-hj4r-gw3q.json index 5f7995e4a46..465858e6931 100644 --- a/advisories/unreviewed/2024/09/GHSA-xr2r-hj4r-gw3q/GHSA-xr2r-hj4r-gw3q.json +++ b/advisories/unreviewed/2024/09/GHSA-xr2r-hj4r-gw3q/GHSA-xr2r-hj4r-gw3q.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-xr75-r9hq-w965/GHSA-xr75-r9hq-w965.json b/advisories/unreviewed/2024/09/GHSA-xr75-r9hq-w965/GHSA-xr75-r9hq-w965.json new file mode 100644 index 00000000000..a4d5c02c3b8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xr75-r9hq-w965/GHSA-xr75-r9hq-w965.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr75-r9hq-w965", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-8415" + ], + "details": "A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /routers/add-ticket.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8415" + }, + { + "type": "WEB", + "url": "https://github.com/Niu-zida/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.402345" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-xxv6-qqx2-xg5m/GHSA-xxv6-qqx2-xg5m.json b/advisories/unreviewed/2024/09/GHSA-xxv6-qqx2-xg5m/GHSA-xxv6-qqx2-xg5m.json new file mode 100644 index 00000000000..6a275bf10bb --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xxv6-qqx2-xg5m/GHSA-xxv6-qqx2-xg5m.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxv6-qqx2-xg5m", + "modified": "2024-09-04T18:30:58Z", + "published": "2024-09-04T18:30:58Z", + "aliases": [ + "CVE-2024-8414" + ], + "details": "A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8414" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1LMkTt5gbVXnRB9m9o2MdgB1S0fsSAvGL/view" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.402344" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-04T17:15:15Z" + } +} \ No newline at end of file