diff --git a/advisories/unreviewed/2024/02/GHSA-4g72-g685-8cc9/GHSA-4g72-g685-8cc9.json b/advisories/unreviewed/2024/02/GHSA-4g72-g685-8cc9/GHSA-4g72-g685-8cc9.json index db5885a097a..5696addee28 100644 --- a/advisories/unreviewed/2024/02/GHSA-4g72-g685-8cc9/GHSA-4g72-g685-8cc9.json +++ b/advisories/unreviewed/2024/02/GHSA-4g72-g685-8cc9/GHSA-4g72-g685-8cc9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g72-g685-8cc9", - "modified": "2024-02-20T18:30:34Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-02-20T18:30:34Z", "aliases": [ "CVE-2024-25366" ], "details": "Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T16:15:10Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json b/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json index b58c7995e18..6f09fbf83df 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json +++ b/advisories/unreviewed/2024/02/GHSA-4rwq-456r-x2vq/GHSA-4rwq-456r-x2vq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rwq-456r-x2vq", - "modified": "2024-02-24T00:30:20Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-02-24T00:30:20Z", "aliases": [ "CVE-2024-25730" ], "details": "Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a \"Hitron\" substring, resulting in insufficient entropy (only about one million possibilities).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-331" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-23T22:15:55Z" diff --git a/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json b/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json index c15235db598..245056faf85 100644 --- a/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json +++ b/advisories/unreviewed/2024/02/GHSA-67vv-989w-hhr5/GHSA-67vv-989w-hhr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67vv-989w-hhr5", - "modified": "2024-02-22T21:30:33Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-02-22T21:30:32Z", "aliases": [ "CVE-2024-25385" ], "details": "An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T19:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-7pg4-9277-v46w/GHSA-7pg4-9277-v46w.json b/advisories/unreviewed/2024/02/GHSA-7pg4-9277-v46w/GHSA-7pg4-9277-v46w.json index d9344d7713a..dd3d25799e1 100644 --- a/advisories/unreviewed/2024/02/GHSA-7pg4-9277-v46w/GHSA-7pg4-9277-v46w.json +++ b/advisories/unreviewed/2024/02/GHSA-7pg4-9277-v46w/GHSA-7pg4-9277-v46w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pg4-9277-v46w", - "modified": "2024-02-16T03:30:51Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-02-16T03:30:51Z", "aliases": [ "CVE-2024-0033" ], "details": "In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:50Z" diff --git a/advisories/unreviewed/2024/02/GHSA-9hcj-pv58-28wg/GHSA-9hcj-pv58-28wg.json b/advisories/unreviewed/2024/02/GHSA-9hcj-pv58-28wg/GHSA-9hcj-pv58-28wg.json index 51961219029..50dccce8af3 100644 --- a/advisories/unreviewed/2024/02/GHSA-9hcj-pv58-28wg/GHSA-9hcj-pv58-28wg.json +++ b/advisories/unreviewed/2024/02/GHSA-9hcj-pv58-28wg/GHSA-9hcj-pv58-28wg.json @@ -33,7 +33,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-pw65-h7gx-qh35/GHSA-pw65-h7gx-qh35.json b/advisories/unreviewed/2024/02/GHSA-pw65-h7gx-qh35/GHSA-pw65-h7gx-qh35.json index 6247cb1bcfa..a1a3135dafa 100644 --- a/advisories/unreviewed/2024/02/GHSA-pw65-h7gx-qh35/GHSA-pw65-h7gx-qh35.json +++ b/advisories/unreviewed/2024/02/GHSA-pw65-h7gx-qh35/GHSA-pw65-h7gx-qh35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pw65-h7gx-qh35", - "modified": "2024-02-22T03:30:35Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-02-22T03:30:35Z", "aliases": [ "CVE-2024-25251" ], "details": "code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T01:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-vhx9-pxpc-mp7q/GHSA-vhx9-pxpc-mp7q.json b/advisories/unreviewed/2024/02/GHSA-vhx9-pxpc-mp7q/GHSA-vhx9-pxpc-mp7q.json index 0cbc7e13271..181d859ff34 100644 --- a/advisories/unreviewed/2024/02/GHSA-vhx9-pxpc-mp7q/GHSA-vhx9-pxpc-mp7q.json +++ b/advisories/unreviewed/2024/02/GHSA-vhx9-pxpc-mp7q/GHSA-vhx9-pxpc-mp7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhx9-pxpc-mp7q", - "modified": "2024-02-15T00:30:32Z", + "modified": "2024-08-16T21:32:34Z", "published": "2024-02-15T00:30:32Z", "aliases": [ "CVE-2024-24300" ], "details": "4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-14T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json b/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json index 3ff4f167ce1..92dc6884116 100644 --- a/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json +++ b/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmmg-4cv8-23px", - "modified": "2024-02-16T09:30:25Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-02-16T09:30:25Z", "aliases": [ "CVE-2024-22854" ], "details": "DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T09:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json b/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json index 8dc8dd64f0d..2eaa1449c13 100644 --- a/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json +++ b/advisories/unreviewed/2024/03/GHSA-3rwq-vmr7-cggq/GHSA-3rwq-vmr7-cggq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3rwq-vmr7-cggq", - "modified": "2024-03-29T15:30:32Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-29T15:30:32Z", "aliases": [ "CVE-2024-30636" ], "details": "Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-29T14:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-57rg-p28x-x2f6/GHSA-57rg-p28x-x2f6.json b/advisories/unreviewed/2024/03/GHSA-57rg-p28x-x2f6/GHSA-57rg-p28x-x2f6.json index 203b96b879e..10776d08028 100644 --- a/advisories/unreviewed/2024/03/GHSA-57rg-p28x-x2f6/GHSA-57rg-p28x-x2f6.json +++ b/advisories/unreviewed/2024/03/GHSA-57rg-p28x-x2f6/GHSA-57rg-p28x-x2f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-57rg-p28x-x2f6", - "modified": "2024-03-05T18:31:14Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-05T18:31:14Z", "aliases": [ "CVE-2024-22253" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-94r9-cwgw-rpvq/GHSA-94r9-cwgw-rpvq.json b/advisories/unreviewed/2024/03/GHSA-94r9-cwgw-rpvq/GHSA-94r9-cwgw-rpvq.json index 50812eb2b0f..5fe6abdf8d3 100644 --- a/advisories/unreviewed/2024/03/GHSA-94r9-cwgw-rpvq/GHSA-94r9-cwgw-rpvq.json +++ b/advisories/unreviewed/2024/03/GHSA-94r9-cwgw-rpvq/GHSA-94r9-cwgw-rpvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94r9-cwgw-rpvq", - "modified": "2024-03-12T09:30:40Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-12T09:30:40Z", "aliases": [ "CVE-2023-49453" ], "details": "Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T08:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-chh2-528g-gx39/GHSA-chh2-528g-gx39.json b/advisories/unreviewed/2024/03/GHSA-chh2-528g-gx39/GHSA-chh2-528g-gx39.json index 4a1846a67fa..fedd56144dd 100644 --- a/advisories/unreviewed/2024/03/GHSA-chh2-528g-gx39/GHSA-chh2-528g-gx39.json +++ b/advisories/unreviewed/2024/03/GHSA-chh2-528g-gx39/GHSA-chh2-528g-gx39.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-chh2-528g-gx39", - "modified": "2024-03-11T18:31:08Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-11T18:31:08Z", "aliases": [ "CVE-2024-23717" ], "details": "In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T17:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gm7f-4r42-pg7c/GHSA-gm7f-4r42-pg7c.json b/advisories/unreviewed/2024/03/GHSA-gm7f-4r42-pg7c/GHSA-gm7f-4r42-pg7c.json index aef3644103f..1f03074d5b9 100644 --- a/advisories/unreviewed/2024/03/GHSA-gm7f-4r42-pg7c/GHSA-gm7f-4r42-pg7c.json +++ b/advisories/unreviewed/2024/03/GHSA-gm7f-4r42-pg7c/GHSA-gm7f-4r42-pg7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm7f-4r42-pg7c", - "modified": "2024-03-04T03:30:26Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-04T03:30:26Z", "aliases": [ "CVE-2024-20031" ], "details": "In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541742.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T03:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-m2f4-hwvj-h9rj/GHSA-m2f4-hwvj-h9rj.json b/advisories/unreviewed/2024/03/GHSA-m2f4-hwvj-h9rj/GHSA-m2f4-hwvj-h9rj.json index 45575024a61..0d62ecbb2ea 100644 --- a/advisories/unreviewed/2024/03/GHSA-m2f4-hwvj-h9rj/GHSA-m2f4-hwvj-h9rj.json +++ b/advisories/unreviewed/2024/03/GHSA-m2f4-hwvj-h9rj/GHSA-m2f4-hwvj-h9rj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2f4-hwvj-h9rj", - "modified": "2024-03-12T09:30:41Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-12T09:30:41Z", "aliases": [ "CVE-2024-27121" ], "details": "Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T08:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json b/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json index c9cb49898e1..c63a8410b15 100644 --- a/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json +++ b/advisories/unreviewed/2024/03/GHSA-p5w7-h2h4-299j/GHSA-p5w7-h2h4-299j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5w7-h2h4-299j", - "modified": "2024-03-28T15:30:32Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-28T15:30:32Z", "aliases": [ "CVE-2024-30594" ], "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T13:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json b/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json index 9e3f8303a9f..01a3b68f466 100644 --- a/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json +++ b/advisories/unreviewed/2024/03/GHSA-qw5g-qccp-wchw/GHSA-qw5g-qccp-wchw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw5g-qccp-wchw", - "modified": "2024-03-28T15:30:32Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-28T15:30:32Z", "aliases": [ "CVE-2024-30586" ], "details": "Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T14:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vf4p-5p2r-42wm/GHSA-vf4p-5p2r-42wm.json b/advisories/unreviewed/2024/03/GHSA-vf4p-5p2r-42wm/GHSA-vf4p-5p2r-42wm.json index 6bffcd8bbd0..1ba75ff7ed2 100644 --- a/advisories/unreviewed/2024/03/GHSA-vf4p-5p2r-42wm/GHSA-vf4p-5p2r-42wm.json +++ b/advisories/unreviewed/2024/03/GHSA-vf4p-5p2r-42wm/GHSA-vf4p-5p2r-42wm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf4p-5p2r-42wm", - "modified": "2024-03-07T03:30:40Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-03-07T03:30:40Z", "aliases": [ "CVE-2023-49988" ], "details": "Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T01:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json b/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json index 8c31968b3e1..4b5fdb6ee40 100644 --- a/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json +++ b/advisories/unreviewed/2024/04/GHSA-4x7j-vfwq-rj38/GHSA-4x7j-vfwq-rj38.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x7j-vfwq-rj38", - "modified": "2024-04-04T21:30:32Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-04-04T21:30:32Z", "aliases": [ "CVE-2024-29387" ], "details": "projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-68vw-2c55-r944/GHSA-68vw-2c55-r944.json b/advisories/unreviewed/2024/04/GHSA-68vw-2c55-r944/GHSA-68vw-2c55-r944.json index 9adb121ca8c..67a804dcf64 100644 --- a/advisories/unreviewed/2024/04/GHSA-68vw-2c55-r944/GHSA-68vw-2c55-r944.json +++ b/advisories/unreviewed/2024/04/GHSA-68vw-2c55-r944/GHSA-68vw-2c55-r944.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68vw-2c55-r944", - "modified": "2024-04-01T18:30:56Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-04-01T18:30:56Z", "aliases": [ "CVE-2024-30859" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T16:15:20Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7vmw-frjx-p3mg/GHSA-7vmw-frjx-p3mg.json b/advisories/unreviewed/2024/04/GHSA-7vmw-frjx-p3mg/GHSA-7vmw-frjx-p3mg.json index 79468110394..75a68c0b382 100644 --- a/advisories/unreviewed/2024/04/GHSA-7vmw-frjx-p3mg/GHSA-7vmw-frjx-p3mg.json +++ b/advisories/unreviewed/2024/04/GHSA-7vmw-frjx-p3mg/GHSA-7vmw-frjx-p3mg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vmw-frjx-p3mg", - "modified": "2024-04-01T15:30:29Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-04-01T15:30:29Z", "aliases": [ "CVE-2024-30870" ], "details": "netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T13:17:28Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json b/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json index 50379c70d28..7c4f1f1b5e5 100644 --- a/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json +++ b/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv9f-467f-xm3f", - "modified": "2024-04-08T00:30:46Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-04-08T00:30:46Z", "aliases": [ "CVE-2021-47208" ], "details": "The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T00:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json b/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json index 25bf64906da..427a0c120ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json +++ b/advisories/unreviewed/2024/04/GHSA-gcvf-qqcq-825h/GHSA-gcvf-qqcq-825h.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-335" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json b/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json index 3dddad13f47..5bc1ab19ddb 100644 --- a/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json +++ b/advisories/unreviewed/2024/04/GHSA-x2m4-5rqp-rhvq/GHSA-x2m4-5rqp-rhvq.json @@ -29,7 +29,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-8cgc-3vjh-qxp8/GHSA-8cgc-3vjh-qxp8.json b/advisories/unreviewed/2024/05/GHSA-8cgc-3vjh-qxp8/GHSA-8cgc-3vjh-qxp8.json index 07e73caba87..27be9cafa2a 100644 --- a/advisories/unreviewed/2024/05/GHSA-8cgc-3vjh-qxp8/GHSA-8cgc-3vjh-qxp8.json +++ b/advisories/unreviewed/2024/05/GHSA-8cgc-3vjh-qxp8/GHSA-8cgc-3vjh-qxp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cgc-3vjh-qxp8", - "modified": "2024-05-23T18:30:56Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-05-23T18:30:56Z", "aliases": [ "CVE-2024-35091" ], "details": "J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T17:15:31Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wmxf-vfxg-wrm4/GHSA-wmxf-vfxg-wrm4.json b/advisories/unreviewed/2024/05/GHSA-wmxf-vfxg-wrm4/GHSA-wmxf-vfxg-wrm4.json index 36b5f3e491f..e353ebc7446 100644 --- a/advisories/unreviewed/2024/05/GHSA-wmxf-vfxg-wrm4/GHSA-wmxf-vfxg-wrm4.json +++ b/advisories/unreviewed/2024/05/GHSA-wmxf-vfxg-wrm4/GHSA-wmxf-vfxg-wrm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmxf-vfxg-wrm4", - "modified": "2024-05-02T18:30:50Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-05-02T18:30:50Z", "aliases": [ "CVE-2023-50685" ], "details": "An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T16:15:07Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4g7q-7v9w-3x8m/GHSA-4g7q-7v9w-3x8m.json b/advisories/unreviewed/2024/06/GHSA-4g7q-7v9w-3x8m/GHSA-4g7q-7v9w-3x8m.json index bdad8803285..69b6f061ce1 100644 --- a/advisories/unreviewed/2024/06/GHSA-4g7q-7v9w-3x8m/GHSA-4g7q-7v9w-3x8m.json +++ b/advisories/unreviewed/2024/06/GHSA-4g7q-7v9w-3x8m/GHSA-4g7q-7v9w-3x8m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-754" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-8q9h-wh74-mr38/GHSA-8q9h-wh74-mr38.json b/advisories/unreviewed/2024/06/GHSA-8q9h-wh74-mr38/GHSA-8q9h-wh74-mr38.json index 437ad477a4f..46a2dd188c5 100644 --- a/advisories/unreviewed/2024/06/GHSA-8q9h-wh74-mr38/GHSA-8q9h-wh74-mr38.json +++ b/advisories/unreviewed/2024/06/GHSA-8q9h-wh74-mr38/GHSA-8q9h-wh74-mr38.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-chpq-g3q7-fq3j/GHSA-chpq-g3q7-fq3j.json b/advisories/unreviewed/2024/06/GHSA-chpq-g3q7-fq3j/GHSA-chpq-g3q7-fq3j.json index e16e3bb0e14..ab39db9306e 100644 --- a/advisories/unreviewed/2024/06/GHSA-chpq-g3q7-fq3j/GHSA-chpq-g3q7-fq3j.json +++ b/advisories/unreviewed/2024/06/GHSA-chpq-g3q7-fq3j/GHSA-chpq-g3q7-fq3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chpq-g3q7-fq3j", - "modified": "2024-06-17T03:31:06Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-06-17T03:31:06Z", "aliases": [ "CVE-2024-6043" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-h6h7-cx32-rhcr/GHSA-h6h7-cx32-rhcr.json b/advisories/unreviewed/2024/06/GHSA-h6h7-cx32-rhcr/GHSA-h6h7-cx32-rhcr.json index a014baf2fbd..64f04cbd4f9 100644 --- a/advisories/unreviewed/2024/06/GHSA-h6h7-cx32-rhcr/GHSA-h6h7-cx32-rhcr.json +++ b/advisories/unreviewed/2024/06/GHSA-h6h7-cx32-rhcr/GHSA-h6h7-cx32-rhcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6h7-cx32-rhcr", - "modified": "2024-06-14T03:31:19Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-06-14T03:31:19Z", "aliases": [ "CVE-2024-5981" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-r438-mxg9-x66p/GHSA-r438-mxg9-x66p.json b/advisories/unreviewed/2024/06/GHSA-r438-mxg9-x66p/GHSA-r438-mxg9-x66p.json index 1e0cf032f49..16c9dbfc3da 100644 --- a/advisories/unreviewed/2024/06/GHSA-r438-mxg9-x66p/GHSA-r438-mxg9-x66p.json +++ b/advisories/unreviewed/2024/06/GHSA-r438-mxg9-x66p/GHSA-r438-mxg9-x66p.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w282-px53-r98p/GHSA-w282-px53-r98p.json b/advisories/unreviewed/2024/06/GHSA-w282-px53-r98p/GHSA-w282-px53-r98p.json index 7ba9b1c239f..6bee27f1247 100644 --- a/advisories/unreviewed/2024/06/GHSA-w282-px53-r98p/GHSA-w282-px53-r98p.json +++ b/advisories/unreviewed/2024/06/GHSA-w282-px53-r98p/GHSA-w282-px53-r98p.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-xcj3-hfw8-h3h5/GHSA-xcj3-hfw8-h3h5.json b/advisories/unreviewed/2024/06/GHSA-xcj3-hfw8-h3h5/GHSA-xcj3-hfw8-h3h5.json index 7e33d72e50f..7c00e71983c 100644 --- a/advisories/unreviewed/2024/06/GHSA-xcj3-hfw8-h3h5/GHSA-xcj3-hfw8-h3h5.json +++ b/advisories/unreviewed/2024/06/GHSA-xcj3-hfw8-h3h5/GHSA-xcj3-hfw8-h3h5.json @@ -1,14 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-xcj3-hfw8-h3h5", - "modified": "2024-06-14T15:31:25Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-06-14T15:31:25Z", "aliases": [ "CVE-2024-37367" ], "details": "A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } ], "affected": [ @@ -27,7 +34,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T15:15:51Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json b/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json index 4560d8a5fdc..09512dad36f 100644 --- a/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json +++ b/advisories/unreviewed/2024/07/GHSA-4rm3-98rm-pmgw/GHSA-4rm3-98rm-pmgw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rm3-98rm-pmgw", - "modified": "2024-07-15T18:31:15Z", + "modified": "2024-08-16T21:32:36Z", "published": "2024-07-15T18:31:15Z", "aliases": [ "CVE-2024-40554" ], "details": "An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-15T16:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json b/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json index 779a60b786f..9c9fe86f1b9 100644 --- a/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json +++ b/advisories/unreviewed/2024/08/GHSA-22qx-rv28-v9m8/GHSA-22qx-rv28-v9m8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json b/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json new file mode 100644 index 00000000000..72975dba44a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-28cx-j4v5-m5fv/GHSA-28cx-j4v5-m5fv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28cx-j4v5-m5fv", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-43042" + ], + "details": "Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43042" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1FnLCFP8xDrE1e_4Ft_TZ7VhC-JBkpsL0/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://github.com/pluck-cms/pluck" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3cw2-m32h-hqj9/GHSA-3cw2-m32h-hqj9.json b/advisories/unreviewed/2024/08/GHSA-3cw2-m32h-hqj9/GHSA-3cw2-m32h-hqj9.json new file mode 100644 index 00000000000..2c3ed0cd18a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3cw2-m32h-hqj9/GHSA-3cw2-m32h-hqj9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cw2-m32h-hqj9", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-42849" + ], + "details": "An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42849" + }, + { + "type": "WEB", + "url": "https://github.com/njmbb8/CVE-2024-42849/tree/main" + }, + { + "type": "WEB", + "url": "http://silverpeas.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3mp6-8h5j-hwh9/GHSA-3mp6-8h5j-hwh9.json b/advisories/unreviewed/2024/08/GHSA-3mp6-8h5j-hwh9/GHSA-3mp6-8h5j-hwh9.json index 51406295241..5267cc18ebb 100644 --- a/advisories/unreviewed/2024/08/GHSA-3mp6-8h5j-hwh9/GHSA-3mp6-8h5j-hwh9.json +++ b/advisories/unreviewed/2024/08/GHSA-3mp6-8h5j-hwh9/GHSA-3mp6-8h5j-hwh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mp6-8h5j-hwh9", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-08-12T15:30:49Z", "aliases": [ "CVE-2024-36035" diff --git a/advisories/unreviewed/2024/08/GHSA-43p9-cg2h-73x3/GHSA-43p9-cg2h-73x3.json b/advisories/unreviewed/2024/08/GHSA-43p9-cg2h-73x3/GHSA-43p9-cg2h-73x3.json new file mode 100644 index 00000000000..5b1ca1a95b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-43p9-cg2h-73x3/GHSA-43p9-cg2h-73x3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43p9-cg2h-73x3", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-43006" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a specially crafted POST request to /user/ask_edit.php?action=add, which includes malicious JavaScript code in the 'content' parameter. When a user visits the ask/show_{newsid}.html page, the injected script is executed in the context of the user's browser, leading to potential theft of cookies, session tokens, or other sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43006" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-43006%20ZZCMS2023%E5%82%A8%E5%AD%98%E5%9E%8BXSS.md" + }, + { + "type": "WEB", + "url": "http://www.zzcms.net/about/download.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json b/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json index 944143945c7..d38cd046f18 100644 --- a/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json +++ b/advisories/unreviewed/2024/08/GHSA-4hmr-hm34-jj9g/GHSA-4hmr-hm34-jj9g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hmr-hm34-jj9g", - "modified": "2024-08-16T18:30:57Z", + "modified": "2024-08-16T21:32:36Z", "published": "2024-08-16T18:30:57Z", "aliases": [ "CVE-2024-42634" ], "details": "A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T16:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5568-wmjg-3246/GHSA-5568-wmjg-3246.json b/advisories/unreviewed/2024/08/GHSA-5568-wmjg-3246/GHSA-5568-wmjg-3246.json new file mode 100644 index 00000000000..f09cf4a0976 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5568-wmjg-3246/GHSA-5568-wmjg-3246.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5568-wmjg-3246", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2022-4405" + ], + "details": "Rejected reason: **REJECT** This is not considered a valid security vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4405" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json b/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json index 93322540771..bf55e0d768a 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json +++ b/advisories/unreviewed/2024/08/GHSA-5wq9-96x8-3hq5/GHSA-5wq9-96x8-3hq5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-6f76-gwc4-m8pr/GHSA-6f76-gwc4-m8pr.json b/advisories/unreviewed/2024/08/GHSA-6f76-gwc4-m8pr/GHSA-6f76-gwc4-m8pr.json new file mode 100644 index 00000000000..07650301d19 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6f76-gwc4-m8pr/GHSA-6f76-gwc4-m8pr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f76-gwc4-m8pr", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2022-33162" + ], + "details": "IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 228570.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33162" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/228570" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7161442" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T19:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json b/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json index ed59278735d..95b6e42e7a3 100644 --- a/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json +++ b/advisories/unreviewed/2024/08/GHSA-6pr8-g9pq-xmj3/GHSA-6pr8-g9pq-xmj3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-849r-jpqc-fm29/GHSA-849r-jpqc-fm29.json b/advisories/unreviewed/2024/08/GHSA-849r-jpqc-fm29/GHSA-849r-jpqc-fm29.json new file mode 100644 index 00000000000..d9d5145d20a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-849r-jpqc-fm29/GHSA-849r-jpqc-fm29.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-849r-jpqc-fm29", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-43472" + ], + "details": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43472" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json b/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json index cf5732d72d5..6c549f8d7ff 100644 --- a/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json +++ b/advisories/unreviewed/2024/08/GHSA-f994-q776-gghm/GHSA-f994-q776-gghm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-ffm7-5xwh-8f68/GHSA-ffm7-5xwh-8f68.json b/advisories/unreviewed/2024/08/GHSA-ffm7-5xwh-8f68/GHSA-ffm7-5xwh-8f68.json new file mode 100644 index 00000000000..89edc89747c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ffm7-5xwh-8f68/GHSA-ffm7-5xwh-8f68.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffm7-5xwh-8f68", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-43005" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43005" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-43005%20ZZCMS2023%E5%8F%8D%E5%B0%84%E5%9E%8BXSS2.md" + }, + { + "type": "WEB", + "url": "http://zzcms.net" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fgp2-h88c-m594/GHSA-fgp2-h88c-m594.json b/advisories/unreviewed/2024/08/GHSA-fgp2-h88c-m594/GHSA-fgp2-h88c-m594.json new file mode 100644 index 00000000000..7f36a9475a1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fgp2-h88c-m594/GHSA-fgp2-h88c-m594.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgp2-h88c-m594", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2023-47728" + ], + "details": "IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM X-Force ID: 272201.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47728" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/272201" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7161427" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json b/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json new file mode 100644 index 00000000000..b20b0e97ffc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g5p7-39ff-j5mv/GHSA-g5p7-39ff-j5mv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5p7-39ff-j5mv", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-43009" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The application directly inserts the value of the HTTP_REFERER header into the HTML response without proper sanitization. An attacker can exploit this vulnerability by tricking a user into visiting a specially crafted URL, which includes a malicious Referer header. This can lead to the execution of arbitrary JavaScript code in the context of the victim's browser, potentially resulting in session hijacking, defacement, or other malicious activities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43009" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-43009%20ZZCMS2023%E5%8F%8D%E5%B0%84%E5%9E%8BXSS.md" + }, + { + "type": "WEB", + "url": "http://www.zzcms.net/about/download.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json b/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json index a0cd1043a73..66eedea5259 100644 --- a/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json +++ b/advisories/unreviewed/2024/08/GHSA-gv29-jxwh-r2gm/GHSA-gv29-jxwh-r2gm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv29-jxwh-r2gm", - "modified": "2024-08-15T21:31:19Z", + "modified": "2024-08-16T21:32:36Z", "published": "2024-08-15T21:31:19Z", "aliases": [ "CVE-2024-27731" ], "details": "Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T19:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json b/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json index 0ed7a05e88c..140c389a32c 100644 --- a/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json +++ b/advisories/unreviewed/2024/08/GHSA-gw56-mg6j-26qj/GHSA-gw56-mg6j-26qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw56-mg6j-26qj", - "modified": "2024-08-13T18:31:13Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-08-08T03:30:49Z", "aliases": [ "CVE-2024-38202" diff --git a/advisories/unreviewed/2024/08/GHSA-h6jq-w432-j26w/GHSA-h6jq-w432-j26w.json b/advisories/unreviewed/2024/08/GHSA-h6jq-w432-j26w/GHSA-h6jq-w432-j26w.json new file mode 100644 index 00000000000..655d1eedfbd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h6jq-w432-j26w/GHSA-h6jq-w432-j26w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6jq-w432-j26w", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-42850" + ], + "details": "An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42850" + }, + { + "type": "WEB", + "url": "https://github.com/njmbb8/CVE-2024-42850" + }, + { + "type": "WEB", + "url": "http://silverpeas.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hh35-wc7m-9qm9/GHSA-hh35-wc7m-9qm9.json b/advisories/unreviewed/2024/08/GHSA-hh35-wc7m-9qm9/GHSA-hh35-wc7m-9qm9.json index 91d6fd4186e..13f1fa44edd 100644 --- a/advisories/unreviewed/2024/08/GHSA-hh35-wc7m-9qm9/GHSA-hh35-wc7m-9qm9.json +++ b/advisories/unreviewed/2024/08/GHSA-hh35-wc7m-9qm9/GHSA-hh35-wc7m-9qm9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hh35-wc7m-9qm9", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-08-16T21:32:36Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-5527" diff --git a/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json b/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json index 99782040605..ed02d3cfa5c 100644 --- a/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json +++ b/advisories/unreviewed/2024/08/GHSA-mccv-36h3-rfv5/GHSA-mccv-36h3-rfv5.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-319" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json b/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json index 4fa9197268f..0b66cb0d871 100644 --- a/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json +++ b/advisories/unreviewed/2024/08/GHSA-mj96-jcmr-6947/GHSA-mj96-jcmr-6947.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj96-jcmr-6947", - "modified": "2024-08-16T18:30:57Z", + "modified": "2024-08-16T21:32:36Z", "published": "2024-08-16T18:30:57Z", "aliases": [ "CVE-2024-42995" ], "details": "VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the \"Migration\" administrative module to disable arbitrary modules.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T17:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mp7v-r97w-f9j9/GHSA-mp7v-r97w-f9j9.json b/advisories/unreviewed/2024/08/GHSA-mp7v-r97w-f9j9/GHSA-mp7v-r97w-f9j9.json index 4c06bb8bfac..472ba424525 100644 --- a/advisories/unreviewed/2024/08/GHSA-mp7v-r97w-f9j9/GHSA-mp7v-r97w-f9j9.json +++ b/advisories/unreviewed/2024/08/GHSA-mp7v-r97w-f9j9/GHSA-mp7v-r97w-f9j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mp7v-r97w-f9j9", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-08-12T15:30:49Z", "aliases": [ "CVE-2024-36034" diff --git a/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json b/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json new file mode 100644 index 00000000000..19a937fcfe6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mw3w-8r3q-gm92/GHSA-mw3w-8r3q-gm92.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw3w-8r3q-gm92", + "modified": "2024-08-16T21:32:36Z", + "published": "2024-08-16T21:32:36Z", + "aliases": [ + "CVE-2024-43011" + ], + "details": "An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of user input for file paths, an attacker can exploit this vulnerability by using directory traversal techniques to delete arbitrary files on the server. This can lead to the deletion of critical files, potentially disrupting the normal operation of the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43011" + }, + { + "type": "WEB", + "url": "https://github.com/gkdgkd123/codeAudit/blob/main/CVE-2024-43011%20ZZCMS2023%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%88%A0%E9%99%A4%E6%BC%8F%E6%B4%9E.md" + }, + { + "type": "WEB", + "url": "http://www.zzcms.net/about/download.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-16T20:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json b/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json index 7c66e802309..08f9889a659 100644 --- a/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json +++ b/advisories/unreviewed/2024/08/GHSA-vf2f-4qh9-fpch/GHSA-vf2f-4qh9-fpch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vf2f-4qh9-fpch", - "modified": "2024-08-16T18:30:57Z", + "modified": "2024-08-16T21:32:36Z", "published": "2024-08-16T18:30:57Z", "aliases": [ "CVE-2024-42994" ], "details": "VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the \"CompanyDetails\" operation of the \"MailManager\" module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-16T17:15:15Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json b/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json index 75866d2d2f7..d0ebeef8d94 100644 --- a/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json +++ b/advisories/unreviewed/2024/08/GHSA-vr5q-96fr-9g77/GHSA-vr5q-96fr-9g77.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-xrf6-53r6-98w9/GHSA-xrf6-53r6-98w9.json b/advisories/unreviewed/2024/08/GHSA-xrf6-53r6-98w9/GHSA-xrf6-53r6-98w9.json index 2fd2a9d535b..3fbde7081eb 100644 --- a/advisories/unreviewed/2024/08/GHSA-xrf6-53r6-98w9/GHSA-xrf6-53r6-98w9.json +++ b/advisories/unreviewed/2024/08/GHSA-xrf6-53r6-98w9/GHSA-xrf6-53r6-98w9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrf6-53r6-98w9", - "modified": "2024-08-12T15:30:51Z", + "modified": "2024-08-16T21:32:35Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-5487"