diff --git a/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json b/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json index 8673bad2ec3..12a60aba446 100644 --- a/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json +++ b/advisories/unreviewed/2022/02/GHSA-43x4-rqpq-prmp/GHSA-43x4-rqpq-prmp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-43x4-rqpq-prmp", - "modified": "2022-02-08T00:00:47Z", + "modified": "2024-08-20T15:32:11Z", "published": "2022-02-08T00:00:47Z", "aliases": [ "CVE-2021-31617" ], "details": "In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json b/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json index 506eacef784..02119afea5e 100644 --- a/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json +++ b/advisories/unreviewed/2022/02/GHSA-4p74-9wgm-4fjq/GHSA-4p74-9wgm-4fjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p74-9wgm-4fjq", - "modified": "2022-07-13T00:01:15Z", + "modified": "2024-08-20T15:32:11Z", "published": "2022-02-01T00:00:37Z", "aliases": [ "CVE-2021-28962" diff --git a/advisories/unreviewed/2022/05/GHSA-cg96-hc49-whwj/GHSA-cg96-hc49-whwj.json b/advisories/unreviewed/2022/05/GHSA-cg96-hc49-whwj/GHSA-cg96-hc49-whwj.json index 004206aef99..eb350061b69 100644 --- a/advisories/unreviewed/2022/05/GHSA-cg96-hc49-whwj/GHSA-cg96-hc49-whwj.json +++ b/advisories/unreviewed/2022/05/GHSA-cg96-hc49-whwj/GHSA-cg96-hc49-whwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg96-hc49-whwj", - "modified": "2022-07-13T00:01:14Z", + "modified": "2024-08-20T15:32:11Z", "published": "2022-05-24T19:01:26Z", "aliases": [ "CVE-2021-28665" @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-401" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qqfg-vxw9-g865/GHSA-qqfg-vxw9-g865.json b/advisories/unreviewed/2022/05/GHSA-qqfg-vxw9-g865/GHSA-qqfg-vxw9-g865.json index bb2ee1a30e9..864844cdb97 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqfg-vxw9-g865/GHSA-qqfg-vxw9-g865.json +++ b/advisories/unreviewed/2022/05/GHSA-qqfg-vxw9-g865/GHSA-qqfg-vxw9-g865.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qqfg-vxw9-g865", - "modified": "2022-05-24T17:43:30Z", + "modified": "2024-08-20T15:32:10Z", "published": "2022-05-24T17:43:30Z", "aliases": [ "CVE-2021-3384" ], "details": "A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP tables management, which would temporarily prevent the system to contact new hosts via IPv4 or IPv6. This affects versions 2.0.0 to 2.7.7, 2.8.0 to 2.16.0, 3.0.0 to 3.7.16, 3.8.0 to 3.11.4, and 4.0.0 to 4.1.5. Fixed in versions 2.7.8, 3.7.17, 3.11.5, and 4.2.0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-rfvf-cm38-cvx4/GHSA-rfvf-cm38-cvx4.json b/advisories/unreviewed/2022/05/GHSA-rfvf-cm38-cvx4/GHSA-rfvf-cm38-cvx4.json index a53bd591d88..6118ef5e612 100644 --- a/advisories/unreviewed/2022/05/GHSA-rfvf-cm38-cvx4/GHSA-rfvf-cm38-cvx4.json +++ b/advisories/unreviewed/2022/05/GHSA-rfvf-cm38-cvx4/GHSA-rfvf-cm38-cvx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfvf-cm38-cvx4", - "modified": "2022-07-02T00:00:30Z", + "modified": "2024-08-20T15:32:11Z", "published": "2022-05-24T17:44:55Z", "aliases": [ "CVE-2021-27506" diff --git a/advisories/unreviewed/2022/08/GHSA-3qrj-m697-ww2v/GHSA-3qrj-m697-ww2v.json b/advisories/unreviewed/2022/08/GHSA-3qrj-m697-ww2v/GHSA-3qrj-m697-ww2v.json index b74f8805579..7e3b5021135 100644 --- a/advisories/unreviewed/2022/08/GHSA-3qrj-m697-ww2v/GHSA-3qrj-m697-ww2v.json +++ b/advisories/unreviewed/2022/08/GHSA-3qrj-m697-ww2v/GHSA-3qrj-m697-ww2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3qrj-m697-ww2v", - "modified": "2022-08-29T00:00:32Z", + "modified": "2024-08-20T15:32:11Z", "published": "2022-08-25T00:00:28Z", "aliases": [ "CVE-2022-27812" diff --git a/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json b/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json index 9de080373bc..a5fcbc31274 100644 --- a/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json +++ b/advisories/unreviewed/2023/12/GHSA-ch6f-2w93-3p64/GHSA-ch6f-2w93-3p64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch6f-2w93-3p64", - "modified": "2024-01-04T03:30:38Z", + "modified": "2024-08-20T15:32:11Z", "published": "2023-12-25T09:30:20Z", "aliases": [ "CVE-2023-47091" diff --git a/advisories/unreviewed/2024/04/GHSA-5rx3-wxg4-cfw8/GHSA-5rx3-wxg4-cfw8.json b/advisories/unreviewed/2024/04/GHSA-5rx3-wxg4-cfw8/GHSA-5rx3-wxg4-cfw8.json index 9148def8a5f..660c0c56bb7 100644 --- a/advisories/unreviewed/2024/04/GHSA-5rx3-wxg4-cfw8/GHSA-5rx3-wxg4-cfw8.json +++ b/advisories/unreviewed/2024/04/GHSA-5rx3-wxg4-cfw8/GHSA-5rx3-wxg4-cfw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rx3-wxg4-cfw8", - "modified": "2024-04-29T18:30:45Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-04-29T18:30:45Z", "aliases": [ "CVE-2024-32269" ], "details": "An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T17:15:19Z" diff --git a/advisories/unreviewed/2024/05/GHSA-35h7-49rx-p783/GHSA-35h7-49rx-p783.json b/advisories/unreviewed/2024/05/GHSA-35h7-49rx-p783/GHSA-35h7-49rx-p783.json index 1cc732fff28..afc105c59a2 100644 --- a/advisories/unreviewed/2024/05/GHSA-35h7-49rx-p783/GHSA-35h7-49rx-p783.json +++ b/advisories/unreviewed/2024/05/GHSA-35h7-49rx-p783/GHSA-35h7-49rx-p783.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-35h7-49rx-p783", - "modified": "2024-05-14T15:32:54Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T15:32:54Z", "aliases": [ "CVE-2024-29159" ], "details": "HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:15:32Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3mcf-4rgf-4fx9/GHSA-3mcf-4rgf-4fx9.json b/advisories/unreviewed/2024/05/GHSA-3mcf-4rgf-4fx9/GHSA-3mcf-4rgf-4fx9.json index 975c42dca68..6358d17d3ac 100644 --- a/advisories/unreviewed/2024/05/GHSA-3mcf-4rgf-4fx9/GHSA-3mcf-4rgf-4fx9.json +++ b/advisories/unreviewed/2024/05/GHSA-3mcf-4rgf-4fx9/GHSA-3mcf-4rgf-4fx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3mcf-4rgf-4fx9", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32621" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8g42-4xgf-8mcj/GHSA-8g42-4xgf-8mcj.json b/advisories/unreviewed/2024/05/GHSA-8g42-4xgf-8mcj/GHSA-8g42-4xgf-8mcj.json index 350c1fa9360..4c4d92fb9b7 100644 --- a/advisories/unreviewed/2024/05/GHSA-8g42-4xgf-8mcj/GHSA-8g42-4xgf-8mcj.json +++ b/advisories/unreviewed/2024/05/GHSA-8g42-4xgf-8mcj/GHSA-8g42-4xgf-8mcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8g42-4xgf-8mcj", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32622" ], "details": "HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g9g4-wrgg-h792/GHSA-g9g4-wrgg-h792.json b/advisories/unreviewed/2024/05/GHSA-g9g4-wrgg-h792/GHSA-g9g4-wrgg-h792.json index ea8662f0c06..42dd3e31ee8 100644 --- a/advisories/unreviewed/2024/05/GHSA-g9g4-wrgg-h792/GHSA-g9g4-wrgg-h792.json +++ b/advisories/unreviewed/2024/05/GHSA-g9g4-wrgg-h792/GHSA-g9g4-wrgg-h792.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9g4-wrgg-h792", - "modified": "2024-05-14T18:30:46Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T18:30:46Z", "aliases": [ "CVE-2024-32617" ], "details": "HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-122" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:36:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h34r-96vv-vxhc/GHSA-h34r-96vv-vxhc.json b/advisories/unreviewed/2024/05/GHSA-h34r-96vv-vxhc/GHSA-h34r-96vv-vxhc.json index cff555c581f..1df649dcda5 100644 --- a/advisories/unreviewed/2024/05/GHSA-h34r-96vv-vxhc/GHSA-h34r-96vv-vxhc.json +++ b/advisories/unreviewed/2024/05/GHSA-h34r-96vv-vxhc/GHSA-h34r-96vv-vxhc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h34r-96vv-vxhc", - "modified": "2024-05-14T18:30:44Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T18:30:44Z", "aliases": [ "CVE-2022-32506" ], "details": "An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1263" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T10:43:41Z" diff --git a/advisories/unreviewed/2024/05/GHSA-q2m4-x7mj-qfqv/GHSA-q2m4-x7mj-qfqv.json b/advisories/unreviewed/2024/05/GHSA-q2m4-x7mj-qfqv/GHSA-q2m4-x7mj-qfqv.json index e8e3f73f66c..2e4267ea438 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2m4-x7mj-qfqv/GHSA-q2m4-x7mj-qfqv.json +++ b/advisories/unreviewed/2024/05/GHSA-q2m4-x7mj-qfqv/GHSA-q2m4-x7mj-qfqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q2m4-x7mj-qfqv", - "modified": "2024-05-14T15:32:50Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T15:32:50Z", "aliases": [ "CVE-2023-46870" ], "details": "extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T13:54:34Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qvvh-gx47-g435/GHSA-qvvh-gx47-g435.json b/advisories/unreviewed/2024/05/GHSA-qvvh-gx47-g435/GHSA-qvvh-gx47-g435.json index d2abda4d63a..d5b8faf6046 100644 --- a/advisories/unreviewed/2024/05/GHSA-qvvh-gx47-g435/GHSA-qvvh-gx47-g435.json +++ b/advisories/unreviewed/2024/05/GHSA-qvvh-gx47-g435/GHSA-qvvh-gx47-g435.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvvh-gx47-g435", - "modified": "2024-05-14T18:31:02Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-35010" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json b/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json index 36c819ec13f..a8a15ec29de 100644 --- a/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json +++ b/advisories/unreviewed/2024/05/GHSA-rv8j-7qfw-8mr3/GHSA-rv8j-7qfw-8mr3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rv8j-7qfw-8mr3", - "modified": "2024-05-20T18:31:24Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-20T18:31:24Z", "aliases": [ "CVE-2024-35580" ], "details": "Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T18:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x9q5-g839-f63f/GHSA-x9q5-g839-f63f.json b/advisories/unreviewed/2024/05/GHSA-x9q5-g839-f63f/GHSA-x9q5-g839-f63f.json index 345b42d40c9..b6d12072ee9 100644 --- a/advisories/unreviewed/2024/05/GHSA-x9q5-g839-f63f/GHSA-x9q5-g839-f63f.json +++ b/advisories/unreviewed/2024/05/GHSA-x9q5-g839-f63f/GHSA-x9q5-g839-f63f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x9q5-g839-f63f", - "modified": "2024-05-14T18:30:52Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-35205" ], "details": "The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:43Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3748-24jp-3mgm/GHSA-3748-24jp-3mgm.json b/advisories/unreviewed/2024/06/GHSA-3748-24jp-3mgm/GHSA-3748-24jp-3mgm.json index 55b5d3e32ae..29734e4e720 100644 --- a/advisories/unreviewed/2024/06/GHSA-3748-24jp-3mgm/GHSA-3748-24jp-3mgm.json +++ b/advisories/unreviewed/2024/06/GHSA-3748-24jp-3mgm/GHSA-3748-24jp-3mgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3748-24jp-3mgm", - "modified": "2024-06-06T21:30:36Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-36734" ], "details": "Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the dim parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T19:15:58Z" diff --git a/advisories/unreviewed/2024/06/GHSA-3862-5qvv-3rvv/GHSA-3862-5qvv-3rvv.json b/advisories/unreviewed/2024/06/GHSA-3862-5qvv-3rvv/GHSA-3862-5qvv-3rvv.json index 4e983324d37..675f8062a95 100644 --- a/advisories/unreviewed/2024/06/GHSA-3862-5qvv-3rvv/GHSA-3862-5qvv-3rvv.json +++ b/advisories/unreviewed/2024/06/GHSA-3862-5qvv-3rvv/GHSA-3862-5qvv-3rvv.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3g2h-7hrx-ghf6/GHSA-3g2h-7hrx-ghf6.json b/advisories/unreviewed/2024/06/GHSA-3g2h-7hrx-ghf6/GHSA-3g2h-7hrx-ghf6.json index c673a1e9dca..f975010ea0b 100644 --- a/advisories/unreviewed/2024/06/GHSA-3g2h-7hrx-ghf6/GHSA-3g2h-7hrx-ghf6.json +++ b/advisories/unreviewed/2024/06/GHSA-3g2h-7hrx-ghf6/GHSA-3g2h-7hrx-ghf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3g2h-7hrx-ghf6", - "modified": "2024-06-27T15:30:45Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-06-27T15:30:45Z", "aliases": [ "CVE-2024-6372" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-64v3-gww5-x3pc/GHSA-64v3-gww5-x3pc.json b/advisories/unreviewed/2024/06/GHSA-64v3-gww5-x3pc/GHSA-64v3-gww5-x3pc.json index 9f4fa9ab091..1d0169ff77f 100644 --- a/advisories/unreviewed/2024/06/GHSA-64v3-gww5-x3pc/GHSA-64v3-gww5-x3pc.json +++ b/advisories/unreviewed/2024/06/GHSA-64v3-gww5-x3pc/GHSA-64v3-gww5-x3pc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-64v3-gww5-x3pc", - "modified": "2024-06-27T15:30:45Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-06-27T15:30:45Z", "aliases": [ "CVE-2024-6373" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json b/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json index 8307bf513ba..9b87eb99bf6 100644 --- a/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json +++ b/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hj37-jcv3-rcw4", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48743" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: amd-xgbe: Fix skb data length underflow\n\nThere will be BUG_ON() triggered in include/linux/skbuff.h leading to\nintermittent kernel panic, when the skb length underflow is detected.\n\nFix this by dropping the packet if such length underflows are seen\nbecause of inconsistencies in the hardware descriptors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:12Z" diff --git a/advisories/unreviewed/2024/06/GHSA-q374-2q36-j342/GHSA-q374-2q36-j342.json b/advisories/unreviewed/2024/06/GHSA-q374-2q36-j342/GHSA-q374-2q36-j342.json index 35f0a66eff9..dd860845e64 100644 --- a/advisories/unreviewed/2024/06/GHSA-q374-2q36-j342/GHSA-q374-2q36-j342.json +++ b/advisories/unreviewed/2024/06/GHSA-q374-2q36-j342/GHSA-q374-2q36-j342.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q374-2q36-j342", - "modified": "2024-06-27T15:30:42Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-06-27T15:30:42Z", "aliases": [ "CVE-2024-6371" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json b/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json index feeafb19f76..2351ee13e1c 100644 --- a/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json +++ b/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qg8q-9c83-3485", - "modified": "2024-06-20T12:31:21Z", + "modified": "2024-08-20T15:32:11Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48742" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtnetlink: make sure to refresh master_dev/m_ops in __rtnl_newlink()\n\nWhile looking at one unrelated syzbot bug, I found the replay logic\nin __rtnl_newlink() to potentially trigger use-after-free.\n\nIt is better to clear master_dev and m_ops inside the loop,\nin case we have to replay it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json b/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json index 075d659bc2d..f5bc29dd57a 100644 --- a/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json +++ b/advisories/unreviewed/2024/07/GHSA-4645-h4xp-pj82/GHSA-4645-h4xp-pj82.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4645-h4xp-pj82", - "modified": "2024-08-13T18:31:13Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40776" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -81,9 +84,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-52gh-pmq6-vv84/GHSA-52gh-pmq6-vv84.json b/advisories/unreviewed/2024/07/GHSA-52gh-pmq6-vv84/GHSA-52gh-pmq6-vv84.json index cb93093465d..c639bc64e2d 100644 --- a/advisories/unreviewed/2024/07/GHSA-52gh-pmq6-vv84/GHSA-52gh-pmq6-vv84.json +++ b/advisories/unreviewed/2024/07/GHSA-52gh-pmq6-vv84/GHSA-52gh-pmq6-vv84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52gh-pmq6-vv84", - "modified": "2024-07-29T21:30:52Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-29T21:30:52Z", "aliases": [ "CVE-2024-37856" ], "details": "Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T19:15:12Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8v86-jpx9-59r6/GHSA-8v86-jpx9-59r6.json b/advisories/unreviewed/2024/07/GHSA-8v86-jpx9-59r6/GHSA-8v86-jpx9-59r6.json index 52aed3f712c..749f8534d27 100644 --- a/advisories/unreviewed/2024/07/GHSA-8v86-jpx9-59r6/GHSA-8v86-jpx9-59r6.json +++ b/advisories/unreviewed/2024/07/GHSA-8v86-jpx9-59r6/GHSA-8v86-jpx9-59r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v86-jpx9-59r6", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-27883" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cj5j-prcq-x46c/GHSA-cj5j-prcq-x46c.json b/advisories/unreviewed/2024/07/GHSA-cj5j-prcq-x46c/GHSA-cj5j-prcq-x46c.json index a78263c7620..79578e9cb9d 100644 --- a/advisories/unreviewed/2024/07/GHSA-cj5j-prcq-x46c/GHSA-cj5j-prcq-x46c.json +++ b/advisories/unreviewed/2024/07/GHSA-cj5j-prcq-x46c/GHSA-cj5j-prcq-x46c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj5j-prcq-x46c", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-27887" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cj8w-4x28-5j67/GHSA-cj8w-4x28-5j67.json b/advisories/unreviewed/2024/07/GHSA-cj8w-4x28-5j67/GHSA-cj8w-4x28-5j67.json index 9338f3b92d9..9131541a131 100644 --- a/advisories/unreviewed/2024/07/GHSA-cj8w-4x28-5j67/GHSA-cj8w-4x28-5j67.json +++ b/advisories/unreviewed/2024/07/GHSA-cj8w-4x28-5j67/GHSA-cj8w-4x28-5j67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj8w-4x28-5j67", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40775" ], "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to leak sensitive user information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rphx-6vqr-23h3/GHSA-rphx-6vqr-23h3.json b/advisories/unreviewed/2024/07/GHSA-rphx-6vqr-23h3/GHSA-rphx-6vqr-23h3.json index 1e5b300f345..aace84d0c7a 100644 --- a/advisories/unreviewed/2024/07/GHSA-rphx-6vqr-23h3/GHSA-rphx-6vqr-23h3.json +++ b/advisories/unreviewed/2024/07/GHSA-rphx-6vqr-23h3/GHSA-rphx-6vqr-23h3.json @@ -56,7 +56,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-121" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-v3xj-22vc-44xg/GHSA-v3xj-22vc-44xg.json b/advisories/unreviewed/2024/07/GHSA-v3xj-22vc-44xg/GHSA-v3xj-22vc-44xg.json index 6509e311e00..f0512a401a7 100644 --- a/advisories/unreviewed/2024/07/GHSA-v3xj-22vc-44xg/GHSA-v3xj-22vc-44xg.json +++ b/advisories/unreviewed/2024/07/GHSA-v3xj-22vc-44xg/GHSA-v3xj-22vc-44xg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3xj-22vc-44xg", - "modified": "2024-07-30T09:31:50Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-27884" ], "details": "This issue was addressed with a new entitlement. This issue is fixed in macOS Sonoma 14.5, watchOS 10.5, visionOS 1.2, tvOS 17.5, iOS 17.5 and iPadOS 17.5. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -63,7 +66,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wqm3-wvfr-qhw4/GHSA-wqm3-wvfr-qhw4.json b/advisories/unreviewed/2024/07/GHSA-wqm3-wvfr-qhw4/GHSA-wqm3-wvfr-qhw4.json index 47940122f0a..8aacb6f34d8 100644 --- a/advisories/unreviewed/2024/07/GHSA-wqm3-wvfr-qhw4/GHSA-wqm3-wvfr-qhw4.json +++ b/advisories/unreviewed/2024/07/GHSA-wqm3-wvfr-qhw4/GHSA-wqm3-wvfr-qhw4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqm3-wvfr-qhw4", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40774" ], "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, macOS Sonoma 14.6. An app may be able to bypass Privacy preferences.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -71,7 +74,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-xrqq-qf24-xjgx/GHSA-xrqq-qf24-xjgx.json b/advisories/unreviewed/2024/07/GHSA-xrqq-qf24-xjgx/GHSA-xrqq-qf24-xjgx.json index 3c65a134a3d..75bddd60d4e 100644 --- a/advisories/unreviewed/2024/07/GHSA-xrqq-qf24-xjgx/GHSA-xrqq-qf24-xjgx.json +++ b/advisories/unreviewed/2024/07/GHSA-xrqq-qf24-xjgx/GHSA-xrqq-qf24-xjgx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xrqq-qf24-xjgx", - "modified": "2024-07-30T03:30:51Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-27882" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json b/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json new file mode 100644 index 00000000000..647f1fff61c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-226h-2qfh-4hf8", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42562" + ], + "details": "Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42562" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/2dcca275bcc18e8058cefef714a2f61b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2h9q-c8x4-7278/GHSA-2h9q-c8x4-7278.json b/advisories/unreviewed/2024/08/GHSA-2h9q-c8x4-7278/GHSA-2h9q-c8x4-7278.json index 1f6e69a4d1b..7fb49c05e00 100644 --- a/advisories/unreviewed/2024/08/GHSA-2h9q-c8x4-7278/GHSA-2h9q-c8x4-7278.json +++ b/advisories/unreviewed/2024/08/GHSA-2h9q-c8x4-7278/GHSA-2h9q-c8x4-7278.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2h9q-c8x4-7278", - "modified": "2024-08-19T21:35:12Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-08-19T21:35:11Z", "aliases": [ "CVE-2024-35538" ], "details": "Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T21:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json b/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json new file mode 100644 index 00000000000..b58f7a2e6b9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2vf4-v2rm-3993/GHSA-2vf4-v2rm-3993.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vf4-v2rm-3993", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42563" + ], + "details": "An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42563" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/f645f99661ff33aed44d65dfa49e36fe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json b/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json new file mode 100644 index 00000000000..1b51f20fde5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vfq-7gxj-92hg", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42553" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42553" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/4b22a22c73b16c7c22c06d4b3f033fdc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2wxw-57mr-pm55/GHSA-2wxw-57mr-pm55.json b/advisories/unreviewed/2024/08/GHSA-2wxw-57mr-pm55/GHSA-2wxw-57mr-pm55.json new file mode 100644 index 00000000000..4725fb163c6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2wxw-57mr-pm55/GHSA-2wxw-57mr-pm55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wxw-57mr-pm55", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42575" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42575" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/2fddc00b33b038cd778c1e4fb1936a15" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-32gf-jv83-x2cj/GHSA-32gf-jv83-x2cj.json b/advisories/unreviewed/2024/08/GHSA-32gf-jv83-x2cj/GHSA-32gf-jv83-x2cj.json new file mode 100644 index 00000000000..b6191315e39 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-32gf-jv83-x2cj/GHSA-32gf-jv83-x2cj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32gf-jv83-x2cj", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42336" + ], + "details": "Servision - CWE-287: Improper Authentication", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42336" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3wq3-9c8f-wfpw/GHSA-3wq3-9c8f-wfpw.json b/advisories/unreviewed/2024/08/GHSA-3wq3-9c8f-wfpw/GHSA-3wq3-9c8f-wfpw.json new file mode 100644 index 00000000000..f3fd655b673 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3wq3-9c8f-wfpw/GHSA-3wq3-9c8f-wfpw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wq3-9c8f-wfpw", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42606" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42606" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/6/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json b/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json new file mode 100644 index 00000000000..e2eb455cd8b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-44v9-q98m-jg4p/GHSA-44v9-q98m-jg4p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44v9-q98m-jg4p", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42608" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42608" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/2/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4643-2q5r-g2gr/GHSA-4643-2q5r-g2gr.json b/advisories/unreviewed/2024/08/GHSA-4643-2q5r-g2gr/GHSA-4643-2q5r-g2gr.json new file mode 100644 index 00000000000..ff95a38a679 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4643-2q5r-g2gr/GHSA-4643-2q5r-g2gr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4643-2q5r-g2gr", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-34458" + ], + "details": "Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34458" + }, + { + "type": "WEB", + "url": "https://trust.keyfactor.com/?itemUid=d73921fd-bc9e-4e35-a974-cfb628e6a226&source=click" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4v95-m49f-6w63/GHSA-4v95-m49f-6w63.json b/advisories/unreviewed/2024/08/GHSA-4v95-m49f-6w63/GHSA-4v95-m49f-6w63.json new file mode 100644 index 00000000000..18c8fc3aba3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4v95-m49f-6w63/GHSA-4v95-m49f-6w63.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v95-m49f-6w63", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-6378" + ], + "details": "A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6378" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-53v3-9rp7-jg5m/GHSA-53v3-9rp7-jg5m.json b/advisories/unreviewed/2024/08/GHSA-53v3-9rp7-jg5m/GHSA-53v3-9rp7-jg5m.json new file mode 100644 index 00000000000..d992bbb9bd7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-53v3-9rp7-jg5m/GHSA-53v3-9rp7-jg5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53v3-9rp7-jg5m", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42335" + ], + "details": "7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42335" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-56fc-v6xr-69v4/GHSA-56fc-v6xr-69v4.json b/advisories/unreviewed/2024/08/GHSA-56fc-v6xr-69v4/GHSA-56fc-v6xr-69v4.json new file mode 100644 index 00000000000..db686898b66 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-56fc-v6xr-69v4/GHSA-56fc-v6xr-69v4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56fc-v6xr-69v4", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42572" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42572" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/c4c9508b8b3ed11f098f716d46572295" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5pwr-c9vv-hq48/GHSA-5pwr-c9vv-hq48.json b/advisories/unreviewed/2024/08/GHSA-5pwr-c9vv-hq48/GHSA-5pwr-c9vv-hq48.json new file mode 100644 index 00000000000..8150bd2b623 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5pwr-c9vv-hq48/GHSA-5pwr-c9vv-hq48.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pwr-c9vv-hq48", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-8003" + ], + "details": "A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log Handler. The manipulation leads to deserialization. The patch is identified as 45ac90d6d1f82716f77dbcdf8e7309c229080e3c. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8003" + }, + { + "type": "WEB", + "url": "https://github.com/Go-Tribe/gotribe-admin/issues/1" + }, + { + "type": "WEB", + "url": "https://github.com/Go-Tribe/gotribe-admin/issues/1#issuecomment-2298187923" + }, + { + "type": "WEB", + "url": "https://github.com/Go-Tribe/gotribe-admin/commit/45ac90d6d1f82716f77dbcdf8e7309c229080e3c" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275198" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275198" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393987" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json b/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json new file mode 100644 index 00000000000..d8c8313f691 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-688r-h6x5-8qpm", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42576" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42576" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/50a1d8ad7effd9ccd089952602c831d3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-68fj-vj36-gmvc/GHSA-68fj-vj36-gmvc.json b/advisories/unreviewed/2024/08/GHSA-68fj-vj36-gmvc/GHSA-68fj-vj36-gmvc.json new file mode 100644 index 00000000000..1c55161c84a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-68fj-vj36-gmvc/GHSA-68fj-vj36-gmvc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68fj-vj36-gmvc", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42581" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42581" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/2bd26343ccdff7c759f62d332c8caff6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6f6p-5vvv-9x8w/GHSA-6f6p-5vvv-9x8w.json b/advisories/unreviewed/2024/08/GHSA-6f6p-5vvv-9x8w/GHSA-6f6p-5vvv-9x8w.json new file mode 100644 index 00000000000..9886ef24988 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6f6p-5vvv-9x8w/GHSA-6f6p-5vvv-9x8w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f6p-5vvv-9x8w", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42616" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42616" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/13/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-77p4-cgh2-jpr9/GHSA-77p4-cgh2-jpr9.json b/advisories/unreviewed/2024/08/GHSA-77p4-cgh2-jpr9/GHSA-77p4-cgh2-jpr9.json new file mode 100644 index 00000000000..8633652b8ff --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-77p4-cgh2-jpr9/GHSA-77p4-cgh2-jpr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77p4-cgh2-jpr9", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42578" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42578" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/5eacc7e418e3b73b7ad1fa05d1a72aeb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-78pr-7p6m-3mmv/GHSA-78pr-7p6m-3mmv.json b/advisories/unreviewed/2024/08/GHSA-78pr-7p6m-3mmv/GHSA-78pr-7p6m-3mmv.json new file mode 100644 index 00000000000..3a3775cebaa --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-78pr-7p6m-3mmv/GHSA-78pr-7p6m-3mmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78pr-7p6m-3mmv", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-6918" + ], + "details": "CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability\nexists that could cause a crash of the Accutech Manager when receiving a specially crafted\nrequest over port 2536/TCP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6918" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-226-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-226-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7c63-hh47-864q/GHSA-7c63-hh47-864q.json b/advisories/unreviewed/2024/08/GHSA-7c63-hh47-864q/GHSA-7c63-hh47-864q.json new file mode 100644 index 00000000000..14d5071755b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7c63-hh47-864q/GHSA-7c63-hh47-864q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c63-hh47-864q", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42609" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42609" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/8/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json b/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json index 3a8aef43e42..fe455a0606b 100644 --- a/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json +++ b/advisories/unreviewed/2024/08/GHSA-7q2m-phm4-h2g3/GHSA-7q2m-phm4-h2g3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7q2m-phm4-h2g3", - "modified": "2024-08-15T21:31:19Z", + "modified": "2024-08-20T15:32:12Z", "published": "2024-08-15T21:31:19Z", "aliases": [ "CVE-2024-27728" ], "details": "Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T19:15:18Z" diff --git a/advisories/unreviewed/2024/08/GHSA-92r2-9q8h-28w4/GHSA-92r2-9q8h-28w4.json b/advisories/unreviewed/2024/08/GHSA-92r2-9q8h-28w4/GHSA-92r2-9q8h-28w4.json new file mode 100644 index 00000000000..0aceba52c62 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-92r2-9q8h-28w4/GHSA-92r2-9q8h-28w4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92r2-9q8h-28w4", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42621" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42621" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/12/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9q95-wcpw-r4hv/GHSA-9q95-wcpw-r4hv.json b/advisories/unreviewed/2024/08/GHSA-9q95-wcpw-r4hv/GHSA-9q95-wcpw-r4hv.json new file mode 100644 index 00000000000..e25a5a168ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9q95-wcpw-r4hv/GHSA-9q95-wcpw-r4hv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q95-wcpw-r4hv", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42604" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42604" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/1/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9qqv-x5jm-x7m4/GHSA-9qqv-x5jm-x7m4.json b/advisories/unreviewed/2024/08/GHSA-9qqv-x5jm-x7m4/GHSA-9qqv-x5jm-x7m4.json new file mode 100644 index 00000000000..3094d929dc9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9qqv-x5jm-x7m4/GHSA-9qqv-x5jm-x7m4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qqv-x5jm-x7m4", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42570" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42570" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/1d9ebca101fc5e30040436d70e522102" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9qx3-hr7q-4q26/GHSA-9qx3-hr7q-4q26.json b/advisories/unreviewed/2024/08/GHSA-9qx3-hr7q-4q26/GHSA-9qx3-hr7q-4q26.json new file mode 100644 index 00000000000..5957733529b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9qx3-hr7q-4q26/GHSA-9qx3-hr7q-4q26.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qx3-hr7q-4q26", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42610" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42610" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/7/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json b/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json new file mode 100644 index 00000000000..8ce55a7a661 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c36j-4grh-9p4v", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42611" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42611" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/4/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c6p4-w9r2-386f/GHSA-c6p4-w9r2-386f.json b/advisories/unreviewed/2024/08/GHSA-c6p4-w9r2-386f/GHSA-c6p4-w9r2-386f.json new file mode 100644 index 00000000000..304cfa6ea52 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c6p4-w9r2-386f/GHSA-c6p4-w9r2-386f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6p4-w9r2-386f", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42006" + ], + "details": "Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42006" + }, + { + "type": "WEB", + "url": "https://trust.keyfactor.com/?itemUid=d73921fd-bc9e-4e35-a974-cfb628e6a226&source=click" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c7jf-2h36-h69f/GHSA-c7jf-2h36-h69f.json b/advisories/unreviewed/2024/08/GHSA-c7jf-2h36-h69f/GHSA-c7jf-2h36-h69f.json new file mode 100644 index 00000000000..dbcd937c343 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7jf-2h36-h69f/GHSA-c7jf-2h36-h69f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7jf-2h36-h69f", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42334" + ], + "details": "Hargal - CWE-284: Improper Access Control", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42334" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c8pv-42w6-g942/GHSA-c8pv-42w6-g942.json b/advisories/unreviewed/2024/08/GHSA-c8pv-42w6-g942/GHSA-c8pv-42w6-g942.json new file mode 100644 index 00000000000..dcf72ccc193 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c8pv-42w6-g942/GHSA-c8pv-42w6-g942.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8pv-42w6-g942", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42577" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42577" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/20ad7b251f2905db38e7a6566b1d46cc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cpwj-j5m3-48m7/GHSA-cpwj-j5m3-48m7.json b/advisories/unreviewed/2024/08/GHSA-cpwj-j5m3-48m7/GHSA-cpwj-j5m3-48m7.json new file mode 100644 index 00000000000..9831cbd0f57 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cpwj-j5m3-48m7/GHSA-cpwj-j5m3-48m7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpwj-j5m3-48m7", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42584" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42584" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/6037eaac5749430c29cf15fdd9df0ba5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cvcv-5m9q-xg6v/GHSA-cvcv-5m9q-xg6v.json b/advisories/unreviewed/2024/08/GHSA-cvcv-5m9q-xg6v/GHSA-cvcv-5m9q-xg6v.json new file mode 100644 index 00000000000..22d04c55504 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cvcv-5m9q-xg6v/GHSA-cvcv-5m9q-xg6v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvcv-5m9q-xg6v", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42583" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42583" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/dac0206b8de14763bdbe2b6bb7020cdc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json b/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json new file mode 100644 index 00000000000..01c5fdd8f36 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwjq-hcgw-p8cp", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42571" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42571" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/5c8e289fa66702fd3acbed558ee449dd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f42m-47hm-q3xw/GHSA-f42m-47hm-q3xw.json b/advisories/unreviewed/2024/08/GHSA-f42m-47hm-q3xw/GHSA-f42m-47hm-q3xw.json new file mode 100644 index 00000000000..447f50b5169 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f42m-47hm-q3xw/GHSA-f42m-47hm-q3xw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f42m-47hm-q3xw", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42580" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42580" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/8a05309486637d8c6ce8c6624ec1e897" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json b/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json new file mode 100644 index 00000000000..492b350ec1f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8fv-2xcx-3x86", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42555" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42555" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/afd445b90e13a27a6422cea2f5ff0f64" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json b/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json new file mode 100644 index 00000000000..0e0a9e5cba4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fcf2-47c2-px5h/GHSA-fcf2-47c2-px5h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcf2-47c2-px5h", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42564" + ], + "details": "ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42564" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/8ccda41cac32fe781b89c6c0db245ab7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json b/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json new file mode 100644 index 00000000000..c8b5b46ed23 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp6w-w9xq-jxfv", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42560" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42560" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/4c05ee72ab4b365ef81c199aaa0558d0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fq63-g6gq-94pm/GHSA-fq63-g6gq-94pm.json b/advisories/unreviewed/2024/08/GHSA-fq63-g6gq-94pm/GHSA-fq63-g6gq-94pm.json new file mode 100644 index 00000000000..5d23e32008f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fq63-g6gq-94pm/GHSA-fq63-g6gq-94pm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq63-g6gq-94pm", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42567" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42567" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/96ba3f6ccd333480aa86e7078c4886d7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json b/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json new file mode 100644 index 00000000000..ceae83cadba --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7q2-vcm2-c3q8", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42561" + ], + "details": "Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42561" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/5d2d9104dc4dd7f5dda99cbbd615a0b8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gp6q-6vxx-w2m3/GHSA-gp6q-6vxx-w2m3.json b/advisories/unreviewed/2024/08/GHSA-gp6q-6vxx-w2m3/GHSA-gp6q-6vxx-w2m3.json new file mode 100644 index 00000000000..66cbb9a1e62 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gp6q-6vxx-w2m3/GHSA-gp6q-6vxx-w2m3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp6q-6vxx-w2m3", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42559" + ], + "details": "An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42559" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/99d2ebf7b5598ef227262ba1b2bb392f/edit" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json b/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json new file mode 100644 index 00000000000..e0a8638a5d9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h3rg-2ghf-ph8j/GHSA-h3rg-2ghf-ph8j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3rg-2ghf-ph8j", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42556" + ], + "details": "Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42556" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/9688bcdd3e05ba79ebf4ff1042609b20" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h6c7-598w-v6r5/GHSA-h6c7-598w-v6r5.json b/advisories/unreviewed/2024/08/GHSA-h6c7-598w-v6r5/GHSA-h6c7-598w-v6r5.json new file mode 100644 index 00000000000..a643c486634 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-h6c7-598w-v6r5/GHSA-h6c7-598w-v6r5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6c7-598w-v6r5", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42557" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42557" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/0785597ae7abc8f10cd5c5537f5467b5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hf3j-2xw8-3rwc/GHSA-hf3j-2xw8-3rwc.json b/advisories/unreviewed/2024/08/GHSA-hf3j-2xw8-3rwc/GHSA-hf3j-2xw8-3rwc.json new file mode 100644 index 00000000000..466c63afbbc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hf3j-2xw8-3rwc/GHSA-hf3j-2xw8-3rwc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf3j-2xw8-3rwc", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-39094" + ], + "details": "Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39094" + }, + { + "type": "WEB", + "url": "https://github.com/friendica/friendica/issues/14220" + }, + { + "type": "WEB", + "url": "https://friendi.ca/2024/08/17/friendica-2024-08-released" + }, + { + "type": "WEB", + "url": "https://github.com/friendica/friendica/releases/tag/2024.08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json b/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json new file mode 100644 index 00000000000..ae2e018907e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf49-mv84-4q97", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-35540" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35540" + }, + { + "type": "WEB", + "url": "https://cyberaz0r.info/2024/08/typecho-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j557-6r6g-gm35/GHSA-j557-6r6g-gm35.json b/advisories/unreviewed/2024/08/GHSA-j557-6r6g-gm35/GHSA-j557-6r6g-gm35.json new file mode 100644 index 00000000000..4efa82a28b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j557-6r6g-gm35/GHSA-j557-6r6g-gm35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j557-6r6g-gm35", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-33872" + ], + "details": "Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33872" + }, + { + "type": "WEB", + "url": "https://trust.keyfactor.com/?itemUid=d73921fd-bc9e-4e35-a974-cfb628e6a226&source=click" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json b/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json new file mode 100644 index 00000000000..4b5c91a3d1f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j5jg-j64j-c6rq/GHSA-j5jg-j64j-c6rq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5jg-j64j-c6rq", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42662" + ], + "details": "An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42662" + }, + { + "type": "WEB", + "url": "https://gist.github.com/len0m0/f0886d579de6c075506ab543e054dc7d" + }, + { + "type": "WEB", + "url": "https://github.com/len0m0/Apolloinfo/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json b/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json new file mode 100644 index 00000000000..80fe4d0fa5f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j5wm-h22f-j8qm/GHSA-j5wm-h22f-j8qm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5wm-h22f-j8qm", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42552" + ], + "details": "Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42552" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/2386856df3f3ffa7bdc4738e24da4af3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json b/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json new file mode 100644 index 00000000000..048f11ffbb2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9c3-gww2-4h3v", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42585" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42585" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/33de7a4bd7a4517a26fa4e4911b7fb1d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jf9v-867q-hmcf/GHSA-jf9v-867q-hmcf.json b/advisories/unreviewed/2024/08/GHSA-jf9v-867q-hmcf/GHSA-jf9v-867q-hmcf.json new file mode 100644 index 00000000000..fb7e9496270 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jf9v-867q-hmcf/GHSA-jf9v-867q-hmcf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf9v-867q-hmcf", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42566" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42566" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/95a8f0d24f1d409a14df4c04e0a8c547" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json b/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json new file mode 100644 index 00000000000..6f358f393e8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhpq-42hq-rch5", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42586" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42586" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/533b962efb1779e397a241bf7a19643c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json b/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json new file mode 100644 index 00000000000..173eb95298f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf3h-674w-gp32", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42569" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42569" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/20a81dbf47d371e1dabe08f350c8185d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p49w-q3f3-473v/GHSA-p49w-q3f3-473v.json b/advisories/unreviewed/2024/08/GHSA-p49w-q3f3-473v/GHSA-p49w-q3f3-473v.json new file mode 100644 index 00000000000..c98cdae58c3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p49w-q3f3-473v/GHSA-p49w-q3f3-473v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p49w-q3f3-473v", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42613" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42613" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/14/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p89j-rm47-9qxx/GHSA-p89j-rm47-9qxx.json b/advisories/unreviewed/2024/08/GHSA-p89j-rm47-9qxx/GHSA-p89j-rm47-9qxx.json new file mode 100644 index 00000000000..9f1c6cb0c7c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p89j-rm47-9qxx/GHSA-p89j-rm47-9qxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p89j-rm47-9qxx", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42605" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42605" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/3/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q567-qjp8-m2mc/GHSA-q567-qjp8-m2mc.json b/advisories/unreviewed/2024/08/GHSA-q567-qjp8-m2mc/GHSA-q567-qjp8-m2mc.json new file mode 100644 index 00000000000..f3ee24fe369 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q567-qjp8-m2mc/GHSA-q567-qjp8-m2mc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q567-qjp8-m2mc", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42565" + ], + "details": "ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42565" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/648f2cd4f5e58560cbc9308d06e2f876" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json b/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json new file mode 100644 index 00000000000..bae96d2b90b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qhpg-jf9r-mqxq/GHSA-qhpg-jf9r-mqxq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhpg-jf9r-mqxq", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-30949" + ], + "details": "An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30949" + }, + { + "type": "WEB", + "url": "https://gist.github.com/visitorckw/6b26e599241ea80210ea136b28441661" + }, + { + "type": "WEB", + "url": "https://inbox.sourceware.org/newlib/20231129035714.469943-1-visitorckw%40gmail.com" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=newlib-cygwin.git%3Ba=commit%3Bh=5f15d7c5817b07a6b18cbab17342c95cb7b42be4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qxvp-w3gv-64gj/GHSA-qxvp-w3gv-64gj.json b/advisories/unreviewed/2024/08/GHSA-qxvp-w3gv-64gj/GHSA-qxvp-w3gv-64gj.json new file mode 100644 index 00000000000..69a5031da8e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qxvp-w3gv-64gj/GHSA-qxvp-w3gv-64gj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxvp-w3gv-64gj", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42579" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42579" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/ed59fb8b35a220dfa064a3a3cb1ecb1b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r39x-24mw-vr93/GHSA-r39x-24mw-vr93.json b/advisories/unreviewed/2024/08/GHSA-r39x-24mw-vr93/GHSA-r39x-24mw-vr93.json new file mode 100644 index 00000000000..824cbafe938 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r39x-24mw-vr93/GHSA-r39x-24mw-vr93.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r39x-24mw-vr93", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-8005" + ], + "details": "A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the component JWT Authentication. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.2 is able to address this issue. The patch is named be702ada7cb6fdabc02689d90b38139c827458a5. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8005" + }, + { + "type": "WEB", + "url": "https://github.com/demozx/gf_cms/issues/5" + }, + { + "type": "WEB", + "url": "https://github.com/demozx/gf_cms/issues/5#issuecomment-2296590417" + }, + { + "type": "WEB", + "url": "https://github.com/demozx/gf_cms/commit/be702ada7cb6fdabc02689d90b38139c827458a5" + }, + { + "type": "WEB", + "url": "https://github.com/demozx/gf_cms/commit/de51cc57a96ccca905c837ef925c2cc3a5241383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.275199" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.275199" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.393981" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r9hx-cmxm-cg5j/GHSA-r9hx-cmxm-cg5j.json b/advisories/unreviewed/2024/08/GHSA-r9hx-cmxm-cg5j/GHSA-r9hx-cmxm-cg5j.json new file mode 100644 index 00000000000..ca093fc9b4a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r9hx-cmxm-cg5j/GHSA-r9hx-cmxm-cg5j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9hx-cmxm-cg5j", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42573" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42573" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/d44aabca29c1a6a9845fde465b924e79" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rq65-jvh5-686f/GHSA-rq65-jvh5-686f.json b/advisories/unreviewed/2024/08/GHSA-rq65-jvh5-686f/GHSA-rq65-jvh5-686f.json new file mode 100644 index 00000000000..08ac27f4e2a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rq65-jvh5-686f/GHSA-rq65-jvh5-686f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq65-jvh5-686f", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42582" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42582" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/c0d78b257ce1e661be30de1ce9551d27" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json b/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json new file mode 100644 index 00000000000..c9f5e9e5ed5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v4cc-wwr9-44vw/GHSA-v4cc-wwr9-44vw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4cc-wwr9-44vw", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-6379" + ], + "details": "An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6379" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v4fq-rjqc-xp4w/GHSA-v4fq-rjqc-xp4w.json b/advisories/unreviewed/2024/08/GHSA-v4fq-rjqc-xp4w/GHSA-v4fq-rjqc-xp4w.json new file mode 100644 index 00000000000..e5abe10781e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v4fq-rjqc-xp4w/GHSA-v4fq-rjqc-xp4w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4fq-rjqc-xp4w", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42574" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42574" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/7064f8bbd3977ee665a098efcd0170c0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json b/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json new file mode 100644 index 00000000000..4c5e8643a48 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v735-hrpq-c278/GHSA-v735-hrpq-c278.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v735-hrpq-c278", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-6377" + ], + "details": "A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6377" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v97r-2c8q-frf2/GHSA-v97r-2c8q-frf2.json b/advisories/unreviewed/2024/08/GHSA-v97r-2c8q-frf2/GHSA-v97r-2c8q-frf2.json new file mode 100644 index 00000000000..91f0c7de4a2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v97r-2c8q-frf2/GHSA-v97r-2c8q-frf2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v97r-2c8q-frf2", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42558" + ], + "details": "Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42558" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/9651b4977e86f5b1bcae7a8959ff3342" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vfhr-rxhw-fm44/GHSA-vfhr-rxhw-fm44.json b/advisories/unreviewed/2024/08/GHSA-vfhr-rxhw-fm44/GHSA-vfhr-rxhw-fm44.json new file mode 100644 index 00000000000..0597642f556 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vfhr-rxhw-fm44/GHSA-vfhr-rxhw-fm44.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfhr-rxhw-fm44", + "modified": "2024-08-20T15:32:14Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42618" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42618" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/16/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wcjm-7fr5-4hrc/GHSA-wcjm-7fr5-4hrc.json b/advisories/unreviewed/2024/08/GHSA-wcjm-7fr5-4hrc/GHSA-wcjm-7fr5-4hrc.json new file mode 100644 index 00000000000..ace80a038cf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wcjm-7fr5-4hrc/GHSA-wcjm-7fr5-4hrc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcjm-7fr5-4hrc", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42568" + ], + "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42568" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/38a30275374ef796ab860795f5df4dac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json b/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json new file mode 100644 index 00000000000..549a1982855 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqq8-c887-jc8m", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42617" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42617" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/11/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x74r-hr36-m64w/GHSA-x74r-hr36-m64w.json b/advisories/unreviewed/2024/08/GHSA-x74r-hr36-m64w/GHSA-x74r-hr36-m64w.json new file mode 100644 index 00000000000..3b948e51381 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x74r-hr36-m64w/GHSA-x74r-hr36-m64w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74r-hr36-m64w", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42603" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42603" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/10/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xch8-494w-5px5/GHSA-xch8-494w-5px5.json b/advisories/unreviewed/2024/08/GHSA-xch8-494w-5px5/GHSA-xch8-494w-5px5.json new file mode 100644 index 00000000000..302df935851 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xch8-494w-5px5/GHSA-xch8-494w-5px5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xch8-494w-5px5", + "modified": "2024-08-20T15:32:13Z", + "published": "2024-08-20T15:32:13Z", + "aliases": [ + "CVE-2024-42607" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42607" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/9/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json b/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json new file mode 100644 index 00000000000..5f4b66642d8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg93-f9hr-8vjh", + "modified": "2024-08-20T15:32:12Z", + "published": "2024-08-20T15:32:12Z", + "aliases": [ + "CVE-2024-42554" + ], + "details": "Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42554" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/7d2ebfe6dfa87eecf8f3e6d4eefc48ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T13:15:06Z" + } +} \ No newline at end of file