Auto-Update: 2024-09-22T04:00:16.705965+00:00

This commit is contained in:
cad-safe-bot 2024-09-22 04:03:16 +00:00
parent 0671431b55
commit c636f2776c
4 changed files with 395 additions and 259 deletions

View File

@ -0,0 +1,25 @@
{
"id": "CVE-2024-47226",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-09-22T02:15:02.797",
"lastModified": "2024-09-22T02:15:02.797",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the \"Configuration History\" feature of the \"Admin\" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the \"Top banner\" field."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/netbox-community/netbox/releases/tag/v4.1.0",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/tu3n4nh/netbox/issues/1",
"source": "cve@mitre.org"
}
]
}

View File

@ -0,0 +1,137 @@
{
"id": "CVE-2024-9077",
"sourceIdentifier": "cna@vuldb.com",
"published": "2024-09-22T02:15:03.650",
"lastModified": "2024-09-22T02:15:03.650",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component Order Checkout. The manipulation of the argument address-name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnerableSystemConfidentiality": "NONE",
"vulnerableSystemIntegrity": "LOW",
"vulnerableSystemAvailability": "NONE",
"subsequentSystemConfidentiality": "NONE",
"subsequentSystemIntegrity": "NONE",
"subsequentSystemAvailability": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirements": "NOT_DEFINED",
"integrityRequirements": "NOT_DEFINED",
"availabilityRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnerableSystemConfidentiality": "NOT_DEFINED",
"modifiedVulnerableSystemIntegrity": "NOT_DEFINED",
"modifiedVulnerableSystemAvailability": "NOT_DEFINED",
"modifiedSubsequentSystemConfidentiality": "NOT_DEFINED",
"modifiedSubsequentSystemIntegrity": "NOT_DEFINED",
"modifiedSubsequentSystemAvailability": "NOT_DEFINED",
"safety": "NOT_DEFINED",
"automatable": "NOT_DEFINED",
"recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 3.5,
"baseSeverity": "LOW"
},
"exploitabilityScore": 2.1,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/Xor-Gerke/webray.com.cn/blob/main/cve/dingfanzu-CMS/dingfanzu-CMS%20order_confirm.html%20Ship-Address%20Stored%20Cross-Site%20Scripting(XSS).md",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.278244",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.278244",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.407527",
"source": "cna@vuldb.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update ### Last Repository Update
```plain ```plain
2024-09-22T02:00:17.239476+00:00 2024-09-22T04:00:16.705965+00:00
``` ```
### Most recent CVE Modification Timestamp synchronized with NVD ### Most recent CVE Modification Timestamp synchronized with NVD
```plain ```plain
2024-09-22T01:15:12.070000+00:00 2024-09-22T02:15:03.650000+00:00
``` ```
### Last Data Feed Release ### Last Data Feed Release
@ -33,49 +33,21 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs ### Total Number of included CVEs
```plain ```plain
263532 263534
``` ```
### CVEs added in the last Commit ### CVEs added in the last Commit
Recently added CVEs: `5` Recently added CVEs: `2`
- [CVE-2024-47218](CVE-2024/CVE-2024-472xx/CVE-2024-47218.json) (`2024-09-22T01:15:11.583`) - [CVE-2024-47226](CVE-2024/CVE-2024-472xx/CVE-2024-47226.json) (`2024-09-22T02:15:02.797`)
- [CVE-2024-47219](CVE-2024/CVE-2024-472xx/CVE-2024-47219.json) (`2024-09-22T01:15:11.890`) - [CVE-2024-9077](CVE-2024/CVE-2024-90xx/CVE-2024-9077.json) (`2024-09-22T02:15:03.650`)
- [CVE-2024-47220](CVE-2024/CVE-2024-472xx/CVE-2024-47220.json) (`2024-09-22T01:15:11.950`)
- [CVE-2024-47221](CVE-2024/CVE-2024-472xx/CVE-2024-47221.json) (`2024-09-22T01:15:12.013`)
- [CVE-2024-9076](CVE-2024/CVE-2024-90xx/CVE-2024-9076.json) (`2024-09-22T01:15:12.070`)
### CVEs modified in the last Commit ### CVEs modified in the last Commit
Recently modified CVEs: `219` Recently modified CVEs: `0`
- [CVE-2024-8280](CVE-2024/CVE-2024-82xx/CVE-2024-8280.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8281](CVE-2024/CVE-2024-82xx/CVE-2024-8281.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8479](CVE-2024/CVE-2024-84xx/CVE-2024-8479.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8651](CVE-2024/CVE-2024-86xx/CVE-2024-8651.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-8652](CVE-2024/CVE-2024-86xx/CVE-2024-8652.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-8653](CVE-2024/CVE-2024-86xx/CVE-2024-8653.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-8669](CVE-2024/CVE-2024-86xx/CVE-2024-8669.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8714](CVE-2024/CVE-2024-87xx/CVE-2024-8714.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8724](CVE-2024/CVE-2024-87xx/CVE-2024-8724.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8730](CVE-2024/CVE-2024-87xx/CVE-2024-8730.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8731](CVE-2024/CVE-2024-87xx/CVE-2024-8731.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8732](CVE-2024/CVE-2024-87xx/CVE-2024-8732.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8734](CVE-2024/CVE-2024-87xx/CVE-2024-8734.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8737](CVE-2024/CVE-2024-87xx/CVE-2024-8737.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8747](CVE-2024/CVE-2024-87xx/CVE-2024-8747.json) (`2024-09-13T16:37:22.997`)
- [CVE-2024-8775](CVE-2024/CVE-2024-87xx/CVE-2024-8775.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8797](CVE-2024/CVE-2024-87xx/CVE-2024-8797.json) (`2024-09-14T11:47:14.677`)
- [CVE-2024-8944](CVE-2024/CVE-2024-89xx/CVE-2024-8944.json) (`2024-09-20T12:30:51.220`)
- [CVE-2024-9006](CVE-2024/CVE-2024-90xx/CVE-2024-9006.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-9007](CVE-2024/CVE-2024-90xx/CVE-2024-9007.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-9009](CVE-2024/CVE-2024-90xx/CVE-2024-9009.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-9011](CVE-2024/CVE-2024-90xx/CVE-2024-9011.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-9030](CVE-2024/CVE-2024-90xx/CVE-2024-9030.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-9031](CVE-2024/CVE-2024-90xx/CVE-2024-9031.json) (`2024-09-20T12:30:17.483`)
- [CVE-2024-9043](CVE-2024/CVE-2024-90xx/CVE-2024-9043.json) (`2024-09-20T12:30:17.483`)
## Download and Usage ## Download and Usage

File diff suppressed because it is too large Load Diff