From 01e1e875302a2108d55fd68eda4528bc00c349e2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 27 Jun 2023 18:31:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-83vp-6jqg-6cmr.json | 3 +- .../GHSA-4pm3-f52j-8ggh.json | 3 +- .../GHSA-5r96-55w4-xch3.json | 2 + .../GHSA-j85g-452w-9q39.json | 2 + .../GHSA-jpxp-6rp5-3wg3.json | 2 + .../GHSA-vchr-42h7-32xh.json | 2 + .../GHSA-9m8m-vxwc-cv74.json | 4 +- .../GHSA-9vf6-r8jp-w3m7.json | 1 + .../GHSA-cr8c-972v-rmp3.json | 1 + .../GHSA-fc43-xqx9-fhvj.json | 2 + .../GHSA-jpjh-85f7-386r.json | 3 +- .../GHSA-v694-r254-m866.json | 4 +- .../GHSA-4p4h-xvff-9p66.json | 4 +- .../GHSA-qm57-rv98-r7ch.json | 1 + .../GHSA-qqm3-6f5j-2j3h.json | 3 +- .../GHSA-vgf4-3x2c-798r.json | 1 + .../GHSA-5rwc-h8m7-5hcc.json | 13 ++++-- .../GHSA-gvc2-c45p-m2r9.json | 1 + .../GHSA-p6cm-wgmg-cc45.json | 2 + .../GHSA-q5pj-mjjc-c94j.json | 1 + .../GHSA-r487-g863-pm8x.json | 1 + .../GHSA-rm62-4x72-vwwp.json | 5 +- .../GHSA-v43h-w929-q37g.json | 1 + .../GHSA-467r-6mjf-fx3w.json | 1 + .../GHSA-c938-72w7-26mv.json | 1 + .../GHSA-fp8x-7f8g-pj5f.json | 1 + .../GHSA-g7rf-g4j7-7fc4.json | 1 + .../GHSA-mx8q-jqwm-85mv.json | 2 + .../GHSA-qvv9-757j-qvmm.json | 1 + .../GHSA-v9x9-r7q4-rfx4.json | 3 +- .../GHSA-2cxw-4p8f-4qp7.json | 2 + .../GHSA-j6v3-2c6w-pwpm.json | 2 + .../GHSA-v6c6-gcwr-p5pm.json | 2 + .../GHSA-vp6v-57g2-v7vw.json | 2 + .../GHSA-w7rj-j5f6-772g.json | 3 +- .../GHSA-xwjg-qxv6-28rv.json | 1 + .../GHSA-65pv-gqpg-397f.json | 1 + .../GHSA-6vv2-x5qj-vq7g.json | 1 + .../GHSA-73mw-p746-xhhj.json | 3 +- .../GHSA-8rff-xvx4-wwhh.json | 3 +- .../GHSA-g4pc-gj78-qfjj.json | 3 +- .../GHSA-h8qw-944w-6vhw.json | 1 + .../GHSA-q53h-7g74-r646.json | 3 +- .../GHSA-v6mw-975h-x9gw.json | 1 + .../GHSA-7xcr-6p4f-q66v.json | 1 + .../GHSA-84rx-9qxm-ffcf.json | 4 +- .../GHSA-c4x3-h9wg-9x78.json | 1 + .../GHSA-gppw-9x58-fhf2.json | 1 + .../GHSA-m732-653h-47jg.json | 1 + .../GHSA-vr82-c8xj-wgj5.json | 3 +- .../GHSA-wp87-5qfw-74x3.json | 1 + .../GHSA-2mjv-m892-jvr8.json | 1 + .../GHSA-3mj6-p6q9-4j76.json | 3 +- .../GHSA-596x-3pr6-hffr.json | 1 + .../GHSA-638f-v29c-5qwq.json | 1 + .../GHSA-75gv-hvw9-rj3c.json | 1 + .../GHSA-7hhw-c2c3-vp77.json | 1 + .../GHSA-chq4-r76r-rh84.json | 1 + .../GHSA-cxvj-jx5h-9xf2.json | 4 +- .../GHSA-f329-hqh6-8qmx.json | 4 +- .../GHSA-hp3q-rgpx-37wq.json | 1 + .../GHSA-mcrx-hfrq-xq94.json | 1 + .../GHSA-xg48-jq9v-2x5f.json | 1 + .../GHSA-hxpv-p77h-pvx2.json | 1 + .../GHSA-w552-xcp4-6hjg.json | 1 + .../GHSA-38w7-g7hm-hwph.json | 4 +- .../GHSA-3xrv-6gjw-8g8c.json | 4 +- .../GHSA-43mf-cpwf-chp9.json | 4 +- .../GHSA-569f-2ggr-6v5w.json | 4 +- .../GHSA-7574-8crw-5432.json | 4 +- .../GHSA-82mv-hvf2-x332.json | 4 +- .../GHSA-gfp2-4w95-v37r.json | 4 +- .../GHSA-hc96-pmx9-jcj6.json | 4 +- .../GHSA-hp26-q6wq-vrfp.json | 2 + .../GHSA-mw9r-vp4h-34mp.json | 2 + .../GHSA-jr6j-p82r-r8p6.json | 8 ++++ .../GHSA-rggp-g5p7-mr37.json | 4 ++ .../GHSA-vpjm-mmm2-rqq5.json | 4 ++ .../GHSA-2jpx-j4q3-c28w.json | 9 ++-- .../GHSA-38g3-58hf-r96c.json | 7 ++- .../GHSA-3p42-c2wq-v9gc.json | 35 ++++++++++++++ .../GHSA-46ch-j8p2-6ppx.json | 7 ++- .../GHSA-47xj-xr7q-9hhq.json | 9 ++-- .../GHSA-4v9h-2pcw-v2q7.json | 35 ++++++++++++++ .../GHSA-5mmx-hq97-58f6.json | 9 ++-- .../GHSA-69wh-x693-q8h3.json | 9 ++-- .../GHSA-6vf9-6gcr-cg7q.json | 7 ++- .../GHSA-75j9-5hgg-gprr.json | 9 ++-- .../GHSA-7wmp-qghr-8g7f.json | 9 ++-- .../GHSA-89hv-5x65-64rf.json | 9 ++-- .../GHSA-94qw-3pc5-wwcm.json | 9 ++-- .../GHSA-95vj-3rv6-35hp.json | 9 ++-- .../GHSA-9j35-h8v6-5943.json | 39 ++++++++++++++++ .../GHSA-9m8g-m8f5-r7v5.json | 9 ++-- .../GHSA-9pv7-q9jh-w7p4.json | 3 +- .../GHSA-ccg9-9wjx-8536.json | 9 ++-- .../GHSA-ccx9-5rv5-mwfr.json | 2 +- .../GHSA-cqw3-c4x8-fq47.json | 35 ++++++++++++++ .../GHSA-cxpq-h2qw-mwp5.json | 9 ++-- .../GHSA-f2fm-6xq7-v8j8.json | 9 ++-- .../GHSA-fxv2-pr8r-g2r2.json | 2 +- .../GHSA-gj5r-368c-rjh3.json | 42 +++++++++++++++++ .../GHSA-gm6j-4vjr-f7cw.json | 2 +- .../GHSA-gqpp-5p7w-52jm.json | 42 +++++++++++++++++ .../GHSA-h3xp-rv2j-px7g.json | 9 ++-- .../GHSA-h7cw-9qxp-4gmq.json | 9 ++-- .../GHSA-j2pm-wg92-65rc.json | 35 ++++++++++++++ .../GHSA-jhmp-h4x3-p89g.json | 9 ++-- .../GHSA-jr8c-7w56-v2rh.json | 9 ++-- .../GHSA-mmvv-xfgf-73jq.json | 35 ++++++++++++++ .../GHSA-ppp2-fxjc-67f9.json | 39 ++++++++++++++++ .../GHSA-qp5q-f4cm-wxh9.json | 4 ++ .../GHSA-rgwc-pg77-vhp2.json | 9 ++-- .../GHSA-rp64-mpmj-44xf.json | 9 ++-- .../GHSA-v37p-3q57-4gv2.json | 46 +++++++++++++++++++ .../GHSA-v3w3-hwx2-r59j.json | 35 ++++++++++++++ .../GHSA-vmp8-hjpw-vp73.json | 2 +- .../GHSA-vp9w-jfm8-64xg.json | 42 +++++++++++++++++ .../GHSA-vv5w-jx3q-w898.json | 39 ++++++++++++++++ .../GHSA-vwhx-3qh6-75xf.json | 9 ++-- .../GHSA-vx98-w6gr-g2gv.json | 4 ++ .../GHSA-w5vj-wrq4-qh78.json | 35 ++++++++++++++ .../GHSA-wqr4-vg37-3923.json | 9 ++-- .../GHSA-x3xh-4gpx-gj42.json | 42 +++++++++++++++++ .../GHSA-x8qg-5w28-wmr9.json | 9 ++-- 125 files changed, 892 insertions(+), 108 deletions(-) create mode 100644 advisories/unreviewed/2023/06/GHSA-3p42-c2wq-v9gc/GHSA-3p42-c2wq-v9gc.json create mode 100644 advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json create mode 100644 advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json create mode 100644 advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json create mode 100644 advisories/unreviewed/2023/06/GHSA-gj5r-368c-rjh3/GHSA-gj5r-368c-rjh3.json create mode 100644 advisories/unreviewed/2023/06/GHSA-gqpp-5p7w-52jm/GHSA-gqpp-5p7w-52jm.json create mode 100644 advisories/unreviewed/2023/06/GHSA-j2pm-wg92-65rc/GHSA-j2pm-wg92-65rc.json create mode 100644 advisories/unreviewed/2023/06/GHSA-mmvv-xfgf-73jq/GHSA-mmvv-xfgf-73jq.json create mode 100644 advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json create mode 100644 advisories/unreviewed/2023/06/GHSA-v37p-3q57-4gv2/GHSA-v37p-3q57-4gv2.json create mode 100644 advisories/unreviewed/2023/06/GHSA-v3w3-hwx2-r59j/GHSA-v3w3-hwx2-r59j.json create mode 100644 advisories/unreviewed/2023/06/GHSA-vp9w-jfm8-64xg/GHSA-vp9w-jfm8-64xg.json create mode 100644 advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json create mode 100644 advisories/unreviewed/2023/06/GHSA-w5vj-wrq4-qh78/GHSA-w5vj-wrq4-qh78.json create mode 100644 advisories/unreviewed/2023/06/GHSA-x3xh-4gpx-gj42/GHSA-x3xh-4gpx-gj42.json diff --git a/advisories/github-reviewed/2022/03/GHSA-83vp-6jqg-6cmr/GHSA-83vp-6jqg-6cmr.json b/advisories/github-reviewed/2022/03/GHSA-83vp-6jqg-6cmr/GHSA-83vp-6jqg-6cmr.json index f176063935f..5bdb67e1052 100644 --- a/advisories/github-reviewed/2022/03/GHSA-83vp-6jqg-6cmr/GHSA-83vp-6jqg-6cmr.json +++ b/advisories/github-reviewed/2022/03/GHSA-83vp-6jqg-6cmr/GHSA-83vp-6jqg-6cmr.json @@ -62,7 +62,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2022/04/GHSA-4pm3-f52j-8ggh/GHSA-4pm3-f52j-8ggh.json b/advisories/github-reviewed/2022/04/GHSA-4pm3-f52j-8ggh/GHSA-4pm3-f52j-8ggh.json index 58067767ab1..a9393f16354 100644 --- a/advisories/github-reviewed/2022/04/GHSA-4pm3-f52j-8ggh/GHSA-4pm3-f52j-8ggh.json +++ b/advisories/github-reviewed/2022/04/GHSA-4pm3-f52j-8ggh/GHSA-4pm3-f52j-8ggh.json @@ -74,7 +74,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-917" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/unreviewed/2022/02/GHSA-5r96-55w4-xch3/GHSA-5r96-55w4-xch3.json b/advisories/unreviewed/2022/02/GHSA-5r96-55w4-xch3/GHSA-5r96-55w4-xch3.json index c5cbc4a4f23..a41c09a376d 100644 --- a/advisories/unreviewed/2022/02/GHSA-5r96-55w4-xch3/GHSA-5r96-55w4-xch3.json +++ b/advisories/unreviewed/2022/02/GHSA-5r96-55w4-xch3/GHSA-5r96-55w4-xch3.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", + "CWE-78", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/02/GHSA-j85g-452w-9q39/GHSA-j85g-452w-9q39.json b/advisories/unreviewed/2022/02/GHSA-j85g-452w-9q39/GHSA-j85g-452w-9q39.json index 85ced0efe72..649313944dc 100644 --- a/advisories/unreviewed/2022/02/GHSA-j85g-452w-9q39/GHSA-j85g-452w-9q39.json +++ b/advisories/unreviewed/2022/02/GHSA-j85g-452w-9q39/GHSA-j85g-452w-9q39.json @@ -40,6 +40,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", + "CWE-639", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-jpxp-6rp5-3wg3/GHSA-jpxp-6rp5-3wg3.json b/advisories/unreviewed/2022/02/GHSA-jpxp-6rp5-3wg3/GHSA-jpxp-6rp5-3wg3.json index 26a5258a636..2bea8b2e0a3 100644 --- a/advisories/unreviewed/2022/02/GHSA-jpxp-6rp5-3wg3/GHSA-jpxp-6rp5-3wg3.json +++ b/advisories/unreviewed/2022/02/GHSA-jpxp-6rp5-3wg3/GHSA-jpxp-6rp5-3wg3.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", + "CWE-295", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-vchr-42h7-32xh/GHSA-vchr-42h7-32xh.json b/advisories/unreviewed/2022/02/GHSA-vchr-42h7-32xh/GHSA-vchr-42h7-32xh.json index 275411ad708..5aac63d4871 100644 --- a/advisories/unreviewed/2022/02/GHSA-vchr-42h7-32xh/GHSA-vchr-42h7-32xh.json +++ b/advisories/unreviewed/2022/02/GHSA-vchr-42h7-32xh/GHSA-vchr-42h7-32xh.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", + "CWE-1284", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/03/GHSA-9m8m-vxwc-cv74/GHSA-9m8m-vxwc-cv74.json b/advisories/unreviewed/2022/03/GHSA-9m8m-vxwc-cv74/GHSA-9m8m-vxwc-cv74.json index 60bb9194485..be1347da1a5 100644 --- a/advisories/unreviewed/2022/03/GHSA-9m8m-vxwc-cv74/GHSA-9m8m-vxwc-cv74.json +++ b/advisories/unreviewed/2022/03/GHSA-9m8m-vxwc-cv74/GHSA-9m8m-vxwc-cv74.json @@ -32,7 +32,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-284", + "CWE-287", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/03/GHSA-9vf6-r8jp-w3m7/GHSA-9vf6-r8jp-w3m7.json b/advisories/unreviewed/2022/03/GHSA-9vf6-r8jp-w3m7/GHSA-9vf6-r8jp-w3m7.json index 5e3ba8f90a0..0b3daf4e77f 100644 --- a/advisories/unreviewed/2022/03/GHSA-9vf6-r8jp-w3m7/GHSA-9vf6-r8jp-w3m7.json +++ b/advisories/unreviewed/2022/03/GHSA-9vf6-r8jp-w3m7/GHSA-9vf6-r8jp-w3m7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/03/GHSA-cr8c-972v-rmp3/GHSA-cr8c-972v-rmp3.json b/advisories/unreviewed/2022/03/GHSA-cr8c-972v-rmp3/GHSA-cr8c-972v-rmp3.json index a224a5717ed..4478a413f09 100644 --- a/advisories/unreviewed/2022/03/GHSA-cr8c-972v-rmp3/GHSA-cr8c-972v-rmp3.json +++ b/advisories/unreviewed/2022/03/GHSA-cr8c-972v-rmp3/GHSA-cr8c-972v-rmp3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-434" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/03/GHSA-fc43-xqx9-fhvj/GHSA-fc43-xqx9-fhvj.json b/advisories/unreviewed/2022/03/GHSA-fc43-xqx9-fhvj/GHSA-fc43-xqx9-fhvj.json index 36a5c9661fc..be72b0a9495 100644 --- a/advisories/unreviewed/2022/03/GHSA-fc43-xqx9-fhvj/GHSA-fc43-xqx9-fhvj.json +++ b/advisories/unreviewed/2022/03/GHSA-fc43-xqx9-fhvj/GHSA-fc43-xqx9-fhvj.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", + "CWE-862", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/03/GHSA-jpjh-85f7-386r/GHSA-jpjh-85f7-386r.json b/advisories/unreviewed/2022/03/GHSA-jpjh-85f7-386r/GHSA-jpjh-85f7-386r.json index e1275ec21af..6fb12f97766 100644 --- a/advisories/unreviewed/2022/03/GHSA-jpjh-85f7-386r/GHSA-jpjh-85f7-386r.json +++ b/advisories/unreviewed/2022/03/GHSA-jpjh-85f7-386r/GHSA-jpjh-85f7-386r.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-425" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/03/GHSA-v694-r254-m866/GHSA-v694-r254-m866.json b/advisories/unreviewed/2022/03/GHSA-v694-r254-m866/GHSA-v694-r254-m866.json index f7d6b36a538..091d68816b4 100644 --- a/advisories/unreviewed/2022/03/GHSA-v694-r254-m866/GHSA-v694-r254-m866.json +++ b/advisories/unreviewed/2022/03/GHSA-v694-r254-m866/GHSA-v694-r254-m866.json @@ -32,7 +32,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-122", + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-4p4h-xvff-9p66/GHSA-4p4h-xvff-9p66.json b/advisories/unreviewed/2022/04/GHSA-4p4h-xvff-9p66/GHSA-4p4h-xvff-9p66.json index 5fae0870ff9..16b29a09577 100644 --- a/advisories/unreviewed/2022/04/GHSA-4p4h-xvff-9p66/GHSA-4p4h-xvff-9p66.json +++ b/advisories/unreviewed/2022/04/GHSA-4p4h-xvff-9p66/GHSA-4p4h-xvff-9p66.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-124", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-qm57-rv98-r7ch/GHSA-qm57-rv98-r7ch.json b/advisories/unreviewed/2022/04/GHSA-qm57-rv98-r7ch/GHSA-qm57-rv98-r7ch.json index f9cf086c1ac..14d72245e64 100644 --- a/advisories/unreviewed/2022/04/GHSA-qm57-rv98-r7ch/GHSA-qm57-rv98-r7ch.json +++ b/advisories/unreviewed/2022/04/GHSA-qm57-rv98-r7ch/GHSA-qm57-rv98-r7ch.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-805" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/04/GHSA-qqm3-6f5j-2j3h/GHSA-qqm3-6f5j-2j3h.json b/advisories/unreviewed/2022/04/GHSA-qqm3-6f5j-2j3h/GHSA-qqm3-6f5j-2j3h.json index 063c484df7f..9aedcf8a7b8 100644 --- a/advisories/unreviewed/2022/04/GHSA-qqm3-6f5j-2j3h/GHSA-qqm3-6f5j-2j3h.json +++ b/advisories/unreviewed/2022/04/GHSA-qqm3-6f5j-2j3h/GHSA-qqm3-6f5j-2j3h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-vgf4-3x2c-798r/GHSA-vgf4-3x2c-798r.json b/advisories/unreviewed/2022/04/GHSA-vgf4-3x2c-798r/GHSA-vgf4-3x2c-798r.json index 6cbc13a65df..ec746f04314 100644 --- a/advisories/unreviewed/2022/04/GHSA-vgf4-3x2c-798r/GHSA-vgf4-3x2c-798r.json +++ b/advisories/unreviewed/2022/04/GHSA-vgf4-3x2c-798r/GHSA-vgf4-3x2c-798r.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-5rwc-h8m7-5hcc/GHSA-5rwc-h8m7-5hcc.json b/advisories/unreviewed/2022/05/GHSA-5rwc-h8m7-5hcc/GHSA-5rwc-h8m7-5hcc.json index 905015f1a27..b2368497e4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-5rwc-h8m7-5hcc/GHSA-5rwc-h8m7-5hcc.json +++ b/advisories/unreviewed/2022/05/GHSA-5rwc-h8m7-5hcc/GHSA-5rwc-h8m7-5hcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rwc-h8m7-5hcc", - "modified": "2022-05-24T17:13:35Z", + "modified": "2023-06-27T18:30:22Z", "published": "2022-05-24T17:13:35Z", "aliases": [ "CVE-2020-11560" ], "details": "NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,15 @@ { "type": "WEB", "url": "https://www.youtube.com/watch?v=V0BWq33qVCs&feature=youtu.be" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173117/NCH-Express-Invoice-7.25-Cleartext-Password.html" } ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-gvc2-c45p-m2r9/GHSA-gvc2-c45p-m2r9.json b/advisories/unreviewed/2022/05/GHSA-gvc2-c45p-m2r9/GHSA-gvc2-c45p-m2r9.json index 152cdf60bc4..771be956658 100644 --- a/advisories/unreviewed/2022/05/GHSA-gvc2-c45p-m2r9/GHSA-gvc2-c45p-m2r9.json +++ b/advisories/unreviewed/2022/05/GHSA-gvc2-c45p-m2r9/GHSA-gvc2-c45p-m2r9.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-p6cm-wgmg-cc45/GHSA-p6cm-wgmg-cc45.json b/advisories/unreviewed/2022/05/GHSA-p6cm-wgmg-cc45/GHSA-p6cm-wgmg-cc45.json index 17ca7bc7dbd..c46fc5560a3 100644 --- a/advisories/unreviewed/2022/05/GHSA-p6cm-wgmg-cc45/GHSA-p6cm-wgmg-cc45.json +++ b/advisories/unreviewed/2022/05/GHSA-p6cm-wgmg-cc45/GHSA-p6cm-wgmg-cc45.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", + "CWE-125", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-q5pj-mjjc-c94j/GHSA-q5pj-mjjc-c94j.json b/advisories/unreviewed/2022/05/GHSA-q5pj-mjjc-c94j/GHSA-q5pj-mjjc-c94j.json index 2503c35597a..b3f748aaba2 100644 --- a/advisories/unreviewed/2022/05/GHSA-q5pj-mjjc-c94j/GHSA-q5pj-mjjc-c94j.json +++ b/advisories/unreviewed/2022/05/GHSA-q5pj-mjjc-c94j/GHSA-q5pj-mjjc-c94j.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-r487-g863-pm8x/GHSA-r487-g863-pm8x.json b/advisories/unreviewed/2022/05/GHSA-r487-g863-pm8x/GHSA-r487-g863-pm8x.json index ac1acba6e3a..a69198fb2d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-r487-g863-pm8x/GHSA-r487-g863-pm8x.json +++ b/advisories/unreviewed/2022/05/GHSA-r487-g863-pm8x/GHSA-r487-g863-pm8x.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-rm62-4x72-vwwp/GHSA-rm62-4x72-vwwp.json b/advisories/unreviewed/2022/05/GHSA-rm62-4x72-vwwp/GHSA-rm62-4x72-vwwp.json index a12bd977bad..ffc7eea376f 100644 --- a/advisories/unreviewed/2022/05/GHSA-rm62-4x72-vwwp/GHSA-rm62-4x72-vwwp.json +++ b/advisories/unreviewed/2022/05/GHSA-rm62-4x72-vwwp/GHSA-rm62-4x72-vwwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rm62-4x72-vwwp", - "modified": "2022-07-05T00:00:54Z", + "modified": "2023-06-27T18:30:24Z", "published": "2022-05-06T00:00:48Z", "aliases": [ "CVE-2022-1516" @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-v43h-w929-q37g/GHSA-v43h-w929-q37g.json b/advisories/unreviewed/2022/05/GHSA-v43h-w929-q37g/GHSA-v43h-w929-q37g.json index 74313dadd9a..66efa9c6074 100644 --- a/advisories/unreviewed/2022/05/GHSA-v43h-w929-q37g/GHSA-v43h-w929-q37g.json +++ b/advisories/unreviewed/2022/05/GHSA-v43h-w929-q37g/GHSA-v43h-w929-q37g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-467r-6mjf-fx3w/GHSA-467r-6mjf-fx3w.json b/advisories/unreviewed/2022/06/GHSA-467r-6mjf-fx3w/GHSA-467r-6mjf-fx3w.json index be985c5f8cf..91ef81e3627 100644 --- a/advisories/unreviewed/2022/06/GHSA-467r-6mjf-fx3w/GHSA-467r-6mjf-fx3w.json +++ b/advisories/unreviewed/2022/06/GHSA-467r-6mjf-fx3w/GHSA-467r-6mjf-fx3w.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-c938-72w7-26mv/GHSA-c938-72w7-26mv.json b/advisories/unreviewed/2022/06/GHSA-c938-72w7-26mv/GHSA-c938-72w7-26mv.json index be0becafa24..6c839d39043 100644 --- a/advisories/unreviewed/2022/06/GHSA-c938-72w7-26mv/GHSA-c938-72w7-26mv.json +++ b/advisories/unreviewed/2022/06/GHSA-c938-72w7-26mv/GHSA-c938-72w7-26mv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-fp8x-7f8g-pj5f/GHSA-fp8x-7f8g-pj5f.json b/advisories/unreviewed/2022/06/GHSA-fp8x-7f8g-pj5f/GHSA-fp8x-7f8g-pj5f.json index 07a9960c235..72e7f83e2d1 100644 --- a/advisories/unreviewed/2022/06/GHSA-fp8x-7f8g-pj5f/GHSA-fp8x-7f8g-pj5f.json +++ b/advisories/unreviewed/2022/06/GHSA-fp8x-7f8g-pj5f/GHSA-fp8x-7f8g-pj5f.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/06/GHSA-g7rf-g4j7-7fc4/GHSA-g7rf-g4j7-7fc4.json b/advisories/unreviewed/2022/06/GHSA-g7rf-g4j7-7fc4/GHSA-g7rf-g4j7-7fc4.json index 6ece430e19d..4890a6ad02b 100644 --- a/advisories/unreviewed/2022/06/GHSA-g7rf-g4j7-7fc4/GHSA-g7rf-g4j7-7fc4.json +++ b/advisories/unreviewed/2022/06/GHSA-g7rf-g4j7-7fc4/GHSA-g7rf-g4j7-7fc4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-mx8q-jqwm-85mv/GHSA-mx8q-jqwm-85mv.json b/advisories/unreviewed/2022/06/GHSA-mx8q-jqwm-85mv/GHSA-mx8q-jqwm-85mv.json index 21d92938cb1..913838c05ce 100644 --- a/advisories/unreviewed/2022/06/GHSA-mx8q-jqwm-85mv/GHSA-mx8q-jqwm-85mv.json +++ b/advisories/unreviewed/2022/06/GHSA-mx8q-jqwm-85mv/GHSA-mx8q-jqwm-85mv.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", + "CWE-209", "CWE-918" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-qvv9-757j-qvmm/GHSA-qvv9-757j-qvmm.json b/advisories/unreviewed/2022/06/GHSA-qvv9-757j-qvmm/GHSA-qvv9-757j-qvmm.json index 9ccdcdc387d..243e9b9b0dc 100644 --- a/advisories/unreviewed/2022/06/GHSA-qvv9-757j-qvmm/GHSA-qvv9-757j-qvmm.json +++ b/advisories/unreviewed/2022/06/GHSA-qvv9-757j-qvmm/GHSA-qvv9-757j-qvmm.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-434" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/06/GHSA-v9x9-r7q4-rfx4/GHSA-v9x9-r7q4-rfx4.json b/advisories/unreviewed/2022/06/GHSA-v9x9-r7q4-rfx4/GHSA-v9x9-r7q4-rfx4.json index 43942169ad2..0be660aadb6 100644 --- a/advisories/unreviewed/2022/06/GHSA-v9x9-r7q4-rfx4/GHSA-v9x9-r7q4-rfx4.json +++ b/advisories/unreviewed/2022/06/GHSA-v9x9-r7q4-rfx4/GHSA-v9x9-r7q4-rfx4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json b/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json index a7f50072238..4432cc0881c 100644 --- a/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json +++ b/advisories/unreviewed/2022/07/GHSA-2cxw-4p8f-4qp7/GHSA-2cxw-4p8f-4qp7.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json b/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json index d39100008c5..21dfb409323 100644 --- a/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json +++ b/advisories/unreviewed/2022/07/GHSA-j6v3-2c6w-pwpm/GHSA-j6v3-2c6w-pwpm.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json b/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json index 2a865e5190f..525e16e8a80 100644 --- a/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json +++ b/advisories/unreviewed/2022/07/GHSA-v6c6-gcwr-p5pm/GHSA-v6c6-gcwr-p5pm.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json b/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json index 8330208d34c..b1d4ae9ff96 100644 --- a/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json +++ b/advisories/unreviewed/2022/07/GHSA-vp6v-57g2-v7vw/GHSA-vp6v-57g2-v7vw.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/07/GHSA-w7rj-j5f6-772g/GHSA-w7rj-j5f6-772g.json b/advisories/unreviewed/2022/07/GHSA-w7rj-j5f6-772g/GHSA-w7rj-j5f6-772g.json index b63fdf6e6f3..96a4c07e884 100644 --- a/advisories/unreviewed/2022/07/GHSA-w7rj-j5f6-772g/GHSA-w7rj-j5f6-772g.json +++ b/advisories/unreviewed/2022/07/GHSA-w7rj-j5f6-772g/GHSA-w7rj-j5f6-772g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json b/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json index 96ed0b358cd..c7b011b1144 100644 --- a/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json +++ b/advisories/unreviewed/2022/07/GHSA-xwjg-qxv6-28rv/GHSA-xwjg-qxv6-28rv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-78" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/08/GHSA-65pv-gqpg-397f/GHSA-65pv-gqpg-397f.json b/advisories/unreviewed/2022/08/GHSA-65pv-gqpg-397f/GHSA-65pv-gqpg-397f.json index fdb68f4b928..6b8d7f8d9bf 100644 --- a/advisories/unreviewed/2022/08/GHSA-65pv-gqpg-397f/GHSA-65pv-gqpg-397f.json +++ b/advisories/unreviewed/2022/08/GHSA-65pv-gqpg-397f/GHSA-65pv-gqpg-397f.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-863", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-6vv2-x5qj-vq7g/GHSA-6vv2-x5qj-vq7g.json b/advisories/unreviewed/2022/08/GHSA-6vv2-x5qj-vq7g/GHSA-6vv2-x5qj-vq7g.json index 3cfc944e4ff..10d9b595828 100644 --- a/advisories/unreviewed/2022/08/GHSA-6vv2-x5qj-vq7g/GHSA-6vv2-x5qj-vq7g.json +++ b/advisories/unreviewed/2022/08/GHSA-6vv2-x5qj-vq7g/GHSA-6vv2-x5qj-vq7g.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-352" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/08/GHSA-73mw-p746-xhhj/GHSA-73mw-p746-xhhj.json b/advisories/unreviewed/2022/08/GHSA-73mw-p746-xhhj/GHSA-73mw-p746-xhhj.json index a9ca1d6391f..d06c6a679c7 100644 --- a/advisories/unreviewed/2022/08/GHSA-73mw-p746-xhhj/GHSA-73mw-p746-xhhj.json +++ b/advisories/unreviewed/2022/08/GHSA-73mw-p746-xhhj/GHSA-73mw-p746-xhhj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-284" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-8rff-xvx4-wwhh/GHSA-8rff-xvx4-wwhh.json b/advisories/unreviewed/2022/08/GHSA-8rff-xvx4-wwhh/GHSA-8rff-xvx4-wwhh.json index 9a867301502..edc068a2493 100644 --- a/advisories/unreviewed/2022/08/GHSA-8rff-xvx4-wwhh/GHSA-8rff-xvx4-wwhh.json +++ b/advisories/unreviewed/2022/08/GHSA-8rff-xvx4-wwhh/GHSA-8rff-xvx4-wwhh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8rff-xvx4-wwhh", - "modified": "2022-08-20T00:00:58Z", + "modified": "2023-06-27T18:30:26Z", "published": "2022-08-18T00:00:16Z", "aliases": [ "CVE-2022-1373" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-g4pc-gj78-qfjj/GHSA-g4pc-gj78-qfjj.json b/advisories/unreviewed/2022/08/GHSA-g4pc-gj78-qfjj/GHSA-g4pc-gj78-qfjj.json index 222b16c654e..75d543f9be2 100644 --- a/advisories/unreviewed/2022/08/GHSA-g4pc-gj78-qfjj/GHSA-g4pc-gj78-qfjj.json +++ b/advisories/unreviewed/2022/08/GHSA-g4pc-gj78-qfjj/GHSA-g4pc-gj78-qfjj.json @@ -34,7 +34,8 @@ "cwe_ids": [ "CWE-200", "CWE-287", - "CWE-306" + "CWE-306", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-h8qw-944w-6vhw/GHSA-h8qw-944w-6vhw.json b/advisories/unreviewed/2022/08/GHSA-h8qw-944w-6vhw/GHSA-h8qw-944w-6vhw.json index 1815fbcb87e..3b2af808005 100644 --- a/advisories/unreviewed/2022/08/GHSA-h8qw-944w-6vhw/GHSA-h8qw-944w-6vhw.json +++ b/advisories/unreviewed/2022/08/GHSA-h8qw-944w-6vhw/GHSA-h8qw-944w-6vhw.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/08/GHSA-q53h-7g74-r646/GHSA-q53h-7g74-r646.json b/advisories/unreviewed/2022/08/GHSA-q53h-7g74-r646/GHSA-q53h-7g74-r646.json index 3576dd64890..c94b5a2eea0 100644 --- a/advisories/unreviewed/2022/08/GHSA-q53h-7g74-r646/GHSA-q53h-7g74-r646.json +++ b/advisories/unreviewed/2022/08/GHSA-q53h-7g74-r646/GHSA-q53h-7g74-r646.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-v6mw-975h-x9gw/GHSA-v6mw-975h-x9gw.json b/advisories/unreviewed/2022/08/GHSA-v6mw-975h-x9gw/GHSA-v6mw-975h-x9gw.json index 1db672eaf07..6ce8d18eb90 100644 --- a/advisories/unreviewed/2022/08/GHSA-v6mw-975h-x9gw/GHSA-v6mw-975h-x9gw.json +++ b/advisories/unreviewed/2022/08/GHSA-v6mw-975h-x9gw/GHSA-v6mw-975h-x9gw.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-7xcr-6p4f-q66v/GHSA-7xcr-6p4f-q66v.json b/advisories/unreviewed/2022/09/GHSA-7xcr-6p4f-q66v/GHSA-7xcr-6p4f-q66v.json index 19ede1da608..fdc9574e096 100644 --- a/advisories/unreviewed/2022/09/GHSA-7xcr-6p4f-q66v/GHSA-7xcr-6p4f-q66v.json +++ b/advisories/unreviewed/2022/09/GHSA-7xcr-6p4f-q66v/GHSA-7xcr-6p4f-q66v.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/09/GHSA-84rx-9qxm-ffcf/GHSA-84rx-9qxm-ffcf.json b/advisories/unreviewed/2022/09/GHSA-84rx-9qxm-ffcf/GHSA-84rx-9qxm-ffcf.json index 2092f7f4f73..55820d9bf0e 100644 --- a/advisories/unreviewed/2022/09/GHSA-84rx-9qxm-ffcf/GHSA-84rx-9qxm-ffcf.json +++ b/advisories/unreviewed/2022/09/GHSA-84rx-9qxm-ffcf/GHSA-84rx-9qxm-ffcf.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-119", + "CWE-120", + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-c4x3-h9wg-9x78/GHSA-c4x3-h9wg-9x78.json b/advisories/unreviewed/2022/09/GHSA-c4x3-h9wg-9x78/GHSA-c4x3-h9wg-9x78.json index a94cc49bfce..131625f3b6a 100644 --- a/advisories/unreviewed/2022/09/GHSA-c4x3-h9wg-9x78/GHSA-c4x3-h9wg-9x78.json +++ b/advisories/unreviewed/2022/09/GHSA-c4x3-h9wg-9x78/GHSA-c4x3-h9wg-9x78.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-gppw-9x58-fhf2/GHSA-gppw-9x58-fhf2.json b/advisories/unreviewed/2022/09/GHSA-gppw-9x58-fhf2/GHSA-gppw-9x58-fhf2.json index 1238cde57ad..ee42b5ce371 100644 --- a/advisories/unreviewed/2022/09/GHSA-gppw-9x58-fhf2/GHSA-gppw-9x58-fhf2.json +++ b/advisories/unreviewed/2022/09/GHSA-gppw-9x58-fhf2/GHSA-gppw-9x58-fhf2.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/09/GHSA-m732-653h-47jg/GHSA-m732-653h-47jg.json b/advisories/unreviewed/2022/09/GHSA-m732-653h-47jg/GHSA-m732-653h-47jg.json index 5be85cd555c..38a1f28d604 100644 --- a/advisories/unreviewed/2022/09/GHSA-m732-653h-47jg/GHSA-m732-653h-47jg.json +++ b/advisories/unreviewed/2022/09/GHSA-m732-653h-47jg/GHSA-m732-653h-47jg.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-367", "CWE-416" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-vr82-c8xj-wgj5/GHSA-vr82-c8xj-wgj5.json b/advisories/unreviewed/2022/09/GHSA-vr82-c8xj-wgj5/GHSA-vr82-c8xj-wgj5.json index de8a731fab1..be2f05bf219 100644 --- a/advisories/unreviewed/2022/09/GHSA-vr82-c8xj-wgj5/GHSA-vr82-c8xj-wgj5.json +++ b/advisories/unreviewed/2022/09/GHSA-vr82-c8xj-wgj5/GHSA-vr82-c8xj-wgj5.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-wp87-5qfw-74x3/GHSA-wp87-5qfw-74x3.json b/advisories/unreviewed/2022/09/GHSA-wp87-5qfw-74x3/GHSA-wp87-5qfw-74x3.json index 65ca59e7a23..714848850cf 100644 --- a/advisories/unreviewed/2022/09/GHSA-wp87-5qfw-74x3/GHSA-wp87-5qfw-74x3.json +++ b/advisories/unreviewed/2022/09/GHSA-wp87-5qfw-74x3/GHSA-wp87-5qfw-74x3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/10/GHSA-2mjv-m892-jvr8/GHSA-2mjv-m892-jvr8.json b/advisories/unreviewed/2022/10/GHSA-2mjv-m892-jvr8/GHSA-2mjv-m892-jvr8.json index f16f454e4f4..a527796a097 100644 --- a/advisories/unreviewed/2022/10/GHSA-2mjv-m892-jvr8/GHSA-2mjv-m892-jvr8.json +++ b/advisories/unreviewed/2022/10/GHSA-2mjv-m892-jvr8/GHSA-2mjv-m892-jvr8.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-3mj6-p6q9-4j76/GHSA-3mj6-p6q9-4j76.json b/advisories/unreviewed/2022/10/GHSA-3mj6-p6q9-4j76/GHSA-3mj6-p6q9-4j76.json index 0dcfd9b5348..f74213bc408 100644 --- a/advisories/unreviewed/2022/10/GHSA-3mj6-p6q9-4j76/GHSA-3mj6-p6q9-4j76.json +++ b/advisories/unreviewed/2022/10/GHSA-3mj6-p6q9-4j76/GHSA-3mj6-p6q9-4j76.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-284" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-596x-3pr6-hffr/GHSA-596x-3pr6-hffr.json b/advisories/unreviewed/2022/10/GHSA-596x-3pr6-hffr/GHSA-596x-3pr6-hffr.json index 1c01f84e942..9e67806d14a 100644 --- a/advisories/unreviewed/2022/10/GHSA-596x-3pr6-hffr/GHSA-596x-3pr6-hffr.json +++ b/advisories/unreviewed/2022/10/GHSA-596x-3pr6-hffr/GHSA-596x-3pr6-hffr.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/10/GHSA-638f-v29c-5qwq/GHSA-638f-v29c-5qwq.json b/advisories/unreviewed/2022/10/GHSA-638f-v29c-5qwq/GHSA-638f-v29c-5qwq.json index ae593ac98a7..b9cc525d2dd 100644 --- a/advisories/unreviewed/2022/10/GHSA-638f-v29c-5qwq/GHSA-638f-v29c-5qwq.json +++ b/advisories/unreviewed/2022/10/GHSA-638f-v29c-5qwq/GHSA-638f-v29c-5qwq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-75gv-hvw9-rj3c/GHSA-75gv-hvw9-rj3c.json b/advisories/unreviewed/2022/10/GHSA-75gv-hvw9-rj3c/GHSA-75gv-hvw9-rj3c.json index f5fbe5758aa..6600e66a4d1 100644 --- a/advisories/unreviewed/2022/10/GHSA-75gv-hvw9-rj3c/GHSA-75gv-hvw9-rj3c.json +++ b/advisories/unreviewed/2022/10/GHSA-75gv-hvw9-rj3c/GHSA-75gv-hvw9-rj3c.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-7hhw-c2c3-vp77/GHSA-7hhw-c2c3-vp77.json b/advisories/unreviewed/2022/10/GHSA-7hhw-c2c3-vp77/GHSA-7hhw-c2c3-vp77.json index a994465fa3c..a62770a4ccc 100644 --- a/advisories/unreviewed/2022/10/GHSA-7hhw-c2c3-vp77/GHSA-7hhw-c2c3-vp77.json +++ b/advisories/unreviewed/2022/10/GHSA-7hhw-c2c3-vp77/GHSA-7hhw-c2c3-vp77.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-chq4-r76r-rh84/GHSA-chq4-r76r-rh84.json b/advisories/unreviewed/2022/10/GHSA-chq4-r76r-rh84/GHSA-chq4-r76r-rh84.json index f78dcd34c57..a7780620142 100644 --- a/advisories/unreviewed/2022/10/GHSA-chq4-r76r-rh84/GHSA-chq4-r76r-rh84.json +++ b/advisories/unreviewed/2022/10/GHSA-chq4-r76r-rh84/GHSA-chq4-r76r-rh84.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-cxvj-jx5h-9xf2/GHSA-cxvj-jx5h-9xf2.json b/advisories/unreviewed/2022/10/GHSA-cxvj-jx5h-9xf2/GHSA-cxvj-jx5h-9xf2.json index c4926b716b8..38fb2bc3339 100644 --- a/advisories/unreviewed/2022/10/GHSA-cxvj-jx5h-9xf2/GHSA-cxvj-jx5h-9xf2.json +++ b/advisories/unreviewed/2022/10/GHSA-cxvj-jx5h-9xf2/GHSA-cxvj-jx5h-9xf2.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-476" + "CWE-252", + "CWE-476", + "CWE-690" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-f329-hqh6-8qmx/GHSA-f329-hqh6-8qmx.json b/advisories/unreviewed/2022/10/GHSA-f329-hqh6-8qmx/GHSA-f329-hqh6-8qmx.json index 990c7492bfe..11847630896 100644 --- a/advisories/unreviewed/2022/10/GHSA-f329-hqh6-8qmx/GHSA-f329-hqh6-8qmx.json +++ b/advisories/unreviewed/2022/10/GHSA-f329-hqh6-8qmx/GHSA-f329-hqh6-8qmx.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-476" + "CWE-252", + "CWE-476", + "CWE-690" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-hp3q-rgpx-37wq/GHSA-hp3q-rgpx-37wq.json b/advisories/unreviewed/2022/10/GHSA-hp3q-rgpx-37wq/GHSA-hp3q-rgpx-37wq.json index c6c76a7ddc6..5f6749ebd33 100644 --- a/advisories/unreviewed/2022/10/GHSA-hp3q-rgpx-37wq/GHSA-hp3q-rgpx-37wq.json +++ b/advisories/unreviewed/2022/10/GHSA-hp3q-rgpx-37wq/GHSA-hp3q-rgpx-37wq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-mcrx-hfrq-xq94/GHSA-mcrx-hfrq-xq94.json b/advisories/unreviewed/2022/10/GHSA-mcrx-hfrq-xq94/GHSA-mcrx-hfrq-xq94.json index 0e5b5c6a693..de91020418c 100644 --- a/advisories/unreviewed/2022/10/GHSA-mcrx-hfrq-xq94/GHSA-mcrx-hfrq-xq94.json +++ b/advisories/unreviewed/2022/10/GHSA-mcrx-hfrq-xq94/GHSA-mcrx-hfrq-xq94.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-xg48-jq9v-2x5f/GHSA-xg48-jq9v-2x5f.json b/advisories/unreviewed/2022/10/GHSA-xg48-jq9v-2x5f/GHSA-xg48-jq9v-2x5f.json index 01a16a63426..c585f9127cc 100644 --- a/advisories/unreviewed/2022/10/GHSA-xg48-jq9v-2x5f/GHSA-xg48-jq9v-2x5f.json +++ b/advisories/unreviewed/2022/10/GHSA-xg48-jq9v-2x5f/GHSA-xg48-jq9v-2x5f.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/11/GHSA-hxpv-p77h-pvx2/GHSA-hxpv-p77h-pvx2.json b/advisories/unreviewed/2022/11/GHSA-hxpv-p77h-pvx2/GHSA-hxpv-p77h-pvx2.json index b9c05ee5429..041abb6b2cd 100644 --- a/advisories/unreviewed/2022/11/GHSA-hxpv-p77h-pvx2/GHSA-hxpv-p77h-pvx2.json +++ b/advisories/unreviewed/2022/11/GHSA-hxpv-p77h-pvx2/GHSA-hxpv-p77h-pvx2.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-862" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/12/GHSA-w552-xcp4-6hjg/GHSA-w552-xcp4-6hjg.json b/advisories/unreviewed/2022/12/GHSA-w552-xcp4-6hjg/GHSA-w552-xcp4-6hjg.json index 0f94617821c..a57e354cf7f 100644 --- a/advisories/unreviewed/2022/12/GHSA-w552-xcp4-6hjg/GHSA-w552-xcp4-6hjg.json +++ b/advisories/unreviewed/2022/12/GHSA-w552-xcp4-6hjg/GHSA-w552-xcp4-6hjg.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-38w7-g7hm-hwph/GHSA-38w7-g7hm-hwph.json b/advisories/unreviewed/2023/01/GHSA-38w7-g7hm-hwph/GHSA-38w7-g7hm-hwph.json index d5477dca1e9..2900ea13ff7 100644 --- a/advisories/unreviewed/2023/01/GHSA-38w7-g7hm-hwph/GHSA-38w7-g7hm-hwph.json +++ b/advisories/unreviewed/2023/01/GHSA-38w7-g7hm-hwph/GHSA-38w7-g7hm-hwph.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-3xrv-6gjw-8g8c/GHSA-3xrv-6gjw-8g8c.json b/advisories/unreviewed/2023/01/GHSA-3xrv-6gjw-8g8c/GHSA-3xrv-6gjw-8g8c.json index 70b6526e65e..b5cded61ba0 100644 --- a/advisories/unreviewed/2023/01/GHSA-3xrv-6gjw-8g8c/GHSA-3xrv-6gjw-8g8c.json +++ b/advisories/unreviewed/2023/01/GHSA-3xrv-6gjw-8g8c/GHSA-3xrv-6gjw-8g8c.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-43mf-cpwf-chp9/GHSA-43mf-cpwf-chp9.json b/advisories/unreviewed/2023/01/GHSA-43mf-cpwf-chp9/GHSA-43mf-cpwf-chp9.json index 93805ad163e..62d8991b837 100644 --- a/advisories/unreviewed/2023/01/GHSA-43mf-cpwf-chp9/GHSA-43mf-cpwf-chp9.json +++ b/advisories/unreviewed/2023/01/GHSA-43mf-cpwf-chp9/GHSA-43mf-cpwf-chp9.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-569f-2ggr-6v5w/GHSA-569f-2ggr-6v5w.json b/advisories/unreviewed/2023/01/GHSA-569f-2ggr-6v5w/GHSA-569f-2ggr-6v5w.json index df63246a4c0..b103117d470 100644 --- a/advisories/unreviewed/2023/01/GHSA-569f-2ggr-6v5w/GHSA-569f-2ggr-6v5w.json +++ b/advisories/unreviewed/2023/01/GHSA-569f-2ggr-6v5w/GHSA-569f-2ggr-6v5w.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-7574-8crw-5432/GHSA-7574-8crw-5432.json b/advisories/unreviewed/2023/01/GHSA-7574-8crw-5432/GHSA-7574-8crw-5432.json index 85944567729..84d45fa02e2 100644 --- a/advisories/unreviewed/2023/01/GHSA-7574-8crw-5432/GHSA-7574-8crw-5432.json +++ b/advisories/unreviewed/2023/01/GHSA-7574-8crw-5432/GHSA-7574-8crw-5432.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-82mv-hvf2-x332/GHSA-82mv-hvf2-x332.json b/advisories/unreviewed/2023/01/GHSA-82mv-hvf2-x332/GHSA-82mv-hvf2-x332.json index d09902a87e6..b0f13b64dff 100644 --- a/advisories/unreviewed/2023/01/GHSA-82mv-hvf2-x332/GHSA-82mv-hvf2-x332.json +++ b/advisories/unreviewed/2023/01/GHSA-82mv-hvf2-x332/GHSA-82mv-hvf2-x332.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-gfp2-4w95-v37r/GHSA-gfp2-4w95-v37r.json b/advisories/unreviewed/2023/01/GHSA-gfp2-4w95-v37r/GHSA-gfp2-4w95-v37r.json index 6038a6ab888..548d2f1ba14 100644 --- a/advisories/unreviewed/2023/01/GHSA-gfp2-4w95-v37r/GHSA-gfp2-4w95-v37r.json +++ b/advisories/unreviewed/2023/01/GHSA-gfp2-4w95-v37r/GHSA-gfp2-4w95-v37r.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-hc96-pmx9-jcj6/GHSA-hc96-pmx9-jcj6.json b/advisories/unreviewed/2023/01/GHSA-hc96-pmx9-jcj6/GHSA-hc96-pmx9-jcj6.json index 8bbab49b744..8e2b69fd256 100644 --- a/advisories/unreviewed/2023/01/GHSA-hc96-pmx9-jcj6/GHSA-hc96-pmx9-jcj6.json +++ b/advisories/unreviewed/2023/01/GHSA-hc96-pmx9-jcj6/GHSA-hc96-pmx9-jcj6.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-77", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-hp26-q6wq-vrfp/GHSA-hp26-q6wq-vrfp.json b/advisories/unreviewed/2023/02/GHSA-hp26-q6wq-vrfp/GHSA-hp26-q6wq-vrfp.json index 10164702971..88435c4cae7 100644 --- a/advisories/unreviewed/2023/02/GHSA-hp26-q6wq-vrfp/GHSA-hp26-q6wq-vrfp.json +++ b/advisories/unreviewed/2023/02/GHSA-hp26-q6wq-vrfp/GHSA-hp26-q6wq-vrfp.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-311", + "CWE-614", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/02/GHSA-mw9r-vp4h-34mp/GHSA-mw9r-vp4h-34mp.json b/advisories/unreviewed/2023/02/GHSA-mw9r-vp4h-34mp/GHSA-mw9r-vp4h-34mp.json index 98bb1879df9..a7d6b5dc7aa 100644 --- a/advisories/unreviewed/2023/02/GHSA-mw9r-vp4h-34mp/GHSA-mw9r-vp4h-34mp.json +++ b/advisories/unreviewed/2023/02/GHSA-mw9r-vp4h-34mp/GHSA-mw9r-vp4h-34mp.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1004", + "CWE-732", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/04/GHSA-jr6j-p82r-r8p6/GHSA-jr6j-p82r-r8p6.json b/advisories/unreviewed/2023/04/GHSA-jr6j-p82r-r8p6/GHSA-jr6j-p82r-r8p6.json index b3a33586480..d40c6679183 100644 --- a/advisories/unreviewed/2023/04/GHSA-jr6j-p82r-r8p6/GHSA-jr6j-p82r-r8p6.json +++ b/advisories/unreviewed/2023/04/GHSA-jr6j-p82r-r8p6/GHSA-jr6j-p82r-r8p6.json @@ -24,6 +24,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28285" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173127/Microsoft-Office-Remote-Code-Execution.html" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173140/Microsoft-365-MSO-2305-Build-16.0.16501.20074-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-rggp-g5p7-mr37/GHSA-rggp-g5p7-mr37.json b/advisories/unreviewed/2023/04/GHSA-rggp-g5p7-mr37/GHSA-rggp-g5p7-mr37.json index f575723e0fb..6435d6d0d88 100644 --- a/advisories/unreviewed/2023/04/GHSA-rggp-g5p7-mr37/GHSA-rggp-g5p7-mr37.json +++ b/advisories/unreviewed/2023/04/GHSA-rggp-g5p7-mr37/GHSA-rggp-g5p7-mr37.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/172300/Windows-Kernel-CmpDoReDoCreateKey-CmpDoReOpenTransKey-Out-Of-Bounds-Read.html" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173135/Microsoft-Windows-11-22h2-Kernel-Privilege-Escalation.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-vpjm-mmm2-rqq5/GHSA-vpjm-mmm2-rqq5.json b/advisories/unreviewed/2023/04/GHSA-vpjm-mmm2-rqq5/GHSA-vpjm-mmm2-rqq5.json index 4eae0566ec1..f9b54001b55 100644 --- a/advisories/unreviewed/2023/04/GHSA-vpjm-mmm2-rqq5/GHSA-vpjm-mmm2-rqq5.json +++ b/advisories/unreviewed/2023/04/GHSA-vpjm-mmm2-rqq5/GHSA-vpjm-mmm2-rqq5.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28288" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173126/Microsoft-SharePoint-Enterprise-Server-2016-Spoofing.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-2jpx-j4q3-c28w/GHSA-2jpx-j4q3-c28w.json b/advisories/unreviewed/2023/06/GHSA-2jpx-j4q3-c28w/GHSA-2jpx-j4q3-c28w.json index 2aab5488090..67bedcd9fa5 100644 --- a/advisories/unreviewed/2023/06/GHSA-2jpx-j4q3-c28w/GHSA-2jpx-j4q3-c28w.json +++ b/advisories/unreviewed/2023/06/GHSA-2jpx-j4q3-c28w/GHSA-2jpx-j4q3-c28w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2jpx-j4q3-c28w", - "modified": "2023-06-20T15:31:09Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:09Z", "aliases": [ "CVE-2020-21474" ], "details": "File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-38g3-58hf-r96c/GHSA-38g3-58hf-r96c.json b/advisories/unreviewed/2023/06/GHSA-38g3-58hf-r96c/GHSA-38g3-58hf-r96c.json index bc972894deb..224d00b4cf2 100644 --- a/advisories/unreviewed/2023/06/GHSA-38g3-58hf-r96c/GHSA-38g3-58hf-r96c.json +++ b/advisories/unreviewed/2023/06/GHSA-38g3-58hf-r96c/GHSA-38g3-58hf-r96c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-38g3-58hf-r96c", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34162" ], "details": "Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may cause repeated HMS Core updates and cause services to fail.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-3p42-c2wq-v9gc/GHSA-3p42-c2wq-v9gc.json b/advisories/unreviewed/2023/06/GHSA-3p42-c2wq-v9gc/GHSA-3p42-c2wq-v9gc.json new file mode 100644 index 00000000000..6e4198fd04e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-3p42-c2wq-v9gc/GHSA-3p42-c2wq-v9gc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p42-c2wq-v9gc", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-34835" + ], + "details": "A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34835" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-34835/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-46ch-j8p2-6ppx/GHSA-46ch-j8p2-6ppx.json b/advisories/unreviewed/2023/06/GHSA-46ch-j8p2-6ppx/GHSA-46ch-j8p2-6ppx.json index 0d119f39ae1..3f7aea08b5e 100644 --- a/advisories/unreviewed/2023/06/GHSA-46ch-j8p2-6ppx/GHSA-46ch-j8p2-6ppx.json +++ b/advisories/unreviewed/2023/06/GHSA-46ch-j8p2-6ppx/GHSA-46ch-j8p2-6ppx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46ch-j8p2-6ppx", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34163" ], "details": "Permission control vulnerability in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json b/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json index d154c12bc0b..c0af8f7e20b 100644 --- a/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json +++ b/advisories/unreviewed/2023/06/GHSA-47xj-xr7q-9hhq/GHSA-47xj-xr7q-9hhq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47xj-xr7q-9hhq", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20969" ], "details": "File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json b/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json new file mode 100644 index 00000000000..8a58a07010b --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-4v9h-2pcw-v2q7/GHSA-4v9h-2pcw-v2q7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9h-2pcw-v2q7", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-33566" + ], + "details": "An unauthorized node injection vulnerability has been identified in ROS2 Foxy Fitzroy versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could allow a malicious user to inject malicious ROS2 nodes into the system remotely. Once injected, these nodes could disrupt the normal operations of the system or cause other potentially harmful behavior.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33566" + }, + { + "type": "WEB", + "url": "https://github.com/16yashpatel/CVE-2023-33566" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-5mmx-hq97-58f6/GHSA-5mmx-hq97-58f6.json b/advisories/unreviewed/2023/06/GHSA-5mmx-hq97-58f6/GHSA-5mmx-hq97-58f6.json index 5d2420551dc..92fb099eb08 100644 --- a/advisories/unreviewed/2023/06/GHSA-5mmx-hq97-58f6/GHSA-5mmx-hq97-58f6.json +++ b/advisories/unreviewed/2023/06/GHSA-5mmx-hq97-58f6/GHSA-5mmx-hq97-58f6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mmx-hq97-58f6", - "modified": "2023-06-20T15:31:09Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:09Z", "aliases": [ "CVE-2020-21400" ], "details": "SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-69wh-x693-q8h3/GHSA-69wh-x693-q8h3.json b/advisories/unreviewed/2023/06/GHSA-69wh-x693-q8h3/GHSA-69wh-x693-q8h3.json index a582bf09e3c..624a949c1e7 100644 --- a/advisories/unreviewed/2023/06/GHSA-69wh-x693-q8h3/GHSA-69wh-x693-q8h3.json +++ b/advisories/unreviewed/2023/06/GHSA-69wh-x693-q8h3/GHSA-69wh-x693-q8h3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-69wh-x693-q8h3", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34158" ], "details": "Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-6vf9-6gcr-cg7q/GHSA-6vf9-6gcr-cg7q.json b/advisories/unreviewed/2023/06/GHSA-6vf9-6gcr-cg7q/GHSA-6vf9-6gcr-cg7q.json index fbed1622818..8a29b8d1647 100644 --- a/advisories/unreviewed/2023/06/GHSA-6vf9-6gcr-cg7q/GHSA-6vf9-6gcr-cg7q.json +++ b/advisories/unreviewed/2023/06/GHSA-6vf9-6gcr-cg7q/GHSA-6vf9-6gcr-cg7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6vf9-6gcr-cg7q", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34159" ], "details": "Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-75j9-5hgg-gprr/GHSA-75j9-5hgg-gprr.json b/advisories/unreviewed/2023/06/GHSA-75j9-5hgg-gprr/GHSA-75j9-5hgg-gprr.json index 5b653cee087..42ce7194bd7 100644 --- a/advisories/unreviewed/2023/06/GHSA-75j9-5hgg-gprr/GHSA-75j9-5hgg-gprr.json +++ b/advisories/unreviewed/2023/06/GHSA-75j9-5hgg-gprr/GHSA-75j9-5hgg-gprr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75j9-5hgg-gprr", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-34414" ], "details": "The error page for sites with invalid TLS certificates was missing the\nactivation-delay Firefox uses to protect prompts and permission dialogs\nfrom attacks that exploit human response time delays. If a malicious\npage elicited user clicks in precise locations immediately before\nnavigating to a site with a certificate error and made the renderer\nextremely busy at the same time, it could create a gap between when\nthe error page was loaded and when the display actually refreshed.\nWith the right timing the elicited clicks could land in that gap and \nactivate the button that overrides the certificate error for that site. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-295" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-7wmp-qghr-8g7f/GHSA-7wmp-qghr-8g7f.json b/advisories/unreviewed/2023/06/GHSA-7wmp-qghr-8g7f/GHSA-7wmp-qghr-8g7f.json index a3d1fa7afde..a528af7de00 100644 --- a/advisories/unreviewed/2023/06/GHSA-7wmp-qghr-8g7f/GHSA-7wmp-qghr-8g7f.json +++ b/advisories/unreviewed/2023/06/GHSA-7wmp-qghr-8g7f/GHSA-7wmp-qghr-8g7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7wmp-qghr-8g7f", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-34415" ], "details": "When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on sites that host an \"open redirect\". Firefox no longer follows HTTP redirects to data: URLs. This vulnerability affects Firefox < 114.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-89hv-5x65-64rf/GHSA-89hv-5x65-64rf.json b/advisories/unreviewed/2023/06/GHSA-89hv-5x65-64rf/GHSA-89hv-5x65-64rf.json index c2b1c3c8d41..5f759838d15 100644 --- a/advisories/unreviewed/2023/06/GHSA-89hv-5x65-64rf/GHSA-89hv-5x65-64rf.json +++ b/advisories/unreviewed/2023/06/GHSA-89hv-5x65-64rf/GHSA-89hv-5x65-64rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89hv-5x65-64rf", - "modified": "2023-06-20T15:31:09Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:09Z", "aliases": [ "CVE-2020-21486" ], "details": "SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json b/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json index 89bddcc7335..93a268fdcf2 100644 --- a/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json +++ b/advisories/unreviewed/2023/06/GHSA-94qw-3pc5-wwcm/GHSA-94qw-3pc5-wwcm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94qw-3pc5-wwcm", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-34416" ], "details": "Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-95vj-3rv6-35hp/GHSA-95vj-3rv6-35hp.json b/advisories/unreviewed/2023/06/GHSA-95vj-3rv6-35hp/GHSA-95vj-3rv6-35hp.json index 015b7f43a52..9e93aa05b87 100644 --- a/advisories/unreviewed/2023/06/GHSA-95vj-3rv6-35hp/GHSA-95vj-3rv6-35hp.json +++ b/advisories/unreviewed/2023/06/GHSA-95vj-3rv6-35hp/GHSA-95vj-3rv6-35hp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95vj-3rv6-35hp", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-21252" ], "details": "Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json b/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json new file mode 100644 index 00000000000..eb07905181e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-9j35-h8v6-5943/GHSA-9j35-h8v6-5943.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j35-h8v6-5943", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-35800" + ], + "details": "Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35800" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu/2023-021/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-9m8g-m8f5-r7v5/GHSA-9m8g-m8f5-r7v5.json b/advisories/unreviewed/2023/06/GHSA-9m8g-m8f5-r7v5/GHSA-9m8g-m8f5-r7v5.json index 8ae1f094d41..dffecc9ff87 100644 --- a/advisories/unreviewed/2023/06/GHSA-9m8g-m8f5-r7v5/GHSA-9m8g-m8f5-r7v5.json +++ b/advisories/unreviewed/2023/06/GHSA-9m8g-m8f5-r7v5/GHSA-9m8g-m8f5-r7v5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m8g-m8f5-r7v5", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34161" ], "details": "nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability may cause features to perform abnormally.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json b/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json index 23734f44b93..353cae5065f 100644 --- a/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json +++ b/advisories/unreviewed/2023/06/GHSA-9pv7-q9jh-w7p4/GHSA-9pv7-q9jh-w7p4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-ccg9-9wjx-8536/GHSA-ccg9-9wjx-8536.json b/advisories/unreviewed/2023/06/GHSA-ccg9-9wjx-8536/GHSA-ccg9-9wjx-8536.json index 23b30d70c3b..f1ad222d60b 100644 --- a/advisories/unreviewed/2023/06/GHSA-ccg9-9wjx-8536/GHSA-ccg9-9wjx-8536.json +++ b/advisories/unreviewed/2023/06/GHSA-ccg9-9wjx-8536/GHSA-ccg9-9wjx-8536.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ccg9-9wjx-8536", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34160" ], "details": "Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-ccx9-5rv5-mwfr/GHSA-ccx9-5rv5-mwfr.json b/advisories/unreviewed/2023/06/GHSA-ccx9-5rv5-mwfr/GHSA-ccx9-5rv5-mwfr.json index 092f5bb3016..998811db1e4 100644 --- a/advisories/unreviewed/2023/06/GHSA-ccx9-5rv5-mwfr/GHSA-ccx9-5rv5-mwfr.json +++ b/advisories/unreviewed/2023/06/GHSA-ccx9-5rv5-mwfr/GHSA-ccx9-5rv5-mwfr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccx9-5rv5-mwfr", - "modified": "2023-06-19T15:30:49Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T15:30:49Z", "aliases": [ "CVE-2023-34373" diff --git a/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json b/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json new file mode 100644 index 00000000000..df2b1aa450c --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-cqw3-c4x8-fq47/GHSA-cqw3-c4x8-fq47.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqw3-c4x8-fq47", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-33567" + ], + "details": "An unauthorized access vulnerability has been discovered in ROS2 Foxy Fitzroy versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized access to multiple ROS2 nodes remotely. Unauthorized access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33567" + }, + { + "type": "WEB", + "url": "https://github.com/16yashpatel/CVE-2023-33567" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-cxpq-h2qw-mwp5/GHSA-cxpq-h2qw-mwp5.json b/advisories/unreviewed/2023/06/GHSA-cxpq-h2qw-mwp5/GHSA-cxpq-h2qw-mwp5.json index 808a720b255..05692994b1e 100644 --- a/advisories/unreviewed/2023/06/GHSA-cxpq-h2qw-mwp5/GHSA-cxpq-h2qw-mwp5.json +++ b/advisories/unreviewed/2023/06/GHSA-cxpq-h2qw-mwp5/GHSA-cxpq-h2qw-mwp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxpq-h2qw-mwp5", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-21325" ], "details": "An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\\common.func.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-f2fm-6xq7-v8j8/GHSA-f2fm-6xq7-v8j8.json b/advisories/unreviewed/2023/06/GHSA-f2fm-6xq7-v8j8/GHSA-f2fm-6xq7-v8j8.json index 869068501f1..c1f90bed4f2 100644 --- a/advisories/unreviewed/2023/06/GHSA-f2fm-6xq7-v8j8/GHSA-f2fm-6xq7-v8j8.json +++ b/advisories/unreviewed/2023/06/GHSA-f2fm-6xq7-v8j8/GHSA-f2fm-6xq7-v8j8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2fm-6xq7-v8j8", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20735" ], "details": "File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-fxv2-pr8r-g2r2/GHSA-fxv2-pr8r-g2r2.json b/advisories/unreviewed/2023/06/GHSA-fxv2-pr8r-g2r2/GHSA-fxv2-pr8r-g2r2.json index 28ff114dc08..a6defe41bd5 100644 --- a/advisories/unreviewed/2023/06/GHSA-fxv2-pr8r-g2r2/GHSA-fxv2-pr8r-g2r2.json +++ b/advisories/unreviewed/2023/06/GHSA-fxv2-pr8r-g2r2/GHSA-fxv2-pr8r-g2r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fxv2-pr8r-g2r2", - "modified": "2023-06-20T12:30:16Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-20T12:30:16Z", "aliases": [ "CVE-2023-35097" diff --git a/advisories/unreviewed/2023/06/GHSA-gj5r-368c-rjh3/GHSA-gj5r-368c-rjh3.json b/advisories/unreviewed/2023/06/GHSA-gj5r-368c-rjh3/GHSA-gj5r-368c-rjh3.json new file mode 100644 index 00000000000..3919f034958 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-gj5r-368c-rjh3/GHSA-gj5r-368c-rjh3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj5r-368c-rjh3", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-26276" + ], + "details": "IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26276" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248147" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7006081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-gm6j-4vjr-f7cw/GHSA-gm6j-4vjr-f7cw.json b/advisories/unreviewed/2023/06/GHSA-gm6j-4vjr-f7cw/GHSA-gm6j-4vjr-f7cw.json index 0d26bb49187..87ddb760a34 100644 --- a/advisories/unreviewed/2023/06/GHSA-gm6j-4vjr-f7cw/GHSA-gm6j-4vjr-f7cw.json +++ b/advisories/unreviewed/2023/06/GHSA-gm6j-4vjr-f7cw/GHSA-gm6j-4vjr-f7cw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gm6j-4vjr-f7cw", - "modified": "2023-06-19T15:30:49Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T15:30:49Z", "aliases": [ "CVE-2023-33213" diff --git a/advisories/unreviewed/2023/06/GHSA-gqpp-5p7w-52jm/GHSA-gqpp-5p7w-52jm.json b/advisories/unreviewed/2023/06/GHSA-gqpp-5p7w-52jm/GHSA-gqpp-5p7w-52jm.json new file mode 100644 index 00000000000..48c192ae1a5 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-gqpp-5p7w-52jm/GHSA-gqpp-5p7w-52jm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqpp-5p7w-52jm", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-26273" + ], + "details": "IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26273" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248134" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7006083" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-h3xp-rv2j-px7g/GHSA-h3xp-rv2j-px7g.json b/advisories/unreviewed/2023/06/GHSA-h3xp-rv2j-px7g/GHSA-h3xp-rv2j-px7g.json index e639d7d4469..6b8b5520317 100644 --- a/advisories/unreviewed/2023/06/GHSA-h3xp-rv2j-px7g/GHSA-h3xp-rv2j-px7g.json +++ b/advisories/unreviewed/2023/06/GHSA-h3xp-rv2j-px7g/GHSA-h3xp-rv2j-px7g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3xp-rv2j-px7g", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-21052" ], "details": "Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-h7cw-9qxp-4gmq/GHSA-h7cw-9qxp-4gmq.json b/advisories/unreviewed/2023/06/GHSA-h7cw-9qxp-4gmq/GHSA-h7cw-9qxp-4gmq.json index dfcd3489613..bb48eb76a61 100644 --- a/advisories/unreviewed/2023/06/GHSA-h7cw-9qxp-4gmq/GHSA-h7cw-9qxp-4gmq.json +++ b/advisories/unreviewed/2023/06/GHSA-h7cw-9qxp-4gmq/GHSA-h7cw-9qxp-4gmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h7cw-9qxp-4gmq", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20919" ], "details": "File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-j2pm-wg92-65rc/GHSA-j2pm-wg92-65rc.json b/advisories/unreviewed/2023/06/GHSA-j2pm-wg92-65rc/GHSA-j2pm-wg92-65rc.json new file mode 100644 index 00000000000..d6a525fec10 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-j2pm-wg92-65rc/GHSA-j2pm-wg92-65rc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2pm-wg92-65rc", + "modified": "2023-06-27T18:30:35Z", + "published": "2023-06-27T18:30:35Z", + "aliases": [ + "CVE-2023-34839" + ], + "details": "A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34839" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-34839/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-jhmp-h4x3-p89g/GHSA-jhmp-h4x3-p89g.json b/advisories/unreviewed/2023/06/GHSA-jhmp-h4x3-p89g/GHSA-jhmp-h4x3-p89g.json index a9f67728123..5ecd57d9c10 100644 --- a/advisories/unreviewed/2023/06/GHSA-jhmp-h4x3-p89g/GHSA-jhmp-h4x3-p89g.json +++ b/advisories/unreviewed/2023/06/GHSA-jhmp-h4x3-p89g/GHSA-jhmp-h4x3-p89g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhmp-h4x3-p89g", - "modified": "2023-06-20T15:31:09Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:09Z", "aliases": [ "CVE-2020-21366" ], "details": "Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json b/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json index 9ecd420e9db..fd7d2db6b91 100644 --- a/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json +++ b/advisories/unreviewed/2023/06/GHSA-jr8c-7w56-v2rh/GHSA-jr8c-7w56-v2rh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jr8c-7w56-v2rh", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-34417" ], "details": "Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-mmvv-xfgf-73jq/GHSA-mmvv-xfgf-73jq.json b/advisories/unreviewed/2023/06/GHSA-mmvv-xfgf-73jq/GHSA-mmvv-xfgf-73jq.json new file mode 100644 index 00000000000..c89b225e289 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-mmvv-xfgf-73jq/GHSA-mmvv-xfgf-73jq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmvv-xfgf-73jq", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-34837" + ], + "details": "A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34837" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-34837/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json b/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json new file mode 100644 index 00000000000..0ddca5903c1 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-ppp2-fxjc-67f9/GHSA-ppp2-fxjc-67f9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppp2-fxjc-67f9", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-35799" + ], + "details": "Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35799" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu/2023-022/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json b/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json index 94e768ae725..077f5612083 100644 --- a/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json +++ b/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://github.com/PrestaShop/PrestaShop/blob/6c05518b807d014ee8edb811041e3de232520c28/classes/Tools.php#L1247" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173136/PrestaShop-Winbiz-Payment-Improper-Limitation.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-rgwc-pg77-vhp2/GHSA-rgwc-pg77-vhp2.json b/advisories/unreviewed/2023/06/GHSA-rgwc-pg77-vhp2/GHSA-rgwc-pg77-vhp2.json index 749f0de3fe7..b49955ec2f7 100644 --- a/advisories/unreviewed/2023/06/GHSA-rgwc-pg77-vhp2/GHSA-rgwc-pg77-vhp2.json +++ b/advisories/unreviewed/2023/06/GHSA-rgwc-pg77-vhp2/GHSA-rgwc-pg77-vhp2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rgwc-pg77-vhp2", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T18:30:33Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-21058" ], "details": "Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json b/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json index 71af666faaa..a0638d98c39 100644 --- a/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json +++ b/advisories/unreviewed/2023/06/GHSA-rp64-mpmj-44xf/GHSA-rp64-mpmj-44xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rp64-mpmj-44xf", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34166" ], "details": "Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-v37p-3q57-4gv2/GHSA-v37p-3q57-4gv2.json b/advisories/unreviewed/2023/06/GHSA-v37p-3q57-4gv2/GHSA-v37p-3q57-4gv2.json new file mode 100644 index 00000000000..ac791e6719d --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-v37p-3q57-4gv2/GHSA-v37p-3q57-4gv2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v37p-3q57-4gv2", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-32339" + ], + "details": "IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32339" + }, + { + "type": "WEB", + "url": "https://https://www.ibm.com/support/pages/node/6998727" + }, + { + "type": "WEB", + "url": "https://https://www.ibm.com/support/pages/node/7001291" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6998727" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-v3w3-hwx2-r59j/GHSA-v3w3-hwx2-r59j.json b/advisories/unreviewed/2023/06/GHSA-v3w3-hwx2-r59j/GHSA-v3w3-hwx2-r59j.json new file mode 100644 index 00000000000..3dcd6794542 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-v3w3-hwx2-r59j/GHSA-v3w3-hwx2-r59j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3w3-hwx2-r59j", + "modified": "2023-06-27T18:30:35Z", + "published": "2023-06-27T18:30:35Z", + "aliases": [ + "CVE-2023-34838" + ], + "details": "A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34838" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-34838/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-vmp8-hjpw-vp73/GHSA-vmp8-hjpw-vp73.json b/advisories/unreviewed/2023/06/GHSA-vmp8-hjpw-vp73/GHSA-vmp8-hjpw-vp73.json index 484bb9f5e60..c7c085c63a2 100644 --- a/advisories/unreviewed/2023/06/GHSA-vmp8-hjpw-vp73/GHSA-vmp8-hjpw-vp73.json +++ b/advisories/unreviewed/2023/06/GHSA-vmp8-hjpw-vp73/GHSA-vmp8-hjpw-vp73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vmp8-hjpw-vp73", - "modified": "2023-06-20T12:30:16Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-20T12:30:16Z", "aliases": [ "CVE-2023-35098" diff --git a/advisories/unreviewed/2023/06/GHSA-vp9w-jfm8-64xg/GHSA-vp9w-jfm8-64xg.json b/advisories/unreviewed/2023/06/GHSA-vp9w-jfm8-64xg/GHSA-vp9w-jfm8-64xg.json new file mode 100644 index 00000000000..3e28b65dd14 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-vp9w-jfm8-64xg/GHSA-vp9w-jfm8-64xg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp9w-jfm8-64xg", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-26274" + ], + "details": "\nIBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26274" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248144" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7006085" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json b/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json new file mode 100644 index 00000000000..b4d290f2f55 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-vv5w-jx3q-w898/GHSA-vv5w-jx3q-w898.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv5w-jx3q-w898", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-34830" + ], + "details": "i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34830" + }, + { + "type": "WEB", + "url": "https://github.com/leekenghwa/CVE-2023-34830---Reflected-XSS-found-in-I-doit-Open-v24-and-below" + }, + { + "type": "WEB", + "url": "https://medium.com/@ray.999/cve-2023-34830-reflected-xss-on-i-doit-open-v24-and-below-ad58036f5407" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json b/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json index 21697591fd3..56b105e6312 100644 --- a/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json +++ b/advisories/unreviewed/2023/06/GHSA-vwhx-3qh6-75xf/GHSA-vwhx-3qh6-75xf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwhx-3qh6-75xf", - "modified": "2023-06-20T12:30:16Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-20T12:30:16Z", "aliases": [ "CVE-2023-35854" ], "details": "Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-vx98-w6gr-g2gv/GHSA-vx98-w6gr-g2gv.json b/advisories/unreviewed/2023/06/GHSA-vx98-w6gr-g2gv/GHSA-vx98-w6gr-g2gv.json index b30360099c7..f3788a95428 100644 --- a/advisories/unreviewed/2023/06/GHSA-vx98-w6gr-g2gv/GHSA-vx98-w6gr-g2gv.json +++ b/advisories/unreviewed/2023/06/GHSA-vx98-w6gr-g2gv/GHSA-vx98-w6gr-g2gv.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33137" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/173148/Microsoft-Excel-365-MSO-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-w5vj-wrq4-qh78/GHSA-w5vj-wrq4-qh78.json b/advisories/unreviewed/2023/06/GHSA-w5vj-wrq4-qh78/GHSA-w5vj-wrq4-qh78.json new file mode 100644 index 00000000000..5ea7078f1b7 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-w5vj-wrq4-qh78/GHSA-w5vj-wrq4-qh78.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5vj-wrq4-qh78", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2023-34836" + ], + "details": "A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34836" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-34836/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-wqr4-vg37-3923/GHSA-wqr4-vg37-3923.json b/advisories/unreviewed/2023/06/GHSA-wqr4-vg37-3923/GHSA-wqr4-vg37-3923.json index fbec6fe76f1..a164896134e 100644 --- a/advisories/unreviewed/2023/06/GHSA-wqr4-vg37-3923/GHSA-wqr4-vg37-3923.json +++ b/advisories/unreviewed/2023/06/GHSA-wqr4-vg37-3923/GHSA-wqr4-vg37-3923.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqr4-vg37-3923", - "modified": "2023-06-19T18:30:48Z", + "modified": "2023-06-27T18:30:32Z", "published": "2023-06-19T18:30:48Z", "aliases": [ "CVE-2023-34167" ], "details": "Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-290" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-x3xh-4gpx-gj42/GHSA-x3xh-4gpx-gj42.json b/advisories/unreviewed/2023/06/GHSA-x3xh-4gpx-gj42/GHSA-x3xh-4gpx-gj42.json new file mode 100644 index 00000000000..1d29bebbb4d --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-x3xh-4gpx-gj42/GHSA-x3xh-4gpx-gj42.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3xh-4gpx-gj42", + "modified": "2023-06-27T18:30:34Z", + "published": "2023-06-27T18:30:34Z", + "aliases": [ + "CVE-2022-34352" + ], + "details": "\nIBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34352" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230403" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7006057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-x8qg-5w28-wmr9/GHSA-x8qg-5w28-wmr9.json b/advisories/unreviewed/2023/06/GHSA-x8qg-5w28-wmr9/GHSA-x8qg-5w28-wmr9.json index 1129815d882..4aaab582aa8 100644 --- a/advisories/unreviewed/2023/06/GHSA-x8qg-5w28-wmr9/GHSA-x8qg-5w28-wmr9.json +++ b/advisories/unreviewed/2023/06/GHSA-x8qg-5w28-wmr9/GHSA-x8qg-5w28-wmr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8qg-5w28-wmr9", - "modified": "2023-06-19T03:30:19Z", + "modified": "2023-06-27T18:30:31Z", "published": "2023-06-19T03:30:19Z", "aliases": [ "CVE-2023-35844" ], "details": "packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": null, "github_reviewed": false,