From 299e8d0b31a796417223b9d0f6be3000679a4c0e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 6 Jul 2023 19:25:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2225-fj3w-f9wh.json | 35 +++++++++++ .../GHSA-225p-3jp7-q6p8.json | 35 +++++++++++ .../GHSA-2332-v8xq-hpvx.json | 39 ++++++++++++ .../GHSA-25c8-qcqq-xpqw.json | 39 ++++++++++++ .../GHSA-25xf-r6x8-6fw5.json | 39 ++++++++++++ .../GHSA-28fv-gqcc-g6m7.json | 35 +++++++++++ .../GHSA-28gc-rmm6-hmpv.json | 39 ++++++++++++ .../GHSA-292m-p3v4-44h4.json | 47 +++++++++++++++ .../GHSA-29wx-wghr-g778.json | 38 ++++++++++++ .../GHSA-2cvp-672x-8283.json | 35 +++++++++++ .../GHSA-2gv8-jcpw-2qg2.json | 38 ++++++++++++ .../GHSA-2jq7-x2v9-98wx.json | 38 ++++++++++++ .../GHSA-2m88-5j35-4r5m.json | 39 ++++++++++++ .../GHSA-2mxh-qvf4-48jc.json | 38 ++++++++++++ .../GHSA-2pg6-wjcp-mmcq.json | 39 ++++++++++++ .../GHSA-2r3h-3gcc-24g5.json | 35 +++++++++++ .../GHSA-2vhr-q545-p6f9.json | 35 +++++++++++ .../GHSA-2wfq-2vjq-pr3g.json | 38 ++++++++++++ .../GHSA-2wjq-7fcc-4p8f.json | 38 ++++++++++++ .../GHSA-325j-rfjm-895c.json | 38 ++++++++++++ .../GHSA-32pr-mxf9-qhx8.json | 35 +++++++++++ .../GHSA-339h-hwgh-x2jc.json | 35 +++++++++++ .../GHSA-33j2-92xf-fwm3.json | 38 ++++++++++++ .../GHSA-3474-xv2c-f5g9.json | 38 ++++++++++++ .../GHSA-34gf-pfjm-cq2w.json | 38 ++++++++++++ .../GHSA-35v3-mvqh-7ffm.json | 38 ++++++++++++ .../GHSA-36g9-fjvv-qmj3.json | 35 +++++++++++ .../GHSA-378h-jm2h-7wrm.json | 39 ++++++++++++ .../GHSA-3883-h64p-r3xm.json | 39 ++++++++++++ .../GHSA-38v3-cwq5-jprx.json | 35 +++++++++++ .../GHSA-3957-gqh2-v47w.json | 38 ++++++++++++ .../GHSA-399c-6449-xhh6.json | 35 +++++++++++ .../GHSA-3chx-g7jg-4263.json | 43 ++++++++++++++ .../GHSA-3gqj-h989-pgq3.json | 35 +++++++++++ .../GHSA-3jhh-jx96-63p5.json | 38 ++++++++++++ .../GHSA-3m5j-rg6q-w4gv.json | 39 ++++++++++++ .../GHSA-3m9g-2gcx-74c7.json | 35 +++++++++++ .../GHSA-3pc2-c878-63rj.json | 38 ++++++++++++ .../GHSA-3pqj-4h6v-gq86.json | 35 +++++++++++ .../GHSA-3q3r-47jp-8cqm.json | 39 ++++++++++++ .../GHSA-3r22-jvx3-7mjc.json | 38 ++++++++++++ .../GHSA-3r96-2j24-682p.json | 35 +++++++++++ .../GHSA-3w99-5f2g-rxfc.json | 35 +++++++++++ .../GHSA-3x77-v8f7-wp2v.json | 35 +++++++++++ .../GHSA-3xrr-7m6p-p7xh.json | 43 ++++++++++++++ .../GHSA-42m7-x4gf-gj25.json | 35 +++++++++++ .../GHSA-42mr-mfcr-7jqh.json | 35 +++++++++++ .../GHSA-433q-36rv-j5jj.json | 35 +++++++++++ .../GHSA-4446-w42r-xvj9.json | 38 ++++++++++++ .../GHSA-4683-xj3v-wqvf.json | 35 +++++++++++ .../GHSA-492f-248q-vxpp.json | 35 +++++++++++ .../GHSA-493h-rq8m-6xjp.json | 35 +++++++++++ .../GHSA-495g-cppx-r4mf.json | 35 +++++++++++ .../GHSA-49jr-333r-mqw3.json | 35 +++++++++++ .../GHSA-49r3-jh88-8r77.json | 42 +++++++++++++ .../GHSA-4fgf-f97h-jg4p.json | 35 +++++++++++ .../GHSA-4fgv-8448-gf82.json | 42 +++++++++++++ .../GHSA-4fhj-86f2-v36p.json | 35 +++++++++++ .../GHSA-4fvv-j62f-2gpq.json | 35 +++++++++++ .../GHSA-4hvh-86q3-7h55.json | 35 +++++++++++ .../GHSA-4hw7-4w59-f39j.json | 35 +++++++++++ .../GHSA-4mx2-p3fc-wx76.json | 35 +++++++++++ .../GHSA-4pmf-3p6f-p5g2.json | 35 +++++++++++ .../GHSA-4pwc-87fv-q86q.json | 38 ++++++++++++ .../GHSA-4r87-mf97-8jj9.json | 39 ++++++++++++ .../GHSA-4rcg-xhqc-237v.json | 35 +++++++++++ .../GHSA-4vhv-9xc2-4v6w.json | 35 +++++++++++ .../GHSA-4vrv-93c7-m92j.json | 59 +++++++++++++++++++ .../GHSA-4x5h-xmv4-99wx.json | 35 +++++++++++ .../GHSA-4x7m-cpcp-9gfm.json | 35 +++++++++++ .../GHSA-4x82-r4q4-7g8x.json | 39 ++++++++++++ .../GHSA-52r6-x37j-435c.json | 35 +++++++++++ .../GHSA-53rw-gcgw-2723.json | 35 +++++++++++ .../GHSA-5497-8frw-qm4r.json | 35 +++++++++++ .../GHSA-554g-vr37-8pqc.json | 35 +++++++++++ .../GHSA-56x4-8xcj-44r6.json | 39 ++++++++++++ .../GHSA-574w-g6v4-fj73.json | 35 +++++++++++ .../GHSA-578c-f9f3-qh5w.json | 35 +++++++++++ .../GHSA-584r-x68q-cm4j.json | 38 ++++++++++++ .../GHSA-59v2-929c-ff97.json | 35 +++++++++++ .../GHSA-5c24-6xxh-4r78.json | 35 +++++++++++ .../GHSA-5fqf-v5cm-7jqg.json | 43 ++++++++++++++ .../GHSA-5fw2-7ccx-9pc8.json | 35 +++++++++++ .../GHSA-5g4j-78x8-fff7.json | 35 +++++++++++ .../GHSA-5g92-3658-j47r.json | 35 +++++++++++ .../GHSA-5p9x-cmrm-q356.json | 39 ++++++++++++ .../GHSA-5r2r-5wx4-7x33.json | 35 +++++++++++ .../GHSA-5r3c-cq8h-c6gx.json | 50 ++++++++++++++++ .../GHSA-5v6h-fqxx-8wv5.json | 35 +++++++++++ .../GHSA-5xr6-mfp2-pfhc.json | 39 ++++++++++++ .../GHSA-6439-9fxj-fc35.json | 35 +++++++++++ .../GHSA-645g-q3pq-8q25.json | 35 +++++++++++ .../GHSA-652h-x93j-jh9w.json | 35 +++++++++++ .../GHSA-65c4-xx3j-xwcj.json | 38 ++++++++++++ .../GHSA-683h-9pw3-vc53.json | 39 ++++++++++++ .../GHSA-6874-289g-f7h7.json | 35 +++++++++++ .../GHSA-6c53-4r43-p32g.json | 38 ++++++++++++ .../GHSA-6grr-xmf3-hgjf.json | 35 +++++++++++ .../GHSA-6h37-c8j2-gj5p.json | 38 ++++++++++++ .../GHSA-6j2v-3cg6-9w64.json | 39 ++++++++++++ .../GHSA-6jf5-53hp-585m.json | 35 +++++++++++ .../GHSA-6jx2-8495-397p.json | 35 +++++++++++ .../GHSA-6pv2-vj8w-6fqg.json | 35 +++++++++++ .../GHSA-6r47-4376-p42h.json | 35 +++++++++++ .../GHSA-6rjf-jv9r-jj4v.json | 35 +++++++++++ .../GHSA-6rqp-hf8j-7x29.json | 35 +++++++++++ .../GHSA-6vvf-9qj9-6mw8.json | 39 ++++++++++++ .../GHSA-6wjj-c22c-pfh3.json | 35 +++++++++++ .../GHSA-6wvc-j264-82hv.json | 35 +++++++++++ .../GHSA-72cj-w3q5-m35c.json | 38 ++++++++++++ .../GHSA-72fh-vmp6-2w2c.json | 35 +++++++++++ .../GHSA-7358-prgh-r77c.json | 35 +++++++++++ .../GHSA-73qq-8mgh-cm29.json | 38 ++++++++++++ .../GHSA-74vj-ghfv-m4x7.json | 38 ++++++++++++ .../GHSA-75hv-856g-q3wx.json | 35 +++++++++++ .../GHSA-775x-85h4-43cp.json | 38 ++++++++++++ .../GHSA-77hr-wvv3-vjx6.json | 35 +++++++++++ .../GHSA-786j-r97c-7r7v.json | 39 ++++++++++++ .../GHSA-7922-hx9c-296c.json | 38 ++++++++++++ .../GHSA-7c88-jh2r-72f2.json | 35 +++++++++++ .../GHSA-7cp4-jcp5-8wrp.json | 38 ++++++++++++ .../GHSA-7fqr-w76q-379j.json | 35 +++++++++++ .../GHSA-7g93-5vcp-frv5.json | 39 ++++++++++++ .../GHSA-7gxc-cpf8-gf68.json | 38 ++++++++++++ .../GHSA-7hcw-vwc2-8cg8.json | 35 +++++++++++ .../GHSA-7j6x-42mm-p7jm.json | 39 ++++++++++++ .../GHSA-7mj9-5274-6hpv.json | 39 ++++++++++++ .../GHSA-7p8v-5pfg-c239.json | 35 +++++++++++ .../GHSA-7q3m-cm45-5qq5.json | 35 +++++++++++ .../GHSA-7w8f-q3m3-pfj7.json | 35 +++++++++++ .../GHSA-7x83-244x-q653.json | 38 ++++++++++++ .../GHSA-7xr3-6fgq-rv6h.json | 38 ++++++++++++ .../GHSA-8267-g4r9-6r3v.json | 39 ++++++++++++ .../GHSA-84p2-3q54-pcv7.json | 35 +++++++++++ .../GHSA-8699-h45g-7hm8.json | 51 ++++++++++++++++ .../GHSA-86vg-36hj-rcm9.json | 38 ++++++++++++ .../GHSA-875q-9h9j-qhmh.json | 43 ++++++++++++++ .../GHSA-895m-p2wc-hxwf.json | 38 ++++++++++++ .../GHSA-89j4-j5mp-mxwm.json | 35 +++++++++++ .../GHSA-89mj-q662-x3r3.json | 35 +++++++++++ .../GHSA-8c5m-67fx-9q72.json | 35 +++++++++++ .../GHSA-8fxh-vwx2-cpw9.json | 35 +++++++++++ .../GHSA-8hvr-7cm7-7fwj.json | 39 ++++++++++++ .../GHSA-8jc9-jhmw-r737.json | 35 +++++++++++ .../GHSA-8q28-r8h6-4fcg.json | 35 +++++++++++ .../GHSA-8x7r-vpqh-4jm4.json | 35 +++++++++++ .../GHSA-8xg2-4v9w-4g38.json | 38 ++++++++++++ .../GHSA-92cv-rhgw-5fm8.json | 38 ++++++++++++ .../GHSA-94c6-66pj-36g9.json | 38 ++++++++++++ .../GHSA-94c6-6qpc-j73m.json | 35 +++++++++++ .../GHSA-94wq-wgcm-m3pq.json | 35 +++++++++++ .../GHSA-95hr-886r-52mf.json | 35 +++++++++++ .../GHSA-95v2-crcm-vvrh.json | 38 ++++++++++++ .../GHSA-965j-qhq7-9qpx.json | 35 +++++++++++ .../GHSA-975q-7mxh-v8gj.json | 39 ++++++++++++ .../GHSA-97vg-58wg-32x4.json | 38 ++++++++++++ .../GHSA-9838-c2wv-jc32.json | 35 +++++++++++ .../GHSA-987p-cg63-5x62.json | 38 ++++++++++++ .../GHSA-9893-2v8q-6v9r.json | 39 ++++++++++++ .../GHSA-98m9-9rrp-w52h.json | 35 +++++++++++ .../GHSA-9f7j-84q4-6vj2.json | 55 +++++++++++++++++ .../GHSA-9f7x-7mw4-rf7j.json | 38 ++++++++++++ .../GHSA-9fh4-jgj2-72qw.json | 38 ++++++++++++ .../GHSA-9fqq-f56x-35gj.json | 38 ++++++++++++ .../GHSA-9fr2-r98v-qc2f.json | 35 +++++++++++ .../GHSA-9fr3-c4cm-2x8r.json | 35 +++++++++++ .../GHSA-9gph-8xxh-c4w6.json | 38 ++++++++++++ .../GHSA-9hv8-pfv2-wqfp.json | 35 +++++++++++ .../GHSA-9mh8-9j64-443f.json | 39 ++++++++++++ .../GHSA-9pqp-62pc-c8g4.json | 35 +++++++++++ .../GHSA-9qj4-8pgw-5j87.json | 35 +++++++++++ .../GHSA-9qwq-rm73-j3gr.json | 39 ++++++++++++ .../GHSA-9vrm-v9xv-x3xr.json | 35 +++++++++++ .../GHSA-9xhg-4cw3-p79r.json | 35 +++++++++++ .../GHSA-9xjj-cx8r-x5m9.json | 35 +++++++++++ .../GHSA-c2px-c8x4-v6mq.json | 38 ++++++++++++ .../GHSA-c2w9-hhfq-2xq9.json | 38 ++++++++++++ .../GHSA-c2xx-vqvr-jxwv.json | 35 +++++++++++ .../GHSA-c3rr-g6jw-68f4.json | 35 +++++++++++ .../GHSA-c5rj-26pj-c7cr.json | 38 ++++++++++++ .../GHSA-c63v-mmf4-hg2w.json | 39 ++++++++++++ .../GHSA-c65j-wcvh-77gc.json | 35 +++++++++++ .../GHSA-c735-wf7c-7c6p.json | 38 ++++++++++++ .../GHSA-c7p4-qvpp-vjjq.json | 35 +++++++++++ .../GHSA-c7w2-f8m6-pxp8.json | 35 +++++++++++ .../GHSA-c8x6-66mv-5gv8.json | 35 +++++++++++ .../GHSA-c99p-c624-4w53.json | 35 +++++++++++ .../GHSA-c9jf-g47r-97q7.json | 35 +++++++++++ .../GHSA-cg4j-xgw8-xrvj.json | 35 +++++++++++ .../GHSA-ch73-x6xh-8mrp.json | 35 +++++++++++ .../GHSA-chpv-rv7m-7qxg.json | 39 ++++++++++++ .../GHSA-chwv-c53r-9qh6.json | 43 ++++++++++++++ .../GHSA-cmjc-52fg-9f7j.json | 42 +++++++++++++ .../GHSA-cmm9-j99w-8844.json | 38 ++++++++++++ .../GHSA-cp7r-qm2p-wcq3.json | 38 ++++++++++++ .../GHSA-cp9w-xxfq-xfcf.json | 35 +++++++++++ .../GHSA-cqjg-qrhw-xfcq.json | 38 ++++++++++++ .../GHSA-cqr6-3x3f-9wr3.json | 35 +++++++++++ .../GHSA-cr4v-27vv-m68q.json | 38 ++++++++++++ .../GHSA-crq6-hjhp-f22c.json | 35 +++++++++++ .../GHSA-cwxp-h4pj-wvp5.json | 35 +++++++++++ .../GHSA-cxv2-g9cc-jg8q.json | 47 +++++++++++++++ .../GHSA-f44g-3vj9-vwv9.json | 35 +++++++++++ .../GHSA-f53g-frr2-jhpf.json | 59 +++++++++++++++++++ .../GHSA-f5c7-p8w5-6jv3.json | 39 ++++++++++++ .../GHSA-f5hf-7qmf-9r6x.json | 35 +++++++++++ .../GHSA-f5m2-fr27-39rx.json | 35 +++++++++++ .../GHSA-f5m5-3q5w-4vrg.json | 35 +++++++++++ .../GHSA-ffr6-hhvx-vgcq.json | 35 +++++++++++ .../GHSA-ffrf-xcmj-f59q.json | 35 +++++++++++ .../GHSA-fg63-fcp8-2qj4.json | 39 ++++++++++++ .../GHSA-fh6x-wwf2-q46r.json | 35 +++++++++++ .../GHSA-fj78-7vc8-pxrm.json | 35 +++++++++++ .../GHSA-fjfr-24j5-f8cq.json | 35 +++++++++++ .../GHSA-fjvx-fw48-vr4j.json | 35 +++++++++++ .../GHSA-fp8q-744c-xpg4.json | 35 +++++++++++ .../GHSA-fqm3-34q3-vw23.json | 38 ++++++++++++ .../GHSA-fr44-f297-ppg9.json | 35 +++++++++++ .../GHSA-fw5r-85gc-4v62.json | 35 +++++++++++ .../GHSA-fw8m-f5g8-v52m.json | 35 +++++++++++ .../GHSA-fww7-pq4g-vxx7.json | 38 ++++++++++++ .../GHSA-fx7f-p7m7-6rcc.json | 35 +++++++++++ .../GHSA-fxcr-gvcw-hmqm.json | 38 ++++++++++++ .../GHSA-fxjg-28fm-pfxh.json | 35 +++++++++++ .../GHSA-fxr5-7g6j-cj5f.json | 38 ++++++++++++ .../GHSA-g237-q563-mgqx.json | 35 +++++++++++ .../GHSA-g276-jg34-q58g.json | 38 ++++++++++++ .../GHSA-g2g3-6rcc-6c9q.json | 35 +++++++++++ .../GHSA-g32g-63v9-68pf.json | 35 +++++++++++ .../GHSA-g37x-jpmr-w7p9.json | 35 +++++++++++ .../GHSA-g722-qfq8-hp64.json | 35 +++++++++++ .../GHSA-g7w9-8ww6-vhhw.json | 38 ++++++++++++ .../GHSA-g7x8-fww2-5qqg.json | 35 +++++++++++ .../GHSA-gcxw-4wrx-xhw5.json | 35 +++++++++++ .../GHSA-gfcp-5456-7q6c.json | 35 +++++++++++ .../GHSA-gh9g-ghf4-75r3.json | 38 ++++++++++++ .../GHSA-gjg3-8mx2-7f8f.json | 39 ++++++++++++ .../GHSA-gjmv-6p6x-5mrf.json | 35 +++++++++++ .../GHSA-gm67-h5wr-w3cv.json | 38 ++++++++++++ .../GHSA-gmm4-c64x-vxp8.json | 39 ++++++++++++ .../GHSA-gpxg-3cwf-59mg.json | 38 ++++++++++++ .../GHSA-gq33-qvc5-v66x.json | 35 +++++++++++ .../GHSA-gqgc-w6w9-6h7c.json | 35 +++++++++++ .../GHSA-gqm5-4x4w-m9wr.json | 35 +++++++++++ .../GHSA-gvjm-jwhg-373p.json | 35 +++++++++++ .../GHSA-gwwh-wv9x-j72w.json | 35 +++++++++++ .../GHSA-gx7w-2wg7-5mcp.json | 35 +++++++++++ .../GHSA-h2w4-r6g5-2cm8.json | 38 ++++++++++++ .../GHSA-h4gh-9cxx-pfjv.json | 35 +++++++++++ .../GHSA-h4pp-x3cc-f8mv.json | 35 +++++++++++ .../GHSA-h6fv-f2m3-r3mm.json | 39 ++++++++++++ .../GHSA-h93h-mcv3-8hvx.json | 39 ++++++++++++ .../GHSA-h9xm-49jv-5p2p.json | 35 +++++++++++ .../GHSA-hc89-xf9q-xh2p.json | 35 +++++++++++ .../GHSA-hhvx-8755-4cvw.json | 35 +++++++++++ .../GHSA-hj63-292f-w39q.json | 39 ++++++++++++ .../GHSA-hjjq-3jj4-c7c6.json | 39 ++++++++++++ .../GHSA-hm6w-2fjv-w79j.json | 38 ++++++++++++ .../GHSA-hvmh-7jp7-68cp.json | 35 +++++++++++ .../GHSA-hwpv-98vq-7mw4.json | 35 +++++++++++ .../GHSA-hwwj-xrc2-6hxg.json | 42 +++++++++++++ .../GHSA-j2j9-pq33-wj97.json | 35 +++++++++++ .../GHSA-j37v-6hvg-rp7r.json | 39 ++++++++++++ .../GHSA-j4g2-785h-m856.json | 38 ++++++++++++ .../GHSA-j4q7-rgmr-c632.json | 35 +++++++++++ .../GHSA-j4r5-9qqm-p694.json | 42 +++++++++++++ .../GHSA-j4w7-pf4q-5fwj.json | 35 +++++++++++ .../GHSA-j62m-xr5c-f9qv.json | 38 ++++++++++++ .../GHSA-j893-r6jv-55xv.json | 38 ++++++++++++ .../GHSA-j9r7-xgvg-h2r5.json | 35 +++++++++++ .../GHSA-jhfw-j77h-rvv3.json | 35 +++++++++++ .../GHSA-jm25-87xp-4h76.json | 35 +++++++++++ .../GHSA-jm67-cprv-v6wx.json | 39 ++++++++++++ .../GHSA-jpg4-8c5p-qm22.json | 35 +++++++++++ .../GHSA-jr7p-69vw-fwhf.json | 39 ++++++++++++ .../GHSA-jrgc-m5wf-7pch.json | 42 +++++++++++++ .../GHSA-jrmv-h6h9-gcm3.json | 35 +++++++++++ .../GHSA-jv37-6f69-j8gw.json | 51 ++++++++++++++++ .../GHSA-jv4j-r7qp-qq7x.json | 38 ++++++++++++ .../GHSA-jv64-r55r-6x87.json | 38 ++++++++++++ .../GHSA-jw27-wjv9-vrx7.json | 35 +++++++++++ .../GHSA-jwcx-m84w-h98g.json | 38 ++++++++++++ .../GHSA-jwp6-2mv6-8gq3.json | 35 +++++++++++ .../GHSA-m29m-7j2f-w35x.json | 39 ++++++++++++ .../GHSA-m2hp-qjqj-65cw.json | 39 ++++++++++++ .../GHSA-m33h-m49h-9cf4.json | 39 ++++++++++++ .../GHSA-m36f-j5wf-g85f.json | 35 +++++++++++ .../GHSA-m3qp-4rm3-pr3q.json | 38 ++++++++++++ .../GHSA-m5gq-rxm3-279g.json | 35 +++++++++++ .../GHSA-m5h8-2pjw-vg3j.json | 35 +++++++++++ .../GHSA-m5q6-vwgv-7m5c.json | 38 ++++++++++++ .../GHSA-m64r-fm27-8wxj.json | 38 ++++++++++++ .../GHSA-m6m9-fxf2-g8mf.json | 35 +++++++++++ .../GHSA-mchj-fc27-3mfm.json | 35 +++++++++++ .../GHSA-mfpq-8q7r-r3fq.json | 38 ++++++++++++ .../GHSA-mj6f-85xq-rjq8.json | 35 +++++++++++ .../GHSA-mm22-v222-j9xr.json | 38 ++++++++++++ .../GHSA-mm8q-cf7f-pmxx.json | 35 +++++++++++ .../GHSA-mr82-9g27-qr4x.json | 35 +++++++++++ .../GHSA-mr98-5j2v-xqmf.json | 35 +++++++++++ .../GHSA-mw67-65x5-h28p.json | 43 ++++++++++++++ .../GHSA-mw9w-2x4j-fvhh.json | 35 +++++++++++ .../GHSA-mxpv-cf8p-pfpr.json | 35 +++++++++++ .../GHSA-mxw6-c2fh-2h9w.json | 43 ++++++++++++++ .../GHSA-p4w7-mhw7-7vgx.json | 35 +++++++++++ .../GHSA-p528-mrgw-3q8p.json | 35 +++++++++++ .../GHSA-p5fw-f837-j4p4.json | 38 ++++++++++++ .../GHSA-p72q-v88c-rprq.json | 35 +++++++++++ .../GHSA-p7r4-77g3-vcrx.json | 39 ++++++++++++ .../GHSA-p7xw-hxjp-35w2.json | 39 ++++++++++++ .../GHSA-p95j-mgmf-79p3.json | 47 +++++++++++++++ .../GHSA-pcx5-cm5r-cf7f.json | 35 +++++++++++ .../GHSA-pf45-p3p9-ghwp.json | 35 +++++++++++ .../GHSA-pf4c-5rqp-wmc9.json | 39 ++++++++++++ .../GHSA-pgrf-qrwj-3vf5.json | 35 +++++++++++ .../GHSA-ph5g-2r58-hm46.json | 39 ++++++++++++ .../GHSA-pj5j-w7mw-w797.json | 35 +++++++++++ .../GHSA-pmp9-6wg3-93fg.json | 35 +++++++++++ .../GHSA-ppfv-9rmx-jjrq.json | 35 +++++++++++ .../GHSA-ppw7-v579-v4cr.json | 42 +++++++++++++ .../GHSA-ppxx-m926-g569.json | 35 +++++++++++ .../GHSA-pr99-j37c-3mxj.json | 38 ++++++++++++ .../GHSA-pv98-6265-3prw.json | 38 ++++++++++++ .../GHSA-pvrw-g6fx-mcx2.json | 39 ++++++++++++ .../GHSA-pw2g-wqc9-f5g9.json | 38 ++++++++++++ .../GHSA-pwhp-27h2-crqj.json | 35 +++++++++++ .../GHSA-q35r-v94g-2r69.json | 35 +++++++++++ .../GHSA-q3x5-vwjf-49p2.json | 35 +++++++++++ .../GHSA-q443-qgfv-3fpg.json | 35 +++++++++++ .../GHSA-q4gj-rcjg-xcwr.json | 35 +++++++++++ .../GHSA-q4jw-3mfc-r879.json | 39 ++++++++++++ .../GHSA-q6hv-g5mr-qgwf.json | 38 ++++++++++++ .../GHSA-q7wq-398w-6957.json | 51 ++++++++++++++++ .../GHSA-q85c-wwvh-p49r.json | 35 +++++++++++ .../GHSA-q89q-qv4f-qvr5.json | 38 ++++++++++++ .../GHSA-q8j4-3fxm-87xm.json | 35 +++++++++++ .../GHSA-qcrm-cg47-3qvc.json | 43 ++++++++++++++ .../GHSA-qf9c-gmgf-6944.json | 35 +++++++++++ .../GHSA-qgvh-g2mh-jwfc.json | 35 +++++++++++ .../GHSA-qh97-v4qr-2c8p.json | 38 ++++++++++++ .../GHSA-qhw5-j89v-5fm3.json | 38 ++++++++++++ .../GHSA-qjmr-8cf3-fcr8.json | 35 +++++++++++ .../GHSA-qjxv-5m4x-5hpr.json | 38 ++++++++++++ .../GHSA-qm4q-mvq2-gj2r.json | 38 ++++++++++++ .../GHSA-qm75-wj63-4j3j.json | 39 ++++++++++++ .../GHSA-qr78-7vm9-2fj7.json | 38 ++++++++++++ .../GHSA-qwrg-xrq4-7mmv.json | 38 ++++++++++++ .../GHSA-r24m-v6jq-pp52.json | 43 ++++++++++++++ .../GHSA-r4cq-hxmv-g6f2.json | 39 ++++++++++++ .../GHSA-r5fc-xr2g-f58g.json | 38 ++++++++++++ .../GHSA-r78m-94wm-v7cv.json | 39 ++++++++++++ .../GHSA-r827-5p5r-w6f5.json | 35 +++++++++++ .../GHSA-r89f-2wvr-q3c7.json | 35 +++++++++++ .../GHSA-r8g3-9qxx-g5x2.json | 35 +++++++++++ .../GHSA-r946-wxvm-h3vx.json | 35 +++++++++++ .../GHSA-rc73-rxx3-qqfc.json | 35 +++++++++++ .../GHSA-rpx4-39vw-744p.json | 38 ++++++++++++ .../GHSA-rrwm-2vxq-5x2h.json | 35 +++++++++++ .../GHSA-rv59-78h6-2m84.json | 38 ++++++++++++ .../GHSA-rvvq-r3qv-fpwc.json | 39 ++++++++++++ .../GHSA-rw86-cvx5-q4pj.json | 35 +++++++++++ .../GHSA-v46q-m532-mg39.json | 35 +++++++++++ .../GHSA-v625-qcpp-j2vf.json | 39 ++++++++++++ .../GHSA-v63h-22hj-7hmg.json | 39 ++++++++++++ .../GHSA-v762-h4q2-77wx.json | 35 +++++++++++ .../GHSA-v77g-284c-r623.json | 35 +++++++++++ .../GHSA-v8c5-pw83-p6v7.json | 38 ++++++++++++ .../GHSA-v95r-pfp9-xw8f.json | 35 +++++++++++ .../GHSA-vcc9-8549-687w.json | 35 +++++++++++ .../GHSA-vcj3-36cm-3c25.json | 39 ++++++++++++ .../GHSA-vmwx-8pmg-4mrr.json | 35 +++++++++++ .../GHSA-vq77-w3cf-rw37.json | 35 +++++++++++ .../GHSA-vrpm-3gh9-qhp6.json | 39 ++++++++++++ .../GHSA-vrr6-jm4r-hqvp.json | 35 +++++++++++ .../GHSA-vw69-xjfm-55g4.json | 35 +++++++++++ .../GHSA-vwqg-h7r8-fqcg.json | 35 +++++++++++ .../GHSA-vx3x-c4x9-q8p5.json | 35 +++++++++++ .../GHSA-vxfj-h2jv-2pgr.json | 35 +++++++++++ .../GHSA-w2x5-hpmg-j98h.json | 51 ++++++++++++++++ .../GHSA-w35h-r9ff-45q4.json | 38 ++++++++++++ .../GHSA-w3rw-649p-m947.json | 35 +++++++++++ .../GHSA-w745-xjqx-7wp8.json | 51 ++++++++++++++++ .../GHSA-w8gp-g46m-jhvc.json | 38 ++++++++++++ .../GHSA-wf8m-qr47-xc9m.json | 35 +++++++++++ .../GHSA-wf94-5wvh-jmpc.json | 35 +++++++++++ .../GHSA-whp2-gjjf-pvgr.json | 35 +++++++++++ .../GHSA-wjg8-pxqj-c3c7.json | 51 ++++++++++++++++ .../GHSA-wmg5-g953-qqfw.json | 35 +++++++++++ .../GHSA-wmgh-44xh-27j6.json | 35 +++++++++++ .../GHSA-wmqm-3p7c-c6j7.json | 35 +++++++++++ .../GHSA-wpfp-vfwj-4xwh.json | 35 +++++++++++ .../GHSA-wr5x-fcf4-h5qm.json | 39 ++++++++++++ .../GHSA-wrhx-52hg-crxx.json | 42 +++++++++++++ .../GHSA-x84r-jrqm-3hj8.json | 35 +++++++++++ .../GHSA-x8qw-cfcr-6hhp.json | 35 +++++++++++ .../GHSA-x8xh-hfg5-qrf9.json | 35 +++++++++++ .../GHSA-x9qv-5m74-x74p.json | 38 ++++++++++++ .../GHSA-xc7w-hcqx-q2x3.json | 38 ++++++++++++ .../GHSA-xg39-26cw-gxj9.json | 38 ++++++++++++ .../GHSA-xgw4-pcqh-286r.json | 35 +++++++++++ .../GHSA-xhm2-m35v-2xw7.json | 39 ++++++++++++ .../GHSA-xjhw-7765-363q.json | 38 ++++++++++++ .../GHSA-xjvc-8mfj-g22v.json | 43 ++++++++++++++ .../GHSA-xmvp-p4p2-hprq.json | 35 +++++++++++ .../GHSA-xv45-qm36-h77q.json | 35 +++++++++++ .../GHSA-xw8j-xwwr-8vqj.json | 35 +++++++++++ .../GHSA-xwf7-9xfx-ghmm.json | 35 +++++++++++ .../GHSA-xwp2-26xm-vq22.json | 39 ++++++++++++ .../GHSA-xxmc-mjxm-2m5r.json | 35 +++++++++++ 409 files changed, 15192 insertions(+) create mode 100644 advisories/unreviewed/2023/07/GHSA-2225-fj3w-f9wh/GHSA-2225-fj3w-f9wh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-225p-3jp7-q6p8/GHSA-225p-3jp7-q6p8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2332-v8xq-hpvx/GHSA-2332-v8xq-hpvx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-25c8-qcqq-xpqw/GHSA-25c8-qcqq-xpqw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-25xf-r6x8-6fw5/GHSA-25xf-r6x8-6fw5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-28fv-gqcc-g6m7/GHSA-28fv-gqcc-g6m7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-28gc-rmm6-hmpv/GHSA-28gc-rmm6-hmpv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-292m-p3v4-44h4/GHSA-292m-p3v4-44h4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-29wx-wghr-g778/GHSA-29wx-wghr-g778.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2cvp-672x-8283/GHSA-2cvp-672x-8283.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2gv8-jcpw-2qg2/GHSA-2gv8-jcpw-2qg2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2jq7-x2v9-98wx/GHSA-2jq7-x2v9-98wx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2m88-5j35-4r5m/GHSA-2m88-5j35-4r5m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2mxh-qvf4-48jc/GHSA-2mxh-qvf4-48jc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2pg6-wjcp-mmcq/GHSA-2pg6-wjcp-mmcq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2vhr-q545-p6f9/GHSA-2vhr-q545-p6f9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2wfq-2vjq-pr3g/GHSA-2wfq-2vjq-pr3g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2wjq-7fcc-4p8f/GHSA-2wjq-7fcc-4p8f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-325j-rfjm-895c/GHSA-325j-rfjm-895c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-32pr-mxf9-qhx8/GHSA-32pr-mxf9-qhx8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-339h-hwgh-x2jc/GHSA-339h-hwgh-x2jc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-33j2-92xf-fwm3/GHSA-33j2-92xf-fwm3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3474-xv2c-f5g9/GHSA-3474-xv2c-f5g9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-34gf-pfjm-cq2w/GHSA-34gf-pfjm-cq2w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-35v3-mvqh-7ffm/GHSA-35v3-mvqh-7ffm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-378h-jm2h-7wrm/GHSA-378h-jm2h-7wrm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3883-h64p-r3xm/GHSA-3883-h64p-r3xm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3957-gqh2-v47w/GHSA-3957-gqh2-v47w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3gqj-h989-pgq3/GHSA-3gqj-h989-pgq3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3jhh-jx96-63p5/GHSA-3jhh-jx96-63p5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3m5j-rg6q-w4gv/GHSA-3m5j-rg6q-w4gv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3m9g-2gcx-74c7/GHSA-3m9g-2gcx-74c7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3pc2-c878-63rj/GHSA-3pc2-c878-63rj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3pqj-4h6v-gq86/GHSA-3pqj-4h6v-gq86.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3q3r-47jp-8cqm/GHSA-3q3r-47jp-8cqm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3r22-jvx3-7mjc/GHSA-3r22-jvx3-7mjc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3r96-2j24-682p/GHSA-3r96-2j24-682p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3w99-5f2g-rxfc/GHSA-3w99-5f2g-rxfc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3x77-v8f7-wp2v/GHSA-3x77-v8f7-wp2v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3xrr-7m6p-p7xh/GHSA-3xrr-7m6p-p7xh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-42m7-x4gf-gj25/GHSA-42m7-x4gf-gj25.json create mode 100644 advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4683-xj3v-wqvf/GHSA-4683-xj3v-wqvf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-492f-248q-vxpp/GHSA-492f-248q-vxpp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-493h-rq8m-6xjp/GHSA-493h-rq8m-6xjp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-495g-cppx-r4mf/GHSA-495g-cppx-r4mf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-49jr-333r-mqw3/GHSA-49jr-333r-mqw3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-49r3-jh88-8r77/GHSA-49r3-jh88-8r77.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4fgf-f97h-jg4p/GHSA-4fgf-f97h-jg4p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4fgv-8448-gf82/GHSA-4fgv-8448-gf82.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4fhj-86f2-v36p/GHSA-4fhj-86f2-v36p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4fvv-j62f-2gpq/GHSA-4fvv-j62f-2gpq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4hvh-86q3-7h55/GHSA-4hvh-86q3-7h55.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4hw7-4w59-f39j/GHSA-4hw7-4w59-f39j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4mx2-p3fc-wx76/GHSA-4mx2-p3fc-wx76.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4pmf-3p6f-p5g2/GHSA-4pmf-3p6f-p5g2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4pwc-87fv-q86q/GHSA-4pwc-87fv-q86q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4r87-mf97-8jj9/GHSA-4r87-mf97-8jj9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4rcg-xhqc-237v/GHSA-4rcg-xhqc-237v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4x5h-xmv4-99wx/GHSA-4x5h-xmv4-99wx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-53rw-gcgw-2723/GHSA-53rw-gcgw-2723.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5497-8frw-qm4r/GHSA-5497-8frw-qm4r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-554g-vr37-8pqc/GHSA-554g-vr37-8pqc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-56x4-8xcj-44r6/GHSA-56x4-8xcj-44r6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-574w-g6v4-fj73/GHSA-574w-g6v4-fj73.json create mode 100644 advisories/unreviewed/2023/07/GHSA-578c-f9f3-qh5w/GHSA-578c-f9f3-qh5w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-584r-x68q-cm4j/GHSA-584r-x68q-cm4j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-59v2-929c-ff97/GHSA-59v2-929c-ff97.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5c24-6xxh-4r78/GHSA-5c24-6xxh-4r78.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5fqf-v5cm-7jqg/GHSA-5fqf-v5cm-7jqg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5fw2-7ccx-9pc8/GHSA-5fw2-7ccx-9pc8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5g4j-78x8-fff7/GHSA-5g4j-78x8-fff7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5g92-3658-j47r/GHSA-5g92-3658-j47r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5p9x-cmrm-q356/GHSA-5p9x-cmrm-q356.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5r2r-5wx4-7x33/GHSA-5r2r-5wx4-7x33.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5r3c-cq8h-c6gx/GHSA-5r3c-cq8h-c6gx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5xr6-mfp2-pfhc/GHSA-5xr6-mfp2-pfhc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json create mode 100644 advisories/unreviewed/2023/07/GHSA-645g-q3pq-8q25/GHSA-645g-q3pq-8q25.json create mode 100644 advisories/unreviewed/2023/07/GHSA-652h-x93j-jh9w/GHSA-652h-x93j-jh9w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-65c4-xx3j-xwcj/GHSA-65c4-xx3j-xwcj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-683h-9pw3-vc53/GHSA-683h-9pw3-vc53.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6874-289g-f7h7/GHSA-6874-289g-f7h7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6c53-4r43-p32g/GHSA-6c53-4r43-p32g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6grr-xmf3-hgjf/GHSA-6grr-xmf3-hgjf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6h37-c8j2-gj5p/GHSA-6h37-c8j2-gj5p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6j2v-3cg6-9w64/GHSA-6j2v-3cg6-9w64.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6jf5-53hp-585m/GHSA-6jf5-53hp-585m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6jx2-8495-397p/GHSA-6jx2-8495-397p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6pv2-vj8w-6fqg/GHSA-6pv2-vj8w-6fqg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6rjf-jv9r-jj4v/GHSA-6rjf-jv9r-jj4v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6vvf-9qj9-6mw8/GHSA-6vvf-9qj9-6mw8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6wjj-c22c-pfh3/GHSA-6wjj-c22c-pfh3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6wvc-j264-82hv/GHSA-6wvc-j264-82hv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-72cj-w3q5-m35c/GHSA-72cj-w3q5-m35c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-72fh-vmp6-2w2c/GHSA-72fh-vmp6-2w2c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7358-prgh-r77c/GHSA-7358-prgh-r77c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-73qq-8mgh-cm29/GHSA-73qq-8mgh-cm29.json create mode 100644 advisories/unreviewed/2023/07/GHSA-74vj-ghfv-m4x7/GHSA-74vj-ghfv-m4x7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-75hv-856g-q3wx/GHSA-75hv-856g-q3wx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-775x-85h4-43cp/GHSA-775x-85h4-43cp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-77hr-wvv3-vjx6/GHSA-77hr-wvv3-vjx6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-786j-r97c-7r7v/GHSA-786j-r97c-7r7v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7922-hx9c-296c/GHSA-7922-hx9c-296c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7c88-jh2r-72f2/GHSA-7c88-jh2r-72f2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7cp4-jcp5-8wrp/GHSA-7cp4-jcp5-8wrp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7fqr-w76q-379j/GHSA-7fqr-w76q-379j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7g93-5vcp-frv5/GHSA-7g93-5vcp-frv5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7gxc-cpf8-gf68/GHSA-7gxc-cpf8-gf68.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7hcw-vwc2-8cg8/GHSA-7hcw-vwc2-8cg8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7j6x-42mm-p7jm/GHSA-7j6x-42mm-p7jm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7mj9-5274-6hpv/GHSA-7mj9-5274-6hpv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7p8v-5pfg-c239/GHSA-7p8v-5pfg-c239.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7q3m-cm45-5qq5/GHSA-7q3m-cm45-5qq5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7w8f-q3m3-pfj7/GHSA-7w8f-q3m3-pfj7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7x83-244x-q653/GHSA-7x83-244x-q653.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8267-g4r9-6r3v/GHSA-8267-g4r9-6r3v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-84p2-3q54-pcv7/GHSA-84p2-3q54-pcv7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8699-h45g-7hm8/GHSA-8699-h45g-7hm8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-86vg-36hj-rcm9/GHSA-86vg-36hj-rcm9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-875q-9h9j-qhmh/GHSA-875q-9h9j-qhmh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-895m-p2wc-hxwf/GHSA-895m-p2wc-hxwf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-89j4-j5mp-mxwm/GHSA-89j4-j5mp-mxwm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-89mj-q662-x3r3/GHSA-89mj-q662-x3r3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8c5m-67fx-9q72/GHSA-8c5m-67fx-9q72.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8fxh-vwx2-cpw9/GHSA-8fxh-vwx2-cpw9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8hvr-7cm7-7fwj/GHSA-8hvr-7cm7-7fwj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8jc9-jhmw-r737/GHSA-8jc9-jhmw-r737.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8q28-r8h6-4fcg/GHSA-8q28-r8h6-4fcg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8x7r-vpqh-4jm4/GHSA-8x7r-vpqh-4jm4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8xg2-4v9w-4g38/GHSA-8xg2-4v9w-4g38.json create mode 100644 advisories/unreviewed/2023/07/GHSA-92cv-rhgw-5fm8/GHSA-92cv-rhgw-5fm8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-94c6-66pj-36g9/GHSA-94c6-66pj-36g9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-94wq-wgcm-m3pq/GHSA-94wq-wgcm-m3pq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-95hr-886r-52mf/GHSA-95hr-886r-52mf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-95v2-crcm-vvrh/GHSA-95v2-crcm-vvrh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-965j-qhq7-9qpx/GHSA-965j-qhq7-9qpx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-975q-7mxh-v8gj/GHSA-975q-7mxh-v8gj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-97vg-58wg-32x4/GHSA-97vg-58wg-32x4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9838-c2wv-jc32/GHSA-9838-c2wv-jc32.json create mode 100644 advisories/unreviewed/2023/07/GHSA-987p-cg63-5x62/GHSA-987p-cg63-5x62.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9893-2v8q-6v9r/GHSA-9893-2v8q-6v9r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-98m9-9rrp-w52h/GHSA-98m9-9rrp-w52h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9f7j-84q4-6vj2/GHSA-9f7j-84q4-6vj2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9f7x-7mw4-rf7j/GHSA-9f7x-7mw4-rf7j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9fh4-jgj2-72qw/GHSA-9fh4-jgj2-72qw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9fqq-f56x-35gj/GHSA-9fqq-f56x-35gj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9fr2-r98v-qc2f/GHSA-9fr2-r98v-qc2f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9fr3-c4cm-2x8r/GHSA-9fr3-c4cm-2x8r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9gph-8xxh-c4w6/GHSA-9gph-8xxh-c4w6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9hv8-pfv2-wqfp/GHSA-9hv8-pfv2-wqfp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9mh8-9j64-443f/GHSA-9mh8-9j64-443f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9pqp-62pc-c8g4/GHSA-9pqp-62pc-c8g4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9qj4-8pgw-5j87/GHSA-9qj4-8pgw-5j87.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9qwq-rm73-j3gr/GHSA-9qwq-rm73-j3gr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9vrm-v9xv-x3xr/GHSA-9vrm-v9xv-x3xr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9xhg-4cw3-p79r/GHSA-9xhg-4cw3-p79r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9xjj-cx8r-x5m9/GHSA-9xjj-cx8r-x5m9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c2px-c8x4-v6mq/GHSA-c2px-c8x4-v6mq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c2w9-hhfq-2xq9/GHSA-c2w9-hhfq-2xq9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c2xx-vqvr-jxwv/GHSA-c2xx-vqvr-jxwv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c3rr-g6jw-68f4/GHSA-c3rr-g6jw-68f4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c5rj-26pj-c7cr/GHSA-c5rj-26pj-c7cr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c63v-mmf4-hg2w/GHSA-c63v-mmf4-hg2w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c735-wf7c-7c6p/GHSA-c735-wf7c-7c6p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c7p4-qvpp-vjjq/GHSA-c7p4-qvpp-vjjq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c7w2-f8m6-pxp8/GHSA-c7w2-f8m6-pxp8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c8x6-66mv-5gv8/GHSA-c8x6-66mv-5gv8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c99p-c624-4w53/GHSA-c99p-c624-4w53.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c9jf-g47r-97q7/GHSA-c9jf-g47r-97q7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cg4j-xgw8-xrvj/GHSA-cg4j-xgw8-xrvj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ch73-x6xh-8mrp/GHSA-ch73-x6xh-8mrp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-chpv-rv7m-7qxg/GHSA-chpv-rv7m-7qxg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-chwv-c53r-9qh6/GHSA-chwv-c53r-9qh6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cmjc-52fg-9f7j/GHSA-cmjc-52fg-9f7j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cmm9-j99w-8844/GHSA-cmm9-j99w-8844.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cp7r-qm2p-wcq3/GHSA-cp7r-qm2p-wcq3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cp9w-xxfq-xfcf/GHSA-cp9w-xxfq-xfcf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cqjg-qrhw-xfcq/GHSA-cqjg-qrhw-xfcq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cqr6-3x3f-9wr3/GHSA-cqr6-3x3f-9wr3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cr4v-27vv-m68q/GHSA-cr4v-27vv-m68q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-crq6-hjhp-f22c/GHSA-crq6-hjhp-f22c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cwxp-h4pj-wvp5/GHSA-cwxp-h4pj-wvp5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cxv2-g9cc-jg8q/GHSA-cxv2-g9cc-jg8q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f44g-3vj9-vwv9/GHSA-f44g-3vj9-vwv9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f53g-frr2-jhpf/GHSA-f53g-frr2-jhpf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f5c7-p8w5-6jv3/GHSA-f5c7-p8w5-6jv3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f5hf-7qmf-9r6x/GHSA-f5hf-7qmf-9r6x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f5m2-fr27-39rx/GHSA-f5m2-fr27-39rx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f5m5-3q5w-4vrg/GHSA-f5m5-3q5w-4vrg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ffr6-hhvx-vgcq/GHSA-ffr6-hhvx-vgcq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fg63-fcp8-2qj4/GHSA-fg63-fcp8-2qj4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fh6x-wwf2-q46r/GHSA-fh6x-wwf2-q46r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fj78-7vc8-pxrm/GHSA-fj78-7vc8-pxrm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fjfr-24j5-f8cq/GHSA-fjfr-24j5-f8cq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fjvx-fw48-vr4j/GHSA-fjvx-fw48-vr4j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fp8q-744c-xpg4/GHSA-fp8q-744c-xpg4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fw5r-85gc-4v62/GHSA-fw5r-85gc-4v62.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fw8m-f5g8-v52m/GHSA-fw8m-f5g8-v52m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fx7f-p7m7-6rcc/GHSA-fx7f-p7m7-6rcc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fxcr-gvcw-hmqm/GHSA-fxcr-gvcw-hmqm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fxjg-28fm-pfxh/GHSA-fxjg-28fm-pfxh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fxr5-7g6j-cj5f/GHSA-fxr5-7g6j-cj5f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g237-q563-mgqx/GHSA-g237-q563-mgqx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g276-jg34-q58g/GHSA-g276-jg34-q58g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g2g3-6rcc-6c9q/GHSA-g2g3-6rcc-6c9q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g32g-63v9-68pf/GHSA-g32g-63v9-68pf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g37x-jpmr-w7p9/GHSA-g37x-jpmr-w7p9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g722-qfq8-hp64/GHSA-g722-qfq8-hp64.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g7w9-8ww6-vhhw/GHSA-g7w9-8ww6-vhhw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g7x8-fww2-5qqg/GHSA-g7x8-fww2-5qqg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gfcp-5456-7q6c/GHSA-gfcp-5456-7q6c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gh9g-ghf4-75r3/GHSA-gh9g-ghf4-75r3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gm67-h5wr-w3cv/GHSA-gm67-h5wr-w3cv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gmm4-c64x-vxp8/GHSA-gmm4-c64x-vxp8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gpxg-3cwf-59mg/GHSA-gpxg-3cwf-59mg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gq33-qvc5-v66x/GHSA-gq33-qvc5-v66x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gqgc-w6w9-6h7c/GHSA-gqgc-w6w9-6h7c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gqm5-4x4w-m9wr/GHSA-gqm5-4x4w-m9wr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gvjm-jwhg-373p/GHSA-gvjm-jwhg-373p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gwwh-wv9x-j72w/GHSA-gwwh-wv9x-j72w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gx7w-2wg7-5mcp/GHSA-gx7w-2wg7-5mcp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h2w4-r6g5-2cm8/GHSA-h2w4-r6g5-2cm8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h4gh-9cxx-pfjv/GHSA-h4gh-9cxx-pfjv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h4pp-x3cc-f8mv/GHSA-h4pp-x3cc-f8mv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h6fv-f2m3-r3mm/GHSA-h6fv-f2m3-r3mm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h93h-mcv3-8hvx/GHSA-h93h-mcv3-8hvx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h9xm-49jv-5p2p/GHSA-h9xm-49jv-5p2p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hhvx-8755-4cvw/GHSA-hhvx-8755-4cvw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hj63-292f-w39q/GHSA-hj63-292f-w39q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hjjq-3jj4-c7c6/GHSA-hjjq-3jj4-c7c6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hm6w-2fjv-w79j/GHSA-hm6w-2fjv-w79j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hvmh-7jp7-68cp/GHSA-hvmh-7jp7-68cp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hwpv-98vq-7mw4/GHSA-hwpv-98vq-7mw4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hwwj-xrc2-6hxg/GHSA-hwwj-xrc2-6hxg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j2j9-pq33-wj97/GHSA-j2j9-pq33-wj97.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j37v-6hvg-rp7r/GHSA-j37v-6hvg-rp7r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j4g2-785h-m856/GHSA-j4g2-785h-m856.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j4q7-rgmr-c632/GHSA-j4q7-rgmr-c632.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j4w7-pf4q-5fwj/GHSA-j4w7-pf4q-5fwj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j62m-xr5c-f9qv/GHSA-j62m-xr5c-f9qv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j893-r6jv-55xv/GHSA-j893-r6jv-55xv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j9r7-xgvg-h2r5/GHSA-j9r7-xgvg-h2r5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jhfw-j77h-rvv3/GHSA-jhfw-j77h-rvv3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jpg4-8c5p-qm22/GHSA-jpg4-8c5p-qm22.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jr7p-69vw-fwhf/GHSA-jr7p-69vw-fwhf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jrgc-m5wf-7pch/GHSA-jrgc-m5wf-7pch.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jv37-6f69-j8gw/GHSA-jv37-6f69-j8gw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jv4j-r7qp-qq7x/GHSA-jv4j-r7qp-qq7x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jv64-r55r-6x87/GHSA-jv64-r55r-6x87.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jw27-wjv9-vrx7/GHSA-jw27-wjv9-vrx7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jwcx-m84w-h98g/GHSA-jwcx-m84w-h98g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jwp6-2mv6-8gq3/GHSA-jwp6-2mv6-8gq3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m29m-7j2f-w35x/GHSA-m29m-7j2f-w35x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m2hp-qjqj-65cw/GHSA-m2hp-qjqj-65cw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m33h-m49h-9cf4/GHSA-m33h-m49h-9cf4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m36f-j5wf-g85f/GHSA-m36f-j5wf-g85f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m5gq-rxm3-279g/GHSA-m5gq-rxm3-279g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m5h8-2pjw-vg3j/GHSA-m5h8-2pjw-vg3j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m5q6-vwgv-7m5c/GHSA-m5q6-vwgv-7m5c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m64r-fm27-8wxj/GHSA-m64r-fm27-8wxj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m6m9-fxf2-g8mf/GHSA-m6m9-fxf2-g8mf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mfpq-8q7r-r3fq/GHSA-mfpq-8q7r-r3fq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mm22-v222-j9xr/GHSA-mm22-v222-j9xr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mm8q-cf7f-pmxx/GHSA-mm8q-cf7f-pmxx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mr82-9g27-qr4x/GHSA-mr82-9g27-qr4x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mr98-5j2v-xqmf/GHSA-mr98-5j2v-xqmf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mw67-65x5-h28p/GHSA-mw67-65x5-h28p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mw9w-2x4j-fvhh/GHSA-mw9w-2x4j-fvhh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mxpv-cf8p-pfpr/GHSA-mxpv-cf8p-pfpr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p4w7-mhw7-7vgx/GHSA-p4w7-mhw7-7vgx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p528-mrgw-3q8p/GHSA-p528-mrgw-3q8p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p5fw-f837-j4p4/GHSA-p5fw-f837-j4p4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p7xw-hxjp-35w2/GHSA-p7xw-hxjp-35w2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p95j-mgmf-79p3/GHSA-p95j-mgmf-79p3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pcx5-cm5r-cf7f/GHSA-pcx5-cm5r-cf7f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ph5g-2r58-hm46/GHSA-ph5g-2r58-hm46.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pj5j-w7mw-w797/GHSA-pj5j-w7mw-w797.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pmp9-6wg3-93fg/GHSA-pmp9-6wg3-93fg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pr99-j37c-3mxj/GHSA-pr99-j37c-3mxj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pv98-6265-3prw/GHSA-pv98-6265-3prw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pvrw-g6fx-mcx2/GHSA-pvrw-g6fx-mcx2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pw2g-wqc9-f5g9/GHSA-pw2g-wqc9-f5g9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pwhp-27h2-crqj/GHSA-pwhp-27h2-crqj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q35r-v94g-2r69/GHSA-q35r-v94g-2r69.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q3x5-vwjf-49p2/GHSA-q3x5-vwjf-49p2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q443-qgfv-3fpg/GHSA-q443-qgfv-3fpg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q4gj-rcjg-xcwr/GHSA-q4gj-rcjg-xcwr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q6hv-g5mr-qgwf/GHSA-q6hv-g5mr-qgwf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q7wq-398w-6957/GHSA-q7wq-398w-6957.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q85c-wwvh-p49r/GHSA-q85c-wwvh-p49r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q89q-qv4f-qvr5/GHSA-q89q-qv4f-qvr5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q8j4-3fxm-87xm/GHSA-q8j4-3fxm-87xm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qcrm-cg47-3qvc/GHSA-qcrm-cg47-3qvc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qf9c-gmgf-6944/GHSA-qf9c-gmgf-6944.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qgvh-g2mh-jwfc/GHSA-qgvh-g2mh-jwfc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qh97-v4qr-2c8p/GHSA-qh97-v4qr-2c8p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qhw5-j89v-5fm3/GHSA-qhw5-j89v-5fm3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qjmr-8cf3-fcr8/GHSA-qjmr-8cf3-fcr8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qjxv-5m4x-5hpr/GHSA-qjxv-5m4x-5hpr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qm4q-mvq2-gj2r/GHSA-qm4q-mvq2-gj2r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qr78-7vm9-2fj7/GHSA-qr78-7vm9-2fj7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qwrg-xrq4-7mmv/GHSA-qwrg-xrq4-7mmv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r24m-v6jq-pp52/GHSA-r24m-v6jq-pp52.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r4cq-hxmv-g6f2/GHSA-r4cq-hxmv-g6f2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r5fc-xr2g-f58g/GHSA-r5fc-xr2g-f58g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r78m-94wm-v7cv/GHSA-r78m-94wm-v7cv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r89f-2wvr-q3c7/GHSA-r89f-2wvr-q3c7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r8g3-9qxx-g5x2/GHSA-r8g3-9qxx-g5x2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r946-wxvm-h3vx/GHSA-r946-wxvm-h3vx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rc73-rxx3-qqfc/GHSA-rc73-rxx3-qqfc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rpx4-39vw-744p/GHSA-rpx4-39vw-744p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rrwm-2vxq-5x2h/GHSA-rrwm-2vxq-5x2h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rv59-78h6-2m84/GHSA-rv59-78h6-2m84.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rvvq-r3qv-fpwc/GHSA-rvvq-r3qv-fpwc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rw86-cvx5-q4pj/GHSA-rw86-cvx5-q4pj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v46q-m532-mg39/GHSA-v46q-m532-mg39.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v625-qcpp-j2vf/GHSA-v625-qcpp-j2vf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v63h-22hj-7hmg/GHSA-v63h-22hj-7hmg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v762-h4q2-77wx/GHSA-v762-h4q2-77wx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v77g-284c-r623/GHSA-v77g-284c-r623.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v8c5-pw83-p6v7/GHSA-v8c5-pw83-p6v7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v95r-pfp9-xw8f/GHSA-v95r-pfp9-xw8f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vcj3-36cm-3c25/GHSA-vcj3-36cm-3c25.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vmwx-8pmg-4mrr/GHSA-vmwx-8pmg-4mrr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vq77-w3cf-rw37/GHSA-vq77-w3cf-rw37.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vrpm-3gh9-qhp6/GHSA-vrpm-3gh9-qhp6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vw69-xjfm-55g4/GHSA-vw69-xjfm-55g4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vwqg-h7r8-fqcg/GHSA-vwqg-h7r8-fqcg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vx3x-c4x9-q8p5/GHSA-vx3x-c4x9-q8p5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vxfj-h2jv-2pgr/GHSA-vxfj-h2jv-2pgr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w2x5-hpmg-j98h/GHSA-w2x5-hpmg-j98h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w35h-r9ff-45q4/GHSA-w35h-r9ff-45q4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w3rw-649p-m947/GHSA-w3rw-649p-m947.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w745-xjqx-7wp8/GHSA-w745-xjqx-7wp8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w8gp-g46m-jhvc/GHSA-w8gp-g46m-jhvc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wf8m-qr47-xc9m/GHSA-wf8m-qr47-xc9m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wf94-5wvh-jmpc/GHSA-wf94-5wvh-jmpc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-whp2-gjjf-pvgr/GHSA-whp2-gjjf-pvgr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wjg8-pxqj-c3c7/GHSA-wjg8-pxqj-c3c7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wmg5-g953-qqfw/GHSA-wmg5-g953-qqfw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wmqm-3p7c-c6j7/GHSA-wmqm-3p7c-c6j7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wpfp-vfwj-4xwh/GHSA-wpfp-vfwj-4xwh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wr5x-fcf4-h5qm/GHSA-wr5x-fcf4-h5qm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wrhx-52hg-crxx/GHSA-wrhx-52hg-crxx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x84r-jrqm-3hj8/GHSA-x84r-jrqm-3hj8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x8qw-cfcr-6hhp/GHSA-x8qw-cfcr-6hhp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x8xh-hfg5-qrf9/GHSA-x8xh-hfg5-qrf9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x9qv-5m74-x74p/GHSA-x9qv-5m74-x74p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xc7w-hcqx-q2x3/GHSA-xc7w-hcqx-q2x3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xg39-26cw-gxj9/GHSA-xg39-26cw-gxj9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xgw4-pcqh-286r/GHSA-xgw4-pcqh-286r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xhm2-m35v-2xw7/GHSA-xhm2-m35v-2xw7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xjhw-7765-363q/GHSA-xjhw-7765-363q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xjvc-8mfj-g22v/GHSA-xjvc-8mfj-g22v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xmvp-p4p2-hprq/GHSA-xmvp-p4p2-hprq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xv45-qm36-h77q/GHSA-xv45-qm36-h77q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xw8j-xwwr-8vqj/GHSA-xw8j-xwwr-8vqj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xwf7-9xfx-ghmm/GHSA-xwf7-9xfx-ghmm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xwp2-26xm-vq22/GHSA-xwp2-26xm-vq22.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xxmc-mjxm-2m5r/GHSA-xxmc-mjxm-2m5r.json diff --git a/advisories/unreviewed/2023/07/GHSA-2225-fj3w-f9wh/GHSA-2225-fj3w-f9wh.json b/advisories/unreviewed/2023/07/GHSA-2225-fj3w-f9wh/GHSA-2225-fj3w-f9wh.json new file mode 100644 index 00000000000..59d25499834 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2225-fj3w-f9wh/GHSA-2225-fj3w-f9wh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2225-fj3w-f9wh", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-46854" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46854" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/launchpad-by-obox/wordpress-launchpad-plugin-1-0-13-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-17T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-225p-3jp7-q6p8/GHSA-225p-3jp7-q6p8.json b/advisories/unreviewed/2023/07/GHSA-225p-3jp7-q6p8/GHSA-225p-3jp7-q6p8.json new file mode 100644 index 00000000000..0d77b853f84 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-225p-3jp7-q6p8/GHSA-225p-3jp7-q6p8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-225p-3jp7-q6p8", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-1252" + ], + "details": "A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with the overlay FS usage. This flaw allows a local user to crash or potentially escalate their privileges on the system. Only if patch 9a2544037600 (\"ovl: fix use after free in struct ovl_aio_req\") not applied yet, the kernel could be affected.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1252" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/20211115165433.449951285@linuxfoundation.org/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2332-v8xq-hpvx/GHSA-2332-v8xq-hpvx.json b/advisories/unreviewed/2023/07/GHSA-2332-v8xq-hpvx/GHSA-2332-v8xq-hpvx.json new file mode 100644 index 00000000000..89fc6c41cff --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2332-v8xq-hpvx/GHSA-2332-v8xq-hpvx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2332-v8xq-hpvx", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22939" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search [bypass SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards). The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22939" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0209" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-25c8-qcqq-xpqw/GHSA-25c8-qcqq-xpqw.json b/advisories/unreviewed/2023/07/GHSA-25c8-qcqq-xpqw/GHSA-25c8-qcqq-xpqw.json new file mode 100644 index 00000000000..166cd1f4bac --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-25c8-qcqq-xpqw/GHSA-25c8-qcqq-xpqw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25c8-qcqq-xpqw", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-38104" + ], + "details": "Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38104" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-plugin-2-0-3-authenticated-wordpress-options-change-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/accordions-or-faqs/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-21T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-25xf-r6x8-6fw5/GHSA-25xf-r6x8-6fw5.json b/advisories/unreviewed/2023/07/GHSA-25xf-r6x8-6fw5/GHSA-25xf-r6x8-6fw5.json new file mode 100644 index 00000000000..babfbd1556f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-25xf-r6x8-6fw5/GHSA-25xf-r6x8-6fw5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25xf-r6x8-6fw5", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-0775" + ], + "details": "An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0775" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/gecko_sdk" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/0698Y00000SMMyGQAX?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-28T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-28fv-gqcc-g6m7/GHSA-28fv-gqcc-g6m7.json b/advisories/unreviewed/2023/07/GHSA-28fv-gqcc-g6m7/GHSA-28fv-gqcc-g6m7.json new file mode 100644 index 00000000000..ae7cfcee231 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-28fv-gqcc-g6m7/GHSA-28fv-gqcc-g6m7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28fv-gqcc-g6m7", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-34148" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/backup/wordpress-backup-guard-plugin-1-6-8-8-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-15T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-28gc-rmm6-hmpv/GHSA-28gc-rmm6-hmpv.json b/advisories/unreviewed/2023/07/GHSA-28gc-rmm6-hmpv/GHSA-28gc-rmm6-hmpv.json new file mode 100644 index 00000000000..c13e9d09455 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-28gc-rmm6-hmpv/GHSA-28gc-rmm6-hmpv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28gc-rmm6-hmpv", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-32776" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-ads/wordpress-advanced-ads-ad-manager-adsense-plugin-1-31-1-authenticated-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/advanced-ads/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-08T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-292m-p3v4-44h4/GHSA-292m-p3v4-44h4.json b/advisories/unreviewed/2023/07/GHSA-292m-p3v4-44h4/GHSA-292m-p3v4-44h4.json new file mode 100644 index 00000000000..74690d05e56 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-292m-p3v4-44h4/GHSA-292m-p3v4-44h4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-292m-p3v4-44h4", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-3424" + ], + "details": "A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3424" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/643a16a0eb1d6ac23744bb6e90a00fc21148a9dc" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2132640" + }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/20221019031445.901570-1-zyytlz.wz@163.com/" + }, + { + "type": "WEB", + "url": "https://www.spinics.net/lists/kernel/msg4518970.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-06T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-29wx-wghr-g778/GHSA-29wx-wghr-g778.json b/advisories/unreviewed/2023/07/GHSA-29wx-wghr-g778/GHSA-29wx-wghr-g778.json new file mode 100644 index 00000000000..3f0519c322b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-29wx-wghr-g778/GHSA-29wx-wghr-g778.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29wx-wghr-g778", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-47608" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47608" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/quick-contact-form/wordpress-quick-contact-form-plugin-8-0-3-1-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2cvp-672x-8283/GHSA-2cvp-672x-8283.json b/advisories/unreviewed/2023/07/GHSA-2cvp-672x-8283/GHSA-2cvp-672x-8283.json new file mode 100644 index 00000000000..586123f6e7d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2cvp-672x-8283/GHSA-2cvp-672x-8283.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cvp-672x-8283", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2022-43480" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/homepage-pop-up/wordpress-homepage-pop-up-plugin-1-2-5-unauth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2gv8-jcpw-2qg2/GHSA-2gv8-jcpw-2qg2.json b/advisories/unreviewed/2023/07/GHSA-2gv8-jcpw-2qg2/GHSA-2gv8-jcpw-2qg2.json new file mode 100644 index 00000000000..9db2e741120 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2gv8-jcpw-2qg2/GHSA-2gv8-jcpw-2qg2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gv8-jcpw-2qg2", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-22698" + ], + "details": "Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22698" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/theme-blvd-responsive-google-maps/wordpress-theme-blvd-responsive-google-maps-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2jq7-x2v9-98wx/GHSA-2jq7-x2v9-98wx.json b/advisories/unreviewed/2023/07/GHSA-2jq7-x2v9-98wx/GHSA-2jq7-x2v9-98wx.json new file mode 100644 index 00000000000..5b43be45d25 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2jq7-x2v9-98wx/GHSA-2jq7-x2v9-98wx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jq7-x2v9-98wx", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-22901" + ], + "details": "ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22901" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7022-2cbe0-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2m88-5j35-4r5m/GHSA-2m88-5j35-4r5m.json b/advisories/unreviewed/2023/07/GHSA-2m88-5j35-4r5m/GHSA-2m88-5j35-4r5m.json new file mode 100644 index 00000000000..02e4a5028bc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2m88-5j35-4r5m/GHSA-2m88-5j35-4r5m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m88-5j35-4r5m", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2020-36669" + ], + "details": "The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9. This is due to missing nonce validation on the backup_guard_get_import_backup() function. This makes it possible for unauthenticated attackers to upload arbitrary files to the vulnerable site's server via a forged request, granted they can trick a site's administrator into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36669" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2341420" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ae8de00-ba4c-48d2-a566-13dac0bc4312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-07T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2mxh-qvf4-48jc/GHSA-2mxh-qvf4-48jc.json b/advisories/unreviewed/2023/07/GHSA-2mxh-qvf4-48jc/GHSA-2mxh-qvf4-48jc.json new file mode 100644 index 00000000000..72675acd852 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2mxh-qvf4-48jc/GHSA-2mxh-qvf4-48jc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mxh-qvf4-48jc", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-43376" + ], + "details": "\n\n\nA CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site\nScripting') vulnerability exists that could cause code and session manipulation when malicious\ncode is inserted into the browser.\n\n Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0\n\n and prior)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43376" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-312-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2pg6-wjcp-mmcq/GHSA-2pg6-wjcp-mmcq.json b/advisories/unreviewed/2023/07/GHSA-2pg6-wjcp-mmcq/GHSA-2pg6-wjcp-mmcq.json new file mode 100644 index 00000000000..66c95dbebf7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2pg6-wjcp-mmcq/GHSA-2pg6-wjcp-mmcq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pg6-wjcp-mmcq", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-0814" + ], + "details": "The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account. This does require the Usermeta shortcode be enabled to be exploited.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0814" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2864329%40profile-builder&new=2864329%40profile-builder&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bbedad66-a5a6-4fb5-b03e-0ecf9fbef19a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T02:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json b/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json new file mode 100644 index 00000000000..d7d8f483a12 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2r3h-3gcc-24g5/GHSA-2r3h-3gcc-24g5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r3h-3gcc-24g5", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2023-0524" + ], + "details": "As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several defense-in-depth fixes alongside. While the probability of successful exploitation is low, Tenable is committed to securing our customers’ environments and our products. The updates have been distributed via the Tenable plugin feed in feed serial numbers equal to or greater than #202212212055.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0524" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2023-04" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-01T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2vhr-q545-p6f9/GHSA-2vhr-q545-p6f9.json b/advisories/unreviewed/2023/07/GHSA-2vhr-q545-p6f9/GHSA-2vhr-q545-p6f9.json new file mode 100644 index 00000000000..df0bf6530a2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2vhr-q545-p6f9/GHSA-2vhr-q545-p6f9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vhr-q545-p6f9", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-27485" + ], + "details": "A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read permission to retrieve arbitrary files from the underlying Linux system via a crafted HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27485" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-060" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2wfq-2vjq-pr3g/GHSA-2wfq-2vjq-pr3g.json b/advisories/unreviewed/2023/07/GHSA-2wfq-2vjq-pr3g/GHSA-2wfq-2vjq-pr3g.json new file mode 100644 index 00000000000..c1bab9c9f79 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2wfq-2vjq-pr3g/GHSA-2wfq-2vjq-pr3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wfq-2vjq-pr3g", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-40741" + ], + "details": "Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40741" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6643-89bfa-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-31T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2wjq-7fcc-4p8f/GHSA-2wjq-7fcc-4p8f.json b/advisories/unreviewed/2023/07/GHSA-2wjq-7fcc-4p8f/GHSA-2wjq-7fcc-4p8f.json new file mode 100644 index 00000000000..c6f51380dfa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2wjq-7fcc-4p8f/GHSA-2wjq-7fcc-4p8f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wjq-7fcc-4p8f", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-38117" + ], + "details": "Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38117" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6630-d4d2f-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-24T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-325j-rfjm-895c/GHSA-325j-rfjm-895c.json b/advisories/unreviewed/2023/07/GHSA-325j-rfjm-895c/GHSA-325j-rfjm-895c.json new file mode 100644 index 00000000000..961af15ced7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-325j-rfjm-895c/GHSA-325j-rfjm-895c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-325j-rfjm-895c", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-24386" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Karishma Arora AI Contact Us Form plugin <= 1.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24386" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ai-contact-us/wordpress-ai-contact-us-form-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-32pr-mxf9-qhx8/GHSA-32pr-mxf9-qhx8.json b/advisories/unreviewed/2023/07/GHSA-32pr-mxf9-qhx8/GHSA-32pr-mxf9-qhx8.json new file mode 100644 index 00000000000..b5a6b70736d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-32pr-mxf9-qhx8/GHSA-32pr-mxf9-qhx8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32pr-mxf9-qhx8", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-43455" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, service_stop, and service_restart modules of the software. This could allow an attacker to start, stop, or restart arbitrary services running on the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43455" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-339h-hwgh-x2jc/GHSA-339h-hwgh-x2jc.json b/advisories/unreviewed/2023/07/GHSA-339h-hwgh-x2jc/GHSA-339h-hwgh-x2jc.json new file mode 100644 index 00000000000..349e60a9210 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-339h-hwgh-x2jc/GHSA-339h-hwgh-x2jc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-339h-hwgh-x2jc", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-32515" + ], + "details": "A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32515" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-03_ConextCombox_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-33j2-92xf-fwm3/GHSA-33j2-92xf-fwm3.json b/advisories/unreviewed/2023/07/GHSA-33j2-92xf-fwm3/GHSA-33j2-92xf-fwm3.json new file mode 100644 index 00000000000..3781f4f533c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-33j2-92xf-fwm3/GHSA-33j2-92xf-fwm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33j2-92xf-fwm3", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2197" + ], + "details": "HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechanisms. An attacker with privileges to modify storage and restart Vault may be able to intercept or modify cipher text in order to derive Vault’s root key. Fixed in 1.13.2", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2197" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2023-14-vault-enterprise-vulnerable-to-padding-oracle-attacks-when-using-a-cbc-based-encryption-mechanism-with-a-hsm/53322" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3474-xv2c-f5g9/GHSA-3474-xv2c-f5g9.json b/advisories/unreviewed/2023/07/GHSA-3474-xv2c-f5g9/GHSA-3474-xv2c-f5g9.json new file mode 100644 index 00000000000..81ee5b0eda9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3474-xv2c-f5g9/GHSA-3474-xv2c-f5g9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3474-xv2c-f5g9", + "modified": "2023-07-06T19:24:20Z", + "published": "2023-07-06T19:24:20Z", + "aliases": [ + "CVE-2023-25784" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bon Plan Gratos Sticky Ad Bar plugin <= 1.3.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25784" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sticky-ad-bar/wordpress-sticky-ad-bar-plugin-plugin-1-3-1-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-34gf-pfjm-cq2w/GHSA-34gf-pfjm-cq2w.json b/advisories/unreviewed/2023/07/GHSA-34gf-pfjm-cq2w/GHSA-34gf-pfjm-cq2w.json new file mode 100644 index 00000000000..8bbe0a74849 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-34gf-pfjm-cq2w/GHSA-34gf-pfjm-cq2w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34gf-pfjm-cq2w", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-22917" + ], + "details": "A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22917" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-35v3-mvqh-7ffm/GHSA-35v3-mvqh-7ffm.json b/advisories/unreviewed/2023/07/GHSA-35v3-mvqh-7ffm/GHSA-35v3-mvqh-7ffm.json new file mode 100644 index 00000000000..75eeb171156 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-35v3-mvqh-7ffm/GHSA-35v3-mvqh-7ffm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35v3-mvqh-7ffm", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-23817" + ], + "details": "Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-pdf-viewer/wordpress-simple-pdf-viewer-plugin-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json b/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json new file mode 100644 index 00000000000..d51204eef29 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36g9-fjvv-qmj3", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27909" + ], + "details": "An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27909" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0004" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-378h-jm2h-7wrm/GHSA-378h-jm2h-7wrm.json b/advisories/unreviewed/2023/07/GHSA-378h-jm2h-7wrm/GHSA-378h-jm2h-7wrm.json new file mode 100644 index 00000000000..7b7ece28985 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-378h-jm2h-7wrm/GHSA-378h-jm2h-7wrm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-378h-jm2h-7wrm", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-0645" + ], + "details": "An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0645" + }, + { + "type": "WEB", + "url": "https://github.com/libjxl/libjxl/pull/2101" + }, + { + "type": "WEB", + "url": "https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3883-h64p-r3xm/GHSA-3883-h64p-r3xm.json b/advisories/unreviewed/2023/07/GHSA-3883-h64p-r3xm/GHSA-3883-h64p-r3xm.json new file mode 100644 index 00000000000..5f72d432ace --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3883-h64p-r3xm/GHSA-3883-h64p-r3xm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3883-h64p-r3xm", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-43781" + ], + "details": "There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43781" + }, + { + "type": "WEB", + "url": "https://confluence.atlassian.com/x/Y4hXRg" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/BSERV-13522" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T00:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json b/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json new file mode 100644 index 00000000000..f6f2d2aaafa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-38v3-cwq5-jprx/GHSA-38v3-cwq5-jprx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38v3-cwq5-jprx", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-31364" + ], + "details": "Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered by sending a series of segmented packets with inconsistent SegN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31364" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1tCJg1uBYtfx4SNvewWPNXd7PB6Z__iiG/edit" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-01T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3957-gqh2-v47w/GHSA-3957-gqh2-v47w.json b/advisories/unreviewed/2023/07/GHSA-3957-gqh2-v47w/GHSA-3957-gqh2-v47w.json new file mode 100644 index 00000000000..ec6c1ebd039 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3957-gqh2-v47w/GHSA-3957-gqh2-v47w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3957-gqh2-v47w", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-23832" + ], + "details": "Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-wp-query-search-filter/wordpress-ultimate-wp-query-search-filter-plugin-1-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json b/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json new file mode 100644 index 00000000000..48079a9c2b0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-399c-6449-xhh6/GHSA-399c-6449-xhh6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-399c-6449-xhh6", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-25836" + ], + "details": "Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Responder and brute forces the Passkey entered by the user into the Initiator. The MITM attacker can use the identified Passkey value to complete authentication with the Responder via Bluetooth pairing method confusion.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25836" + }, + { + "type": "WEB", + "url": "https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-12T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json b/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json new file mode 100644 index 00000000000..7a963ddf76d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3chx-g7jg-4263/GHSA-3chx-g7jg-4263.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3chx-g7jg-4263", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-1073" + ], + "details": "A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1073" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2173403" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/id=b12fece4c64857e5fab4290bf01b2e0317a88456" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/osssecurity/2023/01/17/3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3gqj-h989-pgq3/GHSA-3gqj-h989-pgq3.json b/advisories/unreviewed/2023/07/GHSA-3gqj-h989-pgq3/GHSA-3gqj-h989-pgq3.json new file mode 100644 index 00000000000..76c18297097 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3gqj-h989-pgq3/GHSA-3gqj-h989-pgq3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gqj-h989-pgq3", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-33179" + ], + "details": "A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33179" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2079" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3jhh-jx96-63p5/GHSA-3jhh-jx96-63p5.json b/advisories/unreviewed/2023/07/GHSA-3jhh-jx96-63p5/GHSA-3jhh-jx96-63p5.json new file mode 100644 index 00000000000..a56d6cbee4b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3jhh-jx96-63p5/GHSA-3jhh-jx96-63p5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jhh-jx96-63p5", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-38120" + ], + "details": "UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38120" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6679-a0695-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-10T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3m5j-rg6q-w4gv/GHSA-3m5j-rg6q-w4gv.json b/advisories/unreviewed/2023/07/GHSA-3m5j-rg6q-w4gv/GHSA-3m5j-rg6q-w4gv.json new file mode 100644 index 00000000000..e056098d782 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3m5j-rg6q-w4gv/GHSA-3m5j-rg6q-w4gv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m5j-rg6q-w4gv", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-45820" + ], + "details": "SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45820" + }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/multiple-critical-vulnerabilities-fixed-in-learnpress-plugin-version/" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-plugin-4-1-7-3-2-auth-sql-injection-sqli-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-26T21:17:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3m9g-2gcx-74c7/GHSA-3m9g-2gcx-74c7.json b/advisories/unreviewed/2023/07/GHSA-3m9g-2gcx-74c7/GHSA-3m9g-2gcx-74c7.json new file mode 100644 index 00000000000..738210044f9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3m9g-2gcx-74c7/GHSA-3m9g-2gcx-74c7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m9g-2gcx-74c7", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-40697" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugin <= 3.4.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40697" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/3com-asesor-de-cookies/wordpress-3com-asesor-de-cookies-plugin-3-4-3-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-19T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3pc2-c878-63rj/GHSA-3pc2-c878-63rj.json b/advisories/unreviewed/2023/07/GHSA-3pc2-c878-63rj/GHSA-3pc2-c878-63rj.json new file mode 100644 index 00000000000..be7e42eca03 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3pc2-c878-63rj/GHSA-3pc2-c878-63rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pc2-c878-63rj", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-22914" + ], + "details": "A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22914" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3pqj-4h6v-gq86/GHSA-3pqj-4h6v-gq86.json b/advisories/unreviewed/2023/07/GHSA-3pqj-4h6v-gq86/GHSA-3pqj-4h6v-gq86.json new file mode 100644 index 00000000000..4f2301fc511 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3pqj-4h6v-gq86/GHSA-3pqj-4h6v-gq86.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pqj-4h6v-gq86", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-23973" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23973" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-us-page-contact-people/wordpress-contact-us-page-contact-people-plugin-3-7-0-cross-site-request-forgery-csrf-leading-to-contact-creation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3q3r-47jp-8cqm/GHSA-3q3r-47jp-8cqm.json b/advisories/unreviewed/2023/07/GHSA-3q3r-47jp-8cqm/GHSA-3q3r-47jp-8cqm.json new file mode 100644 index 00000000000..469390b0d52 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3q3r-47jp-8cqm/GHSA-3q3r-47jp-8cqm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q3r-47jp-8cqm", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-4619" + ], + "details": "The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4619" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/codelights-shortcodes-and-widgets/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3feb84c9-fc98-4f59-a124-b6434e5b8a44" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-20T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3r22-jvx3-7mjc/GHSA-3r22-jvx3-7mjc.json b/advisories/unreviewed/2023/07/GHSA-3r22-jvx3-7mjc/GHSA-3r22-jvx3-7mjc.json new file mode 100644 index 00000000000..dd4b9894d39 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3r22-jvx3-7mjc/GHSA-3r22-jvx3-7mjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r22-jvx3-7mjc", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-34755" + ], + "details": "\nA CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker\nwith a local privileged account to place a specially crafted file on the target machine, which may\ngive the attacker the ability to execute arbitrary code during the installation process initiated by a\nvalid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34755" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-06.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3r96-2j24-682p/GHSA-3r96-2j24-682p.json b/advisories/unreviewed/2023/07/GHSA-3r96-2j24-682p/GHSA-3r96-2j24-682p.json new file mode 100644 index 00000000000..e5b1136c7ec --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3r96-2j24-682p/GHSA-3r96-2j24-682p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r96-2j24-682p", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-36401" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36401" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-wallet/wordpress-terawallet-for-woocommerce-plugin-1-3-24-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-02T21:22:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3w99-5f2g-rxfc/GHSA-3w99-5f2g-rxfc.json b/advisories/unreviewed/2023/07/GHSA-3w99-5f2g-rxfc/GHSA-3w99-5f2g-rxfc.json new file mode 100644 index 00000000000..1cc2ef0eda4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3w99-5f2g-rxfc/GHSA-3w99-5f2g-rxfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w99-5f2g-rxfc", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-38209" + ], + "details": "There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38209" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2022-update-2-patch-is-now-available" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3x77-v8f7-wp2v/GHSA-3x77-v8f7-wp2v.json b/advisories/unreviewed/2023/07/GHSA-3x77-v8f7-wp2v/GHSA-3x77-v8f7-wp2v.json new file mode 100644 index 00000000000..51223586a8c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3x77-v8f7-wp2v/GHSA-3x77-v8f7-wp2v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x77-v8f7-wp2v", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-22707" + ], + "details": "Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22707" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/greenshift-animation-and-page-builder-blocks/wordpress-greenshift-animation-and-page-builder-blocks-plugin-4-9-9-svg-upload-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3xrr-7m6p-p7xh/GHSA-3xrr-7m6p-p7xh.json b/advisories/unreviewed/2023/07/GHSA-3xrr-7m6p-p7xh/GHSA-3xrr-7m6p-p7xh.json new file mode 100644 index 00000000000..b4aeb32191f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3xrr-7m6p-p7xh/GHSA-3xrr-7m6p-p7xh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xrr-7m6p-p7xh", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-26119" + ], + "details": "Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26119" + }, + { + "type": "WEB", + "url": "https://github.com/HtmlUnit/htmlunit/commit/641325bbc84702dc9800ec7037aec061ce21956b" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEHTMLUNIT-3252500" + }, + { + "type": "WEB", + "url": "https://siebene.github.io/2022/12/30/HtmlUnit-RCE/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T05:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-42m7-x4gf-gj25/GHSA-42m7-x4gf-gj25.json b/advisories/unreviewed/2023/07/GHSA-42m7-x4gf-gj25/GHSA-42m7-x4gf-gj25.json new file mode 100644 index 00000000000..09d54cd57eb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-42m7-x4gf-gj25/GHSA-42m7-x4gf-gj25.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42m7-x4gf-gj25", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-29067" + ], + "details": "A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29067" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json b/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json new file mode 100644 index 00000000000..54bc40aa85b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42mr-mfcr-7jqh", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-43557" + ], + "details": "The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43557" + }, + { + "type": "WEB", + "url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-bodyguard-pumps-rs-232-interface-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-05T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json b/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json new file mode 100644 index 00000000000..ce17d238b90 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-433q-36rv-j5jj", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0053" + ], + "details": "SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive information such as user credentials to gain access to the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0053" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-02T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json b/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json new file mode 100644 index 00000000000..70fcca92a23 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4446-w42r-xvj9/GHSA-4446-w42r-xvj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4446-w42r-xvj9", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-25626" + ], + "details": "An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25626" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/21136" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-16T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4683-xj3v-wqvf/GHSA-4683-xj3v-wqvf.json b/advisories/unreviewed/2023/07/GHSA-4683-xj3v-wqvf/GHSA-4683-xj3v-wqvf.json new file mode 100644 index 00000000000..555302b2407 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4683-xj3v-wqvf/GHSA-4683-xj3v-wqvf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4683-xj3v-wqvf", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-1831" + ], + "details": "Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1831" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-17T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-492f-248q-vxpp/GHSA-492f-248q-vxpp.json b/advisories/unreviewed/2023/07/GHSA-492f-248q-vxpp/GHSA-492f-248q-vxpp.json new file mode 100644 index 00000000000..714765e13ca --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-492f-248q-vxpp/GHSA-492f-248q-vxpp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-492f-248q-vxpp", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-38467" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38467" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crm-perks-forms/wordpress-crm-perks-forms-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-14T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-493h-rq8m-6xjp/GHSA-493h-rq8m-6xjp.json b/advisories/unreviewed/2023/07/GHSA-493h-rq8m-6xjp/GHSA-493h-rq8m-6xjp.json new file mode 100644 index 00000000000..516fa7aceff --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-493h-rq8m-6xjp/GHSA-493h-rq8m-6xjp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-493h-rq8m-6xjp", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-1617" + ], + "details": "Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality provided in the visualization.\nThis issue affects B&R VC4: from 3.* through 3.96.7, from 4.0* through 4.06.7, from 4.1* through 4.16.3, from 4.2* through 4.26.8, from 4.3* through 4.34.6, from 4.4* through 4.45.1, from 4.5* through 4.45.3, from 4.7* through 4.72.9.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1617" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/downloads_br_productcatalogue/assets/1681046878970-en-original-1.0.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-495g-cppx-r4mf/GHSA-495g-cppx-r4mf.json b/advisories/unreviewed/2023/07/GHSA-495g-cppx-r4mf/GHSA-495g-cppx-r4mf.json new file mode 100644 index 00000000000..14dd1c161f4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-495g-cppx-r4mf/GHSA-495g-cppx-r4mf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-495g-cppx-r4mf", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-2474" + ], + "details": "Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2474" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-28T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-49jr-333r-mqw3/GHSA-49jr-333r-mqw3.json b/advisories/unreviewed/2023/07/GHSA-49jr-333r-mqw3/GHSA-49jr-333r-mqw3.json new file mode 100644 index 00000000000..06f3ce95b34 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-49jr-333r-mqw3/GHSA-49jr-333r-mqw3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49jr-333r-mqw3", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-42733" + ], + "details": "A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42733" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-741697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-49r3-jh88-8r77/GHSA-49r3-jh88-8r77.json b/advisories/unreviewed/2023/07/GHSA-49r3-jh88-8r77/GHSA-49r3-jh88-8r77.json new file mode 100644 index 00000000000..467db09ebc0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-49r3-jh88-8r77/GHSA-49r3-jh88-8r77.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49r3-jh88-8r77", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-30869" + ], + "details": "Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/critical-easy-digital-downloads-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-1-1-4-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4fgf-f97h-jg4p/GHSA-4fgf-f97h-jg4p.json b/advisories/unreviewed/2023/07/GHSA-4fgf-f97h-jg4p/GHSA-4fgf-f97h-jg4p.json new file mode 100644 index 00000000000..3f55187ada2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4fgf-f97h-jg4p/GHSA-4fgf-f97h-jg4p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fgf-f97h-jg4p", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-38210" + ], + "details": "There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a remote, unauthenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38210" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2022-update-2-patch-is-now-available" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4fgv-8448-gf82/GHSA-4fgv-8448-gf82.json b/advisories/unreviewed/2023/07/GHSA-4fgv-8448-gf82/GHSA-4fgv-8448-gf82.json new file mode 100644 index 00000000000..ac03bbb46cb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4fgv-8448-gf82/GHSA-4fgv-8448-gf82.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fgv-8448-gf82", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-32171" + ], + "details": "In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to access the user’s credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32171" + }, + { + "type": "WEB", + "url": "https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d" + }, + { + "type": "WEB", + "url": "https://www.mend.io/vulnerability-database/CVE-2022-32171" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-06T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4fhj-86f2-v36p/GHSA-4fhj-86f2-v36p.json b/advisories/unreviewed/2023/07/GHSA-4fhj-86f2-v36p/GHSA-4fhj-86f2-v36p.json new file mode 100644 index 00000000000..59a670b8948 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4fhj-86f2-v36p/GHSA-4fhj-86f2-v36p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fhj-86f2-v36p", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-2482" + ], + "details": "A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2482" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1274" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-06T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4fvv-j62f-2gpq/GHSA-4fvv-j62f-2gpq.json b/advisories/unreviewed/2023/07/GHSA-4fvv-j62f-2gpq/GHSA-4fvv-j62f-2gpq.json new file mode 100644 index 00000000000..6edab60f190 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4fvv-j62f-2gpq/GHSA-4fvv-j62f-2gpq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fvv-j62f-2gpq", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-23707" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin <= 2.7.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23707" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/embed-any-document/wordpress-embed-any-document-embed-pdf-word-powerpoint-and-excel-files-plugin-2-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4hvh-86q3-7h55/GHSA-4hvh-86q3-7h55.json b/advisories/unreviewed/2023/07/GHSA-4hvh-86q3-7h55/GHSA-4hvh-86q3-7h55.json new file mode 100644 index 00000000000..f35965e4a46 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4hvh-86q3-7h55/GHSA-4hvh-86q3-7h55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hvh-86q3-7h55", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27914" + ], + "details": "A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27914" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4hw7-4w59-f39j/GHSA-4hw7-4w59-f39j.json b/advisories/unreviewed/2023/07/GHSA-4hw7-4w59-f39j/GHSA-4hw7-4w59-f39j.json new file mode 100644 index 00000000000..47bbd3e3d77 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4hw7-4w59-f39j/GHSA-4hw7-4w59-f39j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hw7-4w59-f39j", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-41679" + ], + "details": "Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote attacker to inject javascript code on the “back_url” parameter in appLms/index.php?modname=faq&op=play function. The exploitation of this vulnerability could allow an attacker to steal the user´s cookies in order to log in to the application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41679" + }, + { + "type": "WEB", + "url": "https://www.incibe-cert.es/en/early-warning/security-advisories/multiple-vulnerabilities-forma-lms" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-31T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4mx2-p3fc-wx76/GHSA-4mx2-p3fc-wx76.json b/advisories/unreviewed/2023/07/GHSA-4mx2-p3fc-wx76/GHSA-4mx2-p3fc-wx76.json new file mode 100644 index 00000000000..2d77ce30e4e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4mx2-p3fc-wx76/GHSA-4mx2-p3fc-wx76.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mx2-p3fc-wx76", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-38971" + ], + "details": "Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38971" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/buddyforms/wordpress-buddyforms-plugin-2-7-2-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4pmf-3p6f-p5g2/GHSA-4pmf-3p6f-p5g2.json b/advisories/unreviewed/2023/07/GHSA-4pmf-3p6f-p5g2/GHSA-4pmf-3p6f-p5g2.json new file mode 100644 index 00000000000..bf6d7ff0dd9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4pmf-3p6f-p5g2/GHSA-4pmf-3p6f-p5g2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmf-3p6f-p5g2", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-47917" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to several modules and services of the software. This could allow an attacker to delete arbitrary files and cause a denial-of-service condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47917" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4pwc-87fv-q86q/GHSA-4pwc-87fv-q86q.json b/advisories/unreviewed/2023/07/GHSA-4pwc-87fv-q86q/GHSA-4pwc-87fv-q86q.json new file mode 100644 index 00000000000..d7b36cee168 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4pwc-87fv-q86q/GHSA-4pwc-87fv-q86q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pwc-87fv-q86q", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-3480" + ], + "details": "A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3480" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2022-051/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-15T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4r87-mf97-8jj9/GHSA-4r87-mf97-8jj9.json b/advisories/unreviewed/2023/07/GHSA-4r87-mf97-8jj9/GHSA-4r87-mf97-8jj9.json new file mode 100644 index 00000000000..42618fce20d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4r87-mf97-8jj9/GHSA-4r87-mf97-8jj9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r87-mf97-8jj9", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22942" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway (SSG) app in the ‘kvstore_client’ REST endpoint lets a potential attacker update SSG [App Key Value Store (KV store)](https://docs.splunk.com/Documentation/Splunk/latest/Admin/AboutKVstore) collections using an HTTP GET request. SSG is a Splunk-built app that comes with Splunk Enterprise. The vulnerability affects instances with SSG and Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22942" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0212" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/4742d5f7-ce00-45ce-9c79-5e98b43b4410/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4rcg-xhqc-237v/GHSA-4rcg-xhqc-237v.json b/advisories/unreviewed/2023/07/GHSA-4rcg-xhqc-237v/GHSA-4rcg-xhqc-237v.json new file mode 100644 index 00000000000..ac38d55039a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4rcg-xhqc-237v/GHSA-4rcg-xhqc-237v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rcg-xhqc-237v", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2022-38468" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38468" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nextgen-gallery/wordpress-wordpress-gallery-plugin-nextgen-gallery-plugin-3-28-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json b/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json new file mode 100644 index 00000000000..1a4464a6749 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vhv-9xc2-4v6w", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-47208" + ], + "details": "The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47208" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2022-37" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-16T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json b/advisories/unreviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json new file mode 100644 index 00000000000..01df2a8a183 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vrv-93c7-m92j", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-24441" + ], + "details": "The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges of the application. This vulnerability may be triggered when running the the CLI tool directly, or when running a scan with one of the IDE plugins that invoke the Snyk CLI. Successful exploitation of this issue would likely require some level of social engineering - to coerce an untrusted project to be downloaded and analyzed via the Snyk CLI or opened in an IDE where a Snyk IDE plugin is installed and enabled. Additionally, if the IDE has a Trust feature then the target folder must be marked as ‘trusted’ in order to be vulnerable. **NOTE:** This issue is independent of the one reported in [CVE-2022-40764](https://security.snyk.io/vuln/SNYK-JS-SNYK-3037342), and upgrading to a fixed version for this addresses that issue as well. The affected IDE plugins and versions are: - VS Code - Affected: <=1.8.0, Fixed: 1.9.0 - IntelliJ - Affected: <=2.4.47, Fixed: 2.4.48 - Visual Studio - Affected: <=1.1.30, Fixed: 1.1.31 - Eclipse - Affected: <=v20221115.132308, Fixed: All subsequent versions - Language Server - Affected: <=v20221109.114426, Fixed: All subsequent versions", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24441" + }, + { + "type": "WEB", + "url": "https://github.com/snyk/snyk-eclipse-plugin/commit/b5a8bce25a359ced75f83a729fc6b2393fc9a495" + }, + { + "type": "WEB", + "url": "https://github.com/snyk/snyk-intellij-plugin/commit/56682f4ba6081ce1d95cb980cbfacd3809a826f4" + }, + { + "type": "WEB", + "url": "https://github.com/snyk/snyk-ls/commit/b3229f0142f782871aa72d1a7dcf417546d568ed" + }, + { + "type": "WEB", + "url": "https://github.com/snyk/snyk-visual-studio-plugin/commit/0b53dbbd4a3153c3ef9aaf797af3b5caad0f731a" + }, + { + "type": "WEB", + "url": "https://github.com/snyk/vscode-extension/commit/0db3b4240be0db6a0a5c6d02c0d4231a2c4ba708" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-SNYK-3111871" + }, + { + "type": "WEB", + "url": "https://www.imperva.com/blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-30T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4x5h-xmv4-99wx/GHSA-4x5h-xmv4-99wx.json b/advisories/unreviewed/2023/07/GHSA-4x5h-xmv4-99wx/GHSA-4x5h-xmv4-99wx.json new file mode 100644 index 00000000000..13104ad460d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4x5h-xmv4-99wx/GHSA-4x5h-xmv4-99wx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x5h-xmv4-99wx", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-27987" + ], + "details": "\nIn Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values.\n\n\n\n\nWe recommend users upgrade the version of Linkis to version 1.3.2 And modify the default token value. You can refer to Token authorization[1]\n https://linkis.apache.org/docs/latest/auth/token https://linkis.apache.org/docs/latest/auth/token \n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27987" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/3cr1cz3210wzwngldwrqzm43vwhghp0p" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json b/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json new file mode 100644 index 00000000000..87bf18dfcc0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x7m-cpcp-9gfm", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-41627" + ], + "details": "The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphone’s ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41627" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsma-22-298-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-27T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json b/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json new file mode 100644 index 00000000000..18f3b7922ea --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4x82-r4q4-7g8x/GHSA-4x82-r4q4-7g8x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x82-r4q4-7g8x", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-1829" + ], + "details": "A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root.\nWe recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1829" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8c710f75256bb3cf05ac7b1672c82b92c43f3d28" + }, + { + "type": "WEB", + "url": "https://kernel.dance/#8c710f75256bb3cf05ac7b1672c82b92c43f3d28" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-12T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json b/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json new file mode 100644 index 00000000000..19c3c5d8af6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-52r6-x37j-435c/GHSA-52r6-x37j-435c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52r6-x37j-435c", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-33183" + ], + "details": "A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33183" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2085" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-53rw-gcgw-2723/GHSA-53rw-gcgw-2723.json b/advisories/unreviewed/2023/07/GHSA-53rw-gcgw-2723/GHSA-53rw-gcgw-2723.json new file mode 100644 index 00000000000..6be7f1be564 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-53rw-gcgw-2723/GHSA-53rw-gcgw-2723.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53rw-gcgw-2723", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-42892" + ], + "details": "A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder accessible to the account assigned to the website’s application pool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42892" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-741697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5497-8frw-qm4r/GHSA-5497-8frw-qm4r.json b/advisories/unreviewed/2023/07/GHSA-5497-8frw-qm4r/GHSA-5497-8frw-qm4r.json new file mode 100644 index 00000000000..4797f078bfd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5497-8frw-qm4r/GHSA-5497-8frw-qm4r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5497-8frw-qm4r", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-2155" + ], + "details": "A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to exploit the vulnerability on a customer’s Lumada APM could access unauthorized information by gaining unauthorized access to any Power BI reports installed by the customer. Furthermore, the vulnerability enables an attacker to manipulate asset issue comments on assets, which should not be available to the attacker. Affected versions * Lumada APM on-premises version 6.0.0.0 - 6.4.0.* List of CPEs: * cpe:2.3:a:hitachienergy:lumada_apm:6.0.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.1.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.2.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.3.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.4.0.0:*:*:*:*:*:*:*", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2155" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000112&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-12T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-554g-vr37-8pqc/GHSA-554g-vr37-8pqc.json b/advisories/unreviewed/2023/07/GHSA-554g-vr37-8pqc/GHSA-554g-vr37-8pqc.json new file mode 100644 index 00000000000..deff8c6eee5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-554g-vr37-8pqc/GHSA-554g-vr37-8pqc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-554g-vr37-8pqc", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-23685" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plugin <= 2.8.10 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tlp-portfolio/wordpress-portfolio-wordpress-portfolio-plugin-plugin-2-8-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-04T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-56x4-8xcj-44r6/GHSA-56x4-8xcj-44r6.json b/advisories/unreviewed/2023/07/GHSA-56x4-8xcj-44r6/GHSA-56x4-8xcj-44r6.json new file mode 100644 index 00000000000..3c6f50e2632 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-56x4-8xcj-44r6/GHSA-56x4-8xcj-44r6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56x4-8xcj-44r6", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22941" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) crashes the Splunk daemon (splunkd).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22941" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0211" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/08978eca-caff-44c1-84dc-53f17def4e14/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-574w-g6v4-fj73/GHSA-574w-g6v4-fj73.json b/advisories/unreviewed/2023/07/GHSA-574w-g6v4-fj73/GHSA-574w-g6v4-fj73.json new file mode 100644 index 00000000000..ccde91d63fc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-574w-g6v4-fj73/GHSA-574w-g6v4-fj73.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-574w-g6v4-fj73", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-46369" + ], + "details": "Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts into unspecified input fields.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46369" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-12T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-578c-f9f3-qh5w/GHSA-578c-f9f3-qh5w.json b/advisories/unreviewed/2023/07/GHSA-578c-f9f3-qh5w/GHSA-578c-f9f3-qh5w.json new file mode 100644 index 00000000000..c34773431e8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-578c-f9f3-qh5w/GHSA-578c-f9f3-qh5w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-578c-f9f3-qh5w", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2022-47173" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47173" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-form-integration/wordpress-connect-contact-form-7-woocommerce-to-google-sheets-other-platforms-advanced-form-integration-plugin-1-62-0-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-584r-x68q-cm4j/GHSA-584r-x68q-cm4j.json b/advisories/unreviewed/2023/07/GHSA-584r-x68q-cm4j/GHSA-584r-x68q-cm4j.json new file mode 100644 index 00000000000..4ae7c62c1b6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-584r-x68q-cm4j/GHSA-584r-x68q-cm4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-584r-x68q-cm4j", + "modified": "2023-07-06T19:24:20Z", + "published": "2023-07-06T19:24:20Z", + "aliases": [ + "CVE-2023-25783" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss FireCask Like & Share Button plugin <= 1.1.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/facebook-like-send-button/wordpress-peadig-s-like-share-button-plugin-1-1-5-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-59v2-929c-ff97/GHSA-59v2-929c-ff97.json b/advisories/unreviewed/2023/07/GHSA-59v2-929c-ff97/GHSA-59v2-929c-ff97.json new file mode 100644 index 00000000000..dbfef25b58e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-59v2-929c-ff97/GHSA-59v2-929c-ff97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59v2-929c-ff97", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2022-38077" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38077" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/popup-anything-on-click/wordpress-popup-anything-plugin-2-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5c24-6xxh-4r78/GHSA-5c24-6xxh-4r78.json b/advisories/unreviewed/2023/07/GHSA-5c24-6xxh-4r78/GHSA-5c24-6xxh-4r78.json new file mode 100644 index 00000000000..a67fa8fa8b7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5c24-6xxh-4r78/GHSA-5c24-6xxh-4r78.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c24-6xxh-4r78", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-42734" + ], + "details": "A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42734" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-741697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5fqf-v5cm-7jqg/GHSA-5fqf-v5cm-7jqg.json b/advisories/unreviewed/2023/07/GHSA-5fqf-v5cm-7jqg/GHSA-5fqf-v5cm-7jqg.json new file mode 100644 index 00000000000..7e1e2ead065 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5fqf-v5cm-7jqg/GHSA-5fqf-v5cm-7jqg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fqf-v5cm-7jqg", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2021-4276" + ], + "details": "** DISPUTED ** ** UNSUPPPORTED WHEN ASSIGNED **** UNSUPPORTED WHEN ASSIGNED ** ** DISPUTED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affected by this issue is the function DSCIOManager::dsc_import_input_from_source of the file src/DSCIOManager.cpp. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 58922c345d3d1fe89bb2020111873a3e07ca93ac. It is recommended to apply a patch to fix this issue. VDB-216746 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: We do assume that the Data Manager server can only be accessed by authorised users. Because of this, we don’t believe this specific attack is possible without such a compromise of the Data Manager server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4276" + }, + { + "type": "WEB", + "url": "https://github.com/dns-stats/hedgehog/pull/190" + }, + { + "type": "WEB", + "url": "https://github.com/dns-stats/hedgehog/commit/58922c345d3d1fe89bb2020111873a3e07ca93ac" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.216746" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-25T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5fw2-7ccx-9pc8/GHSA-5fw2-7ccx-9pc8.json b/advisories/unreviewed/2023/07/GHSA-5fw2-7ccx-9pc8/GHSA-5fw2-7ccx-9pc8.json new file mode 100644 index 00000000000..d926d806492 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5fw2-7ccx-9pc8/GHSA-5fw2-7ccx-9pc8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fw2-7ccx-9pc8", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-41134" + ], + "details": "Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plugin <= 1.0.15 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41134" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/optinly/wordpress-optinly-plugin-1-0-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-13T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5g4j-78x8-fff7/GHSA-5g4j-78x8-fff7.json b/advisories/unreviewed/2023/07/GHSA-5g4j-78x8-fff7/GHSA-5g4j-78x8-fff7.json new file mode 100644 index 00000000000..38994d45f1e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5g4j-78x8-fff7/GHSA-5g4j-78x8-fff7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g4j-78x8-fff7", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-3703" + ], + "details": "All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3703" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-10T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5g92-3658-j47r/GHSA-5g92-3658-j47r.json b/advisories/unreviewed/2023/07/GHSA-5g92-3658-j47r/GHSA-5g92-3658-j47r.json new file mode 100644 index 00000000000..ae1a4b894a9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5g92-3658-j47r/GHSA-5g92-3658-j47r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g92-3658-j47r", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-47911" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the backup services of the software. This could allow a remote attacker to access sensitive functions of the application and execute arbitrary system commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47911" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5p9x-cmrm-q356/GHSA-5p9x-cmrm-q356.json b/advisories/unreviewed/2023/07/GHSA-5p9x-cmrm-q356/GHSA-5p9x-cmrm-q356.json new file mode 100644 index 00000000000..20e4756d509 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5p9x-cmrm-q356/GHSA-5p9x-cmrm-q356.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p9x-cmrm-q356", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-4035" + ], + "details": "The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This makes it possible for unauthenticated attackers to inject iFrames when submitting a booking that will execute whenever a user accesses the injected booking details page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4035" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2803896%40appointment-hour-booking&new=2803896%40appointment-hour-booking&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-4035" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5r2r-5wx4-7x33/GHSA-5r2r-5wx4-7x33.json b/advisories/unreviewed/2023/07/GHSA-5r2r-5wx4-7x33/GHSA-5r2r-5wx4-7x33.json new file mode 100644 index 00000000000..1b2401e2d7a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5r2r-5wx4-7x33/GHSA-5r2r-5wx4-7x33.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r2r-5wx4-7x33", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2022-4744" + ], + "details": "A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4744" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=158b515f703e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-30T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5r3c-cq8h-c6gx/GHSA-5r3c-cq8h-c6gx.json b/advisories/unreviewed/2023/07/GHSA-5r3c-cq8h-c6gx/GHSA-5r3c-cq8h-c6gx.json new file mode 100644 index 00000000000..b93deb738d5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5r3c-cq8h-c6gx/GHSA-5r3c-cq8h-c6gx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r3c-cq8h-c6gx", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2297" + ], + "details": "The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2297" + }, + { + "type": "WEB", + "url": "https://lana.codes/lanavdb/512e7307-04a5-4d8b-8f79-f75f37784a9f/" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2864329%40profile-builder&new=2864329%40profile-builder&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/blog/2023/03/vulnerability-patched-in-cozmolabs-profile-builder-plugin-information-disclosure-leads-to-account-takeover/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e731292a-4f95-46eb-889e-b00d58f3444e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json b/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json new file mode 100644 index 00000000000..2e059155a38 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v6h-fqxx-8wv5", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2021-26360" + ], + "details": "An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26360" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1029" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-09T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5xr6-mfp2-pfhc/GHSA-5xr6-mfp2-pfhc.json b/advisories/unreviewed/2023/07/GHSA-5xr6-mfp2-pfhc/GHSA-5xr6-mfp2-pfhc.json new file mode 100644 index 00000000000..63a5d75149b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5xr6-mfp2-pfhc/GHSA-5xr6-mfp2-pfhc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr6-mfp2-pfhc", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-28765" + ], + "details": "An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28765" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3298961" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json b/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json new file mode 100644 index 00000000000..05cfcba2850 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6439-9fxj-fc35/GHSA-6439-9fxj-fc35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6439-9fxj-fc35", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-44039" + ], + "details": "Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of \"fopen\" system function with the mode \"wb\" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44039" + }, + { + "type": "WEB", + "url": "https://pastebin.com/raw/64stbsWu" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-05T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-645g-q3pq-8q25/GHSA-645g-q3pq-8q25.json b/advisories/unreviewed/2023/07/GHSA-645g-q3pq-8q25/GHSA-645g-q3pq-8q25.json new file mode 100644 index 00000000000..3b3d527c98c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-645g-q3pq-8q25/GHSA-645g-q3pq-8q25.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-645g-q3pq-8q25", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-0975" + ], + "details": "A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0975" + }, + { + "type": "WEB", + "url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10396" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-03T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-652h-x93j-jh9w/GHSA-652h-x93j-jh9w.json b/advisories/unreviewed/2023/07/GHSA-652h-x93j-jh9w/GHSA-652h-x93j-jh9w.json new file mode 100644 index 00000000000..c5b23f61c3f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-652h-x93j-jh9w/GHSA-652h-x93j-jh9w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-652h-x93j-jh9w", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2022-41633" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.2.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/peepso-core/wordpress-community-by-peepso-plugin-6-0-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-04T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-65c4-xx3j-xwcj/GHSA-65c4-xx3j-xwcj.json b/advisories/unreviewed/2023/07/GHSA-65c4-xx3j-xwcj/GHSA-65c4-xx3j-xwcj.json new file mode 100644 index 00000000000..81f6f697984 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-65c4-xx3j-xwcj/GHSA-65c4-xx3j-xwcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65c4-xx3j-xwcj", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2022-45080" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45080" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-multiple-marker/wordpress-add-multiple-marker-plugin-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-683h-9pw3-vc53/GHSA-683h-9pw3-vc53.json b/advisories/unreviewed/2023/07/GHSA-683h-9pw3-vc53/GHSA-683h-9pw3-vc53.json new file mode 100644 index 00000000000..74c6c00702b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-683h-9pw3-vc53/GHSA-683h-9pw3-vc53.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-683h-9pw3-vc53", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-4697" + ], + "details": "The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_url’ parameter in versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4697" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2838522%40wp-user-avatar%2Ftrunk&old=2837217%40wp-user-avatar%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3d54f585-0116-4517-84f1-271e89a05539" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-23T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6874-289g-f7h7/GHSA-6874-289g-f7h7.json b/advisories/unreviewed/2023/07/GHSA-6874-289g-f7h7/GHSA-6874-289g-f7h7.json new file mode 100644 index 00000000000..c0fe1e872aa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6874-289g-f7h7/GHSA-6874-289g-f7h7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6874-289g-f7h7", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-45802" + ], + "details": "Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45802" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/thwl1v2h6r3c21x1qwff08o57qzjnst6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6c53-4r43-p32g/GHSA-6c53-4r43-p32g.json b/advisories/unreviewed/2023/07/GHSA-6c53-4r43-p32g/GHSA-6c53-4r43-p32g.json new file mode 100644 index 00000000000..657700cf450 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6c53-4r43-p32g/GHSA-6c53-4r43-p32g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c53-4r43-p32g", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-23710" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23710" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/miniorange-login-openid/wordpress-wordpress-social-login-and-register-discord-google-twitter-linkedin-plugin-7-5-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6grr-xmf3-hgjf/GHSA-6grr-xmf3-hgjf.json b/advisories/unreviewed/2023/07/GHSA-6grr-xmf3-hgjf/GHSA-6grr-xmf3-hgjf.json new file mode 100644 index 00000000000..d235e394aa1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6grr-xmf3-hgjf/GHSA-6grr-xmf3-hgjf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6grr-xmf3-hgjf", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-22702" + ], + "details": "Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22702" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpappninja/wordpress-wpmobile-app-android-and-ios-mobile-application-plugin-11-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6h37-c8j2-gj5p/GHSA-6h37-c8j2-gj5p.json b/advisories/unreviewed/2023/07/GHSA-6h37-c8j2-gj5p/GHSA-6h37-c8j2-gj5p.json new file mode 100644 index 00000000000..415a7854bd2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6h37-c8j2-gj5p/GHSA-6h37-c8j2-gj5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h37-c8j2-gj5p", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-23408" + ], + "details": "Azure Apache Ambari Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23408" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23408" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6j2v-3cg6-9w64/GHSA-6j2v-3cg6-9w64.json b/advisories/unreviewed/2023/07/GHSA-6j2v-3cg6-9w64/GHSA-6j2v-3cg6-9w64.json new file mode 100644 index 00000000000..ad259c05d8d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6j2v-3cg6-9w64/GHSA-6j2v-3cg6-9w64.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j2v-3cg6-9w64", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-29186" + ], + "details": "In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29186" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3305907" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T04:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6jf5-53hp-585m/GHSA-6jf5-53hp-585m.json b/advisories/unreviewed/2023/07/GHSA-6jf5-53hp-585m/GHSA-6jf5-53hp-585m.json new file mode 100644 index 00000000000..ef05f7c4bd2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6jf5-53hp-585m/GHSA-6jf5-53hp-585m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jf5-53hp-585m", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-40603" + ], + "details": "A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40603" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-in-firewalls" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-06T02:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6jx2-8495-397p/GHSA-6jx2-8495-397p.json b/advisories/unreviewed/2023/07/GHSA-6jx2-8495-397p/GHSA-6jx2-8495-397p.json new file mode 100644 index 00000000000..1e17bf6cf5d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6jx2-8495-397p/GHSA-6jx2-8495-397p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jx2-8495-397p", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-0104" + ], + "details": "The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0104" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-045-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-22T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6pv2-vj8w-6fqg/GHSA-6pv2-vj8w-6fqg.json b/advisories/unreviewed/2023/07/GHSA-6pv2-vj8w-6fqg/GHSA-6pv2-vj8w-6fqg.json new file mode 100644 index 00000000000..216cdf7902a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6pv2-vj8w-6fqg/GHSA-6pv2-vj8w-6fqg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pv2-vj8w-6fqg", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-23510" + ], + "details": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a user’s Safari history.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23510" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213605" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-27T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json b/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json new file mode 100644 index 00000000000..2d5f7eaf85e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6r47-4376-p42h/GHSA-6r47-4376-p42h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r47-4376-p42h", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-47209" + ], + "details": "A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47209" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2022-37" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-16T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6rjf-jv9r-jj4v/GHSA-6rjf-jv9r-jj4v.json b/advisories/unreviewed/2023/07/GHSA-6rjf-jv9r-jj4v/GHSA-6rjf-jv9r-jj4v.json new file mode 100644 index 00000000000..92d1f0877f7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6rjf-jv9r-jj4v/GHSA-6rjf-jv9r-jj4v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rjf-jv9r-jj4v", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-41629" + ], + "details": "Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41629" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-07" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-31T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json b/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json new file mode 100644 index 00000000000..1dc944a3596 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rqp-hf8j-7x29", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-46370" + ], + "details": "Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46370" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-12T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6vvf-9qj9-6mw8/GHSA-6vvf-9qj9-6mw8.json b/advisories/unreviewed/2023/07/GHSA-6vvf-9qj9-6mw8/GHSA-6vvf-9qj9-6mw8.json new file mode 100644 index 00000000000..34c9b78256d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6vvf-9qj9-6mw8/GHSA-6vvf-9qj9-6mw8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vvf-9qj9-6mw8", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-42909" + ], + "details": "WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don´t own and print hem without authorization. In order to exploit this vulnerability, the user must have an account with wepanow.com or any of the institutions they serve, and be logged in.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42909" + }, + { + "type": "WEB", + "url": "https://enrique.wtf/CVE-2022-42909" + }, + { + "type": "WEB", + "url": "https://www.incibe-cert.es/en/early-warning/security-advisories/multiple-vulnerabilities-wepa-print-away" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-03T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6wjj-c22c-pfh3/GHSA-6wjj-c22c-pfh3.json b/advisories/unreviewed/2023/07/GHSA-6wjj-c22c-pfh3/GHSA-6wjj-c22c-pfh3.json new file mode 100644 index 00000000000..c6fda714757 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6wjj-c22c-pfh3/GHSA-6wjj-c22c-pfh3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wjj-c22c-pfh3", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2022-40198" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40198" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-wallet/wordpress-terawallet-for-woocommerce-plugin-1-3-24-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6wvc-j264-82hv/GHSA-6wvc-j264-82hv.json b/advisories/unreviewed/2023/07/GHSA-6wvc-j264-82hv/GHSA-6wvc-j264-82hv.json new file mode 100644 index 00000000000..22037707f2b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6wvc-j264-82hv/GHSA-6wvc-j264-82hv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wvc-j264-82hv", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-0681" + ], + "details": "Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0681" + }, + { + "type": "WEB", + "url": "https://docs.rapid7.com/release-notes/nexpose/20230208/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-20T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-72cj-w3q5-m35c/GHSA-72cj-w3q5-m35c.json b/advisories/unreviewed/2023/07/GHSA-72cj-w3q5-m35c/GHSA-72cj-w3q5-m35c.json new file mode 100644 index 00000000000..c5289635781 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-72cj-w3q5-m35c/GHSA-72cj-w3q5-m35c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72cj-w3q5-m35c", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2023-27425" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in James Irving-Swift Electric Studio Client Login plugin <= 0.8.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/electric-studio-client-login/wordpress-electric-studio-client-login-plugin-0-8-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-72fh-vmp6-2w2c/GHSA-72fh-vmp6-2w2c.json b/advisories/unreviewed/2023/07/GHSA-72fh-vmp6-2w2c/GHSA-72fh-vmp6-2w2c.json new file mode 100644 index 00000000000..251c4a9bcab --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-72fh-vmp6-2w2c/GHSA-72fh-vmp6-2w2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72fh-vmp6-2w2c", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2022-37935" + ], + "details": "HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37935" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04449en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7358-prgh-r77c/GHSA-7358-prgh-r77c.json b/advisories/unreviewed/2023/07/GHSA-7358-prgh-r77c/GHSA-7358-prgh-r77c.json new file mode 100644 index 00000000000..782b8e9ca41 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7358-prgh-r77c/GHSA-7358-prgh-r77c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7358-prgh-r77c", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-47422" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-stripe-donation/wordpress-wordpress-stripe-donation-plugin-3-1-5-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-73qq-8mgh-cm29/GHSA-73qq-8mgh-cm29.json b/advisories/unreviewed/2023/07/GHSA-73qq-8mgh-cm29/GHSA-73qq-8mgh-cm29.json new file mode 100644 index 00000000000..575926b3f9c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-73qq-8mgh-cm29/GHSA-73qq-8mgh-cm29.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73qq-8mgh-cm29", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2023-25451" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25451" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cpo-content-types/wordpress-cpo-content-types-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-74vj-ghfv-m4x7/GHSA-74vj-ghfv-m4x7.json b/advisories/unreviewed/2023/07/GHSA-74vj-ghfv-m4x7/GHSA-74vj-ghfv-m4x7.json new file mode 100644 index 00000000000..dad8188f7bc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-74vj-ghfv-m4x7/GHSA-74vj-ghfv-m4x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74vj-ghfv-m4x7", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2022-44594" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/aio-time-clock-lite/wordpress-all-in-one-time-clock-lite-plugin-1-3-320-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-75hv-856g-q3wx/GHSA-75hv-856g-q3wx.json b/advisories/unreviewed/2023/07/GHSA-75hv-856g-q3wx/GHSA-75hv-856g-q3wx.json new file mode 100644 index 00000000000..ff1b354fe8f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-75hv-856g-q3wx/GHSA-75hv-856g-q3wx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75hv-856g-q3wx", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-32747" + ], + "details": "A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32747" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-08_Cybersecurity_Admin_Expert_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-775x-85h4-43cp/GHSA-775x-85h4-43cp.json b/advisories/unreviewed/2023/07/GHSA-775x-85h4-43cp/GHSA-775x-85h4-43cp.json new file mode 100644 index 00000000000..a3af191717b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-775x-85h4-43cp/GHSA-775x-85h4-43cp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-775x-85h4-43cp", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-24842" + ], + "details": "HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24842" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6961-12444-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-77hr-wvv3-vjx6/GHSA-77hr-wvv3-vjx6.json b/advisories/unreviewed/2023/07/GHSA-77hr-wvv3-vjx6/GHSA-77hr-wvv3-vjx6.json new file mode 100644 index 00000000000..4da3e6503ca --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-77hr-wvv3-vjx6/GHSA-77hr-wvv3-vjx6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77hr-wvv3-vjx6", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-22700" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 9.3.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22700" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pixelyoursite/wordpress-pixelyoursite-your-smart-pixel-tag-manager-plugin-9-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-13T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-786j-r97c-7r7v/GHSA-786j-r97c-7r7v.json b/advisories/unreviewed/2023/07/GHSA-786j-r97c-7r7v/GHSA-786j-r97c-7r7v.json new file mode 100644 index 00000000000..ae2df07829a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-786j-r97c-7r7v/GHSA-786j-r97c-7r7v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-786j-r97c-7r7v", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22936" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22936" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0206" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7922-hx9c-296c/GHSA-7922-hx9c-296c.json b/advisories/unreviewed/2023/07/GHSA-7922-hx9c-296c/GHSA-7922-hx9c-296c.json new file mode 100644 index 00000000000..474565abbf5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7922-hx9c-296c/GHSA-7922-hx9c-296c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7922-hx9c-296c", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-38121" + ], + "details": "UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access all users‘ and administrators' account names and passwords via this unprotected configuration file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38121" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6680-af0aa-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-10T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7c88-jh2r-72f2/GHSA-7c88-jh2r-72f2.json b/advisories/unreviewed/2023/07/GHSA-7c88-jh2r-72f2/GHSA-7c88-jh2r-72f2.json new file mode 100644 index 00000000000..7f35a3fea8b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7c88-jh2r-72f2/GHSA-7c88-jh2r-72f2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c88-jh2r-72f2", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-44625" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting') vulnerability in Zephilou Cyklodev WP Notify plugin <= 1.2.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cyklodev-wp-notify/wordpress-cyklodev-wp-notify-plugin-1-2-1-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-13T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7cp4-jcp5-8wrp/GHSA-7cp4-jcp5-8wrp.json b/advisories/unreviewed/2023/07/GHSA-7cp4-jcp5-8wrp/GHSA-7cp4-jcp5-8wrp.json new file mode 100644 index 00000000000..bd7ba15f282 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7cp4-jcp5-8wrp/GHSA-7cp4-jcp5-8wrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cp4-jcp5-8wrp", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-23995" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Reeves & David Stöckl TinyMCE Custom Styles plugin <= 1.1.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tinymce-custom-styles/wordpress-tinymce-custom-styles-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7fqr-w76q-379j/GHSA-7fqr-w76q-379j.json b/advisories/unreviewed/2023/07/GHSA-7fqr-w76q-379j/GHSA-7fqr-w76q-379j.json new file mode 100644 index 00000000000..e399c34e12c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7fqr-w76q-379j/GHSA-7fqr-w76q-379j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fqr-w76q-379j", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-28338" + ], + "details": "Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A sufficiently large file will cause device resources to be exhausted, resulting in the device becoming unusable until it is rebooted.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28338" + }, + { + "type": "WEB", + "url": "https://drupal9.tenable.com/security/research/tra-2023-12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-15T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7g93-5vcp-frv5/GHSA-7g93-5vcp-frv5.json b/advisories/unreviewed/2023/07/GHSA-7g93-5vcp-frv5/GHSA-7g93-5vcp-frv5.json new file mode 100644 index 00000000000..11a28188d2b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7g93-5vcp-frv5/GHSA-7g93-5vcp-frv5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g93-5vcp-frv5", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22931" + ], + "details": "In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22931" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0201" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7gxc-cpf8-gf68/GHSA-7gxc-cpf8-gf68.json b/advisories/unreviewed/2023/07/GHSA-7gxc-cpf8-gf68/GHSA-7gxc-cpf8-gf68.json new file mode 100644 index 00000000000..17bbe716a95 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7gxc-cpf8-gf68/GHSA-7gxc-cpf8-gf68.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gxc-cpf8-gf68", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2022-45074" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45074" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/activity-reactions-for-buddypress/wordpress-activity-reactions-for-buddypress-plugin-1-0-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7hcw-vwc2-8cg8/GHSA-7hcw-vwc2-8cg8.json b/advisories/unreviewed/2023/07/GHSA-7hcw-vwc2-8cg8/GHSA-7hcw-vwc2-8cg8.json new file mode 100644 index 00000000000..19154cc626d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7hcw-vwc2-8cg8/GHSA-7hcw-vwc2-8cg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hcw-vwc2-8cg8", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-39064" + ], + "details": "An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay (i.e. resend) the same frame multiple times, the bulb performs a factory reset. This causes the bulb to lose configuration information about the Zigbee network and current brightness level. After this attack, all lights are on with full brightness, and a user cannot control the bulbs with either the IKEA Home Smart app or the TRÅDFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected. CVSS 3.1 Base Score 7.1 vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39064" + }, + { + "type": "WEB", + "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-14T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7j6x-42mm-p7jm/GHSA-7j6x-42mm-p7jm.json b/advisories/unreviewed/2023/07/GHSA-7j6x-42mm-p7jm/GHSA-7j6x-42mm-p7jm.json new file mode 100644 index 00000000000..b7961d350f2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7j6x-42mm-p7jm/GHSA-7j6x-42mm-p7jm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j6x-42mm-p7jm", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-32172" + ], + "details": "In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32172" + }, + { + "type": "WEB", + "url": "https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d" + }, + { + "type": "WEB", + "url": "https://www.mend.io/vulnerability-database/CVE-2022-32172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-06T18:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7mj9-5274-6hpv/GHSA-7mj9-5274-6hpv.json b/advisories/unreviewed/2023/07/GHSA-7mj9-5274-6hpv/GHSA-7mj9-5274-6hpv.json new file mode 100644 index 00000000000..819de83876e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7mj9-5274-6hpv/GHSA-7mj9-5274-6hpv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mj9-5274-6hpv", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-28761" + ], + "details": "In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and integrity.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28761" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3289994" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7p8v-5pfg-c239/GHSA-7p8v-5pfg-c239.json b/advisories/unreviewed/2023/07/GHSA-7p8v-5pfg-c239/GHSA-7p8v-5pfg-c239.json new file mode 100644 index 00000000000..c468c6bd4e4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7p8v-5pfg-c239/GHSA-7p8v-5pfg-c239.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p8v-5pfg-c239", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-3139" + ], + "details": "The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3139" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/11c89925-4fe9-45f7-9020-55fe7bbae3db" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-17T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7q3m-cm45-5qq5/GHSA-7q3m-cm45-5qq5.json b/advisories/unreviewed/2023/07/GHSA-7q3m-cm45-5qq5/GHSA-7q3m-cm45-5qq5.json new file mode 100644 index 00000000000..57db83373f7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7q3m-cm45-5qq5/GHSA-7q3m-cm45-5qq5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q3m-cm45-5qq5", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-45788" + ], + "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure™ Control Expert (All Versions), EcoStruxure™ Process Expert (Version V2020 & prior), Modicon M340 CPU (part numbers BMXP34*) (All Versions), Modicon M580 CPU (part numbers BMEP* and BMEH*) (All Versions), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions), Modicon Momentum Unity M1E Processor (171CBU*) (All Versions), Modicon MC80 (BMKC80) (All Versions), Legacy Modicon Quantum (140CPU65*) and Premium CPUs (TSXP57*) (All Versions)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45788" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-05_Modicon_Controllers_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7w8f-q3m3-pfj7/GHSA-7w8f-q3m3-pfj7.json b/advisories/unreviewed/2023/07/GHSA-7w8f-q3m3-pfj7/GHSA-7w8f-q3m3-pfj7.json new file mode 100644 index 00000000000..6473312af9a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7w8f-q3m3-pfj7/GHSA-7w8f-q3m3-pfj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w8f-q3m3-pfj7", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2158" + ], + "details": "Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom \"Remember Me\" token. This is possible due to the use of a hard-coded cipher which was used when generating the token. A malicious actor who creates this token can supply it to a separate Code Dx system, provided they know the username they want to impersonate, and impersonate the user.  Score 6.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2158" + }, + { + "type": "WEB", + "url": "https://community.synopsys.com/s/question/0D5Hr00006VdZblKAF/announcement-changelog-code-dx-202342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7x83-244x-q653/GHSA-7x83-244x-q653.json b/advisories/unreviewed/2023/07/GHSA-7x83-244x-q653/GHSA-7x83-244x-q653.json new file mode 100644 index 00000000000..651914459d9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7x83-244x-q653/GHSA-7x83-244x-q653.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x83-244x-q653", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-43378" + ], + "details": "\n\n\n\n\n\n\nA CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that\ncould cause the user to be tricked into performing unintended actions when external address\nframes are not properly restricted.\n\n\n\n\n\n Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0\n\n and prior)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43378" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-312-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json b/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json new file mode 100644 index 00000000000..d2346bbd83f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xr3-6fgq-rv6h", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-24501" + ], + "details": "Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24501" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8267-g4r9-6r3v/GHSA-8267-g4r9-6r3v.json b/advisories/unreviewed/2023/07/GHSA-8267-g4r9-6r3v/GHSA-8267-g4r9-6r3v.json new file mode 100644 index 00000000000..186135b792c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8267-g4r9-6r3v/GHSA-8267-g4r9-6r3v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8267-g4r9-6r3v", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-43561" + ], + "details": "In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43561" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/a974d1ee-ddca-4837-b6ad-d55a8a239c20/" + }, + { + "type": "WEB", + "url": "https://www.splunk.com/en_us/product-security/announcements/svd-2022-1101.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-03T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-84p2-3q54-pcv7/GHSA-84p2-3q54-pcv7.json b/advisories/unreviewed/2023/07/GHSA-84p2-3q54-pcv7/GHSA-84p2-3q54-pcv7.json new file mode 100644 index 00000000000..84178565056 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-84p2-3q54-pcv7/GHSA-84p2-3q54-pcv7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84p2-3q54-pcv7", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-3186" + ], + "details": "Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3186" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-21T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8699-h45g-7hm8/GHSA-8699-h45g-7hm8.json b/advisories/unreviewed/2023/07/GHSA-8699-h45g-7hm8/GHSA-8699-h45g-7hm8.json new file mode 100644 index 00000000000..b2d9bc440fa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8699-h45g-7hm8/GHSA-8699-h45g-7hm8.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8699-h45g-7hm8", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-43695" + ], + "details": "Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist, contains XSS since it was not properly sanitized. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43695" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes" + }, + { + "type": "WEB", + "url": "https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/releases/8.5.10" + }, + { + "type": "WEB", + "url": "https://github.com/concretecms/concretecms/releases/9.1.3" + }, + { + "type": "WEB", + "url": "https://www.concretecms.org/about/project-news/security/concrete-cms-security-advisory-2022-10-31" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-14T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-86vg-36hj-rcm9/GHSA-86vg-36hj-rcm9.json b/advisories/unreviewed/2023/07/GHSA-86vg-36hj-rcm9/GHSA-86vg-36hj-rcm9.json new file mode 100644 index 00000000000..2aa2bd4441d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-86vg-36hj-rcm9/GHSA-86vg-36hj-rcm9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86vg-36hj-rcm9", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-47158" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pakpobox alfred24 Click & Collect plugin <= 1.1.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47158" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/alfred-click-collect/wordpress-alfred24-click-collect-plugin-1-1-7-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-875q-9h9j-qhmh/GHSA-875q-9h9j-qhmh.json b/advisories/unreviewed/2023/07/GHSA-875q-9h9j-qhmh/GHSA-875q-9h9j-qhmh.json new file mode 100644 index 00000000000..f117a360fb7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-875q-9h9j-qhmh/GHSA-875q-9h9j-qhmh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-875q-9h9j-qhmh", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-1390" + ], + "details": "A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1390" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/b77413446408fdd256599daf00d5be72b5f3e7c6" + }, + { + "type": "WEB", + "url": "https://gist.github.com/netspooky/bee2d07022f6350bb88eaa48e571d9b5" + }, + { + "type": "WEB", + "url": "https://infosec.exchange/@_mattata/109427999461122360" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-16T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-895m-p2wc-hxwf/GHSA-895m-p2wc-hxwf.json b/advisories/unreviewed/2023/07/GHSA-895m-p2wc-hxwf/GHSA-895m-p2wc-hxwf.json new file mode 100644 index 00000000000..e62eb0c8a04 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-895m-p2wc-hxwf/GHSA-895m-p2wc-hxwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-895m-p2wc-hxwf", + "modified": "2023-07-06T19:24:20Z", + "published": "2023-07-06T19:24:20Z", + "aliases": [ + "CVE-2023-23723" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23723" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-email-capture/wordpress-wordpress-email-marketing-plugin-wp-email-capture-plugin-3-9-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-89j4-j5mp-mxwm/GHSA-89j4-j5mp-mxwm.json b/advisories/unreviewed/2023/07/GHSA-89j4-j5mp-mxwm/GHSA-89j4-j5mp-mxwm.json new file mode 100644 index 00000000000..450e51ae611 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-89j4-j5mp-mxwm/GHSA-89j4-j5mp-mxwm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89j4-j5mp-mxwm", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-32517" + ], + "details": "A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin into interacting with the application in an unintended way when the product does not implement restrictions on the ability to render within frames on external addresses. Affected Products: Conext™ ComBox (All Versions)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32517" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-03_ConextCombox_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-89mj-q662-x3r3/GHSA-89mj-q662-x3r3.json b/advisories/unreviewed/2023/07/GHSA-89mj-q662-x3r3/GHSA-89mj-q662-x3r3.json new file mode 100644 index 00000000000..4399447c9ec --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-89mj-q662-x3r3/GHSA-89mj-q662-x3r3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89mj-q662-x3r3", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-43947" + ], + "details": "An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid login sessions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43947" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-444" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8c5m-67fx-9q72/GHSA-8c5m-67fx-9q72.json b/advisories/unreviewed/2023/07/GHSA-8c5m-67fx-9q72/GHSA-8c5m-67fx-9q72.json new file mode 100644 index 00000000000..758a693a916 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8c5m-67fx-9q72/GHSA-8c5m-67fx-9q72.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c5m-67fx-9q72", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0911" + ], + "details": "The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0911" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/35404d16-7213-4293-ac0d-926bd6c17444" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-20T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8fxh-vwx2-cpw9/GHSA-8fxh-vwx2-cpw9.json b/advisories/unreviewed/2023/07/GHSA-8fxh-vwx2-cpw9/GHSA-8fxh-vwx2-cpw9.json new file mode 100644 index 00000000000..1ed25d30edf --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8fxh-vwx2-cpw9/GHSA-8fxh-vwx2-cpw9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fxh-vwx2-cpw9", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2022-48431" + ], + "details": "In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48431" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8hvr-7cm7-7fwj/GHSA-8hvr-7cm7-7fwj.json b/advisories/unreviewed/2023/07/GHSA-8hvr-7cm7-7fwj/GHSA-8hvr-7cm7-7fwj.json new file mode 100644 index 00000000000..991a6e60f41 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8hvr-7cm7-7fwj/GHSA-8hvr-7cm7-7fwj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hvr-7cm7-7fwj", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-1263" + ], + "details": "The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1263" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cmp-coming-soon-maintenance/tags/4.1.6/niteo-cmp.php#L2759" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e01b4259-ed8d-44a4-9771-470de45b14a8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-07T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8jc9-jhmw-r737/GHSA-8jc9-jhmw-r737.json b/advisories/unreviewed/2023/07/GHSA-8jc9-jhmw-r737/GHSA-8jc9-jhmw-r737.json new file mode 100644 index 00000000000..69dcef39551 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8jc9-jhmw-r737/GHSA-8jc9-jhmw-r737.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jc9-jhmw-r737", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-32748" + ], + "details": "A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32748" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-08_Cybersecurity_Admin_Expert_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8q28-r8h6-4fcg/GHSA-8q28-r8h6-4fcg.json b/advisories/unreviewed/2023/07/GHSA-8q28-r8h6-4fcg/GHSA-8q28-r8h6-4fcg.json new file mode 100644 index 00000000000..61f4a01b19e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8q28-r8h6-4fcg/GHSA-8q28-r8h6-4fcg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q28-r8h6-4fcg", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-47395" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its monitor services. An attacker could take advantage of this vulnerability to execute arbitrary maintenance operations and cause a denial-of-service condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47395" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8x7r-vpqh-4jm4/GHSA-8x7r-vpqh-4jm4.json b/advisories/unreviewed/2023/07/GHSA-8x7r-vpqh-4jm4/GHSA-8x7r-vpqh-4jm4.json new file mode 100644 index 00000000000..82e6ef63ea0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8x7r-vpqh-4jm4/GHSA-8x7r-vpqh-4jm4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x7r-vpqh-4jm4", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27913" + ], + "details": "A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27913" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8xg2-4v9w-4g38/GHSA-8xg2-4v9w-4g38.json b/advisories/unreviewed/2023/07/GHSA-8xg2-4v9w-4g38/GHSA-8xg2-4v9w-4g38.json new file mode 100644 index 00000000000..77c14b9b784 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8xg2-4v9w-4g38/GHSA-8xg2-4v9w-4g38.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xg2-4v9w-4g38", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25793" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in George Pattihis Link Juice Keeper plugin <= 2.0.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25793" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/link-juice-keeper/wordpress-link-juice-keeper-plugin-2-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-92cv-rhgw-5fm8/GHSA-92cv-rhgw-5fm8.json b/advisories/unreviewed/2023/07/GHSA-92cv-rhgw-5fm8/GHSA-92cv-rhgw-5fm8.json new file mode 100644 index 00000000000..7da243c1f5f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-92cv-rhgw-5fm8/GHSA-92cv-rhgw-5fm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92cv-rhgw-5fm8", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-24839" + ], + "details": "HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24839" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6958-e1a8e-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-94c6-66pj-36g9/GHSA-94c6-66pj-36g9.json b/advisories/unreviewed/2023/07/GHSA-94c6-66pj-36g9/GHSA-94c6-66pj-36g9.json new file mode 100644 index 00000000000..ab93fd55d26 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-94c6-66pj-36g9/GHSA-94c6-66pj-36g9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94c6-66pj-36g9", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-2112" + ], + "details": "Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2112" + }, + { + "type": "WEB", + "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2112/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json b/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json new file mode 100644 index 00000000000..65cb0162518 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-94c6-6qpc-j73m/GHSA-94c6-6qpc-j73m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94c6-6qpc-j73m", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-28663" + ], + "details": "The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28663" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2023-2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-22T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-94wq-wgcm-m3pq/GHSA-94wq-wgcm-m3pq.json b/advisories/unreviewed/2023/07/GHSA-94wq-wgcm-m3pq/GHSA-94wq-wgcm-m3pq.json new file mode 100644 index 00000000000..ea86fdaf230 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-94wq-wgcm-m3pq/GHSA-94wq-wgcm-m3pq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94wq-wgcm-m3pq", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2022-43459" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/captainform/wordpress-forms-by-captainform-2-5-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-28T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-95hr-886r-52mf/GHSA-95hr-886r-52mf.json b/advisories/unreviewed/2023/07/GHSA-95hr-886r-52mf/GHSA-95hr-886r-52mf.json new file mode 100644 index 00000000000..e624b13526e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-95hr-886r-52mf/GHSA-95hr-886r-52mf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95hr-886r-52mf", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-36784" + ], + "details": "Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36784" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-95v2-crcm-vvrh/GHSA-95v2-crcm-vvrh.json b/advisories/unreviewed/2023/07/GHSA-95v2-crcm-vvrh/GHSA-95v2-crcm-vvrh.json new file mode 100644 index 00000000000..e70a0e4af9d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-95v2-crcm-vvrh/GHSA-95v2-crcm-vvrh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95v2-crcm-vvrh", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-24005" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plugin plugin <= 2.5.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24005" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/inline-tweet-sharer/wordpress-inline-tweet-sharer-twitter-sharing-plugin-plugin-2-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-965j-qhq7-9qpx/GHSA-965j-qhq7-9qpx.json b/advisories/unreviewed/2023/07/GHSA-965j-qhq7-9qpx/GHSA-965j-qhq7-9qpx.json new file mode 100644 index 00000000000..fcd48f42dfc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-965j-qhq7-9qpx/GHSA-965j-qhq7-9qpx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-965j-qhq7-9qpx", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-44585" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/homepage-pop-up/wordpress-homepage-popup-plugin-1-2-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-02T21:22:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-975q-7mxh-v8gj/GHSA-975q-7mxh-v8gj.json b/advisories/unreviewed/2023/07/GHSA-975q-7mxh-v8gj/GHSA-975q-7mxh-v8gj.json new file mode 100644 index 00000000000..e10be74e35d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-975q-7mxh-v8gj/GHSA-975q-7mxh-v8gj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-975q-7mxh-v8gj", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2021-4330" + ], + "details": "The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions. This makes it possible for attackers with contributor-lever permissions and above to upload arbitrary files and potentially gain remote code execution in versions up to and including 1.0.13 of Template Kit – Import and versions up to and including 2.0.10 of Envato Elements & Download.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4330" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2617529%40envato-elements&new=2617529%40envato-elements&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/68fe17e2-d5ab-4ebd-a5c6-d65cea327abd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-07T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-97vg-58wg-32x4/GHSA-97vg-58wg-32x4.json b/advisories/unreviewed/2023/07/GHSA-97vg-58wg-32x4/GHSA-97vg-58wg-32x4.json new file mode 100644 index 00000000000..9fed095ce12 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-97vg-58wg-32x4/GHSA-97vg-58wg-32x4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97vg-58wg-32x4", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-2226" + ], + "details": "Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files. \n\nFor this attack to succeed, the attacker needs to be able to introduce malicious files to the system at the same time that Velociraptor attempts to collect any artifacts that attempt to parse PE files, Authenticode signatures, or OLE files. After crashing, the Velociraptor service will restart and it will still be possible to collect other artifacts.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2226" + }, + { + "type": "WEB", + "url": "https://github.com/Velocidex/velociraptor" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9838-c2wv-jc32/GHSA-9838-c2wv-jc32.json b/advisories/unreviewed/2023/07/GHSA-9838-c2wv-jc32/GHSA-9838-c2wv-jc32.json new file mode 100644 index 00000000000..da889cc1909 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9838-c2wv-jc32/GHSA-9838-c2wv-jc32.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9838-c2wv-jc32", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-25059" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in avalex GmbH avalex – Automatically secure legal texts plugin <= 3.0.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25059" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/avalex/wordpress-avalex-plugin-3-0-3-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-07T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-987p-cg63-5x62/GHSA-987p-cg63-5x62.json b/advisories/unreviewed/2023/07/GHSA-987p-cg63-5x62/GHSA-987p-cg63-5x62.json new file mode 100644 index 00000000000..fae7c12b936 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-987p-cg63-5x62/GHSA-987p-cg63-5x62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-987p-cg63-5x62", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2021-34579" + ], + "details": "In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (“ATV profiles”). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34579" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2021-035/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-09T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9893-2v8q-6v9r/GHSA-9893-2v8q-6v9r.json b/advisories/unreviewed/2023/07/GHSA-9893-2v8q-6v9r/GHSA-9893-2v8q-6v9r.json new file mode 100644 index 00000000000..fdbdf615d05 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9893-2v8q-6v9r/GHSA-9893-2v8q-6v9r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9893-2v8q-6v9r", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2023-0038" + ], + "details": "The \"Survey Maker – Best WordPress Survey Plugin\" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts when submitting quizzes that will execute whenever a user accesses the submissions page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0038" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/survey-maker/tags/3.1.4/public/partials/class-survey-maker-submissions-summary-shortcode.php?rev=2839688#L311" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a2a58fab-d4a3-4333-8495-e094ed85bb61" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-03T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-98m9-9rrp-w52h/GHSA-98m9-9rrp-w52h.json b/advisories/unreviewed/2023/07/GHSA-98m9-9rrp-w52h/GHSA-98m9-9rrp-w52h.json new file mode 100644 index 00000000000..397192f46ea --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-98m9-9rrp-w52h/GHSA-98m9-9rrp-w52h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98m9-9rrp-w52h", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-1249" + ], + "details": "A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the system. Only if patch 390031c94211 (\"coredump: Use the vma snapshot in fill_files_note\") not applied yet, then kernel could be affected.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1249" + }, + { + "type": "WEB", + "url": "https://patchwork.kernel.org/project/linux-fsdevel/patch/87iltzn3nd.fsf_-_@email.froward.int.ebiederm.org/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9f7j-84q4-6vj2/GHSA-9f7j-84q4-6vj2.json b/advisories/unreviewed/2023/07/GHSA-9f7j-84q4-6vj2/GHSA-9f7j-84q4-6vj2.json new file mode 100644 index 00000000000..ec99ceb0e66 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9f7j-84q4-6vj2/GHSA-9f7j-84q4-6vj2.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f7j-84q4-6vj2", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-23505" + ], + "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access information about a user’s contacts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23505" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213598" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213599" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213603" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213604" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213605" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/HT213606" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-27T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9f7x-7mw4-rf7j/GHSA-9f7x-7mw4-rf7j.json b/advisories/unreviewed/2023/07/GHSA-9f7x-7mw4-rf7j/GHSA-9f7x-7mw4-rf7j.json new file mode 100644 index 00000000000..ac9d81f9ff0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9f7x-7mw4-rf7j/GHSA-9f7x-7mw4-rf7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f7x-7mw4-rf7j", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-41612" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shareaholic Similar Posts plugin <= 3.1.6 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41612" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/similar-posts/wordpress-similar-posts-plugin-3-1-6-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9fh4-jgj2-72qw/GHSA-9fh4-jgj2-72qw.json b/advisories/unreviewed/2023/07/GHSA-9fh4-jgj2-72qw/GHSA-9fh4-jgj2-72qw.json new file mode 100644 index 00000000000..b050046abf8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9fh4-jgj2-72qw/GHSA-9fh4-jgj2-72qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fh4-jgj2-72qw", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-43437" + ], + "details": "The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43437" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6829-11133-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-03T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9fqq-f56x-35gj/GHSA-9fqq-f56x-35gj.json b/advisories/unreviewed/2023/07/GHSA-9fqq-f56x-35gj/GHSA-9fqq-f56x-35gj.json new file mode 100644 index 00000000000..0035d55b04f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9fqq-f56x-35gj/GHSA-9fqq-f56x-35gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fqq-f56x-35gj", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-44632" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/content-repeater/wordpress-content-repeater-plugin-1-1-13-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9fr2-r98v-qc2f/GHSA-9fr2-r98v-qc2f.json b/advisories/unreviewed/2023/07/GHSA-9fr2-r98v-qc2f/GHSA-9fr2-r98v-qc2f.json new file mode 100644 index 00000000000..428fb90f63c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9fr2-r98v-qc2f/GHSA-9fr2-r98v-qc2f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fr2-r98v-qc2f", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-43765" + ], + "details": "B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43765" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/downloads_br_productcatalogue/assets/1674823095245-en-original-1.0.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-08T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9fr3-c4cm-2x8r/GHSA-9fr3-c4cm-2x8r.json b/advisories/unreviewed/2023/07/GHSA-9fr3-c4cm-2x8r/GHSA-9fr3-c4cm-2x8r.json new file mode 100644 index 00000000000..9af3a8a6f57 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9fr3-c4cm-2x8r/GHSA-9fr3-c4cm-2x8r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fr3-c4cm-2x8r", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-3695" + ], + "details": "\nHitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.   \n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3695" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14739451011981" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9gph-8xxh-c4w6/GHSA-9gph-8xxh-c4w6.json b/advisories/unreviewed/2023/07/GHSA-9gph-8xxh-c4w6/GHSA-9gph-8xxh-c4w6.json new file mode 100644 index 00000000000..0d8909b318f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9gph-8xxh-c4w6/GHSA-9gph-8xxh-c4w6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gph-8xxh-c4w6", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-29057" + ], + "details": "A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29057" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-118321" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9hv8-pfv2-wqfp/GHSA-9hv8-pfv2-wqfp.json b/advisories/unreviewed/2023/07/GHSA-9hv8-pfv2-wqfp/GHSA-9hv8-pfv2-wqfp.json new file mode 100644 index 00000000000..80c3db20bd6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9hv8-pfv2-wqfp/GHSA-9hv8-pfv2-wqfp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hv8-pfv2-wqfp", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-46733" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site scripting in its backup services. An attacker could take advantage of this vulnerability to execute arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46733" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9mh8-9j64-443f/GHSA-9mh8-9j64-443f.json b/advisories/unreviewed/2023/07/GHSA-9mh8-9j64-443f/GHSA-9mh8-9j64-443f.json new file mode 100644 index 00000000000..a5d2f4f7892 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9mh8-9j64-443f/GHSA-9mh8-9j64-443f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mh8-9j64-443f", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-41316" + ], + "details": "HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41316" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2022-24-vaults-tls-cert-auth-method-only-loaded-crl-after-first-request/45483" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-12T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9pqp-62pc-c8g4/GHSA-9pqp-62pc-c8g4.json b/advisories/unreviewed/2023/07/GHSA-9pqp-62pc-c8g4/GHSA-9pqp-62pc-c8g4.json new file mode 100644 index 00000000000..9f65d321b77 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9pqp-62pc-c8g4/GHSA-9pqp-62pc-c8g4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pqp-62pc-c8g4", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-37896" + ], + "details": "A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37896" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-014.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-07T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9qj4-8pgw-5j87/GHSA-9qj4-8pgw-5j87.json b/advisories/unreviewed/2023/07/GHSA-9qj4-8pgw-5j87/GHSA-9qj4-8pgw-5j87.json new file mode 100644 index 00000000000..4307563ae5a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9qj4-8pgw-5j87/GHSA-9qj4-8pgw-5j87.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qj4-8pgw-5j87", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2019-18265" + ], + "details": "Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-18265" + }, + { + "type": "WEB", + "url": "https://www.digitalalertsystems.com/security-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9qwq-rm73-j3gr/GHSA-9qwq-rm73-j3gr.json b/advisories/unreviewed/2023/07/GHSA-9qwq-rm73-j3gr/GHSA-9qwq-rm73-j3gr.json new file mode 100644 index 00000000000..f4fcf67941f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9qwq-rm73-j3gr/GHSA-9qwq-rm73-j3gr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qwq-rm73-j3gr", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2020-36668" + ], + "details": "The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including, 1.4.0 due to a lack of proper capability checking on the backup_guard_get_manual_modal function called via an AJAX action. This makes it possible for subscriber-level attackers, and above, to invoke the function and obtain database table information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36668" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2348984%40backup&new=2348984%40backup&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3e2a9d71-21ef-45a1-99ed-477066ce9620" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-07T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9vrm-v9xv-x3xr/GHSA-9vrm-v9xv-x3xr.json b/advisories/unreviewed/2023/07/GHSA-9vrm-v9xv-x3xr/GHSA-9vrm-v9xv-x3xr.json new file mode 100644 index 00000000000..ca738abc693 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9vrm-v9xv-x3xr/GHSA-9vrm-v9xv-x3xr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vrm-v9xv-x3xr", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-0690" + ], + "details": "HashiCorp Boundary from 0.10.0 through 0.11.2 contain an issue where when using a PKI-based worker with a Key Management Service (KMS) defined in the configuration file, new credentials created after an automatic rotation may not have been encrypted via the intended KMS. This would result in the credentials being stored in plaintext on the Boundary PKI worker’s disk. This issue is fixed in version 0.12.0.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0690" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2023-03-boundary-workers-store-rotated-credentials-in-plaintext-even-when-key-management-service-configured/49907" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-08T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9xhg-4cw3-p79r/GHSA-9xhg-4cw3-p79r.json b/advisories/unreviewed/2023/07/GHSA-9xhg-4cw3-p79r/GHSA-9xhg-4cw3-p79r.json new file mode 100644 index 00000000000..4691838408a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9xhg-4cw3-p79r/GHSA-9xhg-4cw3-p79r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xhg-4cw3-p79r", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-42891" + ], + "details": "A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42891" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-741697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9xjj-cx8r-x5m9/GHSA-9xjj-cx8r-x5m9.json b/advisories/unreviewed/2023/07/GHSA-9xjj-cx8r-x5m9/GHSA-9xjj-cx8r-x5m9.json new file mode 100644 index 00000000000..f8662ad8c58 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9xjj-cx8r-x5m9/GHSA-9xjj-cx8r-x5m9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xjj-cx8r-x5m9", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-41607" + ], + "details": "All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python objects, database files, and more.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41607" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-10T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c2px-c8x4-v6mq/GHSA-c2px-c8x4-v6mq.json b/advisories/unreviewed/2023/07/GHSA-c2px-c8x4-v6mq/GHSA-c2px-c8x4-v6mq.json new file mode 100644 index 00000000000..bfa2eb1dc10 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c2px-c8x4-v6mq/GHSA-c2px-c8x4-v6mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2px-c8x4-v6mq", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-23827" + ], + "details": "Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Google Maps v3 Shortcode plugin <= 1.2.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23827" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/google-maps-v3-shortcode/wordpress-google-maps-v3-shortcode-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c2w9-hhfq-2xq9/GHSA-c2w9-hhfq-2xq9.json b/advisories/unreviewed/2023/07/GHSA-c2w9-hhfq-2xq9/GHSA-c2w9-hhfq-2xq9.json new file mode 100644 index 00000000000..d24188f4cba --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c2w9-hhfq-2xq9/GHSA-c2w9-hhfq-2xq9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2w9-hhfq-2xq9", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2000" + ], + "details": "Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2000" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c2xx-vqvr-jxwv/GHSA-c2xx-vqvr-jxwv.json b/advisories/unreviewed/2023/07/GHSA-c2xx-vqvr-jxwv/GHSA-c2xx-vqvr-jxwv.json new file mode 100644 index 00000000000..8ad5dbf3008 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c2xx-vqvr-jxwv/GHSA-c2xx-vqvr-jxwv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2xx-vqvr-jxwv", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-47163" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47163" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-csv-to-database/wordpress-wp-csv-to-database-plugin-2-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c3rr-g6jw-68f4/GHSA-c3rr-g6jw-68f4.json b/advisories/unreviewed/2023/07/GHSA-c3rr-g6jw-68f4/GHSA-c3rr-g6jw-68f4.json new file mode 100644 index 00000000000..a0d7a5ea55b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c3rr-g6jw-68f4/GHSA-c3rr-g6jw-68f4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3rr-g6jw-68f4", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-33181" + ], + "details": "An information disclosure vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a local authenticated attacker to read sensitive files using switch commands “configshow” and “supportlink”.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33181" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2083" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c5rj-26pj-c7cr/GHSA-c5rj-26pj-c7cr.json b/advisories/unreviewed/2023/07/GHSA-c5rj-26pj-c7cr/GHSA-c5rj-26pj-c7cr.json new file mode 100644 index 00000000000..487ce52454f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c5rj-26pj-c7cr/GHSA-c5rj-26pj-c7cr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5rj-26pj-c7cr", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-24504" + ], + "details": "Electra Central AC unit – Adjacent attacker may cause the unit to connect to unauthorized update server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24504" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c63v-mmf4-hg2w/GHSA-c63v-mmf4-hg2w.json b/advisories/unreviewed/2023/07/GHSA-c63v-mmf4-hg2w/GHSA-c63v-mmf4-hg2w.json new file mode 100644 index 00000000000..c3fc89f08d2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c63v-mmf4-hg2w/GHSA-c63v-mmf4-hg2w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c63v-mmf4-hg2w", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-1305" + ], + "details": "An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1305" + }, + { + "type": "WEB", + "url": "https://docs.divvycloud.com/changelog/23321-release-notes" + }, + { + "type": "WEB", + "url": "https://nephosec.com/exploiting-rapid7s-insightcloudsec/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-21T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json b/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json new file mode 100644 index 00000000000..8d57c7a6ec1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c65j-wcvh-77gc/GHSA-c65j-wcvh-77gc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c65j-wcvh-77gc", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-35739" + ], + "details": "PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35739" + }, + { + "type": "WEB", + "url": "https://www.paessler.com/prtg/history/stable" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c735-wf7c-7c6p/GHSA-c735-wf7c-7c6p.json b/advisories/unreviewed/2023/07/GHSA-c735-wf7c-7c6p/GHSA-c735-wf7c-7c6p.json new file mode 100644 index 00000000000..7f9c5a8c344 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c735-wf7c-7c6p/GHSA-c735-wf7c-7c6p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c735-wf7c-7c6p", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-23806" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davinder Singh Custom Settings plugin <= 1.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-settings/wordpress-wordpress-custom-settings-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c7p4-qvpp-vjjq/GHSA-c7p4-qvpp-vjjq.json b/advisories/unreviewed/2023/07/GHSA-c7p4-qvpp-vjjq/GHSA-c7p4-qvpp-vjjq.json new file mode 100644 index 00000000000..44bf9206d9f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c7p4-qvpp-vjjq/GHSA-c7p4-qvpp-vjjq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7p4-qvpp-vjjq", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-1399" + ], + "details": "N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate privileges in the affected device’s default configuration and achieve remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1399" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c7w2-f8m6-pxp8/GHSA-c7w2-f8m6-pxp8.json b/advisories/unreviewed/2023/07/GHSA-c7w2-f8m6-pxp8/GHSA-c7w2-f8m6-pxp8.json new file mode 100644 index 00000000000..efa94d97eee --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c7w2-f8m6-pxp8/GHSA-c7w2-f8m6-pxp8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7w2-f8m6-pxp8", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-45789" + ], + "details": "A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure™ Control Expert (All Versions), EcoStruxure™ Process Expert (Version V2020 & prior), Modicon M340 CPU (part numbers BMXP34*) (All Versions), Modicon M580 CPU (part numbers BMEP* and BMEH*) (All Versions), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45789" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-06_Modicon_Controllers_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-31T06:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c8x6-66mv-5gv8/GHSA-c8x6-66mv-5gv8.json b/advisories/unreviewed/2023/07/GHSA-c8x6-66mv-5gv8/GHSA-c8x6-66mv-5gv8.json new file mode 100644 index 00000000000..d880dcdf588 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c8x6-66mv-5gv8/GHSA-c8x6-66mv-5gv8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8x6-66mv-5gv8", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27610" + ], + "details": "Auth. (admin+) SQL Injection (SQLi) vulnerability in TransbankDevelopers Transbank Webpay REST plugin <= 1.6.6 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/transbank-webpay-plus-rest/wordpress-transbank-webpay-rest-plugin-1-6-7-admin-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c99p-c624-4w53/GHSA-c99p-c624-4w53.json b/advisories/unreviewed/2023/07/GHSA-c99p-c624-4w53/GHSA-c99p-c624-4w53.json new file mode 100644 index 00000000000..a61b68f3388 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c99p-c624-4w53/GHSA-c99p-c624-4w53.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c99p-c624-4w53", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-41989" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not validate the length of RTLS report payloads during communication. This allows an attacker to send an exceedingly long payload, resulting in an out-of-bounds write to cause a denial-of-service condition or code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41989" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c9jf-g47r-97q7/GHSA-c9jf-g47r-97q7.json b/advisories/unreviewed/2023/07/GHSA-c9jf-g47r-97q7/GHSA-c9jf-g47r-97q7.json new file mode 100644 index 00000000000..ba3815a717e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c9jf-g47r-97q7/GHSA-c9jf-g47r-97q7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9jf-g47r-97q7", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-43980" + ], + "details": "There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network maps, the XSS payload will be executed. The exploitation of this vulnerability could allow an atacker to steal the value of the admin user´s cookie.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43980" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-27T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cg4j-xgw8-xrvj/GHSA-cg4j-xgw8-xrvj.json b/advisories/unreviewed/2023/07/GHSA-cg4j-xgw8-xrvj/GHSA-cg4j-xgw8-xrvj.json new file mode 100644 index 00000000000..bbcd32c1c0a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cg4j-xgw8-xrvj/GHSA-cg4j-xgw8-xrvj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg4j-xgw8-xrvj", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-44737" + ], + "details": "Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44737" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-wp-security-and-firewall/wordpress-all-in-one-wp-security-plugin-5-1-0-multiple-cross-site-request-forgery-csrf-vulnerabilities?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-22T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ch73-x6xh-8mrp/GHSA-ch73-x6xh-8mrp.json b/advisories/unreviewed/2023/07/GHSA-ch73-x6xh-8mrp/GHSA-ch73-x6xh-8mrp.json new file mode 100644 index 00000000000..93a2b5fa136 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ch73-x6xh-8mrp/GHSA-ch73-x6xh-8mrp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch73-x6xh-8mrp", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-1425" + ], + "details": "The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1425" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/578f4179-e7be-4963-9379-5e694911b451" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-chpv-rv7m-7qxg/GHSA-chpv-rv7m-7qxg.json b/advisories/unreviewed/2023/07/GHSA-chpv-rv7m-7qxg/GHSA-chpv-rv7m-7qxg.json new file mode 100644 index 00000000000..af5269d66e3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-chpv-rv7m-7qxg/GHSA-chpv-rv7m-7qxg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chpv-rv7m-7qxg", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-42439" + ], + "details": "IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 238211.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42439" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/238211" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6890607" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-06T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-chwv-c53r-9qh6/GHSA-chwv-c53r-9qh6.json b/advisories/unreviewed/2023/07/GHSA-chwv-c53r-9qh6/GHSA-chwv-c53r-9qh6.json new file mode 100644 index 00000000000..26e4bded404 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-chwv-c53r-9qh6/GHSA-chwv-c53r-9qh6.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chwv-c53r-9qh6", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-0942" + ], + "details": "The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0942" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woocommerce-for-japan/trunk/includes/admin/views/html-admin-setting-screen.php#L63" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2868545%40woocommerce-for-japan%2Ftrunk&old=2863064%40woocommerce-for-japan%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bb606a30-2f7c-41e9-9ebc-9f1b0b84fff8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-21T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cmjc-52fg-9f7j/GHSA-cmjc-52fg-9f7j.json b/advisories/unreviewed/2023/07/GHSA-cmjc-52fg-9f7j/GHSA-cmjc-52fg-9f7j.json new file mode 100644 index 00000000000..df9c7232ed6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cmjc-52fg-9f7j/GHSA-cmjc-52fg-9f7j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmjc-52fg-9f7j", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-30776" + ], + "details": "An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30776" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/s9w9w10mt2sngk3solwnmq5k7md53tsz" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/04/24/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cmm9-j99w-8844/GHSA-cmm9-j99w-8844.json b/advisories/unreviewed/2023/07/GHSA-cmm9-j99w-8844/GHSA-cmm9-j99w-8844.json new file mode 100644 index 00000000000..4e453031db5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cmm9-j99w-8844/GHSA-cmm9-j99w-8844.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmm9-j99w-8844", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25490" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/archivist-custom-archive-templates/wordpress-archivist-custom-archive-templates-plugin-1-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cp7r-qm2p-wcq3/GHSA-cp7r-qm2p-wcq3.json b/advisories/unreviewed/2023/07/GHSA-cp7r-qm2p-wcq3/GHSA-cp7r-qm2p-wcq3.json new file mode 100644 index 00000000000..b6ad8df0468 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cp7r-qm2p-wcq3/GHSA-cp7r-qm2p-wcq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp7r-qm2p-wcq3", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2022-44631" + ], + "details": "Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <= 1.0.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/1app-business-forms/wordpress-1app-business-forms-plugin-1-0-0-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cp9w-xxfq-xfcf/GHSA-cp9w-xxfq-xfcf.json b/advisories/unreviewed/2023/07/GHSA-cp9w-xxfq-xfcf/GHSA-cp9w-xxfq-xfcf.json new file mode 100644 index 00000000000..183820a75e4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cp9w-xxfq-xfcf/GHSA-cp9w-xxfq-xfcf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp9w-xxfq-xfcf", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-25828" + ], + "details": "Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25828" + }, + { + "type": "WEB", + "url": "https://www.synopsys.com/blogs/software-security/pluck-cms-vulnerability/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cqjg-qrhw-xfcq/GHSA-cqjg-qrhw-xfcq.json b/advisories/unreviewed/2023/07/GHSA-cqjg-qrhw-xfcq/GHSA-cqjg-qrhw-xfcq.json new file mode 100644 index 00000000000..8d75bde8821 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cqjg-qrhw-xfcq/GHSA-cqjg-qrhw-xfcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqjg-qrhw-xfcq", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2023-23879" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nicolas Zeh PHP Execution plugin <= 1.0.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/php-execution-plugin/wordpress-php-execution-plugin-1-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cqr6-3x3f-9wr3/GHSA-cqr6-3x3f-9wr3.json b/advisories/unreviewed/2023/07/GHSA-cqr6-3x3f-9wr3/GHSA-cqr6-3x3f-9wr3.json new file mode 100644 index 00000000000..8cdd485b400 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cqr6-3x3f-9wr3/GHSA-cqr6-3x3f-9wr3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqr6-3x3f-9wr3", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-30465" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the \"orderType\" parameter and the ordering of the returned content using an SQL injection attack, an attacker can extract the username of the   user with ID 1 from the \"user\" table, one character at a time.  Users are advised to upgrade to Apache InLong's 1.6.0 or cherry-pick [1] to solve it.\n \n https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html \n\n[1] https://github.com/apache/inlong/issues/7529 https://github.com/apache/inlong/issues/7529 \n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30465" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/mrh4nr3jrlbj6nxkn4q8hddbfh1pnok0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cr4v-27vv-m68q/GHSA-cr4v-27vv-m68q.json b/advisories/unreviewed/2023/07/GHSA-cr4v-27vv-m68q/GHSA-cr4v-27vv-m68q.json new file mode 100644 index 00000000000..3f945eaa7c1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cr4v-27vv-m68q/GHSA-cr4v-27vv-m68q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr4v-27vv-m68q", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-23892" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jamie Poitra M Chart plugin <= 1.9.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23892" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/m-chart/wordpress-m-chart-plugin-1-9-4-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-crq6-hjhp-f22c/GHSA-crq6-hjhp-f22c.json b/advisories/unreviewed/2023/07/GHSA-crq6-hjhp-f22c/GHSA-crq6-hjhp-f22c.json new file mode 100644 index 00000000000..3fbf9442ca9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-crq6-hjhp-f22c/GHSA-crq6-hjhp-f22c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crq6-hjhp-f22c", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-23461" + ], + "details": "Libpeconv – access violation, before commit b076013 (30/11/2022).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23461" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-15T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cwxp-h4pj-wvp5/GHSA-cwxp-h4pj-wvp5.json b/advisories/unreviewed/2023/07/GHSA-cwxp-h4pj-wvp5/GHSA-cwxp-h4pj-wvp5.json new file mode 100644 index 00000000000..9d2a3635de6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cwxp-h4pj-wvp5/GHSA-cwxp-h4pj-wvp5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwxp-h4pj-wvp5", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-26080" + ], + "details": "Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26080" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A6732&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.256117643.1223066510.1678942947-1879524908.1677751217" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-16T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cxv2-g9cc-jg8q/GHSA-cxv2-g9cc-jg8q.json b/advisories/unreviewed/2023/07/GHSA-cxv2-g9cc-jg8q/GHSA-cxv2-g9cc-jg8q.json new file mode 100644 index 00000000000..0c32ba12311 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cxv2-g9cc-jg8q/GHSA-cxv2-g9cc-jg8q.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxv2-g9cc-jg8q", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2015-10049" + ], + "details": "A vulnerability was found in Overdrive Eletrônica course-builder up to 1.7.x and classified as problematic. Affected by this issue is some unknown functionality of the file coursebuilder/modules/oeditor/oeditor.html. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.0 is able to address this issue. The name of the patch is e39645fd714adb7e549908780235911ae282b21b. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218372.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-10049" + }, + { + "type": "WEB", + "url": "https://github.com/overdrive-diy/course-builder/commit/e39645fd714adb7e549908780235911ae282b21b" + }, + { + "type": "WEB", + "url": "https://github.com/overdrive-diy/course-builder/releases/tag/V1.8.0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.218372" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.218372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-15T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f44g-3vj9-vwv9/GHSA-f44g-3vj9-vwv9.json b/advisories/unreviewed/2023/07/GHSA-f44g-3vj9-vwv9/GHSA-f44g-3vj9-vwv9.json new file mode 100644 index 00000000000..42b6df1eab5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f44g-3vj9-vwv9/GHSA-f44g-3vj9-vwv9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f44g-3vj9-vwv9", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22938" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22938" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0208" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f53g-frr2-jhpf/GHSA-f53g-frr2-jhpf.json b/advisories/unreviewed/2023/07/GHSA-f53g-frr2-jhpf/GHSA-f53g-frr2-jhpf.json new file mode 100644 index 00000000000..40aba7acfa5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f53g-frr2-jhpf/GHSA-f53g-frr2-jhpf.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f53g-frr2-jhpf", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0957" + ], + "details": "An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the extraction of data from workspaces, to a full takeover of the workspace.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0957" + }, + { + "type": "WEB", + "url": "https://github.com/gitpod-io/gitpod/pull/16378" + }, + { + "type": "WEB", + "url": "https://github.com/gitpod-io/gitpod/pull/16405" + }, + { + "type": "WEB", + "url": "https://github.com/gitpod-io/gitpod/commit/12956988eec0031f42ffdfa3bdc3359f65628f9f" + }, + { + "type": "WEB", + "url": "https://github.com/gitpod-io/gitpod/commit/673ab6856fa04c13b7b1f2a968e4d090f1d94e4f" + }, + { + "type": "WEB", + "url": "https://app.safebase.io/portal/71ccd717-aa2d-4a1e-942e-c768d37e9e0c/preview?product=default&orgId=71ccd717-aa2d-4a1e-942e-c768d37e9e0c&tcuUid=1d505bda-9a38-4ca5-8724-052e6337f34d" + }, + { + "type": "WEB", + "url": "https://github.com/gitpod-io/gitpod/releases/tag/release-2022.11.2" + }, + { + "type": "WEB", + "url": "https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-03T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f5c7-p8w5-6jv3/GHSA-f5c7-p8w5-6jv3.json b/advisories/unreviewed/2023/07/GHSA-f5c7-p8w5-6jv3/GHSA-f5c7-p8w5-6jv3.json new file mode 100644 index 00000000000..317a324f709 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f5c7-p8w5-6jv3/GHSA-f5c7-p8w5-6jv3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5c7-p8w5-6jv3", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-27267" + ], + "details": "Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27267" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3305369" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f5hf-7qmf-9r6x/GHSA-f5hf-7qmf-9r6x.json b/advisories/unreviewed/2023/07/GHSA-f5hf-7qmf-9r6x/GHSA-f5hf-7qmf-9r6x.json new file mode 100644 index 00000000000..7b1d065d153 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f5hf-7qmf-9r6x/GHSA-f5hf-7qmf-9r6x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5hf-7qmf-9r6x", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-40178" + ], + "details": "A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). Improper Neutralization of Input During Web Page Generation exists in the “Import Files“ functionality of the “Operation” web application, due to the missing validation of the titles of files included in the input package. By uploading a specifically crafted graphics package, a remote low-privileged attacker can execute arbitrary JavaScript code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40178" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-11T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f5m2-fr27-39rx/GHSA-f5m2-fr27-39rx.json b/advisories/unreviewed/2023/07/GHSA-f5m2-fr27-39rx/GHSA-f5m2-fr27-39rx.json new file mode 100644 index 00000000000..7e92ad0e46b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f5m2-fr27-39rx/GHSA-f5m2-fr27-39rx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5m2-fr27-39rx", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2022-1607" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1607" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A6732&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-24T05:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f5m5-3q5w-4vrg/GHSA-f5m5-3q5w-4vrg.json b/advisories/unreviewed/2023/07/GHSA-f5m5-3q5w-4vrg/GHSA-f5m5-3q5w-4vrg.json new file mode 100644 index 00000000000..63456eb09d4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f5m5-3q5w-4vrg/GHSA-f5m5-3q5w-4vrg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5m5-3q5w-4vrg", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-37892" + ], + "details": "A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address this security vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37892" + }, + { + "type": "WEB", + "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-014.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-07T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ffr6-hhvx-vgcq/GHSA-ffr6-hhvx-vgcq.json b/advisories/unreviewed/2023/07/GHSA-ffr6-hhvx-vgcq/GHSA-ffr6-hhvx-vgcq.json new file mode 100644 index 00000000000..cbf581e07cb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ffr6-hhvx-vgcq/GHSA-ffr6-hhvx-vgcq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffr6-hhvx-vgcq", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-4110" + ], + "details": "The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4110" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/037a81b2-8fd8-4898-bb5b-d15d9a38778c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-26T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json b/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json new file mode 100644 index 00000000000..db96f60e6fb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffrf-xcmj-f59q", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27911" + ], + "details": "A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27911" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0004" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fg63-fcp8-2qj4/GHSA-fg63-fcp8-2qj4.json b/advisories/unreviewed/2023/07/GHSA-fg63-fcp8-2qj4/GHSA-fg63-fcp8-2qj4.json new file mode 100644 index 00000000000..9ee72d5b177 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fg63-fcp8-2qj4/GHSA-fg63-fcp8-2qj4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg63-fcp8-2qj4", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-44634" + ], + "details": "Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/import-shopify-to-woocommerce/wordpress-s2w-import-shopify-to-woocommerce-plugin-1-1-12-auth-local-file-inclusion-lfi-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/import-shopify-to-woocommerce/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-18T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fh6x-wwf2-q46r/GHSA-fh6x-wwf2-q46r.json b/advisories/unreviewed/2023/07/GHSA-fh6x-wwf2-q46r/GHSA-fh6x-wwf2-q46r.json new file mode 100644 index 00000000000..af0a0019be5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fh6x-wwf2-q46r/GHSA-fh6x-wwf2-q46r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh6x-wwf2-q46r", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-22687" + ], + "details": "Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/freesoul-deactivate-plugins/wordpress-freesoul-deactivate-plugins-plugin-manager-and-cleanup-plugin-1-9-4-0-content-spoofing?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fj78-7vc8-pxrm/GHSA-fj78-7vc8-pxrm.json b/advisories/unreviewed/2023/07/GHSA-fj78-7vc8-pxrm/GHSA-fj78-7vc8-pxrm.json new file mode 100644 index 00000000000..f20e041d97d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fj78-7vc8-pxrm/GHSA-fj78-7vc8-pxrm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj78-7vc8-pxrm", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0027" + ], + "details": "Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP Server AOI information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0027" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138766" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fjfr-24j5-f8cq/GHSA-fjfr-24j5-f8cq.json b/advisories/unreviewed/2023/07/GHSA-fjfr-24j5-f8cq/GHSA-fjfr-24j5-f8cq.json new file mode 100644 index 00000000000..f94ee9c7a21 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fjfr-24j5-f8cq/GHSA-fjfr-24j5-f8cq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjfr-24j5-f8cq", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-40679" + ], + "details": "An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40679" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-335" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fjvx-fw48-vr4j/GHSA-fjvx-fw48-vr4j.json b/advisories/unreviewed/2023/07/GHSA-fjvx-fw48-vr4j/GHSA-fjvx-fw48-vr4j.json new file mode 100644 index 00000000000..7834b978f3b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fjvx-fw48-vr4j/GHSA-fjvx-fw48-vr4j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjvx-fw48-vr4j", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-40182" + ], + "details": "A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). The device embedded Chromium-based browser is launched as root with the “--no-sandbox” option. Attackers can add arbitrary JavaScript code inside “Operation” graphics and successfully exploit any number of publicly known vulnerabilities against the version of the embedded Chromium-based browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40182" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-11T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fp8q-744c-xpg4/GHSA-fp8q-744c-xpg4.json b/advisories/unreviewed/2023/07/GHSA-fp8q-744c-xpg4/GHSA-fp8q-744c-xpg4.json new file mode 100644 index 00000000000..bc6b4dab062 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fp8q-744c-xpg4/GHSA-fp8q-744c-xpg4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp8q-744c-xpg4", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2023-22611" + ], + "details": "A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. Affected Products: EcoStruxure™ Geo SCADA Expert 2019, EcoStruxure™ Geo SCADA Expert 2020, EcoStruxure™ Geo SCADA Expert 2021 (All versions prior to October 2022), ClearSCADA (All Versions).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22611" + }, + { + "type": "WEB", + "url": "https://www.se.com/ww/en/download/document/SEVD-2023-010-02/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-31T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json b/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json new file mode 100644 index 00000000000..22264fe3f89 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqm3-34q3-vw23", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-24502" + ], + "details": "Electra Central AC unit – The unit opens an AP with an easily calculated password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24502" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json b/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json new file mode 100644 index 00000000000..becc9110a91 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr44-f297-ppg9", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2023-0052" + ], + "details": "SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0052" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-05" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-20T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fw5r-85gc-4v62/GHSA-fw5r-85gc-4v62.json b/advisories/unreviewed/2023/07/GHSA-fw5r-85gc-4v62/GHSA-fw5r-85gc-4v62.json new file mode 100644 index 00000000000..5264ac885dd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fw5r-85gc-4v62/GHSA-fw5r-85gc-4v62.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw5r-85gc-4v62", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-45127" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its backup services. An attacker could take advantage of this vulnerability to execute arbitrary backup operations and cause a denial-of-service condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45127" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fw8m-f5g8-v52m/GHSA-fw8m-f5g8-v52m.json b/advisories/unreviewed/2023/07/GHSA-fw8m-f5g8-v52m/GHSA-fw8m-f5g8-v52m.json new file mode 100644 index 00000000000..506b59fefc9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fw8m-f5g8-v52m/GHSA-fw8m-f5g8-v52m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw8m-f5g8-v52m", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-43565" + ], + "details": "In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43565" + }, + { + "type": "WEB", + "url": "https://www.splunk.com/en_us/product-security/announcements/svd-2022-1105.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-04T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json b/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json new file mode 100644 index 00000000000..f5d8833d3eb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fww7-pq4g-vxx7", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-24500" + ], + "details": "Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24500" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fx7f-p7m7-6rcc/GHSA-fx7f-p7m7-6rcc.json b/advisories/unreviewed/2023/07/GHSA-fx7f-p7m7-6rcc/GHSA-fx7f-p7m7-6rcc.json new file mode 100644 index 00000000000..acf59c45942 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fx7f-p7m7-6rcc/GHSA-fx7f-p7m7-6rcc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx7f-p7m7-6rcc", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-47162" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47162" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dh-anti-adblocker/wordpress-dh-anti-adblocker-plugin-36-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fxcr-gvcw-hmqm/GHSA-fxcr-gvcw-hmqm.json b/advisories/unreviewed/2023/07/GHSA-fxcr-gvcw-hmqm/GHSA-fxcr-gvcw-hmqm.json new file mode 100644 index 00000000000..6f785d3918a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fxcr-gvcw-hmqm/GHSA-fxcr-gvcw-hmqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxcr-gvcw-hmqm", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-22249" + ], + "details": "Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22249" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb23-17.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fxjg-28fm-pfxh/GHSA-fxjg-28fm-pfxh.json b/advisories/unreviewed/2023/07/GHSA-fxjg-28fm-pfxh/GHSA-fxjg-28fm-pfxh.json new file mode 100644 index 00000000000..3bd524c9608 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fxjg-28fm-pfxh/GHSA-fxjg-28fm-pfxh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxjg-28fm-pfxh", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-25504" + ], + "details": "A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery\nattacks and query internal resources on behalf of the server where Superset\nis deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25504" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/tdnzkocfsqg2sbbornnp9g492fn4zhtx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fxr5-7g6j-cj5f/GHSA-fxr5-7g6j-cj5f.json b/advisories/unreviewed/2023/07/GHSA-fxr5-7g6j-cj5f/GHSA-fxr5-7g6j-cj5f.json new file mode 100644 index 00000000000..60c85e2f655 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fxr5-7g6j-cj5f/GHSA-fxr5-7g6j-cj5f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxr5-7g6j-cj5f", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-25550" + ], + "details": "\n\n\n\n\n\n\n\n\nA CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that\nallows remote code execution via the “hostname” parameter when maliciously crafted hostname\nsyntax is entered.\n\n \n\n\n\n\n \n\n \n\n Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25550" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-045-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g237-q563-mgqx/GHSA-g237-q563-mgqx.json b/advisories/unreviewed/2023/07/GHSA-g237-q563-mgqx/GHSA-g237-q563-mgqx.json new file mode 100644 index 00000000000..8c99e71ab82 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g237-q563-mgqx/GHSA-g237-q563-mgqx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g237-q563-mgqx", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-33859" + ], + "details": "A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature. This vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported. Customers are advised to update the software to the latest version (v7.6). Foreseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html .", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33859" + }, + { + "type": "WEB", + "url": "https://www.eaton.com/us/en-us/company/news-insights/cybersecurity/security-notifications.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-28T02:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g276-jg34-q58g/GHSA-g276-jg34-q58g.json b/advisories/unreviewed/2023/07/GHSA-g276-jg34-q58g/GHSA-g276-jg34-q58g.json new file mode 100644 index 00000000000..39b54bf656c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g276-jg34-q58g/GHSA-g276-jg34-q58g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g276-jg34-q58g", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-22913" + ], + "details": "A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in denial-of-service (DoS) conditions on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22913" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g2g3-6rcc-6c9q/GHSA-g2g3-6rcc-6c9q.json b/advisories/unreviewed/2023/07/GHSA-g2g3-6rcc-6c9q/GHSA-g2g3-6rcc-6c9q.json new file mode 100644 index 00000000000..d6eff6f4006 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g2g3-6rcc-6c9q/GHSA-g2g3-6rcc-6c9q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2g3-6rcc-6c9q", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-2640" + ], + "details": "The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2640" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-02T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g32g-63v9-68pf/GHSA-g32g-63v9-68pf.json b/advisories/unreviewed/2023/07/GHSA-g32g-63v9-68pf/GHSA-g32g-63v9-68pf.json new file mode 100644 index 00000000000..b32e9e151c4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g32g-63v9-68pf/GHSA-g32g-63v9-68pf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g32g-63v9-68pf", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2022-47603" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47603" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gallery-album/wordpress-gallery-image-and-video-gallery-with-thumbnails-plugin-2-0-1-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g37x-jpmr-w7p9/GHSA-g37x-jpmr-w7p9.json b/advisories/unreviewed/2023/07/GHSA-g37x-jpmr-w7p9/GHSA-g37x-jpmr-w7p9.json new file mode 100644 index 00000000000..98f105173e5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g37x-jpmr-w7p9/GHSA-g37x-jpmr-w7p9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g37x-jpmr-w7p9", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-3086" + ], + "details": "An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1.1, UC-8540 Series V1.0 to V1.2, UC-8410A Series V2.2, UC-8200 Series V1.0 to V2.4, UC-8100A-ME-T Series V1.0 to V1.1, UC-8100 Series V1.2 to V1.3, UC-5100 Series V1.2, UC-3100 Series V1.2 to V2.0, UC-2100 Series V1.3 to V1.5, and UC-2100-W Series V1.3 to V1.5 can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3086" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-333-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1263" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-02T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g722-qfq8-hp64/GHSA-g722-qfq8-hp64.json b/advisories/unreviewed/2023/07/GHSA-g722-qfq8-hp64/GHSA-g722-qfq8-hp64.json new file mode 100644 index 00000000000..c57ed5e45dc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g722-qfq8-hp64/GHSA-g722-qfq8-hp64.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g722-qfq8-hp64", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-3184" + ], + "details": "Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3184" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-263-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-21T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g7w9-8ww6-vhhw/GHSA-g7w9-8ww6-vhhw.json b/advisories/unreviewed/2023/07/GHSA-g7w9-8ww6-vhhw/GHSA-g7w9-8ww6-vhhw.json new file mode 100644 index 00000000000..782fec667b4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g7w9-8ww6-vhhw/GHSA-g7w9-8ww6-vhhw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7w9-8ww6-vhhw", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-23889" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23889" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/quick-paypal-payments/wordpress-quick-paypal-payments-plugin-5-7-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g7x8-fww2-5qqg/GHSA-g7x8-fww2-5qqg.json b/advisories/unreviewed/2023/07/GHSA-g7x8-fww2-5qqg/GHSA-g7x8-fww2-5qqg.json new file mode 100644 index 00000000000..66c5807deba --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g7x8-fww2-5qqg/GHSA-g7x8-fww2-5qqg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7x8-fww2-5qqg", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-40179" + ], + "details": "A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in endpoints of the “Operation” web application that interpret and execute Axon language queries, due to the missing validation of anti-CSRF tokens or other origin checks. By convincing a victim to click on a malicious link or visit a specifically crafted webpage while logged-in to the device web application, a remote unauthenticated attacker can execute arbitrary Axon queries against the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40179" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-11T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json b/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json new file mode 100644 index 00000000000..945f868aa7a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gcxw-4wrx-xhw5/GHSA-gcxw-4wrx-xhw5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcxw-4wrx-xhw5", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-25837" + ], + "details": "Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code pairing if the MITM negotiates BR/EDR Secure Simple Pairing in Secure Connections mode using the Passkey association model with the pairing Initiator and BR/EDR Legacy PIN code pairing with the pairing Responder and brute forces the Passkey entered by the user into the Responder as a 6-digit PIN code. The MITM attacker can use the identified PIN code value as the Passkey value to complete authentication with the Initiator via Bluetooth pairing method confusion.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25837" + }, + { + "type": "WEB", + "url": "https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/reporting-security/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-12T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gfcp-5456-7q6c/GHSA-gfcp-5456-7q6c.json b/advisories/unreviewed/2023/07/GHSA-gfcp-5456-7q6c/GHSA-gfcp-5456-7q6c.json new file mode 100644 index 00000000000..1ae590ad3ea --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gfcp-5456-7q6c/GHSA-gfcp-5456-7q6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfcp-5456-7q6c", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-36785" + ], + "details": "D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 \"login.asp\" A. The window.location.href = http://192.168.1.1/setupWizard.asp\" http://192.168.1.1/setupWizard.asp\" ; \"admin\" – contains default username value \"login.asp\" B. While accessing the web interface, the login form at *Authorization Bypass – URL by \"setupWizard.asp' while it blocks direct access to – the web interface does not properly validate user identity variables values located at the client side, it is available to access it without a \"login_glag\" and \"login_status\" checking browser and to read the admin user credentials for the web interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36785" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gh9g-ghf4-75r3/GHSA-gh9g-ghf4-75r3.json b/advisories/unreviewed/2023/07/GHSA-gh9g-ghf4-75r3/GHSA-gh9g-ghf4-75r3.json new file mode 100644 index 00000000000..11eae63d374 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gh9g-ghf4-75r3/GHSA-gh9g-ghf4-75r3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh9g-ghf4-75r3", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2022-45361" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Boris Kuzmanov 0mk Shortener plugin <= 0.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45361" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/0mk-shortener/wordpress-0mk-shortener-plugin-0-2-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json b/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json new file mode 100644 index 00000000000..f0c180b304f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjg3-8mx2-7f8f", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2022-38840" + ], + "details": "cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38840" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/folders/1UG5IcL8fFp9MV0vjd78_cx6iXKda5bpM?usp=sharing" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/171439/MAN-EAM-0003-3.2.4-XML-Injection.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T02:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json b/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json new file mode 100644 index 00000000000..547af7e1da3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjmv-6p6x-5mrf", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2022-27677" + ], + "details": "Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27677" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1052" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gm67-h5wr-w3cv/GHSA-gm67-h5wr-w3cv.json b/advisories/unreviewed/2023/07/GHSA-gm67-h5wr-w3cv/GHSA-gm67-h5wr-w3cv.json new file mode 100644 index 00000000000..e8e124a9afc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gm67-h5wr-w3cv/GHSA-gm67-h5wr-w3cv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm67-h5wr-w3cv", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2021-28655" + ], + "details": "The improper Input Validation vulnerability in \"”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-28655" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/bxs056g3xlsofz0jb3wny9dw4llwptd2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-16T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gmm4-c64x-vxp8/GHSA-gmm4-c64x-vxp8.json b/advisories/unreviewed/2023/07/GHSA-gmm4-c64x-vxp8/GHSA-gmm4-c64x-vxp8.json new file mode 100644 index 00000000000..c51a51aad1c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gmm4-c64x-vxp8/GHSA-gmm4-c64x-vxp8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmm4-c64x-vxp8", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-1080" + ], + "details": "The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1080" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gn-publisher/trunk/templates/settings.php#L70" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8a4ee97c-63cd-4a5e-a112-6d4c4c627a57" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-28T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gpxg-3cwf-59mg/GHSA-gpxg-3cwf-59mg.json b/advisories/unreviewed/2023/07/GHSA-gpxg-3cwf-59mg/GHSA-gpxg-3cwf-59mg.json new file mode 100644 index 00000000000..3edb32d950a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gpxg-3cwf-59mg/GHSA-gpxg-3cwf-59mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpxg-3cwf-59mg", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-24835" + ], + "details": "Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or disrupt service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24835" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6955-c7612-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gq33-qvc5-v66x/GHSA-gq33-qvc5-v66x.json b/advisories/unreviewed/2023/07/GHSA-gq33-qvc5-v66x/GHSA-gq33-qvc5-v66x.json new file mode 100644 index 00000000000..a82f4a7077b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gq33-qvc5-v66x/GHSA-gq33-qvc5-v66x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq33-qvc5-v66x", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2023-23950" + ], + "details": "User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23950" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/21174" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-26T21:18:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gqgc-w6w9-6h7c/GHSA-gqgc-w6w9-6h7c.json b/advisories/unreviewed/2023/07/GHSA-gqgc-w6w9-6h7c/GHSA-gqgc-w6w9-6h7c.json new file mode 100644 index 00000000000..2f10351d1ed --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gqgc-w6w9-6h7c/GHSA-gqgc-w6w9-6h7c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqgc-w6w9-6h7c", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-32516" + ], + "details": "A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32516" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-03_ConextCombox_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gqm5-4x4w-m9wr/GHSA-gqm5-4x4w-m9wr.json b/advisories/unreviewed/2023/07/GHSA-gqm5-4x4w-m9wr/GHSA-gqm5-4x4w-m9wr.json new file mode 100644 index 00000000000..fc74582cf6d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gqm5-4x4w-m9wr/GHSA-gqm5-4x4w-m9wr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqm5-4x4w-m9wr", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-47143" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47143" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multiple-pages-generator-by-porthas/wordpress-multiple-pages-generator-by-themeisle-plugin-3-3-9-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gvjm-jwhg-373p/GHSA-gvjm-jwhg-373p.json b/advisories/unreviewed/2023/07/GHSA-gvjm-jwhg-373p/GHSA-gvjm-jwhg-373p.json new file mode 100644 index 00000000000..936f75dfd5c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gvjm-jwhg-373p/GHSA-gvjm-jwhg-373p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvjm-jwhg-373p", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-38207" + ], + "details": "There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked which could execute arbitrary JavaScript code in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38207" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2022-update-2-patch-is-now-available" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gwwh-wv9x-j72w/GHSA-gwwh-wv9x-j72w.json b/advisories/unreviewed/2023/07/GHSA-gwwh-wv9x-j72w/GHSA-gwwh-wv9x-j72w.json new file mode 100644 index 00000000000..96244f6c9aa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gwwh-wv9x-j72w/GHSA-gwwh-wv9x-j72w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwwh-wv9x-j72w", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0460" + ], + "details": "The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from YouTube Main App by retrieving the Main App’s ClassLoader. A potential vulnerability in the binding logic used by the client SDK where the SDK ends up calling bindService() on a malicious app rather than YT Main App. This creates a vulnerability where the SDK can load the malicious app’s ClassLoader instead, allowing the malicious app to load arbitrary code into the calling app whenever the embedded SDK is invoked. In order to trigger this vulnerability, an attacker must masquerade the Youtube app and install it on a device, have a second app that uses the Embedded player and typically distribute both to the victim outside of the Play Store.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0460" + }, + { + "type": "WEB", + "url": "https://developers.google.com/youtube/android/player/downloads" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gx7w-2wg7-5mcp/GHSA-gx7w-2wg7-5mcp.json b/advisories/unreviewed/2023/07/GHSA-gx7w-2wg7-5mcp/GHSA-gx7w-2wg7-5mcp.json new file mode 100644 index 00000000000..e16cb2031ff --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gx7w-2wg7-5mcp/GHSA-gx7w-2wg7-5mcp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx7w-2wg7-5mcp", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-25968" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25968" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/client-portal/wordpress-client-portal-plugin-1-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-15T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h2w4-r6g5-2cm8/GHSA-h2w4-r6g5-2cm8.json b/advisories/unreviewed/2023/07/GHSA-h2w4-r6g5-2cm8/GHSA-h2w4-r6g5-2cm8.json new file mode 100644 index 00000000000..25377f09eba --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h2w4-r6g5-2cm8/GHSA-h2w4-r6g5-2cm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2w4-r6g5-2cm8", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-44735" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44735" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/clictracker/wordpress-clictracker-plugin-1-0-5-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h4gh-9cxx-pfjv/GHSA-h4gh-9cxx-pfjv.json b/advisories/unreviewed/2023/07/GHSA-h4gh-9cxx-pfjv/GHSA-h4gh-9cxx-pfjv.json new file mode 100644 index 00000000000..95f8c0220b2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h4gh-9cxx-pfjv/GHSA-h4gh-9cxx-pfjv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4gh-9cxx-pfjv", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27912" + ], + "details": "A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27912" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h4pp-x3cc-f8mv/GHSA-h4pp-x3cc-f8mv.json b/advisories/unreviewed/2023/07/GHSA-h4pp-x3cc-f8mv/GHSA-h4pp-x3cc-f8mv.json new file mode 100644 index 00000000000..47c147f82ba --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h4pp-x3cc-f8mv/GHSA-h4pp-x3cc-f8mv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4pp-x3cc-f8mv", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-42732" + ], + "details": "A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42732" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-741697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h6fv-f2m3-r3mm/GHSA-h6fv-f2m3-r3mm.json b/advisories/unreviewed/2023/07/GHSA-h6fv-f2m3-r3mm/GHSA-h6fv-f2m3-r3mm.json new file mode 100644 index 00000000000..2f5c7af0a7c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h6fv-f2m3-r3mm/GHSA-h6fv-f2m3-r3mm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6fv-f2m3-r3mm", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22940" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to a summary index that unprivileged users could access. The vulnerability requires a higher privileged user to initiate a request within their browser, and only affects instances with Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22940" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0210" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/endpoint/ee69374a-d27e-4136-adac-956a96ff60fd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h93h-mcv3-8hvx/GHSA-h93h-mcv3-8hvx.json b/advisories/unreviewed/2023/07/GHSA-h93h-mcv3-8hvx/GHSA-h93h-mcv3-8hvx.json new file mode 100644 index 00000000000..f52926c7224 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h93h-mcv3-8hvx/GHSA-h93h-mcv3-8hvx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h93h-mcv3-8hvx", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-43566" + ], + "details": "In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards in the Analytics Workspace. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43566" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/b6d77c6c-f011-4b03-8650-8f10edb7c4a8/" + }, + { + "type": "WEB", + "url": "https://www.splunk.com/en_us/product-security/announcements/svd-2022-1106.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-04T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h9xm-49jv-5p2p/GHSA-h9xm-49jv-5p2p.json b/advisories/unreviewed/2023/07/GHSA-h9xm-49jv-5p2p/GHSA-h9xm-49jv-5p2p.json new file mode 100644 index 00000000000..dd576282fc6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h9xm-49jv-5p2p/GHSA-h9xm-49jv-5p2p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9xm-49jv-5p2p", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2023-22389" + ], + "details": "Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22389" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json b/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json new file mode 100644 index 00000000000..131bcf71835 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc89-xf9q-xh2p", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-27293" + ], + "details": "Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27293" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2023-8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-28T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hhvx-8755-4cvw/GHSA-hhvx-8755-4cvw.json b/advisories/unreviewed/2023/07/GHSA-hhvx-8755-4cvw/GHSA-hhvx-8755-4cvw.json new file mode 100644 index 00000000000..2bc2e22b3dc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hhvx-8755-4cvw/GHSA-hhvx-8755-4cvw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhvx-8755-4cvw", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-1296" + ], + "details": "HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1296" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2023-09-nomad-acls-can-not-deny-access-to-workloads-own-variables/51390" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hj63-292f-w39q/GHSA-hj63-292f-w39q.json b/advisories/unreviewed/2023/07/GHSA-hj63-292f-w39q/GHSA-hj63-292f-w39q.json new file mode 100644 index 00000000000..7ff36f24e7e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hj63-292f-w39q/GHSA-hj63-292f-w39q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj63-292f-w39q", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-1469" + ], + "details": "The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: This can potentially be exploited by lower-privileged users if the `Admin Dashboard Access Permission` setting it set for those users to access the dashboard.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1469" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2879453%40wp-express-checkout&new=2879453%40wp-express-checkout&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b35ee801-f04d-4b22-8238-053b02a6ee0c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-17T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hjjq-3jj4-c7c6/GHSA-hjjq-3jj4-c7c6.json b/advisories/unreviewed/2023/07/GHSA-hjjq-3jj4-c7c6/GHSA-hjjq-3jj4-c7c6.json new file mode 100644 index 00000000000..5f550fcd999 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hjjq-3jj4-c7c6/GHSA-hjjq-3jj4-c7c6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjjq-3jj4-c7c6", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-4139" + ], + "details": "An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4139" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2147572" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2022/11/30/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-27T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hm6w-2fjv-w79j/GHSA-hm6w-2fjv-w79j.json b/advisories/unreviewed/2023/07/GHSA-hm6w-2fjv-w79j/GHSA-hm6w-2fjv-w79j.json new file mode 100644 index 00000000000..483b050c324 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hm6w-2fjv-w79j/GHSA-hm6w-2fjv-w79j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm6w-2fjv-w79j", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-45839" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wha-puzzle/wordpress-wha-puzzle-plugin-1-0-9-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hvmh-7jp7-68cp/GHSA-hvmh-7jp7-68cp.json b/advisories/unreviewed/2023/07/GHSA-hvmh-7jp7-68cp/GHSA-hvmh-7jp7-68cp.json new file mode 100644 index 00000000000..ee986fd9cf4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hvmh-7jp7-68cp/GHSA-hvmh-7jp7-68cp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvmh-7jp7-68cp", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27915" + ], + "details": "A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27915" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hwpv-98vq-7mw4/GHSA-hwpv-98vq-7mw4.json b/advisories/unreviewed/2023/07/GHSA-hwpv-98vq-7mw4/GHSA-hwpv-98vq-7mw4.json new file mode 100644 index 00000000000..3785368dcfb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hwpv-98vq-7mw4/GHSA-hwpv-98vq-7mw4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwpv-98vq-7mw4", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-27628" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-amazon-affiliates-light-version/wordpress-wzone-lite-version-plugin-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-06T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hwwj-xrc2-6hxg/GHSA-hwwj-xrc2-6hxg.json b/advisories/unreviewed/2023/07/GHSA-hwwj-xrc2-6hxg/GHSA-hwwj-xrc2-6hxg.json new file mode 100644 index 00000000000..dae20330aac --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hwwj-xrc2-6hxg/GHSA-hwwj-xrc2-6hxg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwwj-xrc2-6hxg", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2235" + ], + "details": "A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.\n\nThe perf_group_detach function did not check the event's siblings' attach_state before calling add_event_to_groups(), but remove_on_exec made it possible to call list_del_event() on before detaching from their group, making it possible to use a dangling pointer causing a use-after-free vulnerability.\n\nWe recommend upgrading past commit fd0815f632c24878e325821943edccc7fde947a2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2235" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fd0815f632c24878e325821943edccc7fde947a2" + }, + { + "type": "WEB", + "url": "https://kernel.dance/fd0815f632c24878e325821943edccc7fde947a2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j2j9-pq33-wj97/GHSA-j2j9-pq33-wj97.json b/advisories/unreviewed/2023/07/GHSA-j2j9-pq33-wj97/GHSA-j2j9-pq33-wj97.json new file mode 100644 index 00000000000..e5b0ad79a71 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j2j9-pq33-wj97/GHSA-j2j9-pq33-wj97.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2j9-pq33-wj97", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-45444" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database with unrestricted access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45444" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j37v-6hvg-rp7r/GHSA-j37v-6hvg-rp7r.json b/advisories/unreviewed/2023/07/GHSA-j37v-6hvg-rp7r/GHSA-j37v-6hvg-rp7r.json new file mode 100644 index 00000000000..835f71d319f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j37v-6hvg-rp7r/GHSA-j37v-6hvg-rp7r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j37v-6hvg-rp7r", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22933" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’. The vulnerability affects instances with Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22933" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0203" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/9ac2bfea-a234-4a18-9d37-6d747e85c2e4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j4g2-785h-m856/GHSA-j4g2-785h-m856.json b/advisories/unreviewed/2023/07/GHSA-j4g2-785h-m856/GHSA-j4g2-785h-m856.json new file mode 100644 index 00000000000..8344b234ff5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j4g2-785h-m856/GHSA-j4g2-785h-m856.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4g2-785h-m856", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25461" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-insert/wordpress-wp-insert-plugin-2-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j4q7-rgmr-c632/GHSA-j4q7-rgmr-c632.json b/advisories/unreviewed/2023/07/GHSA-j4q7-rgmr-c632/GHSA-j4q7-rgmr-c632.json new file mode 100644 index 00000000000..aaab0f0b3fc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j4q7-rgmr-c632/GHSA-j4q7-rgmr-c632.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4q7-rgmr-c632", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-43770" + ], + "details": "\nHitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   \n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43770" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/14739303079053" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json b/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json new file mode 100644 index 00000000000..e4dbd906a08 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j4r5-9qqm-p694/GHSA-j4r5-9qqm-p694.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4r5-9qqm-p694", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2236" + ], + "details": "A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.\n\nBoth io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.\n\nWe recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2236" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9d94c04c0db024922e886c9fd429659f22f48ea4" + }, + { + "type": "WEB", + "url": "https://kernel.dance/9d94c04c0db024922e886c9fd429659f22f48ea4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j4w7-pf4q-5fwj/GHSA-j4w7-pf4q-5fwj.json b/advisories/unreviewed/2023/07/GHSA-j4w7-pf4q-5fwj/GHSA-j4w7-pf4q-5fwj.json new file mode 100644 index 00000000000..ac63b852431 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j4w7-pf4q-5fwj/GHSA-j4w7-pf4q-5fwj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4w7-pf4q-5fwj", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-23835" + ], + "details": "A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15). Some of the Mendix runtime API’s allow attackers to bypass XPath constraints and retrieve information using XPath queries that trigger errors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23835" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-252808.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j62m-xr5c-f9qv/GHSA-j62m-xr5c-f9qv.json b/advisories/unreviewed/2023/07/GHSA-j62m-xr5c-f9qv/GHSA-j62m-xr5c-f9qv.json new file mode 100644 index 00000000000..c56b3ff37b9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j62m-xr5c-f9qv/GHSA-j62m-xr5c-f9qv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j62m-xr5c-f9qv", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-23717" + ], + "details": "Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in George Gecewicz Portfolio Slideshow plugin <= 1.13.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23717" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/portfolio-slideshow/wordpress-portfolio-slideshow-plugin-1-13-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j893-r6jv-55xv/GHSA-j893-r6jv-55xv.json b/advisories/unreviewed/2023/07/GHSA-j893-r6jv-55xv/GHSA-j893-r6jv-55xv.json new file mode 100644 index 00000000000..15bbb42d197 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j893-r6jv-55xv/GHSA-j893-r6jv-55xv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j893-r6jv-55xv", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-43377" + ], + "details": "\n\n\n\n\nA CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that\ncould cause account takeover when a brute force attack is performed on the account.\n\n\n\n Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0\n\n and prior)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43377" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-312-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j9r7-xgvg-h2r5/GHSA-j9r7-xgvg-h2r5.json b/advisories/unreviewed/2023/07/GHSA-j9r7-xgvg-h2r5/GHSA-j9r7-xgvg-h2r5.json new file mode 100644 index 00000000000..bf7ecf4ab4a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j9r7-xgvg-h2r5/GHSA-j9r7-xgvg-h2r5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9r7-xgvg-h2r5", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-39065" + ], + "details": "A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÅDFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected. CVSS 3.1 Base Score: 6.5 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39065" + }, + { + "type": "WEB", + "url": "https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting-gateway/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-14T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jhfw-j77h-rvv3/GHSA-jhfw-j77h-rvv3.json b/advisories/unreviewed/2023/07/GHSA-jhfw-j77h-rvv3/GHSA-jhfw-j77h-rvv3.json new file mode 100644 index 00000000000..f4aa3c94211 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jhfw-j77h-rvv3/GHSA-jhfw-j77h-rvv3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhfw-j77h-rvv3", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-41671" + ], + "details": "A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41671" + }, + { + "type": "WEB", + "url": "https://www.se.com/ww/en/download/document/SEVD-2022-284-01/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-04T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json b/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json new file mode 100644 index 00000000000..f21bd72f999 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jm25-87xp-4h76/GHSA-jm25-87xp-4h76.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm25-87xp-4h76", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2023-22501" + ], + "details": "An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: * If the attacker is included on Jira issues or requests with these users, or * If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22501" + }, + { + "type": "WEB", + "url": "https://jira.atlassian.com/browse/JSDSERVER-12312" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-01T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json b/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json new file mode 100644 index 00000000000..7f0b1cb1ed1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jm67-cprv-v6wx/GHSA-jm67-cprv-v6wx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm67-cprv-v6wx", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0030" + ], + "details": "A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0030" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/729eba3355674f2d9524629b73683ba1d1cd3f10" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2157270" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-08T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jpg4-8c5p-qm22/GHSA-jpg4-8c5p-qm22.json b/advisories/unreviewed/2023/07/GHSA-jpg4-8c5p-qm22/GHSA-jpg4-8c5p-qm22.json new file mode 100644 index 00000000000..37f8de73bac --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jpg4-8c5p-qm22/GHSA-jpg4-8c5p-qm22.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpg4-8c5p-qm22", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-47605" + ], + "details": "Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-404-pro/wordpress-custom-404-pro-plugin-3-7-0-admin-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-12T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jr7p-69vw-fwhf/GHSA-jr7p-69vw-fwhf.json b/advisories/unreviewed/2023/07/GHSA-jr7p-69vw-fwhf/GHSA-jr7p-69vw-fwhf.json new file mode 100644 index 00000000000..6620e34cd58 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jr7p-69vw-fwhf/GHSA-jr7p-69vw-fwhf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr7p-69vw-fwhf", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2020-36667" + ], + "details": "The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backup_guard_cloud_dropbox, backup_guard_cloud_gdrive, and backup_guard_cloud_oneDrive functions. This makes it possible for authenticated attackers, with minimal permissions, such as a subscriber to change to location of back-ups and potentially steal sensitive information from them.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36667" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2348984%40backup&new=2348984%40backup&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/59532447-1d74-4d34-85f5-d89b65a001d8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-07T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jrgc-m5wf-7pch/GHSA-jrgc-m5wf-7pch.json b/advisories/unreviewed/2023/07/GHSA-jrgc-m5wf-7pch/GHSA-jrgc-m5wf-7pch.json new file mode 100644 index 00000000000..8e065ff12e3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jrgc-m5wf-7pch/GHSA-jrgc-m5wf-7pch.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrgc-m5wf-7pch", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-2248" + ], + "details": "A heap out-of-bounds read/write vulnerability in the Linux Kernel traffic control (QoS) subsystem can be exploited to achieve local privilege escalation.\n\nThe qfq_change_class function does not properly limit the lmax variable which can lead to out-of-bounds read/write. If the TCA_QFQ_LMAX value is not offered through nlattr, lmax is determined by the MTU value of the network device. The MTU of the loopback device can be set up to 2^31-1 and as a result, it is possible to have an lmax value that exceeds QFQ_MIN_LMAX.\n\nWe recommend upgrading past commit 3037933448f60f9acb705997eae62013ecb81e0d.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2248" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3037933448f60f9acb705997eae62013ecb81e0d" + }, + { + "type": "WEB", + "url": "https://kernel.dance/3037933448f60f9acb705997eae62013ecb81e0d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json b/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json new file mode 100644 index 00000000000..1e674d3db28 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jrmv-h6h9-gcm3/GHSA-jrmv-h6h9-gcm3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrmv-h6h9-gcm3", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2021-4314" + ], + "details": "It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS client or the API ML API to query will be deceived into believing the information in the JWT token is valid when it isn’t. It’s possible to use this to persuade the southbound service that different user is authenticated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4314" + }, + { + "type": "WEB", + "url": "https://github.com/zowe/api-layer/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jv37-6f69-j8gw/GHSA-jv37-6f69-j8gw.json b/advisories/unreviewed/2023/07/GHSA-jv37-6f69-j8gw/GHSA-jv37-6f69-j8gw.json new file mode 100644 index 00000000000..cf3a05f4556 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jv37-6f69-j8gw/GHSA-jv37-6f69-j8gw.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv37-6f69-j8gw", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-23762" + ], + "details": "An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do so, an attacker would need write access to the repository and be able to correctly guess the target branch before it’s created by the code maintainer. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.9 and was fixed in versions 3.4.18, 3.5.15, 3.6.11, 3.7.8, and 3.8.1. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23762" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.18" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.6/admin/release-notes#3.6.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.7/admin/release-notes#3.7.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-07T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jv4j-r7qp-qq7x/GHSA-jv4j-r7qp-qq7x.json b/advisories/unreviewed/2023/07/GHSA-jv4j-r7qp-qq7x/GHSA-jv4j-r7qp-qq7x.json new file mode 100644 index 00000000000..a092165676f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jv4j-r7qp-qq7x/GHSA-jv4j-r7qp-qq7x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv4j-r7qp-qq7x", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-45837" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Denis ???????? plugin <= 6.0.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45837" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/weixin-robot-advanced/wordpress-plugin-6-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jv64-r55r-6x87/GHSA-jv64-r55r-6x87.json b/advisories/unreviewed/2023/07/GHSA-jv64-r55r-6x87/GHSA-jv64-r55r-6x87.json new file mode 100644 index 00000000000..8c213214b98 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jv64-r55r-6x87/GHSA-jv64-r55r-6x87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv64-r55r-6x87", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-27619" + ], + "details": "Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/regina-lite/wordpress-regina-lite-theme-2-0-7-reflected-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jw27-wjv9-vrx7/GHSA-jw27-wjv9-vrx7.json b/advisories/unreviewed/2023/07/GHSA-jw27-wjv9-vrx7/GHSA-jw27-wjv9-vrx7.json new file mode 100644 index 00000000000..41f1030c2d1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jw27-wjv9-vrx7/GHSA-jw27-wjv9-vrx7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw27-wjv9-vrx7", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2022-45849" + ], + "details": "Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/activello/wordpress-activello-theme-1-4-4-auth-reflected-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jwcx-m84w-h98g/GHSA-jwcx-m84w-h98g.json b/advisories/unreviewed/2023/07/GHSA-jwcx-m84w-h98g/GHSA-jwcx-m84w-h98g.json new file mode 100644 index 00000000000..92062f195c5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jwcx-m84w-h98g/GHSA-jwcx-m84w-h98g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwcx-m84w-h98g", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-28770" + ], + "details": "The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28770" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jwp6-2mv6-8gq3/GHSA-jwp6-2mv6-8gq3.json b/advisories/unreviewed/2023/07/GHSA-jwp6-2mv6-8gq3/GHSA-jwp6-2mv6-8gq3.json new file mode 100644 index 00000000000..9ff7a4e65f9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jwp6-2mv6-8gq3/GHSA-jwp6-2mv6-8gq3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwp6-2mv6-8gq3", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-43946" + ], + "details": "Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43946" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-429" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m29m-7j2f-w35x/GHSA-m29m-7j2f-w35x.json b/advisories/unreviewed/2023/07/GHSA-m29m-7j2f-w35x/GHSA-m29m-7j2f-w35x.json new file mode 100644 index 00000000000..180a1691711 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m29m-7j2f-w35x/GHSA-m29m-7j2f-w35x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m29m-7j2f-w35x", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2023-0294" + ], + "details": "The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on its AJAX actions function. This makes it possible for unauthenticated attackers to change image categories used by the plugin, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0294" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/mediamatic/trunk/inc/sidebar.php?rev=2652957#L343" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d81ed8d9-4a7a-4b75-aab4-8e4dbd554f32" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-13T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m2hp-qjqj-65cw/GHSA-m2hp-qjqj-65cw.json b/advisories/unreviewed/2023/07/GHSA-m2hp-qjqj-65cw/GHSA-m2hp-qjqj-65cw.json new file mode 100644 index 00000000000..9e5fac87ecd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m2hp-qjqj-65cw/GHSA-m2hp-qjqj-65cw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2hp-qjqj-65cw", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-0895" + ], + "details": "The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0895" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old=2757782&old_path=wp-coder%2Ftrunk%2Fadmin%2Fpartials%2Finclude-data.php&new=&new_path=wp-coder%2Ftrunk%2Fadmin%2Fpartials%2Finclude-data.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e4b6a9cd-4d29-4bd8-afa3-b5d455ad8340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m33h-m49h-9cf4/GHSA-m33h-m49h-9cf4.json b/advisories/unreviewed/2023/07/GHSA-m33h-m49h-9cf4/GHSA-m33h-m49h-9cf4.json new file mode 100644 index 00000000000..25f1248d03a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m33h-m49h-9cf4/GHSA-m33h-m49h-9cf4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m33h-m49h-9cf4", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-45808" + ], + "details": "SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45808" + }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/multiple-critical-vulnerabilities-fixed-in-learnpress-plugin-version/" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-wordpress-lms-plugin-plugin-4-1-7-3-2-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-26T21:17:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m36f-j5wf-g85f/GHSA-m36f-j5wf-g85f.json b/advisories/unreviewed/2023/07/GHSA-m36f-j5wf-g85f/GHSA-m36f-j5wf-g85f.json new file mode 100644 index 00000000000..8fecbb7c65a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m36f-j5wf-g85f/GHSA-m36f-j5wf-g85f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m36f-j5wf-g85f", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-28291" + ], + "details": "Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The vulnerability allows an attacker to access credentials stored in Nessus scanners, potentially compromising its customers’ network of assets.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28291" + }, + { + "type": "WEB", + "url": "https://cybersecurityworks.com/blog/zero-days/csw-expert-discovers-a-zero-day-vulnerability-in-tenables-nessus-scanner.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-17T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json b/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json new file mode 100644 index 00000000000..5d24c5f82de --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3qp-4rm3-pr3q", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-24503" + ], + "details": "Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24503" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m5gq-rxm3-279g/GHSA-m5gq-rxm3-279g.json b/advisories/unreviewed/2023/07/GHSA-m5gq-rxm3-279g/GHSA-m5gq-rxm3-279g.json new file mode 100644 index 00000000000..e45b5e7ad90 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m5gq-rxm3-279g/GHSA-m5gq-rxm3-279g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5gq-rxm3-279g", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2022-47444" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47444" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-user-avatar/wordpress-paid-membership-ecommerce-registration-form-login-form-user-profile-paywall-restrict-content-profilepress-plugin-4-4-1-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m5h8-2pjw-vg3j/GHSA-m5h8-2pjw-vg3j.json b/advisories/unreviewed/2023/07/GHSA-m5h8-2pjw-vg3j/GHSA-m5h8-2pjw-vg3j.json new file mode 100644 index 00000000000..9b4d18c85e4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m5h8-2pjw-vg3j/GHSA-m5h8-2pjw-vg3j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5h8-2pjw-vg3j", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-46365" + ], + "details": "Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to modify and reset the account, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46365" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/f68lcwrp8pcdc4yrbpcm8j7m0f5mjn7h" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m5q6-vwgv-7m5c/GHSA-m5q6-vwgv-7m5c.json b/advisories/unreviewed/2023/07/GHSA-m5q6-vwgv-7m5c/GHSA-m5q6-vwgv-7m5c.json new file mode 100644 index 00000000000..13c584bfef2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m5q6-vwgv-7m5c/GHSA-m5q6-vwgv-7m5c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5q6-vwgv-7m5c", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2022-44743" + ], + "details": "Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44743" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/job-postings/wordpress-jobs-for-wordpress-plugin-2-5-10-2-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m64r-fm27-8wxj/GHSA-m64r-fm27-8wxj.json b/advisories/unreviewed/2023/07/GHSA-m64r-fm27-8wxj/GHSA-m64r-fm27-8wxj.json new file mode 100644 index 00000000000..31437a74a5d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m64r-fm27-8wxj/GHSA-m64r-fm27-8wxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m64r-fm27-8wxj", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2022-47435" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Olive Design WP-OliveCart plugin <= 1.1.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-olivecart/wordpress-wp-olivecart-plugin-1-1-3-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m6m9-fxf2-g8mf/GHSA-m6m9-fxf2-g8mf.json b/advisories/unreviewed/2023/07/GHSA-m6m9-fxf2-g8mf/GHSA-m6m9-fxf2-g8mf.json new file mode 100644 index 00000000000..1777a136935 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m6m9-fxf2-g8mf/GHSA-m6m9-fxf2-g8mf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6m9-fxf2-g8mf", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2022-45358" + ], + "details": "Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45358" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/activello/wordpress-activello-theme-1-4-4-auth-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-13T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json b/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json new file mode 100644 index 00000000000..0607110bf50 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mchj-fc27-3mfm/GHSA-mchj-fc27-3mfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mchj-fc27-3mfm", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-22128" + ], + "details": "Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of Life and are no longer supported. They are also not assessed for potential security issues and do not receive security updates.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22128" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=000367027&type=1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-17T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mfpq-8q7r-r3fq/GHSA-mfpq-8q7r-r3fq.json b/advisories/unreviewed/2023/07/GHSA-mfpq-8q7r-r3fq/GHSA-mfpq-8q7r-r3fq.json new file mode 100644 index 00000000000..6bd0a0dcbe4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mfpq-8q7r-r3fq/GHSA-mfpq-8q7r-r3fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfpq-8q7r-r3fq", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25710" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.4.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25710" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/click-to-call-or-chat-buttons/wordpress-click-to-call-or-chat-buttons-plugin-1-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json b/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json new file mode 100644 index 00000000000..76cb9555d39 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mj6f-85xq-rjq8/GHSA-mj6f-85xq-rjq8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj6f-85xq-rjq8", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-33182" + ], + "details": "A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33182" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2084" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mm22-v222-j9xr/GHSA-mm22-v222-j9xr.json b/advisories/unreviewed/2023/07/GHSA-mm22-v222-j9xr/GHSA-mm22-v222-j9xr.json new file mode 100644 index 00000000000..e5824437528 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mm22-v222-j9xr/GHSA-mm22-v222-j9xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm22-v222-j9xr", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-39039" + ], + "details": "aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39039" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6792-c4a62-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-03T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mm8q-cf7f-pmxx/GHSA-mm8q-cf7f-pmxx.json b/advisories/unreviewed/2023/07/GHSA-mm8q-cf7f-pmxx/GHSA-mm8q-cf7f-pmxx.json new file mode 100644 index 00000000000..59d7cef689b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mm8q-cf7f-pmxx/GHSA-mm8q-cf7f-pmxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm8q-cf7f-pmxx", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2023-22302" + ], + "details": "In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22302" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K58550078" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-01T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mr82-9g27-qr4x/GHSA-mr82-9g27-qr4x.json b/advisories/unreviewed/2023/07/GHSA-mr82-9g27-qr4x/GHSA-mr82-9g27-qr4x.json new file mode 100644 index 00000000000..3841b916a73 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mr82-9g27-qr4x/GHSA-mr82-9g27-qr4x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr82-9g27-qr4x", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-1752" + ], + "details": "The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associated device with only the device’s MAC address.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1752" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-04T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mr98-5j2v-xqmf/GHSA-mr98-5j2v-xqmf.json b/advisories/unreviewed/2023/07/GHSA-mr98-5j2v-xqmf/GHSA-mr98-5j2v-xqmf.json new file mode 100644 index 00000000000..67badc5c52e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mr98-5j2v-xqmf/GHSA-mr98-5j2v-xqmf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr98-5j2v-xqmf", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-28337" + ], + "details": "When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28337" + }, + { + "type": "WEB", + "url": "https://drupal9.tenable.com/security/research/tra-2023-12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-15T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mw67-65x5-h28p/GHSA-mw67-65x5-h28p.json b/advisories/unreviewed/2023/07/GHSA-mw67-65x5-h28p/GHSA-mw67-65x5-h28p.json new file mode 100644 index 00000000000..078e0025a87 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mw67-65x5-h28p/GHSA-mw67-65x5-h28p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw67-65x5-h28p", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-0210" + ], + "details": "A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0210" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit" + }, + { + "type": "WEB", + "url": "https://securityonline.info/cve-2023-0210-flaw-in-linux-kernel-allows-unauthenticated-remote-dos-attacks/" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/01/11/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mw9w-2x4j-fvhh/GHSA-mw9w-2x4j-fvhh.json b/advisories/unreviewed/2023/07/GHSA-mw9w-2x4j-fvhh/GHSA-mw9w-2x4j-fvhh.json new file mode 100644 index 00000000000..3282f5f9d0d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mw9w-2x4j-fvhh/GHSA-mw9w-2x4j-fvhh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9w-2x4j-fvhh", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-43483" + ], + "details": "Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the monitor services of the software. This could allow a remote attacker to access sensitive functions of the application and execute arbitrary system commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43483" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-18T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mxpv-cf8p-pfpr/GHSA-mxpv-cf8p-pfpr.json b/advisories/unreviewed/2023/07/GHSA-mxpv-cf8p-pfpr/GHSA-mxpv-cf8p-pfpr.json new file mode 100644 index 00000000000..aa667890e3d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mxpv-cf8p-pfpr/GHSA-mxpv-cf8p-pfpr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxpv-cf8p-pfpr", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-38198" + ], + "details": "There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below that may allow a remote, unauthenticated attacker to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38198" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/administration/administration/arcgis-server-security-2022-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json b/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json new file mode 100644 index 00000000000..783b9c4ee2e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mxw6-c2fh-2h9w/GHSA-mxw6-c2fh-2h9w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxw6-c2fh-2h9w", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2022-47501" + ], + "details": "Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a \npre-authentication attack.\nThis issue affects Apache OFBiz: before 18.12.07.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47501" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/k8s76l0whydy45bfm4b69vq0mf94p3wc" + }, + { + "type": "WEB", + "url": "https://ofbiz.apache.org/download.html" + }, + { + "type": "WEB", + "url": "https://ofbiz.apache.org/security.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p4w7-mhw7-7vgx/GHSA-p4w7-mhw7-7vgx.json b/advisories/unreviewed/2023/07/GHSA-p4w7-mhw7-7vgx/GHSA-p4w7-mhw7-7vgx.json new file mode 100644 index 00000000000..2e73dcc9a42 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p4w7-mhw7-7vgx/GHSA-p4w7-mhw7-7vgx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4w7-mhw7-7vgx", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2022-44734" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44734" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/car-rental/wordpress-car-rental-by-bestwebsoft-plugin-1-1-2-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p528-mrgw-3q8p/GHSA-p528-mrgw-3q8p.json b/advisories/unreviewed/2023/07/GHSA-p528-mrgw-3q8p/GHSA-p528-mrgw-3q8p.json new file mode 100644 index 00000000000..c46222ad862 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p528-mrgw-3q8p/GHSA-p528-mrgw-3q8p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p528-mrgw-3q8p", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-46368" + ], + "details": "Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46368" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-12T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p5fw-f837-j4p4/GHSA-p5fw-f837-j4p4.json b/advisories/unreviewed/2023/07/GHSA-p5fw-f837-j4p4/GHSA-p5fw-f837-j4p4.json new file mode 100644 index 00000000000..4f010567d39 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p5fw-f837-j4p4/GHSA-p5fw-f837-j4p4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5fw-f837-j4p4", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-27976" + ], + "details": "\nA CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause\nremote code execution when a valid user visits a malicious link provided through the web\nendpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27976" + }, + { + "type": "WEB", + "url": "https://https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json b/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json new file mode 100644 index 00000000000..7f90ff8227d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p72q-v88c-rprq", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-0386" + ], + "details": "A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0386" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=4f11ada10d0a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-22T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json b/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json new file mode 100644 index 00000000000..b542e31fe70 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p7r4-77g3-vcrx/GHSA-p7r4-77g3-vcrx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7r4-77g3-vcrx", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22934" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass [SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards) using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser. The vulnerability affects instances with Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22934" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0204" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p7xw-hxjp-35w2/GHSA-p7xw-hxjp-35w2.json b/advisories/unreviewed/2023/07/GHSA-p7xw-hxjp-35w2/GHSA-p7xw-hxjp-35w2.json new file mode 100644 index 00000000000..c05bf4afbbd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p7xw-hxjp-35w2/GHSA-p7xw-hxjp-35w2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7xw-hxjp-35w2", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2023-0293" + ], + "details": "The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change image categories, which it uses to arrange them in folder views.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0293" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/mediamatic/trunk/inc/sidebar.php?rev=2652957#L343" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e5c87ae0-9a53-4292-a4d3-05b3bdb37b71" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-13T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p95j-mgmf-79p3/GHSA-p95j-mgmf-79p3.json b/advisories/unreviewed/2023/07/GHSA-p95j-mgmf-79p3/GHSA-p95j-mgmf-79p3.json new file mode 100644 index 00000000000..8b0869e869a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p95j-mgmf-79p3/GHSA-p95j-mgmf-79p3.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p95j-mgmf-79p3", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-41685" + ], + "details": "Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin <= 5.6.3.2 and Csomagpontok és szállítási címkék WooCommerce-hez plugin <= 1.9.0.2 on WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hungarian-pickup-points-for-woocommerce/wordpress-csomagpontok-es-szallitasi-cimkek-woocommerce-hez-plugin-1-9-0-2-multiple-cross-site-request-forgery-csrf-vulnerabilities?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/integration-for-szamlazzhu-woocommerce/wordpress-integration-for-szamlazz-hu-woocommerce-plugin-5-6-3-2-multiple-cross-site-request-forgery-csrf-vulnerabilities?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/hungarian-pickup-points-for-woocommerce/#developers" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/integration-for-szamlazzhu-woocommerce/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-18T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pcx5-cm5r-cf7f/GHSA-pcx5-cm5r-cf7f.json b/advisories/unreviewed/2023/07/GHSA-pcx5-cm5r-cf7f/GHSA-pcx5-cm5r-cf7f.json new file mode 100644 index 00000000000..19dd0ea22c3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pcx5-cm5r-cf7f/GHSA-pcx5-cm5r-cf7f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcx5-cm5r-cf7f", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2021-21548" + ], + "details": "Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21548" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-uk/000189606/dsa-2021-134-dell-emc-unisphere-for-powermax-dell-emc-unisphere-for-powermax-virtual-appliance-dell-emc-solutions-enabler-virtual-appliance-and-dell-emc-powermax-embedded-management-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-17T06:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json b/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json new file mode 100644 index 00000000000..686843b1304 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pf45-p3p9-ghwp/GHSA-pf45-p3p9-ghwp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf45-p3p9-ghwp", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-31363" + ], + "details": "Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered during mesh provisioning. Because there is no check for mismatched SegN and TotalLength in Transaction Start PDU.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31363" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1iSZze8Ig6HZVsrldmXw0bibZLGMMTU5w/edit" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-01T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json b/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json new file mode 100644 index 00000000000..9ead3ef7bc9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf4c-5rqp-wmc9", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2021-33974" + ], + "details": "Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: This is a set of vulnerabilities affecting popular software, and the installation packages correspond to versions \"360 Safeguard(12.1.0.1004,12.1.0.1005,13.1.0.1001)\" , \"360 Total Security(10.8.0.1060,10.8.0.1213)\", \"360 Safe Browser & 360 Chrome(12. The attack vector is: On the browser vulnerability, just open a link to complete the vulnerability exploitation remotely; on the client software, you need to locally execute the vulnerability exploitation program, which of course can be achieved with the full chain of browser vulnerability. ¶¶ This is a set of the most serious vulnerabilities that exist on Qihoo 360's PC client multiple popular software, remote vulnerabilities can be accomplished by opening a link to arbitrary code execution on both security browsers, in conjunction with the exploitation of local vulnerabilities that allow spyware to persist without being scanned to permanently reside on the target PC computer (because local vulnerabilities target Qihoo 360 company's antivirus software kernel flaws); this set of remote and local vulnerabilities in perfect coordination, to achieve an information security fallacy, on Qihoo 360's antivirus software vulnerability, not only can not be scanned out of the virus, but will help the virus persistently control the target computer, while Qihoo 360 claims to be a secure browser, which exists in the kernel vulnerability but help the composition of the remote vulnerability.(Security expert \"Memory Corruptor\" have reported this set of vulnerabilities to the corresponding vendor, all vulnerabilities have been fixed and the vendor rewarded thousands of dollars to this security expert)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33974" + }, + { + "type": "WEB", + "url": "https://MemoryCorruptor.blogspot.com/p/vulnerabilities-disclosures.html" + }, + { + "type": "WEB", + "url": "https://pastebin.com/ms1ivjYe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json b/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json new file mode 100644 index 00000000000..37f5264e0a9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgrf-qrwj-3vf5", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-27910" + ], + "details": "A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27910" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0004" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ph5g-2r58-hm46/GHSA-ph5g-2r58-hm46.json b/advisories/unreviewed/2023/07/GHSA-ph5g-2r58-hm46/GHSA-ph5g-2r58-hm46.json new file mode 100644 index 00000000000..53d2677fa76 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ph5g-2r58-hm46/GHSA-ph5g-2r58-hm46.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph5g-2r58-hm46", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-38778" + ], + "details": "A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38778" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elastic-7-17-9-8-5-0-and-8-6-1-security-update/324661" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-08T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pj5j-w7mw-w797/GHSA-pj5j-w7mw-w797.json b/advisories/unreviewed/2023/07/GHSA-pj5j-w7mw-w797/GHSA-pj5j-w7mw-w797.json new file mode 100644 index 00000000000..2dbb3ced079 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pj5j-w7mw-w797/GHSA-pj5j-w7mw-w797.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj5j-w7mw-w797", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-27603" + ], + "details": "\n\n\nIn Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability.\n\n\nWe recommend users upgrade the version of Linkis to version 1.3.2.\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27603" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/6n1vlvnyn441rm02zdqc0wnpckj8ltn8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pmp9-6wg3-93fg/GHSA-pmp9-6wg3-93fg.json b/advisories/unreviewed/2023/07/GHSA-pmp9-6wg3-93fg/GHSA-pmp9-6wg3-93fg.json new file mode 100644 index 00000000000..64ed5c8c4c8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pmp9-6wg3-93fg/GHSA-pmp9-6wg3-93fg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmp9-6wg3-93fg", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2022-47145" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3.5.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47145" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/blockonomics-bitcoin-payments/wordpress-wordpress-bitcoin-payments-blockonomics-plugin-3-5-7-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json b/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json new file mode 100644 index 00000000000..011b1f35b1e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ppfv-9rmx-jjrq/GHSA-ppfv-9rmx-jjrq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppfv-9rmx-jjrq", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2021-36821" + ], + "details": "Unauth. Stored Cross-Site Scripting (XSS) vulnerability in WPMU DEV Forminator – Contact Form, Payment Form & Custom Form Builder plugin <= 1.14.11 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/forminator/wordpress-forminator-plugin-1-14-11-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-16T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json b/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json new file mode 100644 index 00000000000..a292f2b8071 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ppw7-v579-v4cr/GHSA-ppw7-v579-v4cr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppw7-v579-v4cr", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-32177" + ], + "details": "In \"Gin-Vue-Admin\", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-32177" + }, + { + "type": "WEB", + "url": "https://github.com/flipped-aurora/gin-vue-admin/blob/v2.5.3beta/web/src/components/upload/common.vue#L29-L37" + }, + { + "type": "WEB", + "url": "https://www.mend.io/vulnerability-database/CVE-2022-32177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-14T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json b/advisories/unreviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json new file mode 100644 index 00000000000..aa38d37ca63 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-ppxx-m926-g569/GHSA-ppxx-m926-g569.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppxx-m926-g569", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-24697" + ], + "details": "Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24697" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/07mnn9c7o314wrhrwjr10w9j5s82voj4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-13T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pr99-j37c-3mxj/GHSA-pr99-j37c-3mxj.json b/advisories/unreviewed/2023/07/GHSA-pr99-j37c-3mxj/GHSA-pr99-j37c-3mxj.json new file mode 100644 index 00000000000..39be4b9c2c6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pr99-j37c-3mxj/GHSA-pr99-j37c-3mxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr99-j37c-3mxj", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-47598" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Plugins Pro WP Super Popup plugin <= 1.1.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47598" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-super-popup/wordpress-wp-super-popup-plugin-1-1-2-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pv98-6265-3prw/GHSA-pv98-6265-3prw.json b/advisories/unreviewed/2023/07/GHSA-pv98-6265-3prw/GHSA-pv98-6265-3prw.json new file mode 100644 index 00000000000..11fb1e569a0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pv98-6265-3prw/GHSA-pv98-6265-3prw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv98-6265-3prw", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-22718" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in Jason Lau User Meta Manager plugin <= 3.4.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22718" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-meta-manager/wordpress-user-meta-manager-plugin-3-4-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pvrw-g6fx-mcx2/GHSA-pvrw-g6fx-mcx2.json b/advisories/unreviewed/2023/07/GHSA-pvrw-g6fx-mcx2/GHSA-pvrw-g6fx-mcx2.json new file mode 100644 index 00000000000..4973b3cd437 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pvrw-g6fx-mcx2/GHSA-pvrw-g6fx-mcx2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvrw-g6fx-mcx2", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2020-26302" + ], + "details": "is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can cause the regex to loop “forever.\" This vulnerability was found using a CodeQL query which identifies inefficient regular expressions. is.js has no patch for this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26302" + }, + { + "type": "WEB", + "url": "https://github.com/arasatasaygin/is.js/issues/320" + }, + { + "type": "ADVISORY", + "url": "https://securitylab.github.com/advisories/GHSL-2020-295-redos-is.js" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-22T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pw2g-wqc9-f5g9/GHSA-pw2g-wqc9-f5g9.json b/advisories/unreviewed/2023/07/GHSA-pw2g-wqc9-f5g9/GHSA-pw2g-wqc9-f5g9.json new file mode 100644 index 00000000000..b642578edc3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pw2g-wqc9-f5g9/GHSA-pw2g-wqc9-f5g9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw2g-wqc9-f5g9", + "modified": "2023-07-06T19:24:20Z", + "published": "2023-07-06T19:24:20Z", + "aliases": [ + "CVE-2023-22691" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22691" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/category-specific-rss-feed-menu/wordpress-category-specific-rss-feed-subscription-plugin-v2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pwhp-27h2-crqj/GHSA-pwhp-27h2-crqj.json b/advisories/unreviewed/2023/07/GHSA-pwhp-27h2-crqj/GHSA-pwhp-27h2-crqj.json new file mode 100644 index 00000000000..69a3f93e2e2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pwhp-27h2-crqj/GHSA-pwhp-27h2-crqj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwhp-27h2-crqj", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-4634" + ], + "details": "All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4634" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-03T03:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q35r-v94g-2r69/GHSA-q35r-v94g-2r69.json b/advisories/unreviewed/2023/07/GHSA-q35r-v94g-2r69/GHSA-q35r-v94g-2r69.json new file mode 100644 index 00000000000..294afbc0692 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q35r-v94g-2r69/GHSA-q35r-v94g-2r69.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q35r-v94g-2r69", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-25040" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vova Anokhin WordPress Shortcodes Plugin — Shortcodes Ultimate plugin <= 5.12.6 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25040" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-30T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q3x5-vwjf-49p2/GHSA-q3x5-vwjf-49p2.json b/advisories/unreviewed/2023/07/GHSA-q3x5-vwjf-49p2/GHSA-q3x5-vwjf-49p2.json new file mode 100644 index 00000000000..6aad0de7f5f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q3x5-vwjf-49p2/GHSA-q3x5-vwjf-49p2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3x5-vwjf-49p2", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2023-30474" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kilian Evang Ultimate Noindex Nofollow Tool II plugin <= 1.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30474" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-noindex-nofollow-tool-ii/wordpress-ultimate-noindex-nofollow-tool-ii-plugin-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q443-qgfv-3fpg/GHSA-q443-qgfv-3fpg.json b/advisories/unreviewed/2023/07/GHSA-q443-qgfv-3fpg/GHSA-q443-qgfv-3fpg.json new file mode 100644 index 00000000000..08d199aa2bd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q443-qgfv-3fpg/GHSA-q443-qgfv-3fpg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q443-qgfv-3fpg", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-2988" + ], + "details": "A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC(V2.1.0 and prior), EcoStruxure Machine Expert – HVAC(V1.4.0 and prior).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2988" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-01_EcoStruxure_Machine_Expert_Machine_HVAC_Security_Notification.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-30T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q4gj-rcjg-xcwr/GHSA-q4gj-rcjg-xcwr.json b/advisories/unreviewed/2023/07/GHSA-q4gj-rcjg-xcwr/GHSA-q4gj-rcjg-xcwr.json new file mode 100644 index 00000000000..833be710cce --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q4gj-rcjg-xcwr/GHSA-q4gj-rcjg-xcwr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4gj-rcjg-xcwr", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-46367" + ], + "details": "Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46367" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-12T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json b/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json new file mode 100644 index 00000000000..692fede56f4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q4jw-3mfc-r879/GHSA-q4jw-3mfc-r879.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4jw-3mfc-r879", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2021-41526" + ], + "details": "A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-41526" + }, + { + "type": "WEB", + "url": "https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message" + }, + { + "type": "WEB", + "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q6hv-g5mr-qgwf/GHSA-q6hv-g5mr-qgwf.json b/advisories/unreviewed/2023/07/GHSA-q6hv-g5mr-qgwf/GHSA-q6hv-g5mr-qgwf.json new file mode 100644 index 00000000000..dc6a45229e8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q6hv-g5mr-qgwf/GHSA-q6hv-g5mr-qgwf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6hv-g5mr-qgwf", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-45836" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45836" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/download-manager/wordpress-download-manager-plugin-3-2-59-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q7wq-398w-6957/GHSA-q7wq-398w-6957.json b/advisories/unreviewed/2023/07/GHSA-q7wq-398w-6957/GHSA-q7wq-398w-6957.json new file mode 100644 index 00000000000..d433ddce9aa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q7wq-398w-6957/GHSA-q7wq-398w-6957.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7wq-398w-6957", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-23761" + ], + "details": "An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. To do so, a user had to know the secret gist’s URL. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.9 and was fixed in versions 3.4.18, 3.5.15, 3.6.11, 3.7.8, and 3.8.1. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23761" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.4/admin/release-notes#3.4.18" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.5/admin/release-notes#3.5.15" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.6/admin/release-notes#3.6.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.7/admin/release-notes#3.7.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-07T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q85c-wwvh-p49r/GHSA-q85c-wwvh-p49r.json b/advisories/unreviewed/2023/07/GHSA-q85c-wwvh-p49r/GHSA-q85c-wwvh-p49r.json new file mode 100644 index 00000000000..a6b8f637319 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q85c-wwvh-p49r/GHSA-q85c-wwvh-p49r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q85c-wwvh-p49r", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-24003" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-popups-lite/wordpress-wp-popups-wordpress-popup-builder-plugin-2-1-4-8-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-06T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q89q-qv4f-qvr5/GHSA-q89q-qv4f-qvr5.json b/advisories/unreviewed/2023/07/GHSA-q89q-qv4f-qvr5/GHSA-q89q-qv4f-qvr5.json new file mode 100644 index 00000000000..61e3e3edc48 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q89q-qv4f-qvr5/GHSA-q89q-qv4f-qvr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q89q-qv4f-qvr5", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2023-27614" + ], + "details": "Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Ian Haycox Motor Racing League plugin <= 1.9.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27614" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/motor-racing-league/wordpress-motor-racing-league-plugin-1-9-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q8j4-3fxm-87xm/GHSA-q8j4-3fxm-87xm.json b/advisories/unreviewed/2023/07/GHSA-q8j4-3fxm-87xm/GHSA-q8j4-3fxm-87xm.json new file mode 100644 index 00000000000..71c744e2035 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q8j4-3fxm-87xm/GHSA-q8j4-3fxm-87xm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8j4-3fxm-87xm", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2023-0451" + ], + "details": "All versions of Econolite EOS traffic control software are vulnerable to CWE-284: Improper Access Control, and lack a password requirement for gaining “READONLY” access to log files, as well as certain database and configuration files. One such file contains tables with message-digest algorithm 5 (MD5) hashes and usernames for all defined users in the control software, including administrators and technicians.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0451" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-26T21:18:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qcrm-cg47-3qvc/GHSA-qcrm-cg47-3qvc.json b/advisories/unreviewed/2023/07/GHSA-qcrm-cg47-3qvc/GHSA-qcrm-cg47-3qvc.json new file mode 100644 index 00000000000..1d46557ca0e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qcrm-cg47-3qvc/GHSA-qcrm-cg47-3qvc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcrm-cg47-3qvc", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2021-33971" + ], + "details": "Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: This is a set of vulnerabilities affecting popular software, \"360 Safeguard(12.1.0.1004,12.1.0.1005,13.1.0.1001)\" , \"360 Total Security(10.8.0.1060,10.8.0.1213)\", \"360 Safe Browser & 360 Chrome(13.0.2170.0)\". The attack vector is: On the browser vulnerability, just open a link to complete the vulnerability exploitation remotely; on the client software, you need to locally execute the vulnerability exploitation program, which of course can be achieved with the full chain of browser vulnerability. ¶¶ This is a set of the most serious vulnerabilities that exist on Qihoo 360's PC client a variety of popular software, remote vulnerabilities can be completed by opening a link to arbitrary code execution on both security browsers, with the use of local vulnerabilities, not only help the vulnerability code constitutes an escalation of privileges, er can make the spyware persistent without being scanned permanently resides on the target PC computer (because local vulnerability against Qihoo 360 company's antivirus kernel flaws); this group of remote and local vulnerability of the perfect match, to achieve an information security fallacy, in Qihoo 360's antivirus vulnerability, not only can not be scanned out of the virus, but will help the virus persistently control the target computer, while Qihoo 360 claims to be a safe browser, which exists in the kernel vulnerability but helped the composition of the remote vulnerability. (Security expert \"Memory Corruptor\" have reported this set of vulnerabilities to the corresponding vendor, all vulnerabilities have been fixed and the vendor rewarded thousands of dollars to the security experts)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33971" + }, + { + "type": "WEB", + "url": "https://MemoryCorruptor.blogspot.com/p/vulnerabilities-disclosures.html" + }, + { + "type": "WEB", + "url": "https://pastebin.com/31v5JMcG" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/channel/UCLJ6fZxUqbmPe4jiwC6o4hg/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qf9c-gmgf-6944/GHSA-qf9c-gmgf-6944.json b/advisories/unreviewed/2023/07/GHSA-qf9c-gmgf-6944/GHSA-qf9c-gmgf-6944.json new file mode 100644 index 00000000000..c56e33b1ea8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qf9c-gmgf-6944/GHSA-qf9c-gmgf-6944.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf9c-gmgf-6944", + "modified": "2023-07-06T19:24:10Z", + "published": "2023-07-06T19:24:10Z", + "aliases": [ + "CVE-2023-23984" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23984" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bubble-menu/wordpress-bubble-menu-circle-floating-menu-plugin-3-0-1-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-01T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qgvh-g2mh-jwfc/GHSA-qgvh-g2mh-jwfc.json b/advisories/unreviewed/2023/07/GHSA-qgvh-g2mh-jwfc/GHSA-qgvh-g2mh-jwfc.json new file mode 100644 index 00000000000..8045eb4761e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qgvh-g2mh-jwfc/GHSA-qgvh-g2mh-jwfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgvh-g2mh-jwfc", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-1939" + ], + "details": "No access control for the OTP key \n\n on OTP entries\n\n in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1939" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2023-0009" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qh97-v4qr-2c8p/GHSA-qh97-v4qr-2c8p.json b/advisories/unreviewed/2023/07/GHSA-qh97-v4qr-2c8p/GHSA-qh97-v4qr-2c8p.json new file mode 100644 index 00000000000..830b3df76e1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qh97-v4qr-2c8p/GHSA-qh97-v4qr-2c8p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh97-v4qr-2c8p", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-24838" + ], + "details": "HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator’s credential, resulting in performing arbitrary system operation or disrupt service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24838" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-6957-d8f67-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qhw5-j89v-5fm3/GHSA-qhw5-j89v-5fm3.json b/advisories/unreviewed/2023/07/GHSA-qhw5-j89v-5fm3/GHSA-qhw5-j89v-5fm3.json new file mode 100644 index 00000000000..ab1aa478985 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qhw5-j89v-5fm3/GHSA-qhw5-j89v-5fm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhw5-j89v-5fm3", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2022-45084" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45084" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/loginizer/wordpress-loginizer-plugin-1-7-5-unauth-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qjmr-8cf3-fcr8/GHSA-qjmr-8cf3-fcr8.json b/advisories/unreviewed/2023/07/GHSA-qjmr-8cf3-fcr8/GHSA-qjmr-8cf3-fcr8.json new file mode 100644 index 00000000000..b2f3ee0bfe9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qjmr-8cf3-fcr8/GHSA-qjmr-8cf3-fcr8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjmr-8cf3-fcr8", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2022-40177" + ], + "details": "A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). Endpoints of the “Operation” web application that interpret and execute Axon language queries allow file read access to the device file system with root privileges. By supplying specific I/O related Axon queries, a remote low-privileged attacker can read sensitive files on the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40177" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-11T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qjxv-5m4x-5hpr/GHSA-qjxv-5m4x-5hpr.json b/advisories/unreviewed/2023/07/GHSA-qjxv-5m4x-5hpr/GHSA-qjxv-5m4x-5hpr.json new file mode 100644 index 00000000000..4312272c902 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qjxv-5m4x-5hpr/GHSA-qjxv-5m4x-5hpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjxv-5m4x-5hpr", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2023-22686" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nice-paypal-button-lite/wordpress-nice-paypal-button-lite-plugin-1-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qm4q-mvq2-gj2r/GHSA-qm4q-mvq2-gj2r.json b/advisories/unreviewed/2023/07/GHSA-qm4q-mvq2-gj2r/GHSA-qm4q-mvq2-gj2r.json new file mode 100644 index 00000000000..b0b63bf7c0c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qm4q-mvq2-gj2r/GHSA-qm4q-mvq2-gj2r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm4q-mvq2-gj2r", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-22915" + ], + "details": "A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote unauthenticated attacker to cause DoS conditions by sending a crafted HTTP request if the Facebook WiFi function were enabled on an affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22915" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json b/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json new file mode 100644 index 00000000000..74f5ac0565e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm75-wj63-4j3j", + "modified": "2023-07-06T19:24:07Z", + "published": "2023-07-06T19:24:07Z", + "aliases": [ + "CVE-2022-4693" + ], + "details": "The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4693" + }, + { + "type": "WEB", + "url": "https://lana.codes/lanavdb/eeabe1d3-6f64-400a-8fb2-0865efdf6957" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1eee10a8-135f-4b76-8289-c381ff1f51ea" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-23T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qr78-7vm9-2fj7/GHSA-qr78-7vm9-2fj7.json b/advisories/unreviewed/2023/07/GHSA-qr78-7vm9-2fj7/GHSA-qr78-7vm9-2fj7.json new file mode 100644 index 00000000000..2db3ee09041 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qr78-7vm9-2fj7/GHSA-qr78-7vm9-2fj7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr78-7vm9-2fj7", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25479" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/podlove-subscribe-button/wordpress-podlove-subscribe-button-plugin-1-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qwrg-xrq4-7mmv/GHSA-qwrg-xrq4-7mmv.json b/advisories/unreviewed/2023/07/GHSA-qwrg-xrq4-7mmv/GHSA-qwrg-xrq4-7mmv.json new file mode 100644 index 00000000000..1671c9eebc9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qwrg-xrq4-7mmv/GHSA-qwrg-xrq4-7mmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwrg-xrq4-7mmv", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-23866" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Carlos Moreira Interactive Geo Maps plugin <= 1.5.8 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/interactive-geo-maps/wordpress-interactive-geo-maps-plugin-1-5-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r24m-v6jq-pp52/GHSA-r24m-v6jq-pp52.json b/advisories/unreviewed/2023/07/GHSA-r24m-v6jq-pp52/GHSA-r24m-v6jq-pp52.json new file mode 100644 index 00000000000..ca681f26aa0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r24m-v6jq-pp52/GHSA-r24m-v6jq-pp52.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r24m-v6jq-pp52", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-3577" + ], + "details": "An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3577" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git/commit/?h=char-misc-next&id=9d64d2405f7d30d49818f6682acd0392348f0fdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=945a9a8e448b65bec055d37eba58f711b39f66f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc4ef9d5724973193bfa5ebed181dba6de3a56db" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-20T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r4cq-hxmv-g6f2/GHSA-r4cq-hxmv-g6f2.json b/advisories/unreviewed/2023/07/GHSA-r4cq-hxmv-g6f2/GHSA-r4cq-hxmv-g6f2.json new file mode 100644 index 00000000000..5f5edd1f233 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r4cq-hxmv-g6f2/GHSA-r4cq-hxmv-g6f2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4cq-hxmv-g6f2", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2023-0254" + ], + "details": "The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0254" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2829005%40simple-membership-wp-user-import&new=2829005%40simple-membership-wp-user-import&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f781533-b633-4452-95bd-c32ed0de2ea9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-12T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r5fc-xr2g-f58g/GHSA-r5fc-xr2g-f58g.json b/advisories/unreviewed/2023/07/GHSA-r5fc-xr2g-f58g/GHSA-r5fc-xr2g-f58g.json new file mode 100644 index 00000000000..306ed9a084a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r5fc-xr2g-f58g/GHSA-r5fc-xr2g-f58g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5fc-xr2g-f58g", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-23816" + ], + "details": "Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Twardes Sitemap Index plugin <= 1.2.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sitemap-index/wordpress-sitemap-index-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r78m-94wm-v7cv/GHSA-r78m-94wm-v7cv.json b/advisories/unreviewed/2023/07/GHSA-r78m-94wm-v7cv/GHSA-r78m-94wm-v7cv.json new file mode 100644 index 00000000000..fe4aba09a51 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r78m-94wm-v7cv/GHSA-r78m-94wm-v7cv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r78m-94wm-v7cv", + "modified": "2023-07-06T19:24:01Z", + "published": "2023-07-06T19:24:01Z", + "aliases": [ + "CVE-2021-36201" + ], + "details": "Under certain circumstances a C•CURE Portal user could enumerate user accounts in C•CURE 9000 version 2.90 and prior versions. This issue affects: C•CURE 9000 2.90 and earlier version 2.90 and prior versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36201" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-284-03" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/cyber-solutions/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-11T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json b/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json new file mode 100644 index 00000000000..fad8b97e1c7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r827-5p5r-w6f5/GHSA-r827-5p5r-w6f5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r827-5p5r-w6f5", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-2808" + ], + "details": "Algan Yazılım Prens Student Information System product has an authenticated Insecure Direct Object Reference (IDOR) vulnerability. ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2808" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-22-0708" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-02T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r89f-2wvr-q3c7/GHSA-r89f-2wvr-q3c7.json b/advisories/unreviewed/2023/07/GHSA-r89f-2wvr-q3c7/GHSA-r89f-2wvr-q3c7.json new file mode 100644 index 00000000000..a50c1da047a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r89f-2wvr-q3c7/GHSA-r89f-2wvr-q3c7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r89f-2wvr-q3c7", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-2641" + ], + "details": "Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2641" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-02T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r8g3-9qxx-g5x2/GHSA-r8g3-9qxx-g5x2.json b/advisories/unreviewed/2023/07/GHSA-r8g3-9qxx-g5x2/GHSA-r8g3-9qxx-g5x2.json new file mode 100644 index 00000000000..51d044747f1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r8g3-9qxx-g5x2/GHSA-r8g3-9qxx-g5x2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8g3-9qxx-g5x2", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-26008" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay D'Souza Top 10 – Popular posts plugin for WordPress plugin <= 3.2.4 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26008" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/top-10/wordpress-top-10-plugin-3-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-23T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r946-wxvm-h3vx/GHSA-r946-wxvm-h3vx.json b/advisories/unreviewed/2023/07/GHSA-r946-wxvm-h3vx/GHSA-r946-wxvm-h3vx.json new file mode 100644 index 00000000000..03e60e26953 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r946-wxvm-h3vx/GHSA-r946-wxvm-h3vx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r946-wxvm-h3vx", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-28650" + ], + "details": "An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security context.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28650" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-03" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rc73-rxx3-qqfc/GHSA-rc73-rxx3-qqfc.json b/advisories/unreviewed/2023/07/GHSA-rc73-rxx3-qqfc/GHSA-rc73-rxx3-qqfc.json new file mode 100644 index 00000000000..62ee8bc113f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rc73-rxx3-qqfc/GHSA-rc73-rxx3-qqfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc73-rxx3-qqfc", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-40190" + ], + "details": "SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in users’ browsers and steal sensitive information, including user credentials.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40190" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-300-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-31T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rpx4-39vw-744p/GHSA-rpx4-39vw-744p.json b/advisories/unreviewed/2023/07/GHSA-rpx4-39vw-744p/GHSA-rpx4-39vw-744p.json new file mode 100644 index 00000000000..a2fad9f133e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rpx4-39vw-744p/GHSA-rpx4-39vw-744p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpx4-39vw-744p", + "modified": "2023-07-06T19:24:20Z", + "published": "2023-07-06T19:24:20Z", + "aliases": [ + "CVE-2023-23790" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23790" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pods/wordpress-pods-custom-content-types-and-fields-plugin-2-9-10-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rrwm-2vxq-5x2h/GHSA-rrwm-2vxq-5x2h.json b/advisories/unreviewed/2023/07/GHSA-rrwm-2vxq-5x2h/GHSA-rrwm-2vxq-5x2h.json new file mode 100644 index 00000000000..6644e9dc452 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rrwm-2vxq-5x2h/GHSA-rrwm-2vxq-5x2h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrwm-2vxq-5x2h", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-2513" + ], + "details": "A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600 database. An attacker who manages to get access to the exported backup file can exploit the vulnerability and obtain credentials of the IEDs. The credentials may be used to perform unauthorized modifications such as loading incorrect configurations, reboot the IEDs or cause a denial-of-service on the IEDs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2513" + }, + { + "type": "WEB", + "url": "https://search.abb.com/library/Download.aspx?DocumentID=8DBD000120&LanguageCode=en&DocumentPartId=&Action=Launch" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-22T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rv59-78h6-2m84/GHSA-rv59-78h6-2m84.json b/advisories/unreviewed/2023/07/GHSA-rv59-78h6-2m84/GHSA-rv59-78h6-2m84.json new file mode 100644 index 00000000000..88678488eaf --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rv59-78h6-2m84/GHSA-rv59-78h6-2m84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv59-78h6-2m84", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25485" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25485" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/json-content-importer/wordpress-json-content-importer-plugin-1-3-15-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rvvq-r3qv-fpwc/GHSA-rvvq-r3qv-fpwc.json b/advisories/unreviewed/2023/07/GHSA-rvvq-r3qv-fpwc/GHSA-rvvq-r3qv-fpwc.json new file mode 100644 index 00000000000..9c5a13080b9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rvvq-r3qv-fpwc/GHSA-rvvq-r3qv-fpwc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvvq-r3qv-fpwc", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-3586" + ], + "details": "A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3586" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/9efd23297cca" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/upcoming/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-19T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rw86-cvx5-q4pj/GHSA-rw86-cvx5-q4pj.json b/advisories/unreviewed/2023/07/GHSA-rw86-cvx5-q4pj/GHSA-rw86-cvx5-q4pj.json new file mode 100644 index 00000000000..d971ef25102 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rw86-cvx5-q4pj/GHSA-rw86-cvx5-q4pj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw86-cvx5-q4pj", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-38206" + ], + "details": "There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38206" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2022-update-2-patch-is-now-available" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v46q-m532-mg39/GHSA-v46q-m532-mg39.json b/advisories/unreviewed/2023/07/GHSA-v46q-m532-mg39/GHSA-v46q-m532-mg39.json new file mode 100644 index 00000000000..b1592474168 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v46q-m532-mg39/GHSA-v46q-m532-mg39.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v46q-m532-mg39", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-30544" + ], + "details": "Cross-Site Request Forgery (CSRF) in MiKa's OSM – OpenStreetMap plugin <= 6.0.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/osm/wordpress-osm-openstreetmap-plugin-6-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-17T05:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v625-qcpp-j2vf/GHSA-v625-qcpp-j2vf.json b/advisories/unreviewed/2023/07/GHSA-v625-qcpp-j2vf/GHSA-v625-qcpp-j2vf.json new file mode 100644 index 00000000000..db1b0ae7e9e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v625-qcpp-j2vf/GHSA-v625-qcpp-j2vf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v625-qcpp-j2vf", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-41273" + ], + "details": "Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the victim doesn’t suspect the threat, they click on the link, log in to SAP Sourcing and CLM and at this point, they get redirected to a malicious website.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41273" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3270399" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-13T04:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v63h-22hj-7hmg/GHSA-v63h-22hj-7hmg.json b/advisories/unreviewed/2023/07/GHSA-v63h-22hj-7hmg/GHSA-v63h-22hj-7hmg.json new file mode 100644 index 00000000000..58967eccb44 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v63h-22hj-7hmg/GHSA-v63h-22hj-7hmg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v63h-22hj-7hmg", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2023-0087" + ], + "details": "The Swifty Page Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘spm_plugin_options_page_tree_max_width’ parameter in versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0087" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/swifty-page-manager/trunk/view/page_tree.php?rev=1555394#L174" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8550a405-9fa2-41a3-b556-05ff9f577ce4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-05T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v762-h4q2-77wx/GHSA-v762-h4q2-77wx.json b/advisories/unreviewed/2023/07/GHSA-v762-h4q2-77wx/GHSA-v762-h4q2-77wx.json new file mode 100644 index 00000000000..9404df066d3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v762-h4q2-77wx/GHSA-v762-h4q2-77wx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v762-h4q2-77wx", + "modified": "2023-07-06T19:24:15Z", + "published": "2023-07-06T19:24:15Z", + "aliases": [ + "CVE-2022-43458" + ], + "details": "Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-floating-content-lite/wordpress-advanced-floating-content-plugin-1-2-1-multiple-auth-cross-site-scripting-xss-vulnerabilities?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v77g-284c-r623/GHSA-v77g-284c-r623.json b/advisories/unreviewed/2023/07/GHSA-v77g-284c-r623/GHSA-v77g-284c-r623.json new file mode 100644 index 00000000000..57bd4454706 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v77g-284c-r623/GHSA-v77g-284c-r623.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v77g-284c-r623", + "modified": "2023-07-06T19:24:00Z", + "published": "2023-07-06T19:24:00Z", + "aliases": [ + "CVE-2022-40180" + ], + "details": "A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in the “Import Files“ functionality of the “Operation” web application due to the missing validation of anti-CSRF tokens or other origin checks. A remote unauthenticated attacker can upload and enable permanent arbitrary JavaScript code into the device just by convincing a victim to visit a specifically crafted webpage while logged-in to the device web application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40180" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-11T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v8c5-pw83-p6v7/GHSA-v8c5-pw83-p6v7.json b/advisories/unreviewed/2023/07/GHSA-v8c5-pw83-p6v7/GHSA-v8c5-pw83-p6v7.json new file mode 100644 index 00000000000..5a4f86738bb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v8c5-pw83-p6v7/GHSA-v8c5-pw83-p6v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8c5-pw83-p6v7", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2022-45838" + ], + "details": "Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/arforms-form-builder/wordpress-arforms-form-builder-plugin-1-5-3-unauth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v95r-pfp9-xw8f/GHSA-v95r-pfp9-xw8f.json b/advisories/unreviewed/2023/07/GHSA-v95r-pfp9-xw8f/GHSA-v95r-pfp9-xw8f.json new file mode 100644 index 00000000000..dd34096c620 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v95r-pfp9-xw8f/GHSA-v95r-pfp9-xw8f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v95r-pfp9-xw8f", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2022-46862" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46862" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/quiz-master-next/wordpress-quiz-and-survey-master-plugin-8-0-7-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json b/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json new file mode 100644 index 00000000000..ff2cc29483e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vcc9-8549-687w/GHSA-vcc9-8549-687w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcc9-8549-687w", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-2807" + ], + "details": "Algan Yazılım Prens Student Information System product has an unauthenticated SQL Injection vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2807" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-22-0708" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-02T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vcj3-36cm-3c25/GHSA-vcj3-36cm-3c25.json b/advisories/unreviewed/2023/07/GHSA-vcj3-36cm-3c25/GHSA-vcj3-36cm-3c25.json new file mode 100644 index 00000000000..4fe8a3a5118 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vcj3-36cm-3c25/GHSA-vcj3-36cm-3c25.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcj3-36cm-3c25", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-43492" + ], + "details": "Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-comments-wpdiscuz-plugin-7-4-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wpdiscuz/#developers" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-18T23:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vmwx-8pmg-4mrr/GHSA-vmwx-8pmg-4mrr.json b/advisories/unreviewed/2023/07/GHSA-vmwx-8pmg-4mrr/GHSA-vmwx-8pmg-4mrr.json new file mode 100644 index 00000000000..2d5ab41ef72 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vmwx-8pmg-4mrr/GHSA-vmwx-8pmg-4mrr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmwx-8pmg-4mrr", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0890" + ], + "details": "The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected posts", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0890" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8a466f15-f112-4527-8b02-4544a8032671" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-20T16:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vq77-w3cf-rw37/GHSA-vq77-w3cf-rw37.json b/advisories/unreviewed/2023/07/GHSA-vq77-w3cf-rw37/GHSA-vq77-w3cf-rw37.json new file mode 100644 index 00000000000..7107d45249a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vq77-w3cf-rw37/GHSA-vq77-w3cf-rw37.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq77-w3cf-rw37", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-40699" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40699" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yet-another-stars-rating/wordpress-yasr-yet-another-stars-rating-plugin-3-1-2-xss-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-16T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vrpm-3gh9-qhp6/GHSA-vrpm-3gh9-qhp6.json b/advisories/unreviewed/2023/07/GHSA-vrpm-3gh9-qhp6/GHSA-vrpm-3gh9-qhp6.json new file mode 100644 index 00000000000..e9835a80778 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vrpm-3gh9-qhp6/GHSA-vrpm-3gh9-qhp6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrpm-3gh9-qhp6", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-22935" + ], + "details": "In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass [SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards). The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22935" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2023-0205" + }, + { + "type": "WEB", + "url": "https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T18:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json b/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json new file mode 100644 index 00000000000..00f80df9c8c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrr6-jm4r-hqvp", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-3238" + ], + "details": "A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3238" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2127927" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-14T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vw69-xjfm-55g4/GHSA-vw69-xjfm-55g4.json b/advisories/unreviewed/2023/07/GHSA-vw69-xjfm-55g4/GHSA-vw69-xjfm-55g4.json new file mode 100644 index 00000000000..efe11b1f924 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vw69-xjfm-55g4/GHSA-vw69-xjfm-55g4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw69-xjfm-55g4", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-23878" + ], + "details": "Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23878" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-google-map-plugin/wordpress-wordpress-plugin-for-google-maps-wp-maps-plugin-4-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-04T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vwqg-h7r8-fqcg/GHSA-vwqg-h7r8-fqcg.json b/advisories/unreviewed/2023/07/GHSA-vwqg-h7r8-fqcg/GHSA-vwqg-h7r8-fqcg.json new file mode 100644 index 00000000000..622a7e38951 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vwqg-h7r8-fqcg/GHSA-vwqg-h7r8-fqcg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwqg-h7r8-fqcg", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-24402" + ], + "details": "Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24402" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-booking-system/wordpress-wp-booking-system-booking-calendar-plugin-2-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-07T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vx3x-c4x9-q8p5/GHSA-vx3x-c4x9-q8p5.json b/advisories/unreviewed/2023/07/GHSA-vx3x-c4x9-q8p5/GHSA-vx3x-c4x9-q8p5.json new file mode 100644 index 00000000000..7495cd1a442 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vx3x-c4x9-q8p5/GHSA-vx3x-c4x9-q8p5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx3x-c4x9-q8p5", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-33180" + ], + "details": "A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33180" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2022-2079" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vxfj-h2jv-2pgr/GHSA-vxfj-h2jv-2pgr.json b/advisories/unreviewed/2023/07/GHSA-vxfj-h2jv-2pgr/GHSA-vxfj-h2jv-2pgr.json new file mode 100644 index 00000000000..f3e5bccc148 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vxfj-h2jv-2pgr/GHSA-vxfj-h2jv-2pgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxfj-h2jv-2pgr", + "modified": "2023-07-06T19:24:05Z", + "published": "2023-07-06T19:24:05Z", + "aliases": [ + "CVE-2022-2642" + ], + "details": "Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out sensitive values and variable keys from the device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2642" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1108" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-02T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w2x5-hpmg-j98h/GHSA-w2x5-hpmg-j98h.json b/advisories/unreviewed/2023/07/GHSA-w2x5-hpmg-j98h/GHSA-w2x5-hpmg-j98h.json new file mode 100644 index 00000000000..d7bbd98b7cc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w2x5-hpmg-j98h/GHSA-w2x5-hpmg-j98h.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2x5-hpmg-j98h", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2020-36665" + ], + "details": "A vulnerability was found in Artesãos SEOTools up to 0.17.1 and classified as critical. This issue affects the function eachValue of the file TwitterCards.php. The manipulation of the argument value leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component. The identifier VDB-222233 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36665" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/pull/201" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/commit/ca27cd0edf917e0bc805227013859b8b5a1f01fb" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/releases/tag/v0.17.2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.222233" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.222233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-04T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w35h-r9ff-45q4/GHSA-w35h-r9ff-45q4.json b/advisories/unreviewed/2023/07/GHSA-w35h-r9ff-45q4/GHSA-w35h-r9ff-45q4.json new file mode 100644 index 00000000000..e72950b181e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w35h-r9ff-45q4/GHSA-w35h-r9ff-45q4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w35h-r9ff-45q4", + "modified": "2023-07-06T19:24:16Z", + "published": "2023-07-06T19:24:16Z", + "aliases": [ + "CVE-2023-1548" + ], + "details": "\nA CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to\nperform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1548" + }, + { + "type": "WEB", + "url": "https://https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w3rw-649p-m947/GHSA-w3rw-649p-m947.json b/advisories/unreviewed/2023/07/GHSA-w3rw-649p-m947/GHSA-w3rw-649p-m947.json new file mode 100644 index 00000000000..ebe378876c9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w3rw-649p-m947/GHSA-w3rw-649p-m947.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3rw-649p-m947", + "modified": "2023-07-06T19:24:04Z", + "published": "2023-07-06T19:24:04Z", + "aliases": [ + "CVE-2022-42893" + ], + "details": "A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42893" + }, + { + "type": "WEB", + "url": "https://www.siemens-healthineers.com/en-us/support-documentation/cybersecurity/shsa-741697" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w745-xjqx-7wp8/GHSA-w745-xjqx-7wp8.json b/advisories/unreviewed/2023/07/GHSA-w745-xjqx-7wp8/GHSA-w745-xjqx-7wp8.json new file mode 100644 index 00000000000..f0852894f9a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w745-xjqx-7wp8/GHSA-w745-xjqx-7wp8.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w745-xjqx-7wp8", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2020-36664" + ], + "details": "A vulnerability has been found in Artesãos SEOTools up to 0.17.1 and classified as problematic. This vulnerability affects the function setTitle of the file SEOMeta.php. The manipulation of the argument title leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-222232.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36664" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/pull/201" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/commit/ca27cd0edf917e0bc805227013859b8b5a1f01fb" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/releases/tag/v0.17.2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.222232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.222232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-04T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w8gp-g46m-jhvc/GHSA-w8gp-g46m-jhvc.json b/advisories/unreviewed/2023/07/GHSA-w8gp-g46m-jhvc/GHSA-w8gp-g46m-jhvc.json new file mode 100644 index 00000000000..ab6bf666598 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w8gp-g46m-jhvc/GHSA-w8gp-g46m-jhvc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8gp-g46m-jhvc", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-24404" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24404" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/marketing-performance/wordpress-marketing-performance-plugin-2-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wf8m-qr47-xc9m/GHSA-wf8m-qr47-xc9m.json b/advisories/unreviewed/2023/07/GHSA-wf8m-qr47-xc9m/GHSA-wf8m-qr47-xc9m.json new file mode 100644 index 00000000000..1238250a477 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wf8m-qr47-xc9m/GHSA-wf8m-qr47-xc9m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf8m-qr47-xc9m", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-28685" + ], + "details": "Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28685" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2930" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-22T06:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wf94-5wvh-jmpc/GHSA-wf94-5wvh-jmpc.json b/advisories/unreviewed/2023/07/GHSA-wf94-5wvh-jmpc/GHSA-wf94-5wvh-jmpc.json new file mode 100644 index 00000000000..db53294391b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wf94-5wvh-jmpc/GHSA-wf94-5wvh-jmpc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf94-5wvh-jmpc", + "modified": "2023-07-06T19:24:02Z", + "published": "2023-07-06T19:24:02Z", + "aliases": [ + "CVE-2022-38195" + ], + "details": "There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38195" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/administration/administration/arcgis-server-security-2022-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-10-25T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-whp2-gjjf-pvgr/GHSA-whp2-gjjf-pvgr.json b/advisories/unreviewed/2023/07/GHSA-whp2-gjjf-pvgr/GHSA-whp2-gjjf-pvgr.json new file mode 100644 index 00000000000..7f89c791bf2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-whp2-gjjf-pvgr/GHSA-whp2-gjjf-pvgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whp2-gjjf-pvgr", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-1257" + ], + "details": "An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1257" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-333-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1263" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-07T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wjg8-pxqj-c3c7/GHSA-wjg8-pxqj-c3c7.json b/advisories/unreviewed/2023/07/GHSA-wjg8-pxqj-c3c7/GHSA-wjg8-pxqj-c3c7.json new file mode 100644 index 00000000000..b202a0017b6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wjg8-pxqj-c3c7/GHSA-wjg8-pxqj-c3c7.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjg8-pxqj-c3c7", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2020-36663" + ], + "details": "A vulnerability, which was classified as problematic, was found in Artesãos SEOTools up to 0.17.1. This affects the function makeTag of the file OpenGraph.php. The manipulation of the argument value leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222231.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36663" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/pull/201" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/commit/ca27cd0edf917e0bc805227013859b8b5a1f01fb" + }, + { + "type": "WEB", + "url": "https://github.com/artesaos/seotools/releases/tag/v0.17.2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.222231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.222231" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-04T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wmg5-g953-qqfw/GHSA-wmg5-g953-qqfw.json b/advisories/unreviewed/2023/07/GHSA-wmg5-g953-qqfw/GHSA-wmg5-g953-qqfw.json new file mode 100644 index 00000000000..4f99294d882 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wmg5-g953-qqfw/GHSA-wmg5-g953-qqfw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmg5-g953-qqfw", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-24999" + ], + "details": "HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24999" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2023-07-vault-fails-to-verify-if-approle-secretid-belongs-to-role-during-a-destroy-operation/51305" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-11T00:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json b/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json new file mode 100644 index 00000000000..35b87a81068 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmgh-44xh-27j6", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-23462" + ], + "details": "Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23462" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/Departments/faq/cve_advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-15T19:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wmqm-3p7c-c6j7/GHSA-wmqm-3p7c-c6j7.json b/advisories/unreviewed/2023/07/GHSA-wmqm-3p7c-c6j7/GHSA-wmqm-3p7c-c6j7.json new file mode 100644 index 00000000000..d6bbec8fb3f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wmqm-3p7c-c6j7/GHSA-wmqm-3p7c-c6j7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmqm-3p7c-c6j7", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2022-47171" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul C. Schroeder IP Vault – WP Firewall plugin <= 1.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47171" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ip-vault-wp-firewall/wordpress-ip-vault-wp-firewall-plugin-1-1-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-14T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wpfp-vfwj-4xwh/GHSA-wpfp-vfwj-4xwh.json b/advisories/unreviewed/2023/07/GHSA-wpfp-vfwj-4xwh/GHSA-wpfp-vfwj-4xwh.json new file mode 100644 index 00000000000..59547e6c129 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wpfp-vfwj-4xwh/GHSA-wpfp-vfwj-4xwh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpfp-vfwj-4xwh", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2022-48427" + ], + "details": "In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48427" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wr5x-fcf4-h5qm/GHSA-wr5x-fcf4-h5qm.json b/advisories/unreviewed/2023/07/GHSA-wr5x-fcf4-h5qm/GHSA-wr5x-fcf4-h5qm.json new file mode 100644 index 00000000000..7a2392d8bb0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wr5x-fcf4-h5qm/GHSA-wr5x-fcf4-h5qm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr5x-fcf4-h5qm", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2022-47615" + ], + "details": "Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47615" + }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/multiple-critical-vulnerabilities-fixed-in-learnpress-plugin-version/" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-plugin-4-1-7-3-2-local-file-inclusion?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-26T21:18:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wrhx-52hg-crxx/GHSA-wrhx-52hg-crxx.json b/advisories/unreviewed/2023/07/GHSA-wrhx-52hg-crxx/GHSA-wrhx-52hg-crxx.json new file mode 100644 index 00000000000..55b63d97399 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wrhx-52hg-crxx/GHSA-wrhx-52hg-crxx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrhx-52hg-crxx", + "modified": "2023-07-06T19:24:18Z", + "published": "2023-07-06T19:24:18Z", + "aliases": [ + "CVE-2023-22581" + ], + "details": "White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22581" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2023-22581/" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2022-00068/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x84r-jrqm-3hj8/GHSA-x84r-jrqm-3hj8.json b/advisories/unreviewed/2023/07/GHSA-x84r-jrqm-3hj8/GHSA-x84r-jrqm-3hj8.json new file mode 100644 index 00000000000..c7671dce864 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x84r-jrqm-3hj8/GHSA-x84r-jrqm-3hj8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x84r-jrqm-3hj8", + "modified": "2023-07-06T19:24:13Z", + "published": "2023-07-06T19:24:13Z", + "aliases": [ + "CVE-2023-27602" + ], + "details": "\n\n\nIn Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.\n\n\nWe recommend users upgrade the version of Linkis to version 1.3.2. \n\nFor versions \n\n<=1.3.1, we suggest turning on the file path check switch in linkis.properties\n\n`wds.linkis.workspace.filesystem.owner.check=true`\n`wds.linkis.workspace.filesystem.path.check=true`", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27602" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/wt70jfc0yfs6s5g0wg5dr5klnc48nsp1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-10T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x8qw-cfcr-6hhp/GHSA-x8qw-cfcr-6hhp.json b/advisories/unreviewed/2023/07/GHSA-x8qw-cfcr-6hhp/GHSA-x8qw-cfcr-6hhp.json new file mode 100644 index 00000000000..357e58a7bec --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x8qw-cfcr-6hhp/GHSA-x8qw-cfcr-6hhp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8qw-cfcr-6hhp", + "modified": "2023-07-06T19:24:06Z", + "published": "2023-07-06T19:24:06Z", + "aliases": [ + "CVE-2022-38204" + ], + "details": "There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38204" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2022-update-2-patch-is-now-available" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-12-29T20:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x8xh-hfg5-qrf9/GHSA-x8xh-hfg5-qrf9.json b/advisories/unreviewed/2023/07/GHSA-x8xh-hfg5-qrf9/GHSA-x8xh-hfg5-qrf9.json new file mode 100644 index 00000000000..8dd1718ef69 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x8xh-hfg5-qrf9/GHSA-x8xh-hfg5-qrf9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8xh-hfg5-qrf9", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-25708" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25708" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpvr/wordpress-wp-vr-360-panorama-and-virtual-tour-builder-plugin-8-2-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-15T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x9qv-5m74-x74p/GHSA-x9qv-5m74-x74p.json b/advisories/unreviewed/2023/07/GHSA-x9qv-5m74-x74p/GHSA-x9qv-5m74-x74p.json new file mode 100644 index 00000000000..a22064b6133 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x9qv-5m74-x74p/GHSA-x9qv-5m74-x74p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9qv-5m74-x74p", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-28489" + ], + "details": "A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default.\nThe vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28489" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-472454.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T10:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xc7w-hcqx-q2x3/GHSA-xc7w-hcqx-q2x3.json b/advisories/unreviewed/2023/07/GHSA-xc7w-hcqx-q2x3/GHSA-xc7w-hcqx-q2x3.json new file mode 100644 index 00000000000..76c4b4f00ff --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xc7w-hcqx-q2x3/GHSA-xc7w-hcqx-q2x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc7w-hcqx-q2x3", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-25484" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25484" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-yearly-archive/wordpress-simple-yearly-archive-plugin-2-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xg39-26cw-gxj9/GHSA-xg39-26cw-gxj9.json b/advisories/unreviewed/2023/07/GHSA-xg39-26cw-gxj9/GHSA-xg39-26cw-gxj9.json new file mode 100644 index 00000000000..169fea2f4a1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xg39-26cw-gxj9/GHSA-xg39-26cw-gxj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg39-26cw-gxj9", + "modified": "2023-07-06T19:24:19Z", + "published": "2023-07-06T19:24:19Z", + "aliases": [ + "CVE-2023-28769" + ], + "details": "The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28769" + }, + { + "type": "WEB", + "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xgw4-pcqh-286r/GHSA-xgw4-pcqh-286r.json b/advisories/unreviewed/2023/07/GHSA-xgw4-pcqh-286r/GHSA-xgw4-pcqh-286r.json new file mode 100644 index 00000000000..025b0042cb6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xgw4-pcqh-286r/GHSA-xgw4-pcqh-286r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgw4-pcqh-286r", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-22880" + ], + "details": "Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsoft’s telemetry behavior.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22880" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-16T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xhm2-m35v-2xw7/GHSA-xhm2-m35v-2xw7.json b/advisories/unreviewed/2023/07/GHSA-xhm2-m35v-2xw7/GHSA-xhm2-m35v-2xw7.json new file mode 100644 index 00000000000..2a444ae2c8b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xhm2-m35v-2xw7/GHSA-xhm2-m35v-2xw7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhm2-m35v-2xw7", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-3776" + ], + "details": "The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options to name a few . This makes it possible for unauthenticated attackers to perform a variety of administrative actions like modifying forms, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3776" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2807967%40menu-ordering-reservations&new=2807967%40menu-ordering-reservations&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-3776" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-03T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xjhw-7765-363q/GHSA-xjhw-7765-363q.json b/advisories/unreviewed/2023/07/GHSA-xjhw-7765-363q/GHSA-xjhw-7765-363q.json new file mode 100644 index 00000000000..34ee4a227b2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xjhw-7765-363q/GHSA-xjhw-7765-363q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjhw-7765-363q", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2022-44582" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/apptivo-business-site/wordpress-apptivo-business-site-crm-plugin-3-0-12-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xjvc-8mfj-g22v/GHSA-xjvc-8mfj-g22v.json b/advisories/unreviewed/2023/07/GHSA-xjvc-8mfj-g22v/GHSA-xjvc-8mfj-g22v.json new file mode 100644 index 00000000000..50faaf80b05 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xjvc-8mfj-g22v/GHSA-xjvc-8mfj-g22v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjvc-8mfj-g22v", + "modified": "2023-07-06T19:24:03Z", + "published": "2023-07-06T19:24:03Z", + "aliases": [ + "CVE-2022-2696" + ], + "details": "The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2696" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/menu-ordering-reservations/trunk/includes/admin/class-glf-admin-screens.php?rev=2664283" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2793398%40menu-ordering-reservations&new=2793398%40menu-ordering-reservations&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/vulnerability-advisories-continued/#CVE-2022-2696" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2022-11-03T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xmvp-p4p2-hprq/GHSA-xmvp-p4p2-hprq.json b/advisories/unreviewed/2023/07/GHSA-xmvp-p4p2-hprq/GHSA-xmvp-p4p2-hprq.json new file mode 100644 index 00000000000..a3a9070e7f6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xmvp-p4p2-hprq/GHSA-xmvp-p4p2-hprq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmvp-p4p2-hprq", + "modified": "2023-07-06T19:24:09Z", + "published": "2023-07-06T19:24:09Z", + "aliases": [ + "CVE-2023-25065" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25065" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-expand-tabs-free/wordpress-wp-tabs-responsive-tabs-plugin-for-wordpress-plugin-2-1-14-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-02-14T12:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xv45-qm36-h77q/GHSA-xv45-qm36-h77q.json b/advisories/unreviewed/2023/07/GHSA-xv45-qm36-h77q/GHSA-xv45-qm36-h77q.json new file mode 100644 index 00000000000..91003206694 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xv45-qm36-h77q/GHSA-xv45-qm36-h77q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv45-qm36-h77q", + "modified": "2023-07-06T19:24:14Z", + "published": "2023-07-06T19:24:14Z", + "aliases": [ + "CVE-2023-1552" + ], + "details": "ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors. \n\nCustomers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1552" + }, + { + "type": "WEB", + "url": "https://www.ge.com/content/dam/cyber_security/global/en_US/pdfs/2023-03-23_ToolboxST_Deserialization_of_Untrusted_Configuration_Data.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-11T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xw8j-xwwr-8vqj/GHSA-xw8j-xwwr-8vqj.json b/advisories/unreviewed/2023/07/GHSA-xw8j-xwwr-8vqj/GHSA-xw8j-xwwr-8vqj.json new file mode 100644 index 00000000000..a8bbab97271 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xw8j-xwwr-8vqj/GHSA-xw8j-xwwr-8vqj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw8j-xwwr-8vqj", + "modified": "2023-07-06T19:24:17Z", + "published": "2023-07-06T19:24:17Z", + "aliases": [ + "CVE-2023-2118" + ], + "details": "Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2118" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2023-0010" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xwf7-9xfx-ghmm/GHSA-xwf7-9xfx-ghmm.json b/advisories/unreviewed/2023/07/GHSA-xwf7-9xfx-ghmm/GHSA-xwf7-9xfx-ghmm.json new file mode 100644 index 00000000000..8262b7d3520 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xwf7-9xfx-ghmm/GHSA-xwf7-9xfx-ghmm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwf7-9xfx-ghmm", + "modified": "2023-07-06T19:24:12Z", + "published": "2023-07-06T19:24:12Z", + "aliases": [ + "CVE-2023-28597" + ], + "details": "Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28597" + }, + { + "type": "WEB", + "url": "https://explore.zoom.us/en/trust/security/security-bulletin/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-27T21:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xwp2-26xm-vq22/GHSA-xwp2-26xm-vq22.json b/advisories/unreviewed/2023/07/GHSA-xwp2-26xm-vq22/GHSA-xwp2-26xm-vq22.json new file mode 100644 index 00000000000..f7ce436b08e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xwp2-26xm-vq22/GHSA-xwp2-26xm-vq22.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwp2-26xm-vq22", + "modified": "2023-07-06T19:24:11Z", + "published": "2023-07-06T19:24:11Z", + "aliases": [ + "CVE-2023-0968" + ], + "details": "The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0968" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/watu/trunk/views/takings.php#L31" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6341bdcc-c99f-40c3-81c4-ad90ff19f802" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-03T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xxmc-mjxm-2m5r/GHSA-xxmc-mjxm-2m5r.json b/advisories/unreviewed/2023/07/GHSA-xxmc-mjxm-2m5r/GHSA-xxmc-mjxm-2m5r.json new file mode 100644 index 00000000000..36d498f748b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xxmc-mjxm-2m5r/GHSA-xxmc-mjxm-2m5r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxmc-mjxm-2m5r", + "modified": "2023-07-06T19:24:08Z", + "published": "2023-07-06T19:24:08Z", + "aliases": [ + "CVE-2023-22610" + ], + "details": "A CWE-285: Improper Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port. Affected Products: EcoStruxure™ Geo SCADA Expert 2019, EcoStruxure™ Geo SCADA Expert 2020, EcoStruxure™ Geo SCADA Expert 2021 (All versions prior to October 2022), ClearSCADA (All Versions).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22610" + }, + { + "type": "WEB", + "url": "https://www.se.com/ww/en/download/document/SEVD-2023-010-02/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-01-31T17:15:00Z" + } +} \ No newline at end of file