From 2c64139ca15529879d8f938b8c82206c82f7230a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 14 Nov 2023 21:31:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pmgm-pv8c-pw29.json | 7 ++- .../GHSA-ppr5-jp7h-pvxj.json | 7 ++- .../GHSA-2vrv-3jr5-rv6c.json | 7 ++- .../GHSA-4v9x-j7pr-8wxq.json | 1 + .../GHSA-77jf-5mcg-g6m9.json | 7 ++- .../GHSA-c38v-5prm-vhjx.json | 7 ++- .../GHSA-cj8c-4h22-g2gj.json | 9 ++- .../GHSA-cpw5-f693-2r28.json | 7 ++- .../GHSA-fvqh-qwm3-5j87.json | 7 ++- .../GHSA-jx9p-jf7x-8rr2.json | 7 ++- .../GHSA-m7vg-3vj5-h86f.json | 7 ++- .../GHSA-pmpw-4q9q-8w52.json | 4 ++ .../GHSA-w463-hpv4-95pw.json | 7 ++- .../GHSA-w962-fvxv-mrr4.json | 7 ++- .../GHSA-x62f-6xhh-g5fp.json | 7 ++- .../GHSA-2hf7-qg9c-qf4h.json | 4 ++ .../GHSA-77q2-m9gq-g982.json | 4 ++ .../GHSA-7j33-663j-fx7f.json | 4 ++ .../GHSA-9r4w-694r-fm3f.json | 7 ++- .../GHSA-vh59-rfvm-xwqw.json | 4 +- .../GHSA-2764-3pqr-49w6.json | 17 ++++- .../GHSA-45c7-642q-qm9m.json | 30 ++++++++- .../GHSA-7x98-4rw8-872g.json | 16 ++++- .../GHSA-86p4-vhr6-2vv3.json | 30 ++++++++- .../GHSA-8f4h-wr7j-w67m.json | 16 ++++- .../GHSA-cfhp-p6xr-24g5.json | 28 ++++++++- .../GHSA-fcmj-gcwc-rvc5.json | 15 +++-- .../GHSA-mfwc-hx97-869v.json | 16 ++++- .../GHSA-qrwf-www2-hr3h.json | 8 ++- .../GHSA-wpvc-538m-c48m.json | 8 ++- .../GHSA-897q-36v3-jwhm.json | 12 +++- .../GHSA-jgj3-64jr-4g3x.json | 9 ++- .../GHSA-v34c-9rwg-qpf6.json | 15 ++++- .../GHSA-5w38-f33m-gcr8.json | 8 ++- .../GHSA-q77f-64gj-7q7p.json | 8 ++- .../GHSA-c9mw-vpxm-p7rq.json | 15 ++++- .../GHSA-r6w9-hpm6-f3mf.json | 9 ++- .../GHSA-24mv-46g6-jv5x.json | 38 ++++++++++++ .../GHSA-262p-h3cm-wwv8.json | 38 ++++++++++++ .../GHSA-279v-q4q9-mx7j.json | 38 ++++++++++++ .../GHSA-2fpj-cv6p-p352.json | 35 +++++++++++ .../GHSA-2gmf-mp9h-g5xw.json | 38 ++++++++++++ .../GHSA-2jf9-9rxc-j63c.json | 38 ++++++++++++ .../GHSA-2wh3-v786-vq3m.json | 38 ++++++++++++ .../GHSA-34r6-9vgg-pmh3.json | 42 +++++++++++++ .../GHSA-34xr-h92c-2m86.json | 39 ++++++++++++ .../GHSA-35qw-3m24-r2j5.json | 38 ++++++++++++ .../GHSA-3744-988x-mqxh.json | 38 ++++++++++++ .../GHSA-37p9-3q24-hgrc.json | 42 +++++++++++++ .../GHSA-39p9-mvxq-x2gf.json | 38 ++++++++++++ .../GHSA-39w8-7xg4-7fr5.json | 38 ++++++++++++ .../GHSA-3cfv-7x3j-7m2c.json | 9 ++- .../GHSA-3pww-pqg2-m2hm.json | 35 +++++++++++ .../GHSA-3qwh-j562-h8h6.json | 38 ++++++++++++ .../GHSA-3r28-q7qr-3hmj.json | 38 ++++++++++++ .../GHSA-3vm5-5963-pw52.json | 38 ++++++++++++ .../GHSA-3x8j-5c5c-jh43.json | 35 +++++++++++ .../GHSA-3xpq-vc4j-pfj2.json | 38 ++++++++++++ .../GHSA-426h-v87f-gxvw.json | 2 +- .../GHSA-42gp-78x8-7p5j.json | 38 ++++++++++++ .../GHSA-4384-whxj-38x3.json | 38 ++++++++++++ .../GHSA-43wm-36v8-wrcq.json | 9 ++- .../GHSA-44j5-cggq-4pgj.json | 2 +- .../GHSA-4fcv-689w-5fjw.json | 38 ++++++++++++ .../GHSA-4m89-9vr4-fxx8.json | 38 ++++++++++++ .../GHSA-4p9r-m5q5-m33p.json | 38 ++++++++++++ .../GHSA-4qp7-687g-h58j.json | 9 ++- .../GHSA-4rxw-r623-vp2w.json | 38 ++++++++++++ .../GHSA-4xjx-gm5q-6rqm.json | 38 ++++++++++++ .../GHSA-4xv6-mr8c-xp77.json | 38 ++++++++++++ .../GHSA-52rh-vv3q-8jrh.json | 9 ++- .../GHSA-535j-5wpp-p7jm.json | 38 ++++++++++++ .../GHSA-558c-wr25-5fxf.json | 42 +++++++++++++ .../GHSA-55jv-g63w-9jph.json | 38 ++++++++++++ .../GHSA-56m3-ppxh-qp77.json | 38 ++++++++++++ .../GHSA-57xx-rrgm-5cv4.json | 38 ++++++++++++ .../GHSA-58jh-w7hm-m96f.json | 38 ++++++++++++ .../GHSA-58rr-37rr-r6h5.json | 42 +++++++++++++ .../GHSA-59x7-fjc6-6prx.json | 38 ++++++++++++ .../GHSA-5h2m-6q68-2g79.json | 38 ++++++++++++ .../GHSA-5h34-9p23-39p2.json | 38 ++++++++++++ .../GHSA-5hcf-f625-mgr8.json | 9 ++- .../GHSA-5pq2-w3x5-q9f2.json | 39 ++++++++++++ .../GHSA-5prp-6h6f-f55f.json | 35 +++++++++++ .../GHSA-5q3h-x43w-q8hj.json | 9 ++- .../GHSA-5r37-fx4g-5c7h.json | 38 ++++++++++++ .../GHSA-5r5w-vh62-8499.json | 54 ++++++++++++++++ .../GHSA-5rcg-jq54-2r8g.json | 38 ++++++++++++ .../GHSA-5v7j-rmqq-795g.json | 38 ++++++++++++ .../GHSA-5w5f-g3w4-p65h.json | 39 ++++++++++++ .../GHSA-5w9x-5g27-3wqv.json | 43 +++++++++++++ .../GHSA-5x3f-7vj9-g9q2.json | 38 ++++++++++++ .../GHSA-5xr2-69wj-6x93.json | 38 ++++++++++++ .../GHSA-5xw6-9h38-rh99.json | 38 ++++++++++++ .../GHSA-62r6-m6fg-p4wj.json | 38 ++++++++++++ .../GHSA-66vf-xw82-p57g.json | 2 +- .../GHSA-6gv5-48rm-6999.json | 39 ++++++++++++ .../GHSA-6j6r-mmfh-xf8p.json | 38 ++++++++++++ .../GHSA-6v8g-pm53-9xw3.json | 38 ++++++++++++ .../GHSA-6xmc-94m2-r43v.json | 38 ++++++++++++ .../GHSA-75f9-xr67-g7hj.json | 9 ++- .../GHSA-77mh-vg7v-786h.json | 38 ++++++++++++ .../GHSA-7fmg-q86j-f6v7.json | 38 ++++++++++++ .../GHSA-7hq6-r3pg-vcqw.json | 38 ++++++++++++ .../GHSA-7j92-gx3c-pv6x.json | 38 ++++++++++++ .../GHSA-7mw5-v379-5f57.json | 11 ++-- .../GHSA-7r55-mp9r-c8pj.json | 39 ++++++++++++ .../GHSA-7r75-c97x-7676.json | 38 ++++++++++++ .../GHSA-85qm-42j3-mwq3.json | 38 ++++++++++++ .../GHSA-8882-q5f7-v9h8.json | 38 ++++++++++++ .../GHSA-89jm-mj5r-5rp8.json | 9 ++- .../GHSA-8hgg-xxm5-3873.json | 42 +++++++++++++ .../GHSA-8jp5-89m5-6xp3.json | 11 ++-- .../GHSA-8pj8-c4m2-fgh7.json | 38 ++++++++++++ .../GHSA-8qm9-hxp3-h3fp.json | 38 ++++++++++++ .../GHSA-8wpw-g939-rjw4.json | 39 ++++++++++++ .../GHSA-8x2v-m87x-jx78.json | 38 ++++++++++++ .../GHSA-92g5-jmf9-m2wf.json | 38 ++++++++++++ .../GHSA-92w3-2x69-pqhc.json | 54 ++++++++++++++++ .../GHSA-92xq-w7vg-rw26.json | 38 ++++++++++++ .../GHSA-93g9-r9cm-chf3.json | 38 ++++++++++++ .../GHSA-94hw-2w9j-mjr9.json | 9 ++- .../GHSA-956p-f3rr-w9v3.json | 38 ++++++++++++ .../GHSA-9684-7r2w-mm28.json | 38 ++++++++++++ .../GHSA-9cgg-v86h-hw54.json | 62 +++++++++++++++++++ .../GHSA-9cwp-p56f-6gc5.json | 38 ++++++++++++ .../GHSA-9f56-vmhf-r5vv.json | 38 ++++++++++++ .../GHSA-9f83-5mc2-p75r.json | 38 ++++++++++++ .../GHSA-9fmg-2fcx-q3vf.json | 39 ++++++++++++ .../GHSA-9ghc-6jgp-h734.json | 38 ++++++++++++ .../GHSA-9p33-fhfv-86gg.json | 38 ++++++++++++ .../GHSA-9pj9-m7vp-27hp.json | 38 ++++++++++++ .../GHSA-9qfg-vjxj-gjf3.json | 38 ++++++++++++ .../GHSA-9qfm-4g6c-76pf.json | 38 ++++++++++++ .../GHSA-9wxq-3vm5-2pg9.json | 38 ++++++++++++ .../GHSA-c7mf-mh8g-44q2.json | 38 ++++++++++++ .../GHSA-c9fc-7rjq-97gw.json | 38 ++++++++++++ .../GHSA-cc87-35fp-2jp7.json | 38 ++++++++++++ .../GHSA-cc94-45q3-h8pp.json | 38 ++++++++++++ .../GHSA-cf7p-69mj-6266.json | 38 ++++++++++++ .../GHSA-cj6m-445x-9hgm.json | 38 ++++++++++++ .../GHSA-cjh4-hrfc-4xj7.json | 35 +++++++++++ .../GHSA-cjvm-95qv-84m2.json | 38 ++++++++++++ .../GHSA-cp97-6mf7-2cvp.json | 38 ++++++++++++ .../GHSA-cqgf-g3qq-hhxw.json | 39 ++++++++++++ .../GHSA-cv78-jxjg-mfgw.json | 38 ++++++++++++ .../GHSA-cxvw-76f5-px84.json | 38 ++++++++++++ .../GHSA-f346-p877-7wqq.json | 38 ++++++++++++ .../GHSA-f3rw-936p-6899.json | 9 ++- .../GHSA-f6cq-wc24-3mcw.json | 38 ++++++++++++ .../GHSA-f8ch-7h6r-42h6.json | 38 ++++++++++++ .../GHSA-f8rp-47c5-2crv.json | 38 ++++++++++++ .../GHSA-fc85-qvq2-2963.json | 42 +++++++++++++ .../GHSA-ff49-v6jj-fh2j.json | 38 ++++++++++++ .../GHSA-ffwh-fwc7-gh76.json | 38 ++++++++++++ .../GHSA-frwx-7gqv-hj3w.json | 38 ++++++++++++ .../GHSA-fww3-wwgr-mqpw.json | 38 ++++++++++++ .../GHSA-fx6p-v7mp-pw72.json | 38 ++++++++++++ .../GHSA-g3qw-w3wp-f3m2.json | 38 ++++++++++++ .../GHSA-g896-hqwq-6qp3.json | 9 ++- .../GHSA-g9w7-fcq8-mffw.json | 38 ++++++++++++ .../GHSA-ggrf-mj99-j57m.json | 38 ++++++++++++ .../GHSA-gh94-rfj3-873r.json | 38 ++++++++++++ .../GHSA-ghwh-356h-wcgq.json | 38 ++++++++++++ .../GHSA-gpjf-v934-73g5.json | 9 ++- .../GHSA-gqm2-wv4v-659j.json | 38 ++++++++++++ .../GHSA-gqwc-m2xc-gx3c.json | 38 ++++++++++++ .../GHSA-h53x-4j3w-4vcp.json | 38 ++++++++++++ .../GHSA-h5fc-v3m2-vpp2.json | 38 ++++++++++++ .../GHSA-h5hr-qxxj-7g93.json | 12 ++-- .../GHSA-h8jx-25pr-hgm3.json | 9 ++- .../GHSA-hgpx-7mjh-m574.json | 38 ++++++++++++ .../GHSA-hq3p-78fh-v8qw.json | 38 ++++++++++++ .../GHSA-hq6q-c2x6-hmch.json | 42 +++++++++++++ .../GHSA-hwv7-r8wc-xjxc.json | 38 ++++++++++++ .../GHSA-j5vh-m963-h26r.json | 38 ++++++++++++ .../GHSA-j8h9-q858-c787.json | 46 ++++++++++++++ .../GHSA-jgqp-37qx-xpp9.json | 38 ++++++++++++ .../GHSA-jm3v-6m47-cv37.json | 38 ++++++++++++ .../GHSA-jm6q-v8j6-qqwg.json | 38 ++++++++++++ .../GHSA-m2w4-66r4-v852.json | 38 ++++++++++++ .../GHSA-m3hg-fjqc-ww3w.json | 38 ++++++++++++ .../GHSA-m7g3-7cq7-qj74.json | 38 ++++++++++++ .../GHSA-m8cq-xmhh-jr5v.json | 2 +- .../GHSA-m8wv-7jj8-p8pv.json | 2 +- .../GHSA-mfxr-7r69-92fv.json | 50 +++++++++++++++ .../GHSA-mq3f-4x6v-59hg.json | 38 ++++++++++++ .../GHSA-mx9c-3r4g-6f8m.json | 38 ++++++++++++ .../GHSA-p483-8797-gq74.json | 39 ++++++++++++ .../GHSA-pgg7-g5f4-6c8v.json | 38 ++++++++++++ .../GHSA-pjj6-9mq4-p5qc.json | 38 ++++++++++++ .../GHSA-pr3w-9h6r-g7j3.json | 38 ++++++++++++ .../GHSA-pr6q-p3qr-3x6p.json | 2 +- .../GHSA-pv77-783w-qwjw.json | 38 ++++++++++++ .../GHSA-px59-5w52-jv25.json | 38 ++++++++++++ .../GHSA-q2vq-xj2q-g729.json | 38 ++++++++++++ .../GHSA-q57g-38pc-jwv8.json | 42 +++++++++++++ .../GHSA-q69f-x478-xp8g.json | 38 ++++++++++++ .../GHSA-q6v6-32hh-pq9p.json | 9 ++- .../GHSA-q6w8-c6j3-wwc9.json | 38 ++++++++++++ .../GHSA-q84m-vxmr-72ph.json | 38 ++++++++++++ .../GHSA-q9rq-5hwp-7wq9.json | 9 ++- .../GHSA-qc67-fv9p-fpx5.json | 38 ++++++++++++ .../GHSA-qf8h-hpq5-hc5h.json | 38 ++++++++++++ .../GHSA-qp5j-mmrp-vj4f.json | 38 ++++++++++++ .../GHSA-qphr-6rj3-crfc.json | 38 ++++++++++++ .../GHSA-qpw8-mj26-5rc9.json | 38 ++++++++++++ .../GHSA-qq7m-q225-9v82.json | 38 ++++++++++++ .../GHSA-qvcf-7rv4-rh36.json | 11 ++-- .../GHSA-qvg6-x224-c55m.json | 35 +++++++++++ .../GHSA-r2mq-3mfq-2p2w.json | 35 +++++++++++ .../GHSA-r322-c8vr-qgrp.json | 38 ++++++++++++ .../GHSA-r4ch-3qw4-35q9.json | 38 ++++++++++++ .../GHSA-r7xg-3gm7-8q8p.json | 35 +++++++++++ .../GHSA-r8cx-47rc-5x49.json | 9 ++- .../GHSA-rcxc-fhh3-qjq9.json | 46 ++++++++++++++ .../GHSA-rh5g-pqg8-7p3x.json | 38 ++++++++++++ .../GHSA-rp4j-f7fp-cgf2.json | 38 ++++++++++++ .../GHSA-rqj6-65x2-r2vh.json | 38 ++++++++++++ .../GHSA-rv6j-6cr4-gr5q.json | 38 ++++++++++++ .../GHSA-rx9f-2j6q-9pff.json | 9 ++- .../GHSA-v246-p8m5-h759.json | 38 ++++++++++++ .../GHSA-v2hc-cp84-vjqv.json | 35 +++++++++++ .../GHSA-v325-cfqv-359p.json | 38 ++++++++++++ .../GHSA-v3gh-c2m2-h84q.json | 38 ++++++++++++ .../GHSA-v4fc-x53w-j3j2.json | 35 +++++++++++ .../GHSA-v5x9-p45c-rxpc.json | 38 ++++++++++++ .../GHSA-vgxm-8jf8-3h3v.json | 35 +++++++++++ .../GHSA-vxpv-jc8r-m85p.json | 38 ++++++++++++ .../GHSA-w369-f878-vgmj.json | 38 ++++++++++++ .../GHSA-w499-v3vm-68xq.json | 38 ++++++++++++ .../GHSA-w4pv-p6xf-qc53.json | 35 +++++++++++ .../GHSA-w776-w5x6-c2xf.json | 35 +++++++++++ .../GHSA-w7qf-3h78-55fp.json | 38 ++++++++++++ .../GHSA-w8c8-x4x9-r382.json | 38 ++++++++++++ .../GHSA-w8wr-v3q8-68hg.json | 38 ++++++++++++ .../GHSA-wfc8-v3hg-jvrw.json | 38 ++++++++++++ .../GHSA-wh4j-r7mv-vjg8.json | 38 ++++++++++++ .../GHSA-wpw2-hvhc-r9qq.json | 9 ++- .../GHSA-wr7v-h9p2-5fr6.json | 9 ++- .../GHSA-wrgh-9hfh-4fqj.json | 38 ++++++++++++ .../GHSA-wrmf-3x8w-vcx2.json | 35 +++++++++++ .../GHSA-wrv4-h8m2-2rj7.json | 38 ++++++++++++ .../GHSA-wvq7-fmcr-mvgx.json | 50 +++++++++++++++ .../GHSA-x45c-39pv-5956.json | 38 ++++++++++++ .../GHSA-x4vh-ch66-jvcq.json | 38 ++++++++++++ .../GHSA-x4wr-fpxp-h8c3.json | 42 +++++++++++++ .../GHSA-x5jv-p8vx-9cmf.json | 12 ++-- .../GHSA-x6h4-x9x4-vf9g.json | 38 ++++++++++++ .../GHSA-x8q6-xr39-6p4c.json | 38 ++++++++++++ .../GHSA-x8xw-jc3c-cx53.json | 39 ++++++++++++ .../GHSA-x935-fw35-6fjh.json | 42 +++++++++++++ .../GHSA-x9c2-rmrg-4h96.json | 38 ++++++++++++ .../GHSA-xj2m-wgjq-qpmc.json | 38 ++++++++++++ .../GHSA-xmm7-2j6p-p24v.json | 38 ++++++++++++ .../GHSA-xq75-p9cv-wvw7.json | 38 ++++++++++++ .../GHSA-xrh2-77qw-v55j.json | 38 ++++++++++++ .../GHSA-xvfh-vpm8-j2fh.json | 38 ++++++++++++ .../GHSA-xx54-mvr7-rhfj.json | 9 ++- .../GHSA-xxvq-wr93-6r58.json | 38 ++++++++++++ 260 files changed, 7878 insertions(+), 157 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-24mv-46g6-jv5x/GHSA-24mv-46g6-jv5x.json create mode 100644 advisories/unreviewed/2023/11/GHSA-262p-h3cm-wwv8/GHSA-262p-h3cm-wwv8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-279v-q4q9-mx7j/GHSA-279v-q4q9-mx7j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2fpj-cv6p-p352/GHSA-2fpj-cv6p-p352.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2gmf-mp9h-g5xw/GHSA-2gmf-mp9h-g5xw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2jf9-9rxc-j63c/GHSA-2jf9-9rxc-j63c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json create mode 100644 advisories/unreviewed/2023/11/GHSA-34r6-9vgg-pmh3/GHSA-34r6-9vgg-pmh3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json create mode 100644 advisories/unreviewed/2023/11/GHSA-35qw-3m24-r2j5/GHSA-35qw-3m24-r2j5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3744-988x-mqxh/GHSA-3744-988x-mqxh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-37p9-3q24-hgrc/GHSA-37p9-3q24-hgrc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-39p9-mvxq-x2gf/GHSA-39p9-mvxq-x2gf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-39w8-7xg4-7fr5/GHSA-39w8-7xg4-7fr5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3pww-pqg2-m2hm/GHSA-3pww-pqg2-m2hm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3qwh-j562-h8h6/GHSA-3qwh-j562-h8h6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3r28-q7qr-3hmj/GHSA-3r28-q7qr-3hmj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3x8j-5c5c-jh43/GHSA-3x8j-5c5c-jh43.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-42gp-78x8-7p5j/GHSA-42gp-78x8-7p5j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4384-whxj-38x3/GHSA-4384-whxj-38x3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4fcv-689w-5fjw/GHSA-4fcv-689w-5fjw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4m89-9vr4-fxx8/GHSA-4m89-9vr4-fxx8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4p9r-m5q5-m33p/GHSA-4p9r-m5q5-m33p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4rxw-r623-vp2w/GHSA-4rxw-r623-vp2w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4xjx-gm5q-6rqm/GHSA-4xjx-gm5q-6rqm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4xv6-mr8c-xp77/GHSA-4xv6-mr8c-xp77.json create mode 100644 advisories/unreviewed/2023/11/GHSA-535j-5wpp-p7jm/GHSA-535j-5wpp-p7jm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-558c-wr25-5fxf/GHSA-558c-wr25-5fxf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-55jv-g63w-9jph/GHSA-55jv-g63w-9jph.json create mode 100644 advisories/unreviewed/2023/11/GHSA-56m3-ppxh-qp77/GHSA-56m3-ppxh-qp77.json create mode 100644 advisories/unreviewed/2023/11/GHSA-57xx-rrgm-5cv4/GHSA-57xx-rrgm-5cv4.json create mode 100644 advisories/unreviewed/2023/11/GHSA-58jh-w7hm-m96f/GHSA-58jh-w7hm-m96f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-59x7-fjc6-6prx/GHSA-59x7-fjc6-6prx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5h2m-6q68-2g79/GHSA-5h2m-6q68-2g79.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5h34-9p23-39p2/GHSA-5h34-9p23-39p2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5prp-6h6f-f55f/GHSA-5prp-6h6f-f55f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5r37-fx4g-5c7h/GHSA-5r37-fx4g-5c7h.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5r5w-vh62-8499/GHSA-5r5w-vh62-8499.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5rcg-jq54-2r8g/GHSA-5rcg-jq54-2r8g.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5v7j-rmqq-795g/GHSA-5v7j-rmqq-795g.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5w9x-5g27-3wqv/GHSA-5w9x-5g27-3wqv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5x3f-7vj9-g9q2/GHSA-5x3f-7vj9-g9q2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5xr2-69wj-6x93/GHSA-5xr2-69wj-6x93.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5xw6-9h38-rh99/GHSA-5xw6-9h38-rh99.json create mode 100644 advisories/unreviewed/2023/11/GHSA-62r6-m6fg-p4wj/GHSA-62r6-m6fg-p4wj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6j6r-mmfh-xf8p/GHSA-6j6r-mmfh-xf8p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6v8g-pm53-9xw3/GHSA-6v8g-pm53-9xw3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6xmc-94m2-r43v/GHSA-6xmc-94m2-r43v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-77mh-vg7v-786h/GHSA-77mh-vg7v-786h.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7fmg-q86j-f6v7/GHSA-7fmg-q86j-f6v7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7hq6-r3pg-vcqw/GHSA-7hq6-r3pg-vcqw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7j92-gx3c-pv6x/GHSA-7j92-gx3c-pv6x.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7r75-c97x-7676/GHSA-7r75-c97x-7676.json create mode 100644 advisories/unreviewed/2023/11/GHSA-85qm-42j3-mwq3/GHSA-85qm-42j3-mwq3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8hgg-xxm5-3873/GHSA-8hgg-xxm5-3873.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8pj8-c4m2-fgh7/GHSA-8pj8-c4m2-fgh7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8qm9-hxp3-h3fp/GHSA-8qm9-hxp3-h3fp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8x2v-m87x-jx78/GHSA-8x2v-m87x-jx78.json create mode 100644 advisories/unreviewed/2023/11/GHSA-92g5-jmf9-m2wf/GHSA-92g5-jmf9-m2wf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-92w3-2x69-pqhc/GHSA-92w3-2x69-pqhc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-92xq-w7vg-rw26/GHSA-92xq-w7vg-rw26.json create mode 100644 advisories/unreviewed/2023/11/GHSA-93g9-r9cm-chf3/GHSA-93g9-r9cm-chf3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-956p-f3rr-w9v3/GHSA-956p-f3rr-w9v3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9684-7r2w-mm28/GHSA-9684-7r2w-mm28.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9cgg-v86h-hw54/GHSA-9cgg-v86h-hw54.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9cwp-p56f-6gc5/GHSA-9cwp-p56f-6gc5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9f56-vmhf-r5vv/GHSA-9f56-vmhf-r5vv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9f83-5mc2-p75r/GHSA-9f83-5mc2-p75r.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9ghc-6jgp-h734/GHSA-9ghc-6jgp-h734.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9qfm-4g6c-76pf/GHSA-9qfm-4g6c-76pf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9wxq-3vm5-2pg9/GHSA-9wxq-3vm5-2pg9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-c7mf-mh8g-44q2/GHSA-c7mf-mh8g-44q2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-c9fc-7rjq-97gw/GHSA-c9fc-7rjq-97gw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cc87-35fp-2jp7/GHSA-cc87-35fp-2jp7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cc94-45q3-h8pp/GHSA-cc94-45q3-h8pp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cf7p-69mj-6266/GHSA-cf7p-69mj-6266.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cj6m-445x-9hgm/GHSA-cj6m-445x-9hgm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cjvm-95qv-84m2/GHSA-cjvm-95qv-84m2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cp97-6mf7-2cvp/GHSA-cp97-6mf7-2cvp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cv78-jxjg-mfgw/GHSA-cv78-jxjg-mfgw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json create mode 100644 advisories/unreviewed/2023/11/GHSA-f346-p877-7wqq/GHSA-f346-p877-7wqq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-f6cq-wc24-3mcw/GHSA-f6cq-wc24-3mcw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-f8ch-7h6r-42h6/GHSA-f8ch-7h6r-42h6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-f8rp-47c5-2crv/GHSA-f8rp-47c5-2crv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fc85-qvq2-2963/GHSA-fc85-qvq2-2963.json create mode 100644 advisories/unreviewed/2023/11/GHSA-ff49-v6jj-fh2j/GHSA-ff49-v6jj-fh2j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-ffwh-fwc7-gh76/GHSA-ffwh-fwc7-gh76.json create mode 100644 advisories/unreviewed/2023/11/GHSA-frwx-7gqv-hj3w/GHSA-frwx-7gqv-hj3w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fww3-wwgr-mqpw/GHSA-fww3-wwgr-mqpw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fx6p-v7mp-pw72/GHSA-fx6p-v7mp-pw72.json create mode 100644 advisories/unreviewed/2023/11/GHSA-g3qw-w3wp-f3m2/GHSA-g3qw-w3wp-f3m2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-g9w7-fcq8-mffw/GHSA-g9w7-fcq8-mffw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-ggrf-mj99-j57m/GHSA-ggrf-mj99-j57m.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gh94-rfj3-873r/GHSA-gh94-rfj3-873r.json create mode 100644 advisories/unreviewed/2023/11/GHSA-ghwh-356h-wcgq/GHSA-ghwh-356h-wcgq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gqwc-m2xc-gx3c/GHSA-gqwc-m2xc-gx3c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-h53x-4j3w-4vcp/GHSA-h53x-4j3w-4vcp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-h5fc-v3m2-vpp2/GHSA-h5fc-v3m2-vpp2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hgpx-7mjh-m574/GHSA-hgpx-7mjh-m574.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hq3p-78fh-v8qw/GHSA-hq3p-78fh-v8qw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hq6q-c2x6-hmch/GHSA-hq6q-c2x6-hmch.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hwv7-r8wc-xjxc/GHSA-hwv7-r8wc-xjxc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-j5vh-m963-h26r/GHSA-j5vh-m963-h26r.json create mode 100644 advisories/unreviewed/2023/11/GHSA-j8h9-q858-c787/GHSA-j8h9-q858-c787.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jgqp-37qx-xpp9/GHSA-jgqp-37qx-xpp9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jm6q-v8j6-qqwg/GHSA-jm6q-v8j6-qqwg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-m2w4-66r4-v852/GHSA-m2w4-66r4-v852.json create mode 100644 advisories/unreviewed/2023/11/GHSA-m3hg-fjqc-ww3w/GHSA-m3hg-fjqc-ww3w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-m7g3-7cq7-qj74/GHSA-m7g3-7cq7-qj74.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mfxr-7r69-92fv/GHSA-mfxr-7r69-92fv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mq3f-4x6v-59hg/GHSA-mq3f-4x6v-59hg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mx9c-3r4g-6f8m/GHSA-mx9c-3r4g-6f8m.json create mode 100644 advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json create mode 100644 advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-pjj6-9mq4-p5qc/GHSA-pjj6-9mq4-p5qc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-pr3w-9h6r-g7j3/GHSA-pr3w-9h6r-g7j3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-pv77-783w-qwjw/GHSA-pv77-783w-qwjw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-px59-5w52-jv25/GHSA-px59-5w52-jv25.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q57g-38pc-jwv8/GHSA-q57g-38pc-jwv8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q69f-x478-xp8g/GHSA-q69f-x478-xp8g.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q6w8-c6j3-wwc9/GHSA-q6w8-c6j3-wwc9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q84m-vxmr-72ph/GHSA-q84m-vxmr-72ph.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qc67-fv9p-fpx5/GHSA-qc67-fv9p-fpx5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qf8h-hpq5-hc5h/GHSA-qf8h-hpq5-hc5h.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qp5j-mmrp-vj4f/GHSA-qp5j-mmrp-vj4f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qphr-6rj3-crfc/GHSA-qphr-6rj3-crfc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qpw8-mj26-5rc9/GHSA-qpw8-mj26-5rc9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qvg6-x224-c55m/GHSA-qvg6-x224-c55m.json create mode 100644 advisories/unreviewed/2023/11/GHSA-r2mq-3mfq-2p2w/GHSA-r2mq-3mfq-2p2w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-r322-c8vr-qgrp/GHSA-r322-c8vr-qgrp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-r4ch-3qw4-35q9/GHSA-r4ch-3qw4-35q9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rcxc-fhh3-qjq9/GHSA-rcxc-fhh3-qjq9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rh5g-pqg8-7p3x/GHSA-rh5g-pqg8-7p3x.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rp4j-f7fp-cgf2/GHSA-rp4j-f7fp-cgf2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rqj6-65x2-r2vh/GHSA-rqj6-65x2-r2vh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rv6j-6cr4-gr5q/GHSA-rv6j-6cr4-gr5q.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v2hc-cp84-vjqv/GHSA-v2hc-cp84-vjqv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v325-cfqv-359p/GHSA-v325-cfqv-359p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v3gh-c2m2-h84q/GHSA-v3gh-c2m2-h84q.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v4fc-x53w-j3j2/GHSA-v4fc-x53w-j3j2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v5x9-p45c-rxpc/GHSA-v5x9-p45c-rxpc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-vxpv-jc8r-m85p/GHSA-vxpv-jc8r-m85p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w369-f878-vgmj/GHSA-w369-f878-vgmj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w499-v3vm-68xq/GHSA-w499-v3vm-68xq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w4pv-p6xf-qc53/GHSA-w4pv-p6xf-qc53.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w7qf-3h78-55fp/GHSA-w7qf-3h78-55fp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w8c8-x4x9-r382/GHSA-w8c8-x4x9-r382.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w8wr-v3q8-68hg/GHSA-w8wr-v3q8-68hg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wfc8-v3hg-jvrw/GHSA-wfc8-v3hg-jvrw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wh4j-r7mv-vjg8/GHSA-wh4j-r7mv-vjg8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wrgh-9hfh-4fqj/GHSA-wrgh-9hfh-4fqj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wrv4-h8m2-2rj7/GHSA-wrv4-h8m2-2rj7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wvq7-fmcr-mvgx/GHSA-wvq7-fmcr-mvgx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x45c-39pv-5956/GHSA-x45c-39pv-5956.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x4wr-fpxp-h8c3/GHSA-x4wr-fpxp-h8c3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x6h4-x9x4-vf9g/GHSA-x6h4-x9x4-vf9g.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x8q6-xr39-6p4c/GHSA-x8q6-xr39-6p4c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x935-fw35-6fjh/GHSA-x935-fw35-6fjh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x9c2-rmrg-4h96/GHSA-x9c2-rmrg-4h96.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xj2m-wgjq-qpmc/GHSA-xj2m-wgjq-qpmc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xmm7-2j6p-p24v/GHSA-xmm7-2j6p-p24v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xrh2-77qw-v55j/GHSA-xrh2-77qw-v55j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xxvq-wr93-6r58/GHSA-xxvq-wr93-6r58.json diff --git a/advisories/unreviewed/2021/12/GHSA-pmgm-pv8c-pw29/GHSA-pmgm-pv8c-pw29.json b/advisories/unreviewed/2021/12/GHSA-pmgm-pv8c-pw29/GHSA-pmgm-pv8c-pw29.json index 1961b68d58e..8f8b8bab1d2 100644 --- a/advisories/unreviewed/2021/12/GHSA-pmgm-pv8c-pw29/GHSA-pmgm-pv8c-pw29.json +++ b/advisories/unreviewed/2021/12/GHSA-pmgm-pv8c-pw29/GHSA-pmgm-pv8c-pw29.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pmgm-pv8c-pw29", - "modified": "2021-12-23T00:01:54Z", + "modified": "2023-11-14T21:30:47Z", "published": "2021-12-17T00:00:23Z", "aliases": [ "CVE-2021-44315" ], "details": "In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2021/12/GHSA-ppr5-jp7h-pvxj/GHSA-ppr5-jp7h-pvxj.json b/advisories/unreviewed/2021/12/GHSA-ppr5-jp7h-pvxj/GHSA-ppr5-jp7h-pvxj.json index 922a2472ab8..f3fcf4c856c 100644 --- a/advisories/unreviewed/2021/12/GHSA-ppr5-jp7h-pvxj/GHSA-ppr5-jp7h-pvxj.json +++ b/advisories/unreviewed/2021/12/GHSA-ppr5-jp7h-pvxj/GHSA-ppr5-jp7h-pvxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppr5-jp7h-pvxj", - "modified": "2021-12-23T00:01:53Z", + "modified": "2023-11-14T21:30:48Z", "published": "2021-12-17T00:00:23Z", "aliases": [ "CVE-2021-44317" ], "details": "In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-2vrv-3jr5-rv6c/GHSA-2vrv-3jr5-rv6c.json b/advisories/unreviewed/2022/05/GHSA-2vrv-3jr5-rv6c/GHSA-2vrv-3jr5-rv6c.json index 9b4d9531532..dcbe43f76c2 100644 --- a/advisories/unreviewed/2022/05/GHSA-2vrv-3jr5-rv6c/GHSA-2vrv-3jr5-rv6c.json +++ b/advisories/unreviewed/2022/05/GHSA-2vrv-3jr5-rv6c/GHSA-2vrv-3jr5-rv6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vrv-3jr5-rv6c", - "modified": "2022-05-24T19:17:22Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T19:17:22Z", "aliases": [ "CVE-2021-42224" ], "details": "SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-4v9x-j7pr-8wxq/GHSA-4v9x-j7pr-8wxq.json b/advisories/unreviewed/2022/05/GHSA-4v9x-j7pr-8wxq/GHSA-4v9x-j7pr-8wxq.json index 3438ae8cb17..75aa44c9edd 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v9x-j7pr-8wxq/GHSA-4v9x-j7pr-8wxq.json +++ b/advisories/unreviewed/2022/05/GHSA-4v9x-j7pr-8wxq/GHSA-4v9x-j7pr-8wxq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-77jf-5mcg-g6m9/GHSA-77jf-5mcg-g6m9.json b/advisories/unreviewed/2022/05/GHSA-77jf-5mcg-g6m9/GHSA-77jf-5mcg-g6m9.json index 5cb4feef7ec..5ffa6c2f401 100644 --- a/advisories/unreviewed/2022/05/GHSA-77jf-5mcg-g6m9/GHSA-77jf-5mcg-g6m9.json +++ b/advisories/unreviewed/2022/05/GHSA-77jf-5mcg-g6m9/GHSA-77jf-5mcg-g6m9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77jf-5mcg-g6m9", - "modified": "2022-05-24T17:47:45Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:47:45Z", "aliases": [ "CVE-2020-2509" ], "details": "A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-c38v-5prm-vhjx/GHSA-c38v-5prm-vhjx.json b/advisories/unreviewed/2022/05/GHSA-c38v-5prm-vhjx/GHSA-c38v-5prm-vhjx.json index 2a91f96b00a..194cf09ab38 100644 --- a/advisories/unreviewed/2022/05/GHSA-c38v-5prm-vhjx/GHSA-c38v-5prm-vhjx.json +++ b/advisories/unreviewed/2022/05/GHSA-c38v-5prm-vhjx/GHSA-c38v-5prm-vhjx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c38v-5prm-vhjx", - "modified": "2022-05-24T19:17:23Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T19:17:23Z", "aliases": [ "CVE-2021-42223" ], "details": "Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-cj8c-4h22-g2gj/GHSA-cj8c-4h22-g2gj.json b/advisories/unreviewed/2022/05/GHSA-cj8c-4h22-g2gj/GHSA-cj8c-4h22-g2gj.json index c821a7712bd..3346eba85c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-cj8c-4h22-g2gj/GHSA-cj8c-4h22-g2gj.json +++ b/advisories/unreviewed/2022/05/GHSA-cj8c-4h22-g2gj/GHSA-cj8c-4h22-g2gj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cj8c-4h22-g2gj", - "modified": "2022-05-24T17:28:59Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:28:59Z", "aliases": [ "CVE-2020-25487" ], "details": "PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-cpw5-f693-2r28/GHSA-cpw5-f693-2r28.json b/advisories/unreviewed/2022/05/GHSA-cpw5-f693-2r28/GHSA-cpw5-f693-2r28.json index 9a7b27ab808..3178ddfc945 100644 --- a/advisories/unreviewed/2022/05/GHSA-cpw5-f693-2r28/GHSA-cpw5-f693-2r28.json +++ b/advisories/unreviewed/2022/05/GHSA-cpw5-f693-2r28/GHSA-cpw5-f693-2r28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpw5-f693-2r28", - "modified": "2022-05-24T17:37:06Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:37:06Z", "aliases": [ "CVE-2020-35151" ], "details": "The Online Marriage Registration System 1.0 post parameter \"searchdata\" in the user/search.php request is vulnerable to Time Based Sql Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-fvqh-qwm3-5j87/GHSA-fvqh-qwm3-5j87.json b/advisories/unreviewed/2022/05/GHSA-fvqh-qwm3-5j87/GHSA-fvqh-qwm3-5j87.json index 75a81d1de11..7dff8365d38 100644 --- a/advisories/unreviewed/2022/05/GHSA-fvqh-qwm3-5j87/GHSA-fvqh-qwm3-5j87.json +++ b/advisories/unreviewed/2022/05/GHSA-fvqh-qwm3-5j87/GHSA-fvqh-qwm3-5j87.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fvqh-qwm3-5j87", - "modified": "2022-05-24T17:42:16Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:42:16Z", "aliases": [ "CVE-2021-26822" ], "details": "Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-jx9p-jf7x-8rr2/GHSA-jx9p-jf7x-8rr2.json b/advisories/unreviewed/2022/05/GHSA-jx9p-jf7x-8rr2/GHSA-jx9p-jf7x-8rr2.json index d775116d0a7..9a9ab99502e 100644 --- a/advisories/unreviewed/2022/05/GHSA-jx9p-jf7x-8rr2/GHSA-jx9p-jf7x-8rr2.json +++ b/advisories/unreviewed/2022/05/GHSA-jx9p-jf7x-8rr2/GHSA-jx9p-jf7x-8rr2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jx9p-jf7x-8rr2", - "modified": "2022-05-24T17:35:56Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:35:56Z", "aliases": [ "CVE-2020-2494" ], "details": "This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-m7vg-3vj5-h86f/GHSA-m7vg-3vj5-h86f.json b/advisories/unreviewed/2022/05/GHSA-m7vg-3vj5-h86f/GHSA-m7vg-3vj5-h86f.json index d29de7f040d..39c303f6f48 100644 --- a/advisories/unreviewed/2022/05/GHSA-m7vg-3vj5-h86f/GHSA-m7vg-3vj5-h86f.json +++ b/advisories/unreviewed/2022/05/GHSA-m7vg-3vj5-h86f/GHSA-m7vg-3vj5-h86f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m7vg-3vj5-h86f", - "modified": "2022-05-24T17:35:56Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:35:56Z", "aliases": [ "CVE-2020-2498" ], "details": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-pmpw-4q9q-8w52/GHSA-pmpw-4q9q-8w52.json b/advisories/unreviewed/2022/05/GHSA-pmpw-4q9q-8w52/GHSA-pmpw-4q9q-8w52.json index b80e39af507..eabe30d5f51 100644 --- a/advisories/unreviewed/2022/05/GHSA-pmpw-4q9q-8w52/GHSA-pmpw-4q9q-8w52.json +++ b/advisories/unreviewed/2022/05/GHSA-pmpw-4q9q-8w52/GHSA-pmpw-4q9q-8w52.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1816" }, + { + "type": "WEB", + "url": "https://github.com/Xor-Gerke/webray.com.cn/blob/main/cve/Zoo-Management-System/Zoo-Management-System%28XSS%29.md" + }, { "type": "WEB", "url": "https://github.com/Xor-Gerke/webray.com.cn/blob/main/cve/Zoo-Management-System/Zoo-Management-System(XSS).md" diff --git a/advisories/unreviewed/2022/05/GHSA-w463-hpv4-95pw/GHSA-w463-hpv4-95pw.json b/advisories/unreviewed/2022/05/GHSA-w463-hpv4-95pw/GHSA-w463-hpv4-95pw.json index 6bcc0003335..977e334d82a 100644 --- a/advisories/unreviewed/2022/05/GHSA-w463-hpv4-95pw/GHSA-w463-hpv4-95pw.json +++ b/advisories/unreviewed/2022/05/GHSA-w463-hpv4-95pw/GHSA-w463-hpv4-95pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w463-hpv4-95pw", - "modified": "2022-05-24T19:06:42Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T19:06:42Z", "aliases": [ "CVE-2021-28423" ], "details": "Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-w962-fvxv-mrr4/GHSA-w962-fvxv-mrr4.json b/advisories/unreviewed/2022/05/GHSA-w962-fvxv-mrr4/GHSA-w962-fvxv-mrr4.json index 6bfc0ee6892..ccc3c352c94 100644 --- a/advisories/unreviewed/2022/05/GHSA-w962-fvxv-mrr4/GHSA-w962-fvxv-mrr4.json +++ b/advisories/unreviewed/2022/05/GHSA-w962-fvxv-mrr4/GHSA-w962-fvxv-mrr4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w962-fvxv-mrr4", - "modified": "2022-05-24T17:41:16Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T17:41:16Z", "aliases": [ "CVE-2020-26052" ], "details": "Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-x62f-6xhh-g5fp/GHSA-x62f-6xhh-g5fp.json b/advisories/unreviewed/2022/05/GHSA-x62f-6xhh-g5fp/GHSA-x62f-6xhh-g5fp.json index 99ecdb8795a..af1b983ee94 100644 --- a/advisories/unreviewed/2022/05/GHSA-x62f-6xhh-g5fp/GHSA-x62f-6xhh-g5fp.json +++ b/advisories/unreviewed/2022/05/GHSA-x62f-6xhh-g5fp/GHSA-x62f-6xhh-g5fp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x62f-6xhh-g5fp", - "modified": "2022-05-24T19:06:42Z", + "modified": "2023-11-14T21:30:47Z", "published": "2022-05-24T19:06:42Z", "aliases": [ "CVE-2021-28424" ], "details": "A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/08/GHSA-2hf7-qg9c-qf4h/GHSA-2hf7-qg9c-qf4h.json b/advisories/unreviewed/2022/08/GHSA-2hf7-qg9c-qf4h/GHSA-2hf7-qg9c-qf4h.json index ef46f97deff..bbc0a7aaab4 100644 --- a/advisories/unreviewed/2022/08/GHSA-2hf7-qg9c-qf4h/GHSA-2hf7-qg9c-qf4h.json +++ b/advisories/unreviewed/2022/08/GHSA-2hf7-qg9c-qf4h/GHSA-2hf7-qg9c-qf4h.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot" }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html" + }, { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/309662" diff --git a/advisories/unreviewed/2022/08/GHSA-77q2-m9gq-g982/GHSA-77q2-m9gq-g982.json b/advisories/unreviewed/2022/08/GHSA-77q2-m9gq-g982/GHSA-77q2-m9gq-g982.json index ea98712c88d..e0c692cac21 100644 --- a/advisories/unreviewed/2022/08/GHSA-77q2-m9gq-g982/GHSA-77q2-m9gq-g982.json +++ b/advisories/unreviewed/2022/08/GHSA-77q2-m9gq-g982/GHSA-77q2-m9gq-g982.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot" }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html" + }, { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/309662" diff --git a/advisories/unreviewed/2022/08/GHSA-7j33-663j-fx7f/GHSA-7j33-663j-fx7f.json b/advisories/unreviewed/2022/08/GHSA-7j33-663j-fx7f/GHSA-7j33-663j-fx7f.json index d2f62929ba5..e96f51566e6 100644 --- a/advisories/unreviewed/2022/08/GHSA-7j33-663j-fx7f/GHSA-7j33-663j-fx7f.json +++ b/advisories/unreviewed/2022/08/GHSA-7j33-663j-fx7f/GHSA-7j33-663j-fx7f.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot" }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html" + }, { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/309662" diff --git a/advisories/unreviewed/2022/11/GHSA-9r4w-694r-fm3f/GHSA-9r4w-694r-fm3f.json b/advisories/unreviewed/2022/11/GHSA-9r4w-694r-fm3f/GHSA-9r4w-694r-fm3f.json index 6e9b998c9d5..838235a7cb1 100644 --- a/advisories/unreviewed/2022/11/GHSA-9r4w-694r-fm3f/GHSA-9r4w-694r-fm3f.json +++ b/advisories/unreviewed/2022/11/GHSA-9r4w-694r-fm3f/GHSA-9r4w-694r-fm3f.json @@ -24,11 +24,16 @@ { "type": "WEB", "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00747.html" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" } ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-277" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-vh59-rfvm-xwqw/GHSA-vh59-rfvm-xwqw.json b/advisories/unreviewed/2023/05/GHSA-vh59-rfvm-xwqw/GHSA-vh59-rfvm-xwqw.json index c2b5d051079..233b99a71bf 100644 --- a/advisories/unreviewed/2023/05/GHSA-vh59-rfvm-xwqw/GHSA-vh59-rfvm-xwqw.json +++ b/advisories/unreviewed/2023/05/GHSA-vh59-rfvm-xwqw/GHSA-vh59-rfvm-xwqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vh59-rfvm-xwqw", - "modified": "2023-05-26T21:30:22Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-05-23T15:30:29Z", "aliases": [ "CVE-2023-33338" @@ -30,7 +30,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-23T13:15:09Z" diff --git a/advisories/unreviewed/2023/07/GHSA-2764-3pqr-49w6/GHSA-2764-3pqr-49w6.json b/advisories/unreviewed/2023/07/GHSA-2764-3pqr-49w6/GHSA-2764-3pqr-49w6.json index 013f5769576..9fc4c5cf2df 100644 --- a/advisories/unreviewed/2023/07/GHSA-2764-3pqr-49w6/GHSA-2764-3pqr-49w6.json +++ b/advisories/unreviewed/2023/07/GHSA-2764-3pqr-49w6/GHSA-2764-3pqr-49w6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2764-3pqr-49w6", - "modified": "2023-07-24T18:30:44Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-24T18:30:44Z", "aliases": [ "CVE-2023-33951" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33951" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6583" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7077" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-33951" @@ -36,9 +48,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-24T16:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json b/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json index 1b810436521..df2b36f82b3 100644 --- a/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json +++ b/advisories/unreviewed/2023/07/GHSA-45c7-642q-qm9m/GHSA-45c7-642q-qm9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45c7-642q-qm9m", - "modified": "2023-07-20T18:33:43Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-20T18:33:43Z", "aliases": [ "CVE-2023-34966" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34966" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6667" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7139" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34966" @@ -29,6 +37,22 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2222793" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230731-0010/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5477" + }, { "type": "WEB", "url": "https://www.samba.org/samba/security/CVE-2023-34966" @@ -36,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-20T15:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json b/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json index df54c8ce016..1986f53ca0e 100644 --- a/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json +++ b/advisories/unreviewed/2023/07/GHSA-7x98-4rw8-872g/GHSA-7x98-4rw8-872g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x98-4rw8-872g", - "modified": "2023-10-20T00:30:24Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-25T18:30:32Z", "aliases": [ "CVE-2023-3772" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3772" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6583" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7077" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3772" @@ -50,7 +62,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-25T16:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json b/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json index 6edf543c210..31af724d7cc 100644 --- a/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json +++ b/advisories/unreviewed/2023/07/GHSA-86p4-vhr6-2vv3/GHSA-86p4-vhr6-2vv3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86p4-vhr6-2vv3", - "modified": "2023-07-20T18:33:43Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-20T18:33:43Z", "aliases": [ "CVE-2023-34967" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34967" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6667" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7139" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34967" @@ -29,6 +37,22 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2222794" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230731-0010/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5477" + }, { "type": "WEB", "url": "https://www.samba.org/samba/security/CVE-2023-34967.html" @@ -36,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-843" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-20T15:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-8f4h-wr7j-w67m/GHSA-8f4h-wr7j-w67m.json b/advisories/unreviewed/2023/07/GHSA-8f4h-wr7j-w67m/GHSA-8f4h-wr7j-w67m.json index 20360954af0..ac357d1ac51 100644 --- a/advisories/unreviewed/2023/07/GHSA-8f4h-wr7j-w67m/GHSA-8f4h-wr7j-w67m.json +++ b/advisories/unreviewed/2023/07/GHSA-8f4h-wr7j-w67m/GHSA-8f4h-wr7j-w67m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f4h-wr7j-w67m", - "modified": "2023-07-24T18:30:44Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-24T18:30:44Z", "aliases": [ "CVE-2023-33952" @@ -21,6 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33952" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6583" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7077" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-33952" @@ -38,7 +50,7 @@ "cwe_ids": [ "CWE-415" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-24T16:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json b/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json index 7147daae351..c6f2eb3a8e7 100644 --- a/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json +++ b/advisories/unreviewed/2023/07/GHSA-cfhp-p6xr-24g5/GHSA-cfhp-p6xr-24g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfhp-p6xr-24g5", - "modified": "2023-07-20T18:33:43Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-20T18:33:43Z", "aliases": [ "CVE-2023-34968" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34968" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6667" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7139" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-34968" @@ -29,6 +37,22 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2222795" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230731-0010/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5477" + }, { "type": "WEB", "url": "https://www.samba.org/samba/security/CVE-2023-34968.html" @@ -38,7 +62,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-20T15:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json b/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json index a852bd94869..ba2277dbd05 100644 --- a/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json +++ b/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fcmj-gcwc-rvc5", - "modified": "2023-07-10T18:30:50Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-10T18:30:50Z", "aliases": [ "CVE-2023-36940" ], "details": "Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36940" }, + { + "type": "WEB", + "url": "https://medium.com/%40ridheshgohil1092/cve-2023-36940-xss-on-online-fire-reporting-system-v-1-2-1d3fa170e4d6" + }, { "type": "WEB", "url": "https://medium.com/@ridheshgohil1092/cve-2023-36940-xss-on-online-fire-reporting-system-v-1-2-1d3fa170e4d6" @@ -29,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-10T18:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json b/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json index c75809da5ba..ebac24aacf2 100644 --- a/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json +++ b/advisories/unreviewed/2023/07/GHSA-mfwc-hx97-869v/GHSA-mfwc-hx97-869v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfwc-hx97-869v", - "modified": "2023-07-20T18:33:43Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-20T18:33:43Z", "aliases": [ "CVE-2022-2127" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2127" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6667" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7139" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2022-2127" @@ -41,6 +49,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230731-0010/" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5477" + }, { "type": "WEB", "url": "https://www.samba.org/samba/security/CVE-2022-2127.html" @@ -50,7 +62,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-20T15:15:11Z" diff --git a/advisories/unreviewed/2023/07/GHSA-qrwf-www2-hr3h/GHSA-qrwf-www2-hr3h.json b/advisories/unreviewed/2023/07/GHSA-qrwf-www2-hr3h/GHSA-qrwf-www2-hr3h.json index 5db133337b1..619a73ca8cf 100644 --- a/advisories/unreviewed/2023/07/GHSA-qrwf-www2-hr3h/GHSA-qrwf-www2-hr3h.json +++ b/advisories/unreviewed/2023/07/GHSA-qrwf-www2-hr3h/GHSA-qrwf-www2-hr3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrwf-www2-hr3h", - "modified": "2023-08-03T15:30:28Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-27T21:30:22Z", "aliases": [ "CVE-2023-36942" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36942" }, + { + "type": "WEB", + "url": "https://medium.com/%40ridheshgohil1092/cve-2023-36942-xss-on-online-fire-reporting-system-v-1-2-19357e54978c" + }, { "type": "WEB", "url": "https://medium.com/@ridheshgohil1092/cve-2023-36942-xss-on-online-fire-reporting-system-v-1-2-19357e54978c" @@ -34,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-27T20:15:10Z" diff --git a/advisories/unreviewed/2023/07/GHSA-wpvc-538m-c48m/GHSA-wpvc-538m-c48m.json b/advisories/unreviewed/2023/07/GHSA-wpvc-538m-c48m/GHSA-wpvc-538m-c48m.json index ff2de30341a..c6211bfcbdd 100644 --- a/advisories/unreviewed/2023/07/GHSA-wpvc-538m-c48m/GHSA-wpvc-538m-c48m.json +++ b/advisories/unreviewed/2023/07/GHSA-wpvc-538m-c48m/GHSA-wpvc-538m-c48m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wpvc-538m-c48m", - "modified": "2023-08-03T15:30:28Z", + "modified": "2023-11-14T21:30:49Z", "published": "2023-07-27T18:30:35Z", "aliases": [ "CVE-2023-36941" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36941" }, + { + "type": "WEB", + "url": "https://medium.com/%40ridheshgohil1092/cve-2023-36941-xss-on-online-fire-reporting-system-v-1-2-df84d7ac3fd1" + }, { "type": "WEB", "url": "https://medium.com/@ridheshgohil1092/cve-2023-36941-xss-on-online-fire-reporting-system-v-1-2-df84d7ac3fd1" @@ -34,7 +38,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-27T18:15:10Z" diff --git a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json index a42a87c7f88..173f43c3454 100644 --- a/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json +++ b/advisories/unreviewed/2023/08/GHSA-897q-36v3-jwhm/GHSA-897q-36v3-jwhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-897q-36v3-jwhm", - "modified": "2023-08-03T18:30:35Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-08-03T18:30:35Z", "aliases": [ "CVE-2023-4132" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4132" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7077" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4132" @@ -50,7 +58,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-03T15:15:32Z" diff --git a/advisories/unreviewed/2023/08/GHSA-jgj3-64jr-4g3x/GHSA-jgj3-64jr-4g3x.json b/advisories/unreviewed/2023/08/GHSA-jgj3-64jr-4g3x/GHSA-jgj3-64jr-4g3x.json index 975f349ea73..1ed8b3c0c36 100644 --- a/advisories/unreviewed/2023/08/GHSA-jgj3-64jr-4g3x/GHSA-jgj3-64jr-4g3x.json +++ b/advisories/unreviewed/2023/08/GHSA-jgj3-64jr-4g3x/GHSA-jgj3-64jr-4g3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jgj3-64jr-4g3x", - "modified": "2023-08-23T15:30:51Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-08-23T15:30:51Z", "aliases": [ "CVE-2023-4042" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4042" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7053" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4042" @@ -36,9 +40,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-23T13:15:07Z" diff --git a/advisories/unreviewed/2023/08/GHSA-v34c-9rwg-qpf6/GHSA-v34c-9rwg-qpf6.json b/advisories/unreviewed/2023/08/GHSA-v34c-9rwg-qpf6/GHSA-v34c-9rwg-qpf6.json index 07ccad67fc5..7faf8db0cfc 100644 --- a/advisories/unreviewed/2023/08/GHSA-v34c-9rwg-qpf6/GHSA-v34c-9rwg-qpf6.json +++ b/advisories/unreviewed/2023/08/GHSA-v34c-9rwg-qpf6/GHSA-v34c-9rwg-qpf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v34c-9rwg-qpf6", - "modified": "2023-08-01T18:30:27Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-08-01T18:30:27Z", "aliases": [ "CVE-2023-38559" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38559" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6544" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7053" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-38559" @@ -52,9 +60,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-08-01T17:15:09Z" diff --git a/advisories/unreviewed/2023/09/GHSA-5w38-f33m-gcr8/GHSA-5w38-f33m-gcr8.json b/advisories/unreviewed/2023/09/GHSA-5w38-f33m-gcr8/GHSA-5w38-f33m-gcr8.json index ff3ab76fc5d..d278ad6a57b 100644 --- a/advisories/unreviewed/2023/09/GHSA-5w38-f33m-gcr8/GHSA-5w38-f33m-gcr8.json +++ b/advisories/unreviewed/2023/09/GHSA-5w38-f33m-gcr8/GHSA-5w38-f33m-gcr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5w38-f33m-gcr8", - "modified": "2023-09-23T00:30:40Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-09-22T00:30:29Z", "aliases": [ "CVE-2023-41614" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41614" }, + { + "type": "WEB", + "url": "https://medium.com/%40guravtushar231/stored-xss-in-admin-panel-a38d1feb9ec4" + }, { "type": "WEB", "url": "https://medium.com/@guravtushar231/stored-xss-in-admin-panel-a38d1feb9ec4" @@ -30,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-21T23:15:09Z" diff --git a/advisories/unreviewed/2023/09/GHSA-q77f-64gj-7q7p/GHSA-q77f-64gj-7q7p.json b/advisories/unreviewed/2023/09/GHSA-q77f-64gj-7q7p/GHSA-q77f-64gj-7q7p.json index cc60416a238..5f29b44c872 100644 --- a/advisories/unreviewed/2023/09/GHSA-q77f-64gj-7q7p/GHSA-q77f-64gj-7q7p.json +++ b/advisories/unreviewed/2023/09/GHSA-q77f-64gj-7q7p/GHSA-q77f-64gj-7q7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q77f-64gj-7q7p", - "modified": "2023-09-12T15:30:20Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-09-08T03:30:21Z", "aliases": [ "CVE-2023-41615" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41615" }, + { + "type": "WEB", + "url": "https://medium.com/%40guravtushar231/sql-injection-in-login-field-a9073780f7e8" + }, { "type": "WEB", "url": "https://medium.com/@guravtushar231/sql-injection-in-login-field-a9073780f7e8" @@ -38,7 +42,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-08T03:15:09Z" diff --git a/advisories/unreviewed/2023/10/GHSA-c9mw-vpxm-p7rq/GHSA-c9mw-vpxm-p7rq.json b/advisories/unreviewed/2023/10/GHSA-c9mw-vpxm-p7rq/GHSA-c9mw-vpxm-p7rq.json index 2defc71550c..bfa65f84ca3 100644 --- a/advisories/unreviewed/2023/10/GHSA-c9mw-vpxm-p7rq/GHSA-c9mw-vpxm-p7rq.json +++ b/advisories/unreviewed/2023/10/GHSA-c9mw-vpxm-p7rq/GHSA-c9mw-vpxm-p7rq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9mw-vpxm-p7rq", - "modified": "2023-10-03T18:30:23Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-10-03T18:30:23Z", "aliases": [ "CVE-2023-4732" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4732" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7077" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-4732" @@ -32,9 +40,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-362" + "CWE-362", + "CWE-366" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-03T17:15:09Z" diff --git a/advisories/unreviewed/2023/10/GHSA-r6w9-hpm6-f3mf/GHSA-r6w9-hpm6-f3mf.json b/advisories/unreviewed/2023/10/GHSA-r6w9-hpm6-f3mf/GHSA-r6w9-hpm6-f3mf.json index 2402e9f4b9e..4e238c4319d 100644 --- a/advisories/unreviewed/2023/10/GHSA-r6w9-hpm6-f3mf/GHSA-r6w9-hpm6-f3mf.json +++ b/advisories/unreviewed/2023/10/GHSA-r6w9-hpm6-f3mf/GHSA-r6w9-hpm6-f3mf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r6w9-hpm6-f3mf", - "modified": "2023-10-26T15:30:27Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-10-26T15:30:27Z", "aliases": [ "CVE-2023-45867" ], "details": "ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially retrieve confidential files stored on the web server. The attacker can access files that are readable by the web server user www-data; this may include sensitive configuration files and documents located outside the documentRoot. The vulnerability is exploited by an attacker who manipulates the file parameter in a URL, inserting directory traversal sequences in order to access unauthorized files. This manipulation allows the attacker to retrieve sensitive files, such as /etc/passwd, potentially compromising the system's security. This issue poses a significant risk to confidentiality and is remotely exploitable over the internet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-26T15:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-24mv-46g6-jv5x/GHSA-24mv-46g6-jv5x.json b/advisories/unreviewed/2023/11/GHSA-24mv-46g6-jv5x/GHSA-24mv-46g6-jv5x.json new file mode 100644 index 00000000000..8fcde4508ea --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-24mv-46g6-jv5x/GHSA-24mv-46g6-jv5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24mv-46g6-jv5x", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42542" + ], + "details": "Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42542" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-262p-h3cm-wwv8/GHSA-262p-h3cm-wwv8.json b/advisories/unreviewed/2023/11/GHSA-262p-h3cm-wwv8/GHSA-262p-h3cm-wwv8.json new file mode 100644 index 00000000000..236518276ac --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-262p-h3cm-wwv8/GHSA-262p-h3cm-wwv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-262p-h3cm-wwv8", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-31203" + ], + "details": "Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31203" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00901.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-279v-q4q9-mx7j/GHSA-279v-q4q9-mx7j.json b/advisories/unreviewed/2023/11/GHSA-279v-q4q9-mx7j/GHSA-279v-q4q9-mx7j.json new file mode 100644 index 00000000000..92e984b8fc8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-279v-q4q9-mx7j/GHSA-279v-q4q9-mx7j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-279v-q4q9-mx7j", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-27306" + ], + "details": "Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27306" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00758.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2fpj-cv6p-p352/GHSA-2fpj-cv6p-p352.json b/advisories/unreviewed/2023/11/GHSA-2fpj-cv6p-p352/GHSA-2fpj-cv6p-p352.json new file mode 100644 index 00000000000..26ac2933277 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2fpj-cv6p-p352/GHSA-2fpj-cv6p-p352.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fpj-cv6p-p352", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47384" + ], + "details": "MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47384" + }, + { + "type": "WEB", + "url": "https://github.com/gpac/gpac/issues/2672" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2gmf-mp9h-g5xw/GHSA-2gmf-mp9h-g5xw.json b/advisories/unreviewed/2023/11/GHSA-2gmf-mp9h-g5xw/GHSA-2gmf-mp9h-g5xw.json new file mode 100644 index 00000000000..ad25a524e62 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2gmf-mp9h-g5xw/GHSA-2gmf-mp9h-g5xw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gmf-mp9h-g5xw", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-40540" + ], + "details": "Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40540" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1303" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2jf9-9rxc-j63c/GHSA-2jf9-9rxc-j63c.json b/advisories/unreviewed/2023/11/GHSA-2jf9-9rxc-j63c/GHSA-2jf9-9rxc-j63c.json new file mode 100644 index 00000000000..cdec57de307 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2jf9-9rxc-j63c/GHSA-2jf9-9rxc-j63c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jf9-9rxc-j63c", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-41723" + ], + "details": "A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41723" + }, + { + "type": "WEB", + "url": "https://www.veeam.com/kb4508" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json b/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json new file mode 100644 index 00000000000..177adf2e7fa --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2wh3-v786-vq3m/GHSA-2wh3-v786-vq3m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wh3-v786-vq3m", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-47455" + ], + "details": "Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47455" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1806/setSchedWifi.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-34r6-9vgg-pmh3/GHSA-34r6-9vgg-pmh3.json b/advisories/unreviewed/2023/11/GHSA-34r6-9vgg-pmh3/GHSA-34r6-9vgg-pmh3.json new file mode 100644 index 00000000000..71949295cd4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-34r6-9vgg-pmh3/GHSA-34r6-9vgg-pmh3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34r6-9vgg-pmh3", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5709" + ], + "details": "The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5709" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/widget-twitter/trunk/twitter.php?rev=2212825#L161" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86cdbfec-b1af-48ec-ae70-f97768694e44?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json b/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json new file mode 100644 index 00000000000..cad0ace5d21 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-34xr-h92c-2m86/GHSA-34xr-h92c-2m86.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34xr-h92c-2m86", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2021-46766" + ], + "details": "Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46766" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-35qw-3m24-r2j5/GHSA-35qw-3m24-r2j5.json b/advisories/unreviewed/2023/11/GHSA-35qw-3m24-r2j5/GHSA-35qw-3m24-r2j5.json new file mode 100644 index 00000000000..42fc8832cdb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-35qw-3m24-r2j5/GHSA-35qw-3m24-r2j5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35qw-3m24-r2j5", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-24587" + ], + "details": "Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24587" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00758.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-691" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3744-988x-mqxh/GHSA-3744-988x-mqxh.json b/advisories/unreviewed/2023/11/GHSA-3744-988x-mqxh/GHSA-3744-988x-mqxh.json new file mode 100644 index 00000000000..dc1e9d360a7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3744-988x-mqxh/GHSA-3744-988x-mqxh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3744-988x-mqxh", + "modified": "2023-11-14T21:30:51Z", + "published": "2023-11-14T21:30:51Z", + "aliases": [ + "CVE-2023-5748" + ], + "details": "Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5748" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_23_12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T04:24:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-37p9-3q24-hgrc/GHSA-37p9-3q24-hgrc.json b/advisories/unreviewed/2023/11/GHSA-37p9-3q24-hgrc/GHSA-37p9-3q24-hgrc.json new file mode 100644 index 00000000000..6219650c3c5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-37p9-3q24-hgrc/GHSA-37p9-3q24-hgrc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37p9-3q24-hgrc", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-5567" + ], + "details": "The QR Code Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'qrcodetag' shortcode in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5567" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/qr-code-tag/trunk/lib/qrct/QrctWp.php?rev=1705525#L369" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be004002-a3ac-46e9-b0c1-258f05f97b2a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-39p9-mvxq-x2gf/GHSA-39p9-mvxq-x2gf.json b/advisories/unreviewed/2023/11/GHSA-39p9-mvxq-x2gf/GHSA-39p9-mvxq-x2gf.json new file mode 100644 index 00000000000..90c22dba260 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-39p9-mvxq-x2gf/GHSA-39p9-mvxq-x2gf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39p9-mvxq-x2gf", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-34430" + ], + "details": "Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34430" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00843.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-39w8-7xg4-7fr5/GHSA-39w8-7xg4-7fr5.json b/advisories/unreviewed/2023/11/GHSA-39w8-7xg4-7fr5/GHSA-39w8-7xg4-7fr5.json new file mode 100644 index 00000000000..2523c3079d1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-39w8-7xg4-7fr5/GHSA-39w8-7xg4-7fr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39w8-7xg4-7fr5", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25075" + ], + "details": "Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25075" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00925.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json b/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json index 70ab3e0335a..9785fc289ce 100644 --- a/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json +++ b/advisories/unreviewed/2023/11/GHSA-3cfv-7x3j-7m2c/GHSA-3cfv-7x3j-7m2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cfv-7x3j-7m2c", - "modified": "2023-11-08T12:30:33Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46760" ], "details": "Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T10:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-3pww-pqg2-m2hm/GHSA-3pww-pqg2-m2hm.json b/advisories/unreviewed/2023/11/GHSA-3pww-pqg2-m2hm/GHSA-3pww-pqg2-m2hm.json new file mode 100644 index 00000000000..bafb38865d5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3pww-pqg2-m2hm/GHSA-3pww-pqg2-m2hm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pww-pqg2-m2hm", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20519" + ], + "details": "A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20519" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3qwh-j562-h8h6/GHSA-3qwh-j562-h8h6.json b/advisories/unreviewed/2023/11/GHSA-3qwh-j562-h8h6/GHSA-3qwh-j562-h8h6.json new file mode 100644 index 00000000000..5d0aec0ab21 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3qwh-j562-h8h6/GHSA-3qwh-j562-h8h6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qwh-j562-h8h6", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-27229" + ], + "details": "Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27229" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3r28-q7qr-3hmj/GHSA-3r28-q7qr-3hmj.json b/advisories/unreviewed/2023/11/GHSA-3r28-q7qr-3hmj/GHSA-3r28-q7qr-3hmj.json new file mode 100644 index 00000000000..8a35bb71049 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3r28-q7qr-3hmj/GHSA-3r28-q7qr-3hmj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r28-q7qr-3hmj", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-46298" + ], + "details": "Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46298" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json b/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json new file mode 100644 index 00000000000..db2f462ba78 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3vm5-5963-pw52/GHSA-3vm5-5963-pw52.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vm5-5963-pw52", + "modified": "2023-11-14T21:30:52Z", + "published": "2023-11-14T21:30:52Z", + "aliases": [ + "CVE-2023-33045" + ], + "details": "Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33045" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3x8j-5c5c-jh43/GHSA-3x8j-5c5c-jh43.json b/advisories/unreviewed/2023/11/GHSA-3x8j-5c5c-jh43/GHSA-3x8j-5c5c-jh43.json new file mode 100644 index 00000000000..1c5fd8db993 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3x8j-5c5c-jh43/GHSA-3x8j-5c5c-jh43.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x8j-5c5c-jh43", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20571" + ], + "details": "A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20571" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json b/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json new file mode 100644 index 00000000000..435b8b26405 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3xpq-vc4j-pfj2/GHSA-3xpq-vc4j-pfj2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xpq-vc4j-pfj2", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-33061" + ], + "details": "Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33061" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-426h-v87f-gxvw/GHSA-426h-v87f-gxvw.json b/advisories/unreviewed/2023/11/GHSA-426h-v87f-gxvw/GHSA-426h-v87f-gxvw.json index 00cef94290e..b8a07134873 100644 --- a/advisories/unreviewed/2023/11/GHSA-426h-v87f-gxvw/GHSA-426h-v87f-gxvw.json +++ b/advisories/unreviewed/2023/11/GHSA-426h-v87f-gxvw/GHSA-426h-v87f-gxvw.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-42gp-78x8-7p5j/GHSA-42gp-78x8-7p5j.json b/advisories/unreviewed/2023/11/GHSA-42gp-78x8-7p5j/GHSA-42gp-78x8-7p5j.json new file mode 100644 index 00000000000..12dafaa11c9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-42gp-78x8-7p5j/GHSA-42gp-78x8-7p5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42gp-78x8-7p5j", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-39221" + ], + "details": "Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39221" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4384-whxj-38x3/GHSA-4384-whxj-38x3.json b/advisories/unreviewed/2023/11/GHSA-4384-whxj-38x3/GHSA-4384-whxj-38x3.json new file mode 100644 index 00000000000..79a692830dd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4384-whxj-38x3/GHSA-4384-whxj-38x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4384-whxj-38x3", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28388" + ], + "details": "Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28388" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00870.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json b/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json index 0d9035d9102..8f2ec87ec36 100644 --- a/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json +++ b/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-43wm-36v8-wrcq", - "modified": "2023-11-08T21:30:37Z", + "modified": "2023-11-14T21:30:55Z", "published": "2023-11-08T21:30:37Z", "aliases": [ "CVE-2023-47223" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T19:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-44j5-cggq-4pgj/GHSA-44j5-cggq-4pgj.json b/advisories/unreviewed/2023/11/GHSA-44j5-cggq-4pgj/GHSA-44j5-cggq-4pgj.json index 1092443186b..0daedcfc7b8 100644 --- a/advisories/unreviewed/2023/11/GHSA-44j5-cggq-4pgj/GHSA-44j5-cggq-4pgj.json +++ b/advisories/unreviewed/2023/11/GHSA-44j5-cggq-4pgj/GHSA-44j5-cggq-4pgj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-4fcv-689w-5fjw/GHSA-4fcv-689w-5fjw.json b/advisories/unreviewed/2023/11/GHSA-4fcv-689w-5fjw/GHSA-4fcv-689w-5fjw.json new file mode 100644 index 00000000000..5a9719142d9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4fcv-689w-5fjw/GHSA-4fcv-689w-5fjw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fcv-689w-5fjw", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-33479" + ], + "details": "RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33479" + }, + { + "type": "WEB", + "url": "https://github.com/remoteclinic/RemoteClinic/issues/23" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4m89-9vr4-fxx8/GHSA-4m89-9vr4-fxx8.json b/advisories/unreviewed/2023/11/GHSA-4m89-9vr4-fxx8/GHSA-4m89-9vr4-fxx8.json new file mode 100644 index 00000000000..42295e1dba8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4m89-9vr4-fxx8/GHSA-4m89-9vr4-fxx8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m89-9vr4-fxx8", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47656" + ], + "details": "Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47656" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/avcp/wordpress-anac-xml-bandi-di-gara-plugin-7-5-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4p9r-m5q5-m33p/GHSA-4p9r-m5q5-m33p.json b/advisories/unreviewed/2023/11/GHSA-4p9r-m5q5-m33p/GHSA-4p9r-m5q5-m33p.json new file mode 100644 index 00000000000..51dc0e5ee14 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4p9r-m5q5-m33p/GHSA-4p9r-m5q5-m33p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p9r-m5q5-m33p", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-41659" + ], + "details": "Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41659" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4qp7-687g-h58j/GHSA-4qp7-687g-h58j.json b/advisories/unreviewed/2023/11/GHSA-4qp7-687g-h58j/GHSA-4qp7-687g-h58j.json index ca641c54674..372de8d7dd6 100644 --- a/advisories/unreviewed/2023/11/GHSA-4qp7-687g-h58j/GHSA-4qp7-687g-h58j.json +++ b/advisories/unreviewed/2023/11/GHSA-4qp7-687g-h58j/GHSA-4qp7-687g-h58j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qp7-687g-h58j", - "modified": "2023-11-14T12:30:26Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-14T12:30:26Z", "aliases": [ "CVE-2023-3889" ], "details": "A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T16:15:28Z" diff --git a/advisories/unreviewed/2023/11/GHSA-4rxw-r623-vp2w/GHSA-4rxw-r623-vp2w.json b/advisories/unreviewed/2023/11/GHSA-4rxw-r623-vp2w/GHSA-4rxw-r623-vp2w.json new file mode 100644 index 00000000000..1ca27e8262e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4rxw-r623-vp2w/GHSA-4rxw-r623-vp2w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rxw-r623-vp2w", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-39230" + ], + "details": "Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39230" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00961.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4xjx-gm5q-6rqm/GHSA-4xjx-gm5q-6rqm.json b/advisories/unreviewed/2023/11/GHSA-4xjx-gm5q-6rqm/GHSA-4xjx-gm5q-6rqm.json new file mode 100644 index 00000000000..0c70604cf0a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4xjx-gm5q-6rqm/GHSA-4xjx-gm5q-6rqm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xjx-gm5q-6rqm", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-29510" + ], + "details": "Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29510" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00719.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4xv6-mr8c-xp77/GHSA-4xv6-mr8c-xp77.json b/advisories/unreviewed/2023/11/GHSA-4xv6-mr8c-xp77/GHSA-4xv6-mr8c-xp77.json new file mode 100644 index 00000000000..b7ff33079a8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4xv6-mr8c-xp77/GHSA-4xv6-mr8c-xp77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xv6-mr8c-xp77", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47654" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in livescore.Bz BZScore – Live Score plugin <= 1.03 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47654" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bzscore-live-score/wordpress-bzscore-live-score-plugin-1-03-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json b/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json index 0731eb02e4b..2222e5a1f42 100644 --- a/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json +++ b/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52rh-vv3q-8jrh", - "modified": "2023-11-08T21:30:36Z", + "modified": "2023-11-14T21:30:55Z", "published": "2023-11-08T21:30:36Z", "aliases": [ "CVE-2023-47190" ], "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T19:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-535j-5wpp-p7jm/GHSA-535j-5wpp-p7jm.json b/advisories/unreviewed/2023/11/GHSA-535j-5wpp-p7jm/GHSA-535j-5wpp-p7jm.json new file mode 100644 index 00000000000..e7a42834196 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-535j-5wpp-p7jm/GHSA-535j-5wpp-p7jm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-535j-5wpp-p7jm", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42540" + ], + "details": "Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42540" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-558c-wr25-5fxf/GHSA-558c-wr25-5fxf.json b/advisories/unreviewed/2023/11/GHSA-558c-wr25-5fxf/GHSA-558c-wr25-5fxf.json new file mode 100644 index 00000000000..a27cf09919a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-558c-wr25-5fxf/GHSA-558c-wr25-5fxf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-558c-wr25-5fxf", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5660" + ], + "details": "The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5660" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/sendpress/tags/1.22.3.31/classes/sc/class-sendpress-sc-unsubscribe-form.php#L57" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cbce42a0-29a7-40df-973c-1fe7338f6c94?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-55jv-g63w-9jph/GHSA-55jv-g63w-9jph.json b/advisories/unreviewed/2023/11/GHSA-55jv-g63w-9jph/GHSA-55jv-g63w-9jph.json new file mode 100644 index 00000000000..14768d94b75 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-55jv-g63w-9jph/GHSA-55jv-g63w-9jph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55jv-g63w-9jph", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-33481" + ], + "details": "RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33481" + }, + { + "type": "WEB", + "url": "https://github.com/remoteclinic/RemoteClinic/issues/25" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-56m3-ppxh-qp77/GHSA-56m3-ppxh-qp77.json b/advisories/unreviewed/2023/11/GHSA-56m3-ppxh-qp77/GHSA-56m3-ppxh-qp77.json new file mode 100644 index 00000000000..ca5f07fa51a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-56m3-ppxh-qp77/GHSA-56m3-ppxh-qp77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56m3-ppxh-qp77", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28377" + ], + "details": "Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28377" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-57xx-rrgm-5cv4/GHSA-57xx-rrgm-5cv4.json b/advisories/unreviewed/2023/11/GHSA-57xx-rrgm-5cv4/GHSA-57xx-rrgm-5cv4.json new file mode 100644 index 00000000000..074307219c3 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-57xx-rrgm-5cv4/GHSA-57xx-rrgm-5cv4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57xx-rrgm-5cv4", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-45469" + ], + "details": "Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45469" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-58jh-w7hm-m96f/GHSA-58jh-w7hm-m96f.json b/advisories/unreviewed/2023/11/GHSA-58jh-w7hm-m96f/GHSA-58jh-w7hm-m96f.json new file mode 100644 index 00000000000..3102cfa2966 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-58jh-w7hm-m96f/GHSA-58jh-w7hm-m96f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58jh-w7hm-m96f", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47658" + ], + "details": "Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in actpro Extra Product Options for WooCommerce plugin <= 3.0.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/extra-product-options-for-woocommerce/wordpress-extra-product-options-for-woocommerce-plugin-3-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json b/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json new file mode 100644 index 00000000000..70b0129dcc2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58rr-37rr-r6h5", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-41425" + ], + "details": "Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41425" + }, + { + "type": "WEB", + "url": "https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413" + }, + { + "type": "WEB", + "url": "http://wondercms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-59x7-fjc6-6prx/GHSA-59x7-fjc6-6prx.json b/advisories/unreviewed/2023/11/GHSA-59x7-fjc6-6prx/GHSA-59x7-fjc6-6prx.json new file mode 100644 index 00000000000..fced61d11cc --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-59x7-fjc6-6prx/GHSA-59x7-fjc6-6prx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59x7-fjc6-6prx", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-33898" + ], + "details": "Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33898" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5h2m-6q68-2g79/GHSA-5h2m-6q68-2g79.json b/advisories/unreviewed/2023/11/GHSA-5h2m-6q68-2g79/GHSA-5h2m-6q68-2g79.json new file mode 100644 index 00000000000..b6a979a164b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5h2m-6q68-2g79/GHSA-5h2m-6q68-2g79.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h2m-6q68-2g79", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-47549" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/eazydocs/wordpress-eazydocs-plugin-2-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5h34-9p23-39p2/GHSA-5h34-9p23-39p2.json b/advisories/unreviewed/2023/11/GHSA-5h34-9p23-39p2/GHSA-5h34-9p23-39p2.json new file mode 100644 index 00000000000..2f0594944e4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5h34-9p23-39p2/GHSA-5h34-9p23-39p2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h34-9p23-39p2", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32279" + ], + "details": "Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthenticated user to potentially enable information disclosure via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32279" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00944.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5hcf-f625-mgr8/GHSA-5hcf-f625-mgr8.json b/advisories/unreviewed/2023/11/GHSA-5hcf-f625-mgr8/GHSA-5hcf-f625-mgr8.json index 7e51c8ce8ae..c29fc87f2c8 100644 --- a/advisories/unreviewed/2023/11/GHSA-5hcf-f625-mgr8/GHSA-5hcf-f625-mgr8.json +++ b/advisories/unreviewed/2023/11/GHSA-5hcf-f625-mgr8/GHSA-5hcf-f625-mgr8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hcf-f625-mgr8", - "modified": "2023-11-08T12:30:33Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46761" ], "details": "Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T10:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json b/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json new file mode 100644 index 00000000000..65d879bbea2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5pq2-w3x5-q9f2/GHSA-5pq2-w3x5-q9f2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pq2-w3x5-q9f2", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20533" + ], + "details": "Insufficient DRAM address validation in System\nManagement Unit (SMU) may allow an attacker to read/write from/to an invalid\nDRAM address, potentially resulting in denial-of-service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20533" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5prp-6h6f-f55f/GHSA-5prp-6h6f-f55f.json b/advisories/unreviewed/2023/11/GHSA-5prp-6h6f-f55f/GHSA-5prp-6h6f-f55f.json new file mode 100644 index 00000000000..f3ffd07d555 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5prp-6h6f-f55f/GHSA-5prp-6h6f-f55f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5prp-6h6f-f55f", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20592" + ], + "details": "Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20592" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3005" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5q3h-x43w-q8hj/GHSA-5q3h-x43w-q8hj.json b/advisories/unreviewed/2023/11/GHSA-5q3h-x43w-q8hj/GHSA-5q3h-x43w-q8hj.json index 6b31c6ef470..e6d480d60b8 100644 --- a/advisories/unreviewed/2023/11/GHSA-5q3h-x43w-q8hj/GHSA-5q3h-x43w-q8hj.json +++ b/advisories/unreviewed/2023/11/GHSA-5q3h-x43w-q8hj/GHSA-5q3h-x43w-q8hj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q3h-x43w-q8hj", - "modified": "2023-11-08T12:30:33Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2022-48613" ], "details": "Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T10:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-5r37-fx4g-5c7h/GHSA-5r37-fx4g-5c7h.json b/advisories/unreviewed/2023/11/GHSA-5r37-fx4g-5c7h/GHSA-5r37-fx4g-5c7h.json new file mode 100644 index 00000000000..938bda99dec --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5r37-fx4g-5c7h/GHSA-5r37-fx4g-5c7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r37-fx4g-5c7h", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22305" + ], + "details": "Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22305" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-680" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5r5w-vh62-8499/GHSA-5r5w-vh62-8499.json b/advisories/unreviewed/2023/11/GHSA-5r5w-vh62-8499/GHSA-5r5w-vh62-8499.json new file mode 100644 index 00000000000..6ba88b369c6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5r5w-vh62-8499/GHSA-5r5w-vh62-8499.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r5w-vh62-8499", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2021-4431" + ], + "details": "A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of the file FMDataAPI_Sample.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 23 is able to address this issue. The patch is identified as 3bd1709a8f7b1720529bf5dfc9855ad609f436cf. It is recommended to upgrade the affected component. VDB-244494 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4431" + }, + { + "type": "WEB", + "url": "https://github.com/msyk/FMDataAPI/pull/54" + }, + { + "type": "WEB", + "url": "https://github.com/msyk/FMDataAPI/commit/3bd1709a8f7b1720529bf5dfc9855ad609f436cf" + }, + { + "type": "WEB", + "url": "https://github.com/msyk/FMDataAPI/releases/tag/23" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.244494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.244494" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5rcg-jq54-2r8g/GHSA-5rcg-jq54-2r8g.json b/advisories/unreviewed/2023/11/GHSA-5rcg-jq54-2r8g/GHSA-5rcg-jq54-2r8g.json new file mode 100644 index 00000000000..f5c449d5654 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5rcg-jq54-2r8g/GHSA-5rcg-jq54-2r8g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rcg-jq54-2r8g", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25071" + ], + "details": "NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25071" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-395" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5v7j-rmqq-795g/GHSA-5v7j-rmqq-795g.json b/advisories/unreviewed/2023/11/GHSA-5v7j-rmqq-795g/GHSA-5v7j-rmqq-795g.json new file mode 100644 index 00000000000..f32f2123aa2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5v7j-rmqq-795g/GHSA-5v7j-rmqq-795g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v7j-rmqq-795g", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-38548" + ], + "details": "A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38548" + }, + { + "type": "WEB", + "url": "https://www.veeam.com/kb4508" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json b/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json new file mode 100644 index 00000000000..f30b396964b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5w5f-g3w4-p65h/GHSA-5w5f-g3w4-p65h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w5f-g3w4-p65h", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-4295" + ], + "details": "A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4295" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119", + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5w9x-5g27-3wqv/GHSA-5w9x-5g27-3wqv.json b/advisories/unreviewed/2023/11/GHSA-5w9x-5g27-3wqv/GHSA-5w9x-5g27-3wqv.json new file mode 100644 index 00000000000..24df91ebef0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5w9x-5g27-3wqv/GHSA-5w9x-5g27-3wqv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w9x-5g27-3wqv", + "modified": "2023-11-14T21:30:51Z", + "published": "2023-11-14T21:30:51Z", + "aliases": [ + "CVE-2023-5900" + ], + "details": "Missing Authorization in GitHub repository pkp/pkp-lib prior to 3.3.0-16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5900" + }, + { + "type": "WEB", + "url": "https://github.com/pkp/pkp-lib/commit/4d77a00be9050fac7eb8d2d1cbedcdaaa1a5a803" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c3f011d4-9f76-4b2b-b3d4-a5e2ecd2e354" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352", + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T04:24:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5x3f-7vj9-g9q2/GHSA-5x3f-7vj9-g9q2.json b/advisories/unreviewed/2023/11/GHSA-5x3f-7vj9-g9q2/GHSA-5x3f-7vj9-g9q2.json new file mode 100644 index 00000000000..1c5e284aecb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5x3f-7vj9-g9q2/GHSA-5x3f-7vj9-g9q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x3f-7vj9-g9q2", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-46646" + ], + "details": "Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46646" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5xr2-69wj-6x93/GHSA-5xr2-69wj-6x93.json b/advisories/unreviewed/2023/11/GHSA-5xr2-69wj-6x93/GHSA-5xr2-69wj-6x93.json new file mode 100644 index 00000000000..53d149ab40b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5xr2-69wj-6x93/GHSA-5xr2-69wj-6x93.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr2-69wj-6x93", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47550" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47550" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5xw6-9h38-rh99/GHSA-5xw6-9h38-rh99.json b/advisories/unreviewed/2023/11/GHSA-5xw6-9h38-rh99/GHSA-5xw6-9h38-rh99.json new file mode 100644 index 00000000000..db45bec4392 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5xw6-9h38-rh99/GHSA-5xw6-9h38-rh99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xw6-9h38-rh99", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-38549" + ], + "details": "A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38549" + }, + { + "type": "WEB", + "url": "https://www.veeam.com/kb4508" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-62r6-m6fg-p4wj/GHSA-62r6-m6fg-p4wj.json b/advisories/unreviewed/2023/11/GHSA-62r6-m6fg-p4wj/GHSA-62r6-m6fg-p4wj.json new file mode 100644 index 00000000000..d6ac7355e65 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-62r6-m6fg-p4wj/GHSA-62r6-m6fg-p4wj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62r6-m6fg-p4wj", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-42879" + ], + "details": "NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42879" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-395" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-66vf-xw82-p57g/GHSA-66vf-xw82-p57g.json b/advisories/unreviewed/2023/11/GHSA-66vf-xw82-p57g/GHSA-66vf-xw82-p57g.json index d9b3ed3ef7e..9410b36eb54 100644 --- a/advisories/unreviewed/2023/11/GHSA-66vf-xw82-p57g/GHSA-66vf-xw82-p57g.json +++ b/advisories/unreviewed/2023/11/GHSA-66vf-xw82-p57g/GHSA-66vf-xw82-p57g.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-326" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json b/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json new file mode 100644 index 00000000000..1cef17f6a89 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6gv5-48rm-6999/GHSA-6gv5-48rm-6999.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gv5-48rm-6999", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20526" + ], + "details": "Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20526" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6j6r-mmfh-xf8p/GHSA-6j6r-mmfh-xf8p.json b/advisories/unreviewed/2023/11/GHSA-6j6r-mmfh-xf8p/GHSA-6j6r-mmfh-xf8p.json new file mode 100644 index 00000000000..c279302c9c6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6j6r-mmfh-xf8p/GHSA-6j6r-mmfh-xf8p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j6r-mmfh-xf8p", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-36374" + ], + "details": "Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36374" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6v8g-pm53-9xw3/GHSA-6v8g-pm53-9xw3.json b/advisories/unreviewed/2023/11/GHSA-6v8g-pm53-9xw3/GHSA-6v8g-pm53-9xw3.json new file mode 100644 index 00000000000..9f1a4740cc5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6v8g-pm53-9xw3/GHSA-6v8g-pm53-9xw3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v8g-pm53-9xw3", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-33878" + ], + "details": "Path transversal in some Intel(R) NUC P14E Laptop Element Audio Install Package software before version 156 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33878" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6xmc-94m2-r43v/GHSA-6xmc-94m2-r43v.json b/advisories/unreviewed/2023/11/GHSA-6xmc-94m2-r43v/GHSA-6xmc-94m2-r43v.json new file mode 100644 index 00000000000..daf3f7bd10a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6xmc-94m2-r43v/GHSA-6xmc-94m2-r43v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xmc-94m2-r43v", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32658" + ], + "details": "Unquoted search path in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32658" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json b/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json index 07a8b39604a..106b55fbd23 100644 --- a/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json +++ b/advisories/unreviewed/2023/11/GHSA-75f9-xr67-g7hj/GHSA-75f9-xr67-g7hj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75f9-xr67-g7hj", - "modified": "2023-11-08T12:30:33Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46755" ], "details": "Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T10:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-77mh-vg7v-786h/GHSA-77mh-vg7v-786h.json b/advisories/unreviewed/2023/11/GHSA-77mh-vg7v-786h/GHSA-77mh-vg7v-786h.json new file mode 100644 index 00000000000..fa89b081cba --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-77mh-vg7v-786h/GHSA-77mh-vg7v-786h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77mh-vg7v-786h", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47646" + ], + "details": "Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47646" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/recently-viewed-and-most-viewed-products/wordpress-recently-viewed-and-most-viewed-products-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7fmg-q86j-f6v7/GHSA-7fmg-q86j-f6v7.json b/advisories/unreviewed/2023/11/GHSA-7fmg-q86j-f6v7/GHSA-7fmg-q86j-f6v7.json new file mode 100644 index 00000000000..49fbb859ac3 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7fmg-q86j-f6v7/GHSA-7fmg-q86j-f6v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fmg-q86j-f6v7", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32204" + ], + "details": "Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32204" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00900.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7hq6-r3pg-vcqw/GHSA-7hq6-r3pg-vcqw.json b/advisories/unreviewed/2023/11/GHSA-7hq6-r3pg-vcqw/GHSA-7hq6-r3pg-vcqw.json new file mode 100644 index 00000000000..575d0fe5d7f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7hq6-r3pg-vcqw/GHSA-7hq6-r3pg-vcqw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hq6-r3pg-vcqw", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-47545" + ], + "details": "Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin <= 2.5.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47545" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mailchimp-wp/wordpress-forms-for-mailchimp-by-optin-cat-plugin-2-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7j92-gx3c-pv6x/GHSA-7j92-gx3c-pv6x.json b/advisories/unreviewed/2023/11/GHSA-7j92-gx3c-pv6x/GHSA-7j92-gx3c-pv6x.json new file mode 100644 index 00000000000..4ee583ddefe --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7j92-gx3c-pv6x/GHSA-7j92-gx3c-pv6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j92-gx3c-pv6x", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28401" + ], + "details": "Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28401" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7mw5-v379-5f57/GHSA-7mw5-v379-5f57.json b/advisories/unreviewed/2023/11/GHSA-7mw5-v379-5f57/GHSA-7mw5-v379-5f57.json index cb176253d41..9cb34e440e0 100644 --- a/advisories/unreviewed/2023/11/GHSA-7mw5-v379-5f57/GHSA-7mw5-v379-5f57.json +++ b/advisories/unreviewed/2023/11/GHSA-7mw5-v379-5f57/GHSA-7mw5-v379-5f57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7mw5-v379-5f57", - "modified": "2023-11-08T09:30:25Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T09:30:25Z", "aliases": [ "CVE-2023-46483" ], "details": "Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T08:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json b/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json new file mode 100644 index 00000000000..91e9c290b63 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7r55-mp9r-c8pj/GHSA-7r55-mp9r-c8pj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r55-mp9r-c8pj", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20521" + ], + "details": "TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20521" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7r75-c97x-7676/GHSA-7r75-c97x-7676.json b/advisories/unreviewed/2023/11/GHSA-7r75-c97x-7676/GHSA-7r75-c97x-7676.json new file mode 100644 index 00000000000..01f8193ff35 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7r75-c97x-7676/GHSA-7r75-c97x-7676.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r75-c97x-7676", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-38131" + ], + "details": "Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38131" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-85qm-42j3-mwq3/GHSA-85qm-42j3-mwq3.json b/advisories/unreviewed/2023/11/GHSA-85qm-42j3-mwq3/GHSA-85qm-42j3-mwq3.json new file mode 100644 index 00000000000..51a95e1cfe4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-85qm-42j3-mwq3/GHSA-85qm-42j3-mwq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85qm-42j3-mwq3", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-47544" + ], + "details": "Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.12 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/atarim-visual-collaboration/wordpress-atarim-plugin-3-11-unauthenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json b/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json new file mode 100644 index 00000000000..e2943ee5d8c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8882-q5f7-v9h8/GHSA-8882-q5f7-v9h8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8882-q5f7-v9h8", + "modified": "2023-11-14T21:30:52Z", + "published": "2023-11-14T21:30:52Z", + "aliases": [ + "CVE-2023-28570" + ], + "details": "Memory corruption while processing audio effects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28570" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json b/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json index cc4d8b5f408..36d8fb0573c 100644 --- a/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json +++ b/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89jm-mj5r-5rp8", - "modified": "2023-11-08T21:30:37Z", + "modified": "2023-11-14T21:30:55Z", "published": "2023-11-08T21:30:37Z", "aliases": [ "CVE-2023-47227" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one place plugin <= 1.5.4.6 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-8hgg-xxm5-3873/GHSA-8hgg-xxm5-3873.json b/advisories/unreviewed/2023/11/GHSA-8hgg-xxm5-3873/GHSA-8hgg-xxm5-3873.json new file mode 100644 index 00000000000..bd34587d825 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8hgg-xxm5-3873/GHSA-8hgg-xxm5-3873.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hgg-xxm5-3873", + "modified": "2023-11-14T21:30:51Z", + "published": "2023-11-14T21:30:51Z", + "aliases": [ + "CVE-2019-25155" + ], + "details": "DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel=\"noopener noreferrer\"' attribute.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25155" + }, + { + "type": "WEB", + "url": "https://github.com/cure53/DOMPurify/pull/337/files" + }, + { + "type": "WEB", + "url": "https://github.com/cure53/DOMPurify/compare/1.0.10...1.0.11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T03:09:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8jp5-89m5-6xp3/GHSA-8jp5-89m5-6xp3.json b/advisories/unreviewed/2023/11/GHSA-8jp5-89m5-6xp3/GHSA-8jp5-89m5-6xp3.json index e0b3fba917a..75cf97b2b0b 100644 --- a/advisories/unreviewed/2023/11/GHSA-8jp5-89m5-6xp3/GHSA-8jp5-89m5-6xp3.json +++ b/advisories/unreviewed/2023/11/GHSA-8jp5-89m5-6xp3/GHSA-8jp5-89m5-6xp3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jp5-89m5-6xp3", - "modified": "2023-11-06T06:30:26Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-11-06T06:30:26Z", "aliases": [ "CVE-2023-38406" ], "details": "bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a \"flowspec overflow.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-755" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T06:15:40Z" diff --git a/advisories/unreviewed/2023/11/GHSA-8pj8-c4m2-fgh7/GHSA-8pj8-c4m2-fgh7.json b/advisories/unreviewed/2023/11/GHSA-8pj8-c4m2-fgh7/GHSA-8pj8-c4m2-fgh7.json new file mode 100644 index 00000000000..6361a49f5f2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8pj8-c4m2-fgh7/GHSA-8pj8-c4m2-fgh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pj8-c4m2-fgh7", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-33478" + ], + "details": "RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33478" + }, + { + "type": "WEB", + "url": "https://github.com/remoteclinic/RemoteClinic/issues/22" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8qm9-hxp3-h3fp/GHSA-8qm9-hxp3-h3fp.json b/advisories/unreviewed/2023/11/GHSA-8qm9-hxp3-h3fp/GHSA-8qm9-hxp3-h3fp.json new file mode 100644 index 00000000000..592e6e6f5ae --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8qm9-hxp3-h3fp/GHSA-8qm9-hxp3-h3fp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qm9-hxp3-h3fp", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22663" + ], + "details": "Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22663" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json b/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json new file mode 100644 index 00000000000..cefc883c5a8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8wpw-g939-rjw4/GHSA-8wpw-g939-rjw4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wpw-g939-rjw4", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2021-46774" + ], + "details": "Insufficient DRAM address validation in System\nManagement Unit (SMU) may allow an attacker to read/write from/to an invalid\nDRAM address, potentially resulting in denial-of-service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46774" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8x2v-m87x-jx78/GHSA-8x2v-m87x-jx78.json b/advisories/unreviewed/2023/11/GHSA-8x2v-m87x-jx78/GHSA-8x2v-m87x-jx78.json new file mode 100644 index 00000000000..8494d565657 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8x2v-m87x-jx78/GHSA-8x2v-m87x-jx78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x2v-m87x-jx78", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25603" + ], + "details": "A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted web requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25603" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-518" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-942" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-92g5-jmf9-m2wf/GHSA-92g5-jmf9-m2wf.json b/advisories/unreviewed/2023/11/GHSA-92g5-jmf9-m2wf/GHSA-92g5-jmf9-m2wf.json new file mode 100644 index 00000000000..a83591b51f8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-92g5-jmf9-m2wf/GHSA-92g5-jmf9-m2wf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92g5-jmf9-m2wf", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-27513" + ], + "details": "Uncontrolled search path element in some Intel(R) Server Information Retrieval Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27513" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00894.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-92w3-2x69-pqhc/GHSA-92w3-2x69-pqhc.json b/advisories/unreviewed/2023/11/GHSA-92w3-2x69-pqhc/GHSA-92w3-2x69-pqhc.json new file mode 100644 index 00000000000..ac021268e91 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-92w3-2x69-pqhc/GHSA-92w3-2x69-pqhc.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92w3-2x69-pqhc", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-4888" + ], + "details": "The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sfp-page-plugin' shortcode in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4888" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/simple-facebook-plugin/trunk/views/view-page-plugin.php?rev=2083359#L37" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/simple-facebook-plugin/trunk/views/view-page-plugin.php?rev=2083359#L38" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/simple-facebook-plugin/trunk/views/view-page-plugin.php?rev=2083359#L39" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2988694/simple-facebook-plugin#file17" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f81df26f-4390-4626-8539-367a52f8a027?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-92xq-w7vg-rw26/GHSA-92xq-w7vg-rw26.json b/advisories/unreviewed/2023/11/GHSA-92xq-w7vg-rw26/GHSA-92xq-w7vg-rw26.json new file mode 100644 index 00000000000..fae13e55dcf --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-92xq-w7vg-rw26/GHSA-92xq-w7vg-rw26.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92xq-w7vg-rw26", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-22285" + ], + "details": "Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22285" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-93g9-r9cm-chf3/GHSA-93g9-r9cm-chf3.json b/advisories/unreviewed/2023/11/GHSA-93g9-r9cm-chf3/GHSA-93g9-r9cm-chf3.json new file mode 100644 index 00000000000..967a25ca212 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-93g9-r9cm-chf3/GHSA-93g9-r9cm-chf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93g9-r9cm-chf3", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-36007" + ], + "details": "Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36007" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-94hw-2w9j-mjr9/GHSA-94hw-2w9j-mjr9.json b/advisories/unreviewed/2023/11/GHSA-94hw-2w9j-mjr9/GHSA-94hw-2w9j-mjr9.json index 0ac3331a371..e001fd1b2c2 100644 --- a/advisories/unreviewed/2023/11/GHSA-94hw-2w9j-mjr9/GHSA-94hw-2w9j-mjr9.json +++ b/advisories/unreviewed/2023/11/GHSA-94hw-2w9j-mjr9/GHSA-94hw-2w9j-mjr9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-94hw-2w9j-mjr9", - "modified": "2023-11-10T09:30:30Z", + "modified": "2023-11-14T21:30:53Z", "published": "2023-11-10T09:30:30Z", "aliases": [ "CVE-2023-46819" ], "details": "Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin.\nThis issue affects Apache OFBiz: before 18.12.09. \n\nUsers are recommended to upgrade to version 18.12.09\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ "CWE-306" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T11:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-956p-f3rr-w9v3/GHSA-956p-f3rr-w9v3.json b/advisories/unreviewed/2023/11/GHSA-956p-f3rr-w9v3/GHSA-956p-f3rr-w9v3.json new file mode 100644 index 00000000000..3e69e714164 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-956p-f3rr-w9v3/GHSA-956p-f3rr-w9v3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-956p-f3rr-w9v3", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-33056" + ], + "details": "Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33056" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9684-7r2w-mm28/GHSA-9684-7r2w-mm28.json b/advisories/unreviewed/2023/11/GHSA-9684-7r2w-mm28/GHSA-9684-7r2w-mm28.json new file mode 100644 index 00000000000..bc56b5d135b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9684-7r2w-mm28/GHSA-9684-7r2w-mm28.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9684-7r2w-mm28", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25080" + ], + "details": "Protection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25080" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00901.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9cgg-v86h-hw54/GHSA-9cgg-v86h-hw54.json b/advisories/unreviewed/2023/11/GHSA-9cgg-v86h-hw54/GHSA-9cgg-v86h-hw54.json new file mode 100644 index 00000000000..fedf9f90a08 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9cgg-v86h-hw54/GHSA-9cgg-v86h-hw54.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cgg-v86h-hw54", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-23583" + ], + "details": "Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23583" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/14/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/14/5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/14/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/14/7" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/14/8" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/14/9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1281" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9cwp-p56f-6gc5/GHSA-9cwp-p56f-6gc5.json b/advisories/unreviewed/2023/11/GHSA-9cwp-p56f-6gc5/GHSA-9cwp-p56f-6gc5.json new file mode 100644 index 00000000000..759f4cb1cd9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9cwp-p56f-6gc5/GHSA-9cwp-p56f-6gc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cwp-p56f-6gc5", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47554" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DenK BV Actueel Financieel Nieuws – Denk Internet Solutions plugin <= 5.1.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47554" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/denk-internet-solutions/wordpress-actueel-financieel-nieuws-denk-internet-solutions-plugin-5-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9f56-vmhf-r5vv/GHSA-9f56-vmhf-r5vv.json b/advisories/unreviewed/2023/11/GHSA-9f56-vmhf-r5vv/GHSA-9f56-vmhf-r5vv.json new file mode 100644 index 00000000000..8e2733e2038 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9f56-vmhf-r5vv/GHSA-9f56-vmhf-r5vv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f56-vmhf-r5vv", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28397" + ], + "details": "Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28397" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9f83-5mc2-p75r/GHSA-9f83-5mc2-p75r.json b/advisories/unreviewed/2023/11/GHSA-9f83-5mc2-p75r/GHSA-9f83-5mc2-p75r.json new file mode 100644 index 00000000000..c757d131839 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9f83-5mc2-p75r/GHSA-9f83-5mc2-p75r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f83-5mc2-p75r", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-41689" + ], + "details": "Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41689" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00968.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json b/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json new file mode 100644 index 00000000000..a6f46c2a28b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9fmg-2fcx-q3vf/GHSA-9fmg-2fcx-q3vf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fmg-2fcx-q3vf", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2022-23820" + ], + "details": "Failure to validate the AMD SMM communication buffer\nmay allow an attacker to corrupt the SMRAM potentially leading to arbitrary\ncode execution.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23820" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9ghc-6jgp-h734/GHSA-9ghc-6jgp-h734.json b/advisories/unreviewed/2023/11/GHSA-9ghc-6jgp-h734/GHSA-9ghc-6jgp-h734.json new file mode 100644 index 00000000000..985df66ff8e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9ghc-6jgp-h734/GHSA-9ghc-6jgp-h734.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ghc-6jgp-h734", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42541" + ], + "details": "Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42541" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json b/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json new file mode 100644 index 00000000000..4c4832d8a76 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9p33-fhfv-86gg/GHSA-9p33-fhfv-86gg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p33-fhfv-86gg", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-33074" + ], + "details": "Memory corruption in Audio when SSR event is triggered after music playback is stopped.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33074" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json b/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json new file mode 100644 index 00000000000..19efcfed8e8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9pj9-m7vp-27hp/GHSA-9pj9-m7vp-27hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pj9-m7vp-27hp", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-33048" + ], + "details": "Transient DOS in WLAN Firmware while parsing t2lm buffers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33048" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json b/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json new file mode 100644 index 00000000000..5a95dc73f65 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9qfg-vjxj-gjf3/GHSA-9qfg-vjxj-gjf3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qfg-vjxj-gjf3", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-33059" + ], + "details": "Memory corruption in Audio while processing the VOC packet data from ADSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33059" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9qfm-4g6c-76pf/GHSA-9qfm-4g6c-76pf.json b/advisories/unreviewed/2023/11/GHSA-9qfm-4g6c-76pf/GHSA-9qfm-4g6c-76pf.json new file mode 100644 index 00000000000..344f20bc4e8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9qfm-4g6c-76pf/GHSA-9qfm-4g6c-76pf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qfm-4g6c-76pf", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22290" + ], + "details": "Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22290" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9wxq-3vm5-2pg9/GHSA-9wxq-3vm5-2pg9.json b/advisories/unreviewed/2023/11/GHSA-9wxq-3vm5-2pg9/GHSA-9wxq-3vm5-2pg9.json new file mode 100644 index 00000000000..ebe6f9264b2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9wxq-3vm5-2pg9/GHSA-9wxq-3vm5-2pg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wxq-3vm5-2pg9", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22310" + ], + "details": "Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22310" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-421" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c7mf-mh8g-44q2/GHSA-c7mf-mh8g-44q2.json b/advisories/unreviewed/2023/11/GHSA-c7mf-mh8g-44q2/GHSA-c7mf-mh8g-44q2.json new file mode 100644 index 00000000000..a02d736fd89 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-c7mf-mh8g-44q2/GHSA-c7mf-mh8g-44q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7mf-mh8g-44q2", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-43666" + ], + "details": "Exposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43666" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1258" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c9fc-7rjq-97gw/GHSA-c9fc-7rjq-97gw.json b/advisories/unreviewed/2023/11/GHSA-c9fc-7rjq-97gw/GHSA-c9fc-7rjq-97gw.json new file mode 100644 index 00000000000..ecd08ee8325 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-c9fc-7rjq-97gw/GHSA-c9fc-7rjq-97gw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9fc-7rjq-97gw", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-43477" + ], + "details": "Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43477" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cc87-35fp-2jp7/GHSA-cc87-35fp-2jp7.json b/advisories/unreviewed/2023/11/GHSA-cc87-35fp-2jp7/GHSA-cc87-35fp-2jp7.json new file mode 100644 index 00000000000..4e2b743d5ec --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cc87-35fp-2jp7/GHSA-cc87-35fp-2jp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc87-35fp-2jp7", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-27383" + ], + "details": "Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27383" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00841.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cc94-45q3-h8pp/GHSA-cc94-45q3-h8pp.json b/advisories/unreviewed/2023/11/GHSA-cc94-45q3-h8pp/GHSA-cc94-45q3-h8pp.json new file mode 100644 index 00000000000..af240678106 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cc94-45q3-h8pp/GHSA-cc94-45q3-h8pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc94-45q3-h8pp", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-31273" + ], + "details": "Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31273" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00902.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-693" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cf7p-69mj-6266/GHSA-cf7p-69mj-6266.json b/advisories/unreviewed/2023/11/GHSA-cf7p-69mj-6266/GHSA-cf7p-69mj-6266.json new file mode 100644 index 00000000000..834e4da7e2d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cf7p-69mj-6266/GHSA-cf7p-69mj-6266.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf7p-69mj-6266", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-47653" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abu Bakar TWB Woocommerce Reviews plugin <= 1.7.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47653" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/twb-woocommerce-reviews/wordpress-twb-woocommerce-reviews-plugin-1-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cj6m-445x-9hgm/GHSA-cj6m-445x-9hgm.json b/advisories/unreviewed/2023/11/GHSA-cj6m-445x-9hgm/GHSA-cj6m-445x-9hgm.json new file mode 100644 index 00000000000..33144e3583d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cj6m-445x-9hgm/GHSA-cj6m-445x-9hgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj6m-445x-9hgm", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-47510" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPSolutions-HQ WPDBSpringClean plugin <= 1.6 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47510" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpdbspringclean/wordpress-wpdbspringclean-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json b/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json new file mode 100644 index 00000000000..c42f55c6a37 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cjh4-hrfc-4xj7/GHSA-cjh4-hrfc-4xj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjh4-hrfc-4xj7", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20563" + ], + "details": "Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20563" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cjvm-95qv-84m2/GHSA-cjvm-95qv-84m2.json b/advisories/unreviewed/2023/11/GHSA-cjvm-95qv-84m2/GHSA-cjvm-95qv-84m2.json new file mode 100644 index 00000000000..f535007eedc --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cjvm-95qv-84m2/GHSA-cjvm-95qv-84m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjvm-95qv-84m2", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-29504" + ], + "details": "Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29504" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00871.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cp97-6mf7-2cvp/GHSA-cp97-6mf7-2cvp.json b/advisories/unreviewed/2023/11/GHSA-cp97-6mf7-2cvp/GHSA-cp97-6mf7-2cvp.json new file mode 100644 index 00000000000..a3d392f0463 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cp97-6mf7-2cvp/GHSA-cp97-6mf7-2cvp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp97-6mf7-2cvp", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22292" + ], + "details": "Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22292" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json b/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json new file mode 100644 index 00000000000..b0c3115ff2d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cqgf-g3qq-hhxw/GHSA-cqgf-g3qq-hhxw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqgf-g3qq-hhxw", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20568" + ], + "details": "Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20568" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cv78-jxjg-mfgw/GHSA-cv78-jxjg-mfgw.json b/advisories/unreviewed/2023/11/GHSA-cv78-jxjg-mfgw/GHSA-cv78-jxjg-mfgw.json new file mode 100644 index 00000000000..146948b8017 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cv78-jxjg-mfgw/GHSA-cv78-jxjg-mfgw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv78-jxjg-mfgw", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-29157" + ], + "details": "Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29157" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00900.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json b/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json new file mode 100644 index 00000000000..58f3c551676 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cxvw-76f5-px84/GHSA-cxvw-76f5-px84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxvw-76f5-px84", + "modified": "2023-11-14T21:30:52Z", + "published": "2023-11-14T21:30:52Z", + "aliases": [ + "CVE-2023-28574" + ], + "details": "Memory corruption in core services when Diag handler receives a command to configure event listeners.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28574" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f346-p877-7wqq/GHSA-f346-p877-7wqq.json b/advisories/unreviewed/2023/11/GHSA-f346-p877-7wqq/GHSA-f346-p877-7wqq.json new file mode 100644 index 00000000000..5776d9fc62c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-f346-p877-7wqq/GHSA-f346-p877-7wqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f346-p877-7wqq", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-38547" + ], + "details": "A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38547" + }, + { + "type": "WEB", + "url": "https://www.veeam.com/kb4508" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f3rw-936p-6899/GHSA-f3rw-936p-6899.json b/advisories/unreviewed/2023/11/GHSA-f3rw-936p-6899/GHSA-f3rw-936p-6899.json index 01456af1dba..be28931683f 100644 --- a/advisories/unreviewed/2023/11/GHSA-f3rw-936p-6899/GHSA-f3rw-936p-6899.json +++ b/advisories/unreviewed/2023/11/GHSA-f3rw-936p-6899/GHSA-f3rw-936p-6899.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3rw-936p-6899", - "modified": "2023-11-06T21:31:09Z", + "modified": "2023-11-14T21:30:51Z", "published": "2023-11-06T21:31:09Z", "aliases": [ "CVE-2023-5605" ], "details": "The URL Shortify WordPress plugin through 1.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T21:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-f6cq-wc24-3mcw/GHSA-f6cq-wc24-3mcw.json b/advisories/unreviewed/2023/11/GHSA-f6cq-wc24-3mcw/GHSA-f6cq-wc24-3mcw.json new file mode 100644 index 00000000000..f84d1a1bc1d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-f6cq-wc24-3mcw/GHSA-f6cq-wc24-3mcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6cq-wc24-3mcw", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28723" + ], + "details": "Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28723" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f8ch-7h6r-42h6/GHSA-f8ch-7h6r-42h6.json b/advisories/unreviewed/2023/11/GHSA-f8ch-7h6r-42h6/GHSA-f8ch-7h6r-42h6.json new file mode 100644 index 00000000000..b42fb923319 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-f8ch-7h6r-42h6/GHSA-f8ch-7h6r-42h6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8ch-7h6r-42h6", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-33874" + ], + "details": "Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version 2.2.2.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33874" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f8rp-47c5-2crv/GHSA-f8rp-47c5-2crv.json b/advisories/unreviewed/2023/11/GHSA-f8rp-47c5-2crv/GHSA-f8rp-47c5-2crv.json new file mode 100644 index 00000000000..0d31feac8f8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-f8rp-47c5-2crv/GHSA-f8rp-47c5-2crv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8rp-47c5-2crv", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22327" + ], + "details": "Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22327" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00957.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fc85-qvq2-2963/GHSA-fc85-qvq2-2963.json b/advisories/unreviewed/2023/11/GHSA-fc85-qvq2-2963/GHSA-fc85-qvq2-2963.json new file mode 100644 index 00000000000..66d22e5eb4e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fc85-qvq2-2963/GHSA-fc85-qvq2-2963.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc85-qvq2-2963", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5577" + ], + "details": "The Bitly's plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpbitly' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5577" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-bitly/trunk/includes/class-wp-bitly-shortlink.php?rev=2767772#L238" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/31522e54-f260-46d0-8d57-2d46af7d3450?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ff49-v6jj-fh2j/GHSA-ff49-v6jj-fh2j.json b/advisories/unreviewed/2023/11/GHSA-ff49-v6jj-fh2j/GHSA-ff49-v6jj-fh2j.json new file mode 100644 index 00000000000..bd7f985ea4c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ff49-v6jj-fh2j/GHSA-ff49-v6jj-fh2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff49-v6jj-fh2j", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42283" + ], + "details": "Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42283" + }, + { + "type": "WEB", + "url": "https://github.com/andreysanyuk/CVE-2023-42283" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ffwh-fwc7-gh76/GHSA-ffwh-fwc7-gh76.json b/advisories/unreviewed/2023/11/GHSA-ffwh-fwc7-gh76/GHSA-ffwh-fwc7-gh76.json new file mode 100644 index 00000000000..8cd0047ccd1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ffwh-fwc7-gh76/GHSA-ffwh-fwc7-gh76.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffwh-fwc7-gh76", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-24588" + ], + "details": "Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24588" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00758.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-frwx-7gqv-hj3w/GHSA-frwx-7gqv-hj3w.json b/advisories/unreviewed/2023/11/GHSA-frwx-7gqv-hj3w/GHSA-frwx-7gqv-hj3w.json new file mode 100644 index 00000000000..7c3737ae67a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-frwx-7gqv-hj3w/GHSA-frwx-7gqv-hj3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frwx-7gqv-hj3w", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22313" + ], + "details": "Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22313" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00861.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fww3-wwgr-mqpw/GHSA-fww3-wwgr-mqpw.json b/advisories/unreviewed/2023/11/GHSA-fww3-wwgr-mqpw/GHSA-fww3-wwgr-mqpw.json new file mode 100644 index 00000000000..fc2d0f12ad8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fww3-wwgr-mqpw/GHSA-fww3-wwgr-mqpw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fww3-wwgr-mqpw", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42543" + ], + "details": "Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42543" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fx6p-v7mp-pw72/GHSA-fx6p-v7mp-pw72.json b/advisories/unreviewed/2023/11/GHSA-fx6p-v7mp-pw72/GHSA-fx6p-v7mp-pw72.json new file mode 100644 index 00000000000..d3cfadaf975 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fx6p-v7mp-pw72/GHSA-fx6p-v7mp-pw72.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx6p-v7mp-pw72", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32641" + ], + "details": "Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32641" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00945.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g3qw-w3wp-f3m2/GHSA-g3qw-w3wp-f3m2.json b/advisories/unreviewed/2023/11/GHSA-g3qw-w3wp-f3m2/GHSA-g3qw-w3wp-f3m2.json new file mode 100644 index 00000000000..89550fc6005 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g3qw-w3wp-f3m2/GHSA-g3qw-w3wp-f3m2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3qw-w3wp-f3m2", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32701" + ], + "details": " Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32701" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/kb/articleDetail?articleNumber=000112401" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json b/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json index 439a8428348..a993f2228d0 100644 --- a/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json +++ b/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g896-hqwq-6qp3", - "modified": "2023-11-08T21:30:37Z", + "modified": "2023-11-14T21:30:55Z", "published": "2023-11-08T21:30:37Z", "aliases": [ "CVE-2023-47228" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-g9w7-fcq8-mffw/GHSA-g9w7-fcq8-mffw.json b/advisories/unreviewed/2023/11/GHSA-g9w7-fcq8-mffw/GHSA-g9w7-fcq8-mffw.json new file mode 100644 index 00000000000..e42f6c509b4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g9w7-fcq8-mffw/GHSA-g9w7-fcq8-mffw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9w7-fcq8-mffw", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32660" + ], + "details": "Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32660" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ggrf-mj99-j57m/GHSA-ggrf-mj99-j57m.json b/advisories/unreviewed/2023/11/GHSA-ggrf-mj99-j57m/GHSA-ggrf-mj99-j57m.json new file mode 100644 index 00000000000..6e6fcfcb689 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ggrf-mj99-j57m/GHSA-ggrf-mj99-j57m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggrf-mj99-j57m", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-40681" + ], + "details": "A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40681" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-299" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gh94-rfj3-873r/GHSA-gh94-rfj3-873r.json b/advisories/unreviewed/2023/11/GHSA-gh94-rfj3-873r/GHSA-gh94-rfj3-873r.json new file mode 100644 index 00000000000..852f6afec7e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gh94-rfj3-873r/GHSA-gh94-rfj3-873r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh94-rfj3-873r", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-4272" + ], + "details": "A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4272" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1251" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ghwh-356h-wcgq/GHSA-ghwh-356h-wcgq.json b/advisories/unreviewed/2023/11/GHSA-ghwh-356h-wcgq/GHSA-ghwh-356h-wcgq.json new file mode 100644 index 00000000000..f00950e55dd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ghwh-356h-wcgq/GHSA-ghwh-356h-wcgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghwh-356h-wcgq", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-33480" + ], + "details": "RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access control in the staff/register.php endpoint and the edit-my-profile.php page. By sending a series of specially crafted requests to the RemoteClinic application, an attacker can create admin users with more privileges than their own, upload a PHP file containing arbitrary code, and execute arbitrary commands via the PHP shell.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33480" + }, + { + "type": "WEB", + "url": "https://github.com/remoteclinic/RemoteClinic/issues/24" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gpjf-v934-73g5/GHSA-gpjf-v934-73g5.json b/advisories/unreviewed/2023/11/GHSA-gpjf-v934-73g5/GHSA-gpjf-v934-73g5.json index 6b71cbd1b01..5d016832b9d 100644 --- a/advisories/unreviewed/2023/11/GHSA-gpjf-v934-73g5/GHSA-gpjf-v934-73g5.json +++ b/advisories/unreviewed/2023/11/GHSA-gpjf-v934-73g5/GHSA-gpjf-v934-73g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpjf-v934-73g5", - "modified": "2023-11-07T21:30:24Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2023-41798" ], "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T18:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json b/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json new file mode 100644 index 00000000000..8af81ae0473 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gqm2-wv4v-659j/GHSA-gqm2-wv4v-659j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqm2-wv4v-659j", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28376" + ], + "details": "Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28376" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00869.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gqwc-m2xc-gx3c/GHSA-gqwc-m2xc-gx3c.json b/advisories/unreviewed/2023/11/GHSA-gqwc-m2xc-gx3c/GHSA-gqwc-m2xc-gx3c.json new file mode 100644 index 00000000000..14349eb47e5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gqwc-m2xc-gx3c/GHSA-gqwc-m2xc-gx3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqwc-m2xc-gx3c", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-34431" + ], + "details": "Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34431" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00719.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-h53x-4j3w-4vcp/GHSA-h53x-4j3w-4vcp.json b/advisories/unreviewed/2023/11/GHSA-h53x-4j3w-4vcp/GHSA-h53x-4j3w-4vcp.json new file mode 100644 index 00000000000..962db7cf5df --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-h53x-4j3w-4vcp/GHSA-h53x-4j3w-4vcp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h53x-4j3w-4vcp", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32655" + ], + "details": "Path transversal in some Intel(R) NUC Kits & Mini PCs - NUC8i7HVK & NUC8HNK USB Type C power delivery controller installatio software before version 1.0.10.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32655" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-h5fc-v3m2-vpp2/GHSA-h5fc-v3m2-vpp2.json b/advisories/unreviewed/2023/11/GHSA-h5fc-v3m2-vpp2/GHSA-h5fc-v3m2-vpp2.json new file mode 100644 index 00000000000..63e9dc8c1ad --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-h5fc-v3m2-vpp2/GHSA-h5fc-v3m2-vpp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5fc-v3m2-vpp2", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28740" + ], + "details": "Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28740" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00861.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json b/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json index 08a0734b4fe..5cea10a6658 100644 --- a/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json +++ b/advisories/unreviewed/2023/11/GHSA-h5hr-qxxj-7g93/GHSA-h5hr-qxxj-7g93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5hr-qxxj-7g93", - "modified": "2023-11-08T12:30:33Z", + "modified": "2023-11-14T21:30:55Z", "published": "2023-11-08T12:30:33Z", "aliases": [ "CVE-2023-46762" ], "details": "Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T10:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-h8jx-25pr-hgm3/GHSA-h8jx-25pr-hgm3.json b/advisories/unreviewed/2023/11/GHSA-h8jx-25pr-hgm3/GHSA-h8jx-25pr-hgm3.json index 3ccc7205ecc..0b87f8253c5 100644 --- a/advisories/unreviewed/2023/11/GHSA-h8jx-25pr-hgm3/GHSA-h8jx-25pr-hgm3.json +++ b/advisories/unreviewed/2023/11/GHSA-h8jx-25pr-hgm3/GHSA-h8jx-25pr-hgm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8jx-25pr-hgm3", - "modified": "2023-11-06T21:31:09Z", + "modified": "2023-11-14T21:30:51Z", "published": "2023-11-06T21:31:09Z", "aliases": [ "CVE-2023-5601" ], "details": "The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T21:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-hgpx-7mjh-m574/GHSA-hgpx-7mjh-m574.json b/advisories/unreviewed/2023/11/GHSA-hgpx-7mjh-m574/GHSA-hgpx-7mjh-m574.json new file mode 100644 index 00000000000..1908c3b1bea --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hgpx-7mjh-m574/GHSA-hgpx-7mjh-m574.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgpx-7mjh-m574", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-33945" + ], + "details": "Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33945" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00719.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hq3p-78fh-v8qw/GHSA-hq3p-78fh-v8qw.json b/advisories/unreviewed/2023/11/GHSA-hq3p-78fh-v8qw/GHSA-hq3p-78fh-v8qw.json new file mode 100644 index 00000000000..5de680c6ce7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hq3p-78fh-v8qw/GHSA-hq3p-78fh-v8qw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq3p-78fh-v8qw", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-39228" + ], + "details": "Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39228" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hq6q-c2x6-hmch/GHSA-hq6q-c2x6-hmch.json b/advisories/unreviewed/2023/11/GHSA-hq6q-c2x6-hmch/GHSA-hq6q-c2x6-hmch.json new file mode 100644 index 00000000000..747f8b74926 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hq6q-c2x6-hmch/GHSA-hq6q-c2x6-hmch.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq6q-c2x6-hmch", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-5528" + ], + "details": "A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5528" + }, + { + "type": "WEB", + "url": "https://github.com/kubernetes/kubernetes/issues/121879" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/kubernetes-security-announce/c/SL_d4NR8pzA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hwv7-r8wc-xjxc/GHSA-hwv7-r8wc-xjxc.json b/advisories/unreviewed/2023/11/GHSA-hwv7-r8wc-xjxc/GHSA-hwv7-r8wc-xjxc.json new file mode 100644 index 00000000000..7f2fdd0641d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hwv7-r8wc-xjxc/GHSA-hwv7-r8wc-xjxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwv7-r8wc-xjxc", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-24592" + ], + "details": "Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24592" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00841.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-j5vh-m963-h26r/GHSA-j5vh-m963-h26r.json b/advisories/unreviewed/2023/11/GHSA-j5vh-m963-h26r/GHSA-j5vh-m963-h26r.json new file mode 100644 index 00000000000..c9ed49dd5e6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j5vh-m963-h26r/GHSA-j5vh-m963-h26r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5vh-m963-h26r", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25949" + ], + "details": "Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25949" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-j8h9-q858-c787/GHSA-j8h9-q858-c787.json b/advisories/unreviewed/2023/11/GHSA-j8h9-q858-c787/GHSA-j8h9-q858-c787.json new file mode 100644 index 00000000000..005d6fd79bb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j8h9-q858-c787/GHSA-j8h9-q858-c787.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8h9-q858-c787", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5669" + ], + "details": "The Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and post meta in all versions up to, and including, 0.8.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5669" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/featured-image-caption/trunk/classes/MetaBox.php?rev=2300545#L91" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/featured-image-caption/trunk/classes/MetaBox.php?rev=2300545#L92" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c43a88c-6374-414f-97ae-26ba15d75cdc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jgqp-37qx-xpp9/GHSA-jgqp-37qx-xpp9.json b/advisories/unreviewed/2023/11/GHSA-jgqp-37qx-xpp9/GHSA-jgqp-37qx-xpp9.json new file mode 100644 index 00000000000..ba146c1e68f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jgqp-37qx-xpp9/GHSA-jgqp-37qx-xpp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgqp-37qx-xpp9", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28378" + ], + "details": "Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28378" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00861.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json b/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json new file mode 100644 index 00000000000..3cb52c9cf07 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jm3v-6m47-cv37/GHSA-jm3v-6m47-cv37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm3v-6m47-cv37", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22329" + ], + "details": "Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22329" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00924.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jm6q-v8j6-qqwg/GHSA-jm6q-v8j6-qqwg.json b/advisories/unreviewed/2023/11/GHSA-jm6q-v8j6-qqwg/GHSA-jm6q-v8j6-qqwg.json new file mode 100644 index 00000000000..2e7bcb7a711 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jm6q-v8j6-qqwg/GHSA-jm6q-v8j6-qqwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm6q-v8j6-qqwg", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-38411" + ], + "details": "Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38411" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00863.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m2w4-66r4-v852/GHSA-m2w4-66r4-v852.json b/advisories/unreviewed/2023/11/GHSA-m2w4-66r4-v852/GHSA-m2w4-66r4-v852.json new file mode 100644 index 00000000000..dadef8adc7b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m2w4-66r4-v852/GHSA-m2w4-66r4-v852.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2w4-66r4-v852", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-46647" + ], + "details": "Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46647" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m3hg-fjqc-ww3w/GHSA-m3hg-fjqc-ww3w.json b/advisories/unreviewed/2023/11/GHSA-m3hg-fjqc-ww3w/GHSA-m3hg-fjqc-ww3w.json new file mode 100644 index 00000000000..02070b9bcab --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m3hg-fjqc-ww3w/GHSA-m3hg-fjqc-ww3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3hg-fjqc-ww3w", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-33872" + ], + "details": "Improper access control in the Intel Support android application all verions may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33872" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00976.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m7g3-7cq7-qj74/GHSA-m7g3-7cq7-qj74.json b/advisories/unreviewed/2023/11/GHSA-m7g3-7cq7-qj74/GHSA-m7g3-7cq7-qj74.json new file mode 100644 index 00000000000..54c267b6739 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m7g3-7cq7-qj74/GHSA-m7g3-7cq7-qj74.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7g3-7cq7-qj74", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-39412" + ], + "details": "Cross-site request forgery in some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39412" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m8cq-xmhh-jr5v/GHSA-m8cq-xmhh-jr5v.json b/advisories/unreviewed/2023/11/GHSA-m8cq-xmhh-jr5v/GHSA-m8cq-xmhh-jr5v.json index 45b4c2b967e..3d213dd898f 100644 --- a/advisories/unreviewed/2023/11/GHSA-m8cq-xmhh-jr5v/GHSA-m8cq-xmhh-jr5v.json +++ b/advisories/unreviewed/2023/11/GHSA-m8cq-xmhh-jr5v/GHSA-m8cq-xmhh-jr5v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-m8wv-7jj8-p8pv/GHSA-m8wv-7jj8-p8pv.json b/advisories/unreviewed/2023/11/GHSA-m8wv-7jj8-p8pv/GHSA-m8wv-7jj8-p8pv.json index cec0205daa7..7e0122f74ba 100644 --- a/advisories/unreviewed/2023/11/GHSA-m8wv-7jj8-p8pv/GHSA-m8wv-7jj8-p8pv.json +++ b/advisories/unreviewed/2023/11/GHSA-m8wv-7jj8-p8pv/GHSA-m8wv-7jj8-p8pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8wv-7jj8-p8pv", - "modified": "2023-11-06T21:31:09Z", + "modified": "2023-11-14T21:30:51Z", "published": "2023-11-06T21:31:09Z", "aliases": [ "CVE-2023-5771" diff --git a/advisories/unreviewed/2023/11/GHSA-mfxr-7r69-92fv/GHSA-mfxr-7r69-92fv.json b/advisories/unreviewed/2023/11/GHSA-mfxr-7r69-92fv/GHSA-mfxr-7r69-92fv.json new file mode 100644 index 00000000000..3de552726fe --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mfxr-7r69-92fv/GHSA-mfxr-7r69-92fv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfxr-7r69-92fv", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-4842" + ], + "details": "The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4842" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.1/lib/buttons-panel/SWP_Buttons_Panel_Trait.php#L304" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.1/lib/buttons-panel/SWP_Buttons_Panel_Trait.php#L877" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2982662/social-warfare#file0" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8f5b9aff-0833-4887-ae59-df5bc88c7f91?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mq3f-4x6v-59hg/GHSA-mq3f-4x6v-59hg.json b/advisories/unreviewed/2023/11/GHSA-mq3f-4x6v-59hg/GHSA-mq3f-4x6v-59hg.json new file mode 100644 index 00000000000..2fc8c48a858 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mq3f-4x6v-59hg/GHSA-mq3f-4x6v-59hg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq3f-4x6v-59hg", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32278" + ], + "details": "Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installation software before version 1.0.1.7 for Intel(R) NUC Software Studio may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32278" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mx9c-3r4g-6f8m/GHSA-mx9c-3r4g-6f8m.json b/advisories/unreviewed/2023/11/GHSA-mx9c-3r4g-6f8m/GHSA-mx9c-3r4g-6f8m.json new file mode 100644 index 00000000000..024c5648ecc --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mx9c-3r4g-6f8m/GHSA-mx9c-3r4g-6f8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx9c-3r4g-6f8m", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-36437" + ], + "details": "Azure DevOps Server Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36437" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36437" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json b/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json new file mode 100644 index 00000000000..926402833be --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-p483-8797-gq74/GHSA-p483-8797-gq74.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p483-8797-gq74", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2021-46748" + ], + "details": "Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46748" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json b/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json new file mode 100644 index 00000000000..c1bf6d4d49a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-pgg7-g5f4-6c8v/GHSA-pgg7-g5f4-6c8v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgg7-g5f4-6c8v", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25756" + ], + "details": "Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25756" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00924.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pjj6-9mq4-p5qc/GHSA-pjj6-9mq4-p5qc.json b/advisories/unreviewed/2023/11/GHSA-pjj6-9mq4-p5qc/GHSA-pjj6-9mq4-p5qc.json new file mode 100644 index 00000000000..4035c4c309d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-pjj6-9mq4-p5qc/GHSA-pjj6-9mq4-p5qc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjj6-9mq4-p5qc", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32638" + ], + "details": "Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32638" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00952.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pr3w-9h6r-g7j3/GHSA-pr3w-9h6r-g7j3.json b/advisories/unreviewed/2023/11/GHSA-pr3w-9h6r-g7j3/GHSA-pr3w-9h6r-g7j3.json new file mode 100644 index 00000000000..8eb818055d2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-pr3w-9h6r-g7j3/GHSA-pr3w-9h6r-g7j3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr3w-9h6r-g7j3", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-34997" + ], + "details": "Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34997" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00925.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pr6q-p3qr-3x6p/GHSA-pr6q-p3qr-3x6p.json b/advisories/unreviewed/2023/11/GHSA-pr6q-p3qr-3x6p/GHSA-pr6q-p3qr-3x6p.json index 1699473b8c2..a62d42a1b15 100644 --- a/advisories/unreviewed/2023/11/GHSA-pr6q-p3qr-3x6p/GHSA-pr6q-p3qr-3x6p.json +++ b/advisories/unreviewed/2023/11/GHSA-pr6q-p3qr-3x6p/GHSA-pr6q-p3qr-3x6p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-pv77-783w-qwjw/GHSA-pv77-783w-qwjw.json b/advisories/unreviewed/2023/11/GHSA-pv77-783w-qwjw/GHSA-pv77-783w-qwjw.json new file mode 100644 index 00000000000..90b7fed2528 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-pv77-783w-qwjw/GHSA-pv77-783w-qwjw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv77-783w-qwjw", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-47546" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/oneclick-whatsapp-order/wordpress-oneclick-chat-to-order-plugin-1-0-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-px59-5w52-jv25/GHSA-px59-5w52-jv25.json b/advisories/unreviewed/2023/11/GHSA-px59-5w52-jv25/GHSA-px59-5w52-jv25.json new file mode 100644 index 00000000000..5f9f87c645b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-px59-5w52-jv25/GHSA-px59-5w52-jv25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px59-5w52-jv25", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-24379" + ], + "details": "Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24379" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00719.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json b/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json new file mode 100644 index 00000000000..b97d65c85d8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q2vq-xj2q-g729/GHSA-q2vq-xj2q-g729.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2vq-xj2q-g729", + "modified": "2023-11-14T21:30:52Z", + "published": "2023-11-14T21:30:52Z", + "aliases": [ + "CVE-2023-28569" + ], + "details": "Information disclosure in WLAN HAL while handling command through WMI interfaces.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28569" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q57g-38pc-jwv8/GHSA-q57g-38pc-jwv8.json b/advisories/unreviewed/2023/11/GHSA-q57g-38pc-jwv8/GHSA-q57g-38pc-jwv8.json new file mode 100644 index 00000000000..122889814c6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q57g-38pc-jwv8/GHSA-q57g-38pc-jwv8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q57g-38pc-jwv8", + "modified": "2023-11-14T21:30:51Z", + "published": "2023-11-14T21:30:51Z", + "aliases": [ + "CVE-2023-5976" + ], + "details": "Improper Access Control in GitHub repository microweber/microweber prior to 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5976" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/commit/bc537ebe235bf9924c6557a46114f5f9557cd16a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2004e4a9-c5f6-406a-89b0-571f808882fa" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T04:24:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q69f-x478-xp8g/GHSA-q69f-x478-xp8g.json b/advisories/unreviewed/2023/11/GHSA-q69f-x478-xp8g/GHSA-q69f-x478-xp8g.json new file mode 100644 index 00000000000..a9b595354a0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q69f-x478-xp8g/GHSA-q69f-x478-xp8g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q69f-x478-xp8g", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-25952" + ], + "details": "Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25952" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q6v6-32hh-pq9p/GHSA-q6v6-32hh-pq9p.json b/advisories/unreviewed/2023/11/GHSA-q6v6-32hh-pq9p/GHSA-q6v6-32hh-pq9p.json index 3fda19ec7a5..2d4af5bd93f 100644 --- a/advisories/unreviewed/2023/11/GHSA-q6v6-32hh-pq9p/GHSA-q6v6-32hh-pq9p.json +++ b/advisories/unreviewed/2023/11/GHSA-q6v6-32hh-pq9p/GHSA-q6v6-32hh-pq9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q6v6-32hh-pq9p", - "modified": "2023-11-07T21:30:24Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2022-46809" ], "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1236" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T17:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-q6w8-c6j3-wwc9/GHSA-q6w8-c6j3-wwc9.json b/advisories/unreviewed/2023/11/GHSA-q6w8-c6j3-wwc9/GHSA-q6w8-c6j3-wwc9.json new file mode 100644 index 00000000000..21e41fbaebf --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q6w8-c6j3-wwc9/GHSA-q6w8-c6j3-wwc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6w8-c6j3-wwc9", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-29262" + ], + "details": "Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29262" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00719.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q84m-vxmr-72ph/GHSA-q84m-vxmr-72ph.json b/advisories/unreviewed/2023/11/GHSA-q84m-vxmr-72ph/GHSA-q84m-vxmr-72ph.json new file mode 100644 index 00000000000..08e7f7d315d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q84m-vxmr-72ph/GHSA-q84m-vxmr-72ph.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q84m-vxmr-72ph", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-34350" + ], + "details": "Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34350" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00941.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q9rq-5hwp-7wq9/GHSA-q9rq-5hwp-7wq9.json b/advisories/unreviewed/2023/11/GHSA-q9rq-5hwp-7wq9/GHSA-q9rq-5hwp-7wq9.json index 74383855406..418ab0758ee 100644 --- a/advisories/unreviewed/2023/11/GHSA-q9rq-5hwp-7wq9/GHSA-q9rq-5hwp-7wq9.json +++ b/advisories/unreviewed/2023/11/GHSA-q9rq-5hwp-7wq9/GHSA-q9rq-5hwp-7wq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q9rq-5hwp-7wq9", - "modified": "2023-11-07T21:30:24Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2022-46803" ], "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1236" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T17:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-qc67-fv9p-fpx5/GHSA-qc67-fv9p-fpx5.json b/advisories/unreviewed/2023/11/GHSA-qc67-fv9p-fpx5/GHSA-qc67-fv9p-fpx5.json new file mode 100644 index 00000000000..0b8d85bd373 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qc67-fv9p-fpx5/GHSA-qc67-fv9p-fpx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc67-fv9p-fpx5", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-29161" + ], + "details": "Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29161" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00900.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qf8h-hpq5-hc5h/GHSA-qf8h-hpq5-hc5h.json b/advisories/unreviewed/2023/11/GHSA-qf8h-hpq5-hc5h/GHSA-qf8h-hpq5-hc5h.json new file mode 100644 index 00000000000..e85b854757d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qf8h-hpq5-hc5h/GHSA-qf8h-hpq5-hc5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf8h-hpq5-hc5h", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-27879" + ], + "details": "Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27879" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00758.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qp5j-mmrp-vj4f/GHSA-qp5j-mmrp-vj4f.json b/advisories/unreviewed/2023/11/GHSA-qp5j-mmrp-vj4f/GHSA-qp5j-mmrp-vj4f.json new file mode 100644 index 00000000000..b8c0a236c30 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qp5j-mmrp-vj4f/GHSA-qp5j-mmrp-vj4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp5j-mmrp-vj4f", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-36860" + ], + "details": "Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36860" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qphr-6rj3-crfc/GHSA-qphr-6rj3-crfc.json b/advisories/unreviewed/2023/11/GHSA-qphr-6rj3-crfc/GHSA-qphr-6rj3-crfc.json new file mode 100644 index 00000000000..a6d5353f61a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qphr-6rj3-crfc/GHSA-qphr-6rj3-crfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qphr-6rj3-crfc", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-38786" + ], + "details": "Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38786" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00843.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qpw8-mj26-5rc9/GHSA-qpw8-mj26-5rc9.json b/advisories/unreviewed/2023/11/GHSA-qpw8-mj26-5rc9/GHSA-qpw8-mj26-5rc9.json new file mode 100644 index 00000000000..4394fb13ebd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qpw8-mj26-5rc9/GHSA-qpw8-mj26-5rc9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpw8-mj26-5rc9", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32662" + ], + "details": "Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32662" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00843.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json b/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json new file mode 100644 index 00000000000..26f2256186e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qq7m-q225-9v82/GHSA-qq7m-q225-9v82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq7m-q225-9v82", + "modified": "2023-11-14T21:30:52Z", + "published": "2023-11-14T21:30:52Z", + "aliases": [ + "CVE-2023-28572" + ], + "details": "Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28572" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json b/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json index 44f037cf815..2c2f24ca611 100644 --- a/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json +++ b/advisories/unreviewed/2023/11/GHSA-qvcf-7rv4-rh36/GHSA-qvcf-7rv4-rh36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvcf-7rv4-rh36", - "modified": "2023-11-06T06:30:27Z", + "modified": "2023-11-14T21:30:50Z", "published": "2023-11-06T06:30:27Z", "aliases": [ "CVE-2023-47253" ], "details": "Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-06T06:15:40Z" diff --git a/advisories/unreviewed/2023/11/GHSA-qvg6-x224-c55m/GHSA-qvg6-x224-c55m.json b/advisories/unreviewed/2023/11/GHSA-qvg6-x224-c55m/GHSA-qvg6-x224-c55m.json new file mode 100644 index 00000000000..03173054929 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qvg6-x224-c55m/GHSA-qvg6-x224-c55m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvg6-x224-c55m", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2021-46758" + ], + "details": "Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-46758" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r2mq-3mfq-2p2w/GHSA-r2mq-3mfq-2p2w.json b/advisories/unreviewed/2023/11/GHSA-r2mq-3mfq-2p2w/GHSA-r2mq-3mfq-2p2w.json new file mode 100644 index 00000000000..585de417dec --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-r2mq-3mfq-2p2w/GHSA-r2mq-3mfq-2p2w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2mq-3mfq-2p2w", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20596" + ], + "details": "Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20596" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7011" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r322-c8vr-qgrp/GHSA-r322-c8vr-qgrp.json b/advisories/unreviewed/2023/11/GHSA-r322-c8vr-qgrp/GHSA-r322-c8vr-qgrp.json new file mode 100644 index 00000000000..b2672c8257e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-r322-c8vr-qgrp/GHSA-r322-c8vr-qgrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r322-c8vr-qgrp", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22337" + ], + "details": "Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22337" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r4ch-3qw4-35q9/GHSA-r4ch-3qw4-35q9.json b/advisories/unreviewed/2023/11/GHSA-r4ch-3qw4-35q9/GHSA-r4ch-3qw4-35q9.json new file mode 100644 index 00000000000..0e1a36179e4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-r4ch-3qw4-35q9/GHSA-r4ch-3qw4-35q9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4ch-3qw4-35q9", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-29165" + ], + "details": "Unquoted search path or element in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29165" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json b/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json new file mode 100644 index 00000000000..daec60ac70e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-r7xg-3gm7-8q8p/GHSA-r7xg-3gm7-8q8p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7xg-3gm7-8q8p", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-23830" + ], + "details": "SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23830" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json b/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json index 2033d48ee24..d18535dcd4a 100644 --- a/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json +++ b/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8cx-47rc-5x49", - "modified": "2023-11-08T21:30:37Z", + "modified": "2023-11-14T21:30:55Z", "published": "2023-11-08T21:30:37Z", "aliases": [ "CVE-2023-47226" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Post Sliders & Post Grids plugin <= 1.0.20 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-rcxc-fhh3-qjq9/GHSA-rcxc-fhh3-qjq9.json b/advisories/unreviewed/2023/11/GHSA-rcxc-fhh3-qjq9/GHSA-rcxc-fhh3-qjq9.json new file mode 100644 index 00000000000..e80b10ec181 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rcxc-fhh3-qjq9/GHSA-rcxc-fhh3-qjq9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcxc-fhh3-qjq9", + "modified": "2023-11-14T21:30:51Z", + "published": "2023-11-14T21:30:51Z", + "aliases": [ + "CVE-2023-40453" + ], + "details": "Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40453" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1916285" + }, + { + "type": "WEB", + "url": "https://github.com/docker/machine/releases" + }, + { + "type": "WEB", + "url": "https://vin01.github.io/piptagole/docker/security/gitlab/docker-machine/2023/07/07/docker-machine-attack-surface.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T04:20:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rh5g-pqg8-7p3x/GHSA-rh5g-pqg8-7p3x.json b/advisories/unreviewed/2023/11/GHSA-rh5g-pqg8-7p3x/GHSA-rh5g-pqg8-7p3x.json new file mode 100644 index 00000000000..50751e54c68 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rh5g-pqg8-7p3x/GHSA-rh5g-pqg8-7p3x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh5g-pqg8-7p3x", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-36396" + ], + "details": "Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36396" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rp4j-f7fp-cgf2/GHSA-rp4j-f7fp-cgf2.json b/advisories/unreviewed/2023/11/GHSA-rp4j-f7fp-cgf2/GHSA-rp4j-f7fp-cgf2.json new file mode 100644 index 00000000000..698d691ec4a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rp4j-f7fp-cgf2/GHSA-rp4j-f7fp-cgf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp4j-f7fp-cgf2", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-29177" + ], + "details": "Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29177" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rqj6-65x2-r2vh/GHSA-rqj6-65x2-r2vh.json b/advisories/unreviewed/2023/11/GHSA-rqj6-65x2-r2vh/GHSA-rqj6-65x2-r2vh.json new file mode 100644 index 00000000000..205f931f024 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rqj6-65x2-r2vh/GHSA-rqj6-65x2-r2vh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqj6-65x2-r2vh", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-46299" + ], + "details": "Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46299" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-691" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rv6j-6cr4-gr5q/GHSA-rv6j-6cr4-gr5q.json b/advisories/unreviewed/2023/11/GHSA-rv6j-6cr4-gr5q/GHSA-rv6j-6cr4-gr5q.json new file mode 100644 index 00000000000..07bf8ab642c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rv6j-6cr4-gr5q/GHSA-rv6j-6cr4-gr5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv6j-6cr4-gr5q", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-22448" + ], + "details": "Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22448" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rx9f-2j6q-9pff/GHSA-rx9f-2j6q-9pff.json b/advisories/unreviewed/2023/11/GHSA-rx9f-2j6q-9pff/GHSA-rx9f-2j6q-9pff.json index eb3e77b5683..2f7b5bb5bf5 100644 --- a/advisories/unreviewed/2023/11/GHSA-rx9f-2j6q-9pff/GHSA-rx9f-2j6q-9pff.json +++ b/advisories/unreviewed/2023/11/GHSA-rx9f-2j6q-9pff/GHSA-rx9f-2j6q-9pff.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rx9f-2j6q-9pff", - "modified": "2023-11-07T21:30:24Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2022-46801" ], "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1236" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T17:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json b/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json new file mode 100644 index 00000000000..a77921fa546 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v246-p8m5-h759/GHSA-v246-p8m5-h759.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v246-p8m5-h759", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-47456" + ], + "details": "Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47456" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1806/fromSetWirelessRepeat.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v2hc-cp84-vjqv/GHSA-v2hc-cp84-vjqv.json b/advisories/unreviewed/2023/11/GHSA-v2hc-cp84-vjqv/GHSA-v2hc-cp84-vjqv.json new file mode 100644 index 00000000000..956c29dc43a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v2hc-cp84-vjqv/GHSA-v2hc-cp84-vjqv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2hc-cp84-vjqv", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20566" + ], + "details": "Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20566" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v325-cfqv-359p/GHSA-v325-cfqv-359p.json b/advisories/unreviewed/2023/11/GHSA-v325-cfqv-359p/GHSA-v325-cfqv-359p.json new file mode 100644 index 00000000000..d084311abce --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v325-cfqv-359p/GHSA-v325-cfqv-359p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v325-cfqv-359p", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28404" + ], + "details": "Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28404" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v3gh-c2m2-h84q/GHSA-v3gh-c2m2-h84q.json b/advisories/unreviewed/2023/11/GHSA-v3gh-c2m2-h84q/GHSA-v3gh-c2m2-h84q.json new file mode 100644 index 00000000000..de27966ef50 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v3gh-c2m2-h84q/GHSA-v3gh-c2m2-h84q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3gh-c2m2-h84q", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-39411" + ], + "details": "Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39411" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v4fc-x53w-j3j2/GHSA-v4fc-x53w-j3j2.json b/advisories/unreviewed/2023/11/GHSA-v4fc-x53w-j3j2/GHSA-v4fc-x53w-j3j2.json new file mode 100644 index 00000000000..02b56ecdb3c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v4fc-x53w-j3j2/GHSA-v4fc-x53w-j3j2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4fc-x53w-j3j2", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-31320" + ], + "details": "Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31320" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v5x9-p45c-rxpc/GHSA-v5x9-p45c-rxpc.json b/advisories/unreviewed/2023/11/GHSA-v5x9-p45c-rxpc/GHSA-v5x9-p45c-rxpc.json new file mode 100644 index 00000000000..2b73191e275 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v5x9-p45c-rxpc/GHSA-v5x9-p45c-rxpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5x9-p45c-rxpc", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-40719" + ], + "details": "A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40719" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json b/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json new file mode 100644 index 00000000000..eb8c5990eba --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vgxm-8jf8-3h3v/GHSA-vgxm-8jf8-3h3v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgxm-8jf8-3h3v", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2021-26345" + ], + "details": "Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26345" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vxpv-jc8r-m85p/GHSA-vxpv-jc8r-m85p.json b/advisories/unreviewed/2023/11/GHSA-vxpv-jc8r-m85p/GHSA-vxpv-jc8r-m85p.json new file mode 100644 index 00000000000..d08cc1e9ff4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vxpv-jc8r-m85p/GHSA-vxpv-jc8r-m85p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxpv-jc8r-m85p", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-34314" + ], + "details": "Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34314" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00943.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w369-f878-vgmj/GHSA-w369-f878-vgmj.json b/advisories/unreviewed/2023/11/GHSA-w369-f878-vgmj/GHSA-w369-f878-vgmj.json new file mode 100644 index 00000000000..9ac2bd457ae --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w369-f878-vgmj/GHSA-w369-f878-vgmj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w369-f878-vgmj", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32283" + ], + "details": "Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32283" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00914.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w499-v3vm-68xq/GHSA-w499-v3vm-68xq.json b/advisories/unreviewed/2023/11/GHSA-w499-v3vm-68xq/GHSA-w499-v3vm-68xq.json new file mode 100644 index 00000000000..182d9e8c5a5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w499-v3vm-68xq/GHSA-w499-v3vm-68xq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w499-v3vm-68xq", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-26222" + ], + "details": "The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26222" + }, + { + "type": "WEB", + "url": "https://www.tibco.com/services/support/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w4pv-p6xf-qc53/GHSA-w4pv-p6xf-qc53.json b/advisories/unreviewed/2023/11/GHSA-w4pv-p6xf-qc53/GHSA-w4pv-p6xf-qc53.json new file mode 100644 index 00000000000..60f21d99854 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w4pv-p6xf-qc53/GHSA-w4pv-p6xf-qc53.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4pv-p6xf-qc53", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-34060" + ], + "details": "VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from\nan older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login\nrestrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . This bypass is not present on port 443 (VCD provider\nand tenant login). On a new installation of VMware Cloud Director Appliance 10.5, the bypass is not present.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34060" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2023-0026.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json b/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json new file mode 100644 index 00000000000..892927aacff --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w776-w5x6-c2xf/GHSA-w776-w5x6-c2xf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w776-w5x6-c2xf", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20565" + ], + "details": "Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20565" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w7qf-3h78-55fp/GHSA-w7qf-3h78-55fp.json b/advisories/unreviewed/2023/11/GHSA-w7qf-3h78-55fp/GHSA-w7qf-3h78-55fp.json new file mode 100644 index 00000000000..a00286b16d3 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w7qf-3h78-55fp/GHSA-w7qf-3h78-55fp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7qf-3h78-55fp", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-27305" + ], + "details": "Incorrect default permissions in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27305" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00864.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w8c8-x4x9-r382/GHSA-w8c8-x4x9-r382.json b/advisories/unreviewed/2023/11/GHSA-w8c8-x4x9-r382/GHSA-w8c8-x4x9-r382.json new file mode 100644 index 00000000000..e59a34428ed --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w8c8-x4x9-r382/GHSA-w8c8-x4x9-r382.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8c8-x4x9-r382", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-32661" + ], + "details": "Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32661" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w8wr-v3q8-68hg/GHSA-w8wr-v3q8-68hg.json b/advisories/unreviewed/2023/11/GHSA-w8wr-v3q8-68hg/GHSA-w8wr-v3q8-68hg.json new file mode 100644 index 00000000000..f78f8d4eb08 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w8wr-v3q8-68hg/GHSA-w8wr-v3q8-68hg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8wr-v3q8-68hg", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42284" + ], + "details": "Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42284" + }, + { + "type": "WEB", + "url": "https://github.com/andreysanyuk/CVE-2023-42284" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wfc8-v3hg-jvrw/GHSA-wfc8-v3hg-jvrw.json b/advisories/unreviewed/2023/11/GHSA-wfc8-v3hg-jvrw/GHSA-wfc8-v3hg-jvrw.json new file mode 100644 index 00000000000..94062082db8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wfc8-v3hg-jvrw/GHSA-wfc8-v3hg-jvrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfc8-v3hg-jvrw", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-26589" + ], + "details": "Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26589" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wh4j-r7mv-vjg8/GHSA-wh4j-r7mv-vjg8.json b/advisories/unreviewed/2023/11/GHSA-wh4j-r7mv-vjg8/GHSA-wh4j-r7mv-vjg8.json new file mode 100644 index 00000000000..5f212974108 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wh4j-r7mv-vjg8/GHSA-wh4j-r7mv-vjg8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh4j-r7mv-vjg8", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28737" + ], + "details": "Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28737" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json b/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json index 5e7a2f6a954..32e10c5dc65 100644 --- a/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json +++ b/advisories/unreviewed/2023/11/GHSA-wpw2-hvhc-r9qq/GHSA-wpw2-hvhc-r9qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpw2-hvhc-r9qq", - "modified": "2023-11-08T09:30:26Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T09:30:26Z", "aliases": [ "CVE-2023-46771" ], "details": "Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T09:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-wr7v-h9p2-5fr6/GHSA-wr7v-h9p2-5fr6.json b/advisories/unreviewed/2023/11/GHSA-wr7v-h9p2-5fr6/GHSA-wr7v-h9p2-5fr6.json index a28c5dea79c..6e846c15e1e 100644 --- a/advisories/unreviewed/2023/11/GHSA-wr7v-h9p2-5fr6/GHSA-wr7v-h9p2-5fr6.json +++ b/advisories/unreviewed/2023/11/GHSA-wr7v-h9p2-5fr6/GHSA-wr7v-h9p2-5fr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wr7v-h9p2-5fr6", - "modified": "2023-11-07T21:30:24Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2022-45810" ], "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce.This issue affects Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce: from n/a through 5.5.2.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1236" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T17:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-wrgh-9hfh-4fqj/GHSA-wrgh-9hfh-4fqj.json b/advisories/unreviewed/2023/11/GHSA-wrgh-9hfh-4fqj/GHSA-wrgh-9hfh-4fqj.json new file mode 100644 index 00000000000..da3876c12aa --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wrgh-9hfh-4fqj/GHSA-wrgh-9hfh-4fqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrgh-9hfh-4fqj", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-38570" + ], + "details": "Access of memory location after end of buffer for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38570" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-788" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json b/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json new file mode 100644 index 00000000000..de15c9d137d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wrmf-3x8w-vcx2/GHSA-wrmf-3x8w-vcx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrmf-3x8w-vcx2", + "modified": "2023-11-14T21:30:59Z", + "published": "2023-11-14T21:30:59Z", + "aliases": [ + "CVE-2022-23821" + ], + "details": "Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23821" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wrv4-h8m2-2rj7/GHSA-wrv4-h8m2-2rj7.json b/advisories/unreviewed/2023/11/GHSA-wrv4-h8m2-2rj7/GHSA-wrv4-h8m2-2rj7.json new file mode 100644 index 00000000000..a635bfd3387 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wrv4-h8m2-2rj7/GHSA-wrv4-h8m2-2rj7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrv4-h8m2-2rj7", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-46301" + ], + "details": "Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46301" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wvq7-fmcr-mvgx/GHSA-wvq7-fmcr-mvgx.json b/advisories/unreviewed/2023/11/GHSA-wvq7-fmcr-mvgx/GHSA-wvq7-fmcr-mvgx.json new file mode 100644 index 00000000000..7dea6b52020 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wvq7-fmcr-mvgx/GHSA-wvq7-fmcr-mvgx.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvq7-fmcr-mvgx", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5703" + ], + "details": "The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'giftup' shortcode in all versions up to, and including, 2.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5703" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gift-up/tags/2.20.1/view/giftup-checkout.php#L46" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gift-up/tags/2.20.1/view/giftup-checkout.php#L48" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2989802/gift-up#file3" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4e498706-3dbe-4c48-9c0d-0d90677aba0d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x45c-39pv-5956/GHSA-x45c-39pv-5956.json b/advisories/unreviewed/2023/11/GHSA-x45c-39pv-5956/GHSA-x45c-39pv-5956.json new file mode 100644 index 00000000000..8ee11cf4619 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x45c-39pv-5956/GHSA-x45c-39pv-5956.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x45c-39pv-5956", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-41700" + ], + "details": "Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41700" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-277" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json b/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json new file mode 100644 index 00000000000..19d6ae68b1e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x4vh-ch66-jvcq/GHSA-x4vh-ch66-jvcq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4vh-ch66-jvcq", + "modified": "2023-11-14T21:30:52Z", + "published": "2023-11-14T21:30:52Z", + "aliases": [ + "CVE-2023-33031" + ], + "details": "Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33031" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x4wr-fpxp-h8c3/GHSA-x4wr-fpxp-h8c3.json b/advisories/unreviewed/2023/11/GHSA-x4wr-fpxp-h8c3/GHSA-x4wr-fpxp-h8c3.json new file mode 100644 index 00000000000..dfe688ea3d7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x4wr-fpxp-h8c3/GHSA-x4wr-fpxp-h8c3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4wr-fpxp-h8c3", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5659" + ], + "details": "The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interact-quiz' shortcode in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5659" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/interact-quiz-embed/tags/3.0.7/interact-quiz-embed.php#L53" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/69ba1a39-ddb0-4661-8104-d8bb71710e0c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json b/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json index 0c454adbe34..b371a78d888 100644 --- a/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json +++ b/advisories/unreviewed/2023/11/GHSA-x5jv-p8vx-9cmf/GHSA-x5jv-p8vx-9cmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x5jv-p8vx-9cmf", - "modified": "2023-11-08T09:30:26Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-08T09:30:26Z", "aliases": [ "CVE-2023-44098" ], "details": "Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-311" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T09:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-x6h4-x9x4-vf9g/GHSA-x6h4-x9x4-vf9g.json b/advisories/unreviewed/2023/11/GHSA-x6h4-x9x4-vf9g/GHSA-x6h4-x9x4-vf9g.json new file mode 100644 index 00000000000..2f356e58682 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x6h4-x9x4-vf9g/GHSA-x6h4-x9x4-vf9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6h4-x9x4-vf9g", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-27519" + ], + "details": "Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27519" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00758.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x8q6-xr39-6p4c/GHSA-x8q6-xr39-6p4c.json b/advisories/unreviewed/2023/11/GHSA-x8q6-xr39-6p4c/GHSA-x8q6-xr39-6p4c.json new file mode 100644 index 00000000000..662b14db6a8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x8q6-xr39-6p4c/GHSA-x8q6-xr39-6p4c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8q6-xr39-6p4c", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-47533" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Countdown and CountUp, WooCommerce Sales Timer plugin <= 1.8.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47533" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/countdown-wpdevart-extended/wordpress-countdown-and-countup-woocommerce-sales-timer-plugin-1-8-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json b/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json new file mode 100644 index 00000000000..bae73a93c4c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x8xw-jc3c-cx53/GHSA-x8xw-jc3c-cx53.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8xw-jc3c-cx53", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2023-20567" + ], + "details": "Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20567" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x935-fw35-6fjh/GHSA-x935-fw35-6fjh.json b/advisories/unreviewed/2023/11/GHSA-x935-fw35-6fjh/GHSA-x935-fw35-6fjh.json new file mode 100644 index 00000000000..565ea0099df --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x935-fw35-6fjh/GHSA-x935-fw35-6fjh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x935-fw35-6fjh", + "modified": "2023-11-14T21:30:54Z", + "published": "2023-11-14T21:30:54Z", + "aliases": [ + "CVE-2023-5661" + ], + "details": "The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcode in all versions up to, and including, 1.5.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5661" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/add-facebook/tags/1.5.4.6/public/templates/default/template.php#L417" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8b145772-624e-4af0-9156-03c483bf8381?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x9c2-rmrg-4h96/GHSA-x9c2-rmrg-4h96.json b/advisories/unreviewed/2023/11/GHSA-x9c2-rmrg-4h96/GHSA-x9c2-rmrg-4h96.json new file mode 100644 index 00000000000..76327d6af89 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x9c2-rmrg-4h96/GHSA-x9c2-rmrg-4h96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9c2-rmrg-4h96", + "modified": "2023-11-14T21:31:00Z", + "published": "2023-11-14T21:31:00Z", + "aliases": [ + "CVE-2022-45109" + ], + "details": "Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45109" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00963.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-665" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xj2m-wgjq-qpmc/GHSA-xj2m-wgjq-qpmc.json b/advisories/unreviewed/2023/11/GHSA-xj2m-wgjq-qpmc/GHSA-xj2m-wgjq-qpmc.json new file mode 100644 index 00000000000..73a73ce01e5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xj2m-wgjq-qpmc/GHSA-xj2m-wgjq-qpmc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj2m-wgjq-qpmc", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-42539" + ], + "details": "PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42539" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xmm7-2j6p-p24v/GHSA-xmm7-2j6p-p24v.json b/advisories/unreviewed/2023/11/GHSA-xmm7-2j6p-p24v/GHSA-xmm7-2j6p-p24v.json new file mode 100644 index 00000000000..4db97c571b4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xmm7-2j6p-p24v/GHSA-xmm7-2j6p-p24v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmm7-2j6p-p24v", + "modified": "2023-11-14T21:31:02Z", + "published": "2023-11-14T21:31:02Z", + "aliases": [ + "CVE-2023-40220" + ], + "details": "Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40220" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json b/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json new file mode 100644 index 00000000000..c98e6136482 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xq75-p9cv-wvw7/GHSA-xq75-p9cv-wvw7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq75-p9cv-wvw7", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-33047" + ], + "details": "Transient DOS in WLAN Firmware while parsing no-inherit IES.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33047" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xrh2-77qw-v55j/GHSA-xrh2-77qw-v55j.json b/advisories/unreviewed/2023/11/GHSA-xrh2-77qw-v55j/GHSA-xrh2-77qw-v55j.json new file mode 100644 index 00000000000..3cc4b6c710d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xrh2-77qw-v55j/GHSA-xrh2-77qw-v55j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrh2-77qw-v55j", + "modified": "2023-11-14T21:31:03Z", + "published": "2023-11-14T21:31:03Z", + "aliases": [ + "CVE-2023-47547" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/export-woocommerce/wordpress-products-order-customers-export-for-woocommerce-plugin-2-0-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json b/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json new file mode 100644 index 00000000000..96d32deb93d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xvfh-vpm8-j2fh/GHSA-xvfh-vpm8-j2fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvfh-vpm8-j2fh", + "modified": "2023-11-14T21:30:53Z", + "published": "2023-11-14T21:30:53Z", + "aliases": [ + "CVE-2023-33055" + ], + "details": "Memory Corruption in Audio while invoking callback function in driver from ADSP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33055" + }, + { + "type": "WEB", + "url": "https://www.qualcomm.com/company/product-security/bulletins/november-2023-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xx54-mvr7-rhfj/GHSA-xx54-mvr7-rhfj.json b/advisories/unreviewed/2023/11/GHSA-xx54-mvr7-rhfj/GHSA-xx54-mvr7-rhfj.json index 02f060ff5ac..e4ab89461f8 100644 --- a/advisories/unreviewed/2023/11/GHSA-xx54-mvr7-rhfj/GHSA-xx54-mvr7-rhfj.json +++ b/advisories/unreviewed/2023/11/GHSA-xx54-mvr7-rhfj/GHSA-xx54-mvr7-rhfj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx54-mvr7-rhfj", - "modified": "2023-11-07T21:30:24Z", + "modified": "2023-11-14T21:30:54Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2022-46804" ], "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in Narola Infotech Solutions LLP Export Users Data Distinct.This issue affects Export Users Data Distinct: from n/a through 1.3.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-07T17:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-xxvq-wr93-6r58/GHSA-xxvq-wr93-6r58.json b/advisories/unreviewed/2023/11/GHSA-xxvq-wr93-6r58/GHSA-xxvq-wr93-6r58.json new file mode 100644 index 00000000000..88b4edebf61 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xxvq-wr93-6r58/GHSA-xxvq-wr93-6r58.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxvq-wr93-6r58", + "modified": "2023-11-14T21:31:01Z", + "published": "2023-11-14T21:31:01Z", + "aliases": [ + "CVE-2023-28741" + ], + "details": "Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28741" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00861.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-14T19:15:23Z" + } +} \ No newline at end of file