From 35295b5035e4fc711f07c0678c1f5a003d74e5f7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 8 Jan 2024 21:32:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-24x8-275w-hwpr.json | 35 ++++++++++++ .../GHSA-2g38-fxhq-9w3p.json | 35 ++++++++++++ .../GHSA-3fm4-698v-g632.json | 39 ++++++++++++++ .../GHSA-44qm-928x-6p3g.json | 3 +- .../GHSA-4gcw-p8mg-cmch.json | 38 +++++++++++++ .../GHSA-4q33-wj3r-p79q.json | 2 +- .../GHSA-5f35-x73c-jq69.json | 54 +++++++++++++++++++ .../GHSA-5g4j-2gfr-rxr3.json | 38 +++++++++++++ .../GHSA-5rfq-95qv-rxwp.json | 11 ++-- .../GHSA-5w5c-6hmq-mgpr.json | 2 +- .../GHSA-65ph-fjq3-j5hx.json | 38 +++++++++++++ .../GHSA-6hc7-6677-28mx.json | 38 +++++++++++++ .../GHSA-6xcx-h3hh-6q6h.json | 39 ++++++++++++++ .../GHSA-769h-g9v6-cwg7.json | 46 ++++++++++++++++ .../GHSA-7p5c-pch3-5mg6.json | 46 ++++++++++++++++ .../GHSA-7pjg-9jch-7gjc.json | 38 +++++++++++++ .../GHSA-7qh3-wv79-v2r6.json | 35 ++++++++++++ .../GHSA-835p-c6x8-xh5f.json | 3 +- .../GHSA-83wx-v283-85g9.json | 11 ++-- .../GHSA-877p-v8mm-jqg9.json | 39 ++++++++++++++ .../GHSA-89vh-9hfj-x469.json | 11 ++-- .../GHSA-8cpj-q267-9h4x.json | 39 ++++++++++++++ .../GHSA-9243-gh96-v7h6.json | 35 ++++++++++++ .../GHSA-95jv-pcxp-g9qj.json | 35 ++++++++++++ .../GHSA-9954-329g-42vc.json | 38 +++++++++++++ .../GHSA-9vwj-7j5p-7q44.json | 38 +++++++++++++ .../GHSA-c87c-56pw-mwgh.json | 11 ++-- .../GHSA-cv8x-5cww-p4pf.json | 2 +- .../GHSA-f8j7-qgh6-xg5f.json | 38 +++++++++++++ .../GHSA-fwrh-jr8g-7mf2.json | 35 ++++++++++++ .../GHSA-g554-v8g8-hm96.json | 38 +++++++++++++ .../GHSA-gf8x-c888-36h7.json | 2 +- .../GHSA-gg47-6mxg-9jcv.json | 38 +++++++++++++ .../GHSA-gh6x-qpj6-x25r.json | 38 +++++++++++++ .../GHSA-ghcj-p98x-79p3.json | 38 +++++++++++++ .../GHSA-gm6c-33w6-46gc.json | 35 ++++++++++++ .../GHSA-gq65-6w6h-w9gj.json | 38 +++++++++++++ .../GHSA-gqr9-4fcc-c9jq.json | 11 ++-- .../GHSA-gwm5-99v5-pwf9.json | 38 +++++++++++++ .../GHSA-hfgf-j9pj-wg8w.json | 38 +++++++++++++ .../GHSA-jjjw-x8pv-g64q.json | 9 ++-- .../GHSA-jp26-vw47-9r58.json | 35 ++++++++++++ .../GHSA-m866-4h9x-6c44.json | 35 ++++++++++++ .../GHSA-mqv9-v5xg-xp9h.json | 35 ++++++++++++ .../GHSA-p288-w88f-r2qg.json | 35 ++++++++++++ .../GHSA-p5jr-rfj3-98f5.json | 11 ++-- .../GHSA-p6wf-q8mw-wpwr.json | 38 +++++++++++++ .../GHSA-pcwc-j2m8-3j5j.json | 46 ++++++++++++++++ .../GHSA-pfp2-75wj-3h2f.json | 35 ++++++++++++ .../GHSA-pmx3-5c86-vxfm.json | 35 ++++++++++++ .../GHSA-q7rh-w25v-mpj8.json | 42 +++++++++++++++ .../GHSA-q942-jjg3-5jhx.json | 35 ++++++++++++ .../GHSA-qmm7-7fgh-3877.json | 38 +++++++++++++ .../GHSA-qwm2-x6hp-6h68.json | 2 +- .../GHSA-r2px-vqx2-ww27.json | 38 +++++++++++++ .../GHSA-r67f-8hjg-55w3.json | 39 ++++++++++++++ .../GHSA-r7v9-5wqr-cqv8.json | 38 +++++++++++++ .../GHSA-rm8m-fq9m-823j.json | 35 ++++++++++++ .../GHSA-rmpv-5qmj-3fgc.json | 2 +- .../GHSA-w23w-39xh-22v5.json | 35 ++++++++++++ .../GHSA-w8x8-g534-x4rp.json | 11 ++-- .../GHSA-wc7m-mx46-8xfv.json | 38 +++++++++++++ .../GHSA-x8v8-8hj9-w975.json | 38 +++++++++++++ .../GHSA-xcwv-4qfh-f8xj.json | 38 +++++++++++++ .../GHSA-xjh6-43fr-h892.json | 35 ++++++++++++ 65 files changed, 1925 insertions(+), 39 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-24x8-275w-hwpr/GHSA-24x8-275w-hwpr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-2g38-fxhq-9w3p/GHSA-2g38-fxhq-9w3p.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3fm4-698v-g632/GHSA-3fm4-698v-g632.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4gcw-p8mg-cmch/GHSA-4gcw-p8mg-cmch.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5f35-x73c-jq69/GHSA-5f35-x73c-jq69.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5g4j-2gfr-rxr3/GHSA-5g4j-2gfr-rxr3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-65ph-fjq3-j5hx/GHSA-65ph-fjq3-j5hx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6hc7-6677-28mx/GHSA-6hc7-6677-28mx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6xcx-h3hh-6q6h/GHSA-6xcx-h3hh-6q6h.json create mode 100644 advisories/unreviewed/2024/01/GHSA-769h-g9v6-cwg7/GHSA-769h-g9v6-cwg7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7pjg-9jch-7gjc/GHSA-7pjg-9jch-7gjc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7qh3-wv79-v2r6/GHSA-7qh3-wv79-v2r6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-877p-v8mm-jqg9/GHSA-877p-v8mm-jqg9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-8cpj-q267-9h4x/GHSA-8cpj-q267-9h4x.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9243-gh96-v7h6/GHSA-9243-gh96-v7h6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-95jv-pcxp-g9qj/GHSA-95jv-pcxp-g9qj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9vwj-7j5p-7q44/GHSA-9vwj-7j5p-7q44.json create mode 100644 advisories/unreviewed/2024/01/GHSA-f8j7-qgh6-xg5f/GHSA-f8j7-qgh6-xg5f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fwrh-jr8g-7mf2/GHSA-fwrh-jr8g-7mf2.json create mode 100644 advisories/unreviewed/2024/01/GHSA-g554-v8g8-hm96/GHSA-g554-v8g8-hm96.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gg47-6mxg-9jcv/GHSA-gg47-6mxg-9jcv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json create mode 100644 advisories/unreviewed/2024/01/GHSA-ghcj-p98x-79p3/GHSA-ghcj-p98x-79p3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gm6c-33w6-46gc/GHSA-gm6c-33w6-46gc.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gq65-6w6h-w9gj/GHSA-gq65-6w6h-w9gj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gwm5-99v5-pwf9/GHSA-gwm5-99v5-pwf9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hfgf-j9pj-wg8w/GHSA-hfgf-j9pj-wg8w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jp26-vw47-9r58/GHSA-jp26-vw47-9r58.json create mode 100644 advisories/unreviewed/2024/01/GHSA-m866-4h9x-6c44/GHSA-m866-4h9x-6c44.json create mode 100644 advisories/unreviewed/2024/01/GHSA-mqv9-v5xg-xp9h/GHSA-mqv9-v5xg-xp9h.json create mode 100644 advisories/unreviewed/2024/01/GHSA-p288-w88f-r2qg/GHSA-p288-w88f-r2qg.json create mode 100644 advisories/unreviewed/2024/01/GHSA-p6wf-q8mw-wpwr/GHSA-p6wf-q8mw-wpwr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pcwc-j2m8-3j5j/GHSA-pcwc-j2m8-3j5j.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pfp2-75wj-3h2f/GHSA-pfp2-75wj-3h2f.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pmx3-5c86-vxfm/GHSA-pmx3-5c86-vxfm.json create mode 100644 advisories/unreviewed/2024/01/GHSA-q7rh-w25v-mpj8/GHSA-q7rh-w25v-mpj8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-q942-jjg3-5jhx/GHSA-q942-jjg3-5jhx.json create mode 100644 advisories/unreviewed/2024/01/GHSA-qmm7-7fgh-3877/GHSA-qmm7-7fgh-3877.json create mode 100644 advisories/unreviewed/2024/01/GHSA-r2px-vqx2-ww27/GHSA-r2px-vqx2-ww27.json create mode 100644 advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json create mode 100644 advisories/unreviewed/2024/01/GHSA-r7v9-5wqr-cqv8/GHSA-r7v9-5wqr-cqv8.json create mode 100644 advisories/unreviewed/2024/01/GHSA-rm8m-fq9m-823j/GHSA-rm8m-fq9m-823j.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w23w-39xh-22v5/GHSA-w23w-39xh-22v5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-wc7m-mx46-8xfv/GHSA-wc7m-mx46-8xfv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-x8v8-8hj9-w975/GHSA-x8v8-8hj9-w975.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xcwv-4qfh-f8xj/GHSA-xcwv-4qfh-f8xj.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xjh6-43fr-h892/GHSA-xjh6-43fr-h892.json diff --git a/advisories/unreviewed/2024/01/GHSA-24x8-275w-hwpr/GHSA-24x8-275w-hwpr.json b/advisories/unreviewed/2024/01/GHSA-24x8-275w-hwpr/GHSA-24x8-275w-hwpr.json new file mode 100644 index 00000000000..ef8810c6425 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-24x8-275w-hwpr/GHSA-24x8-275w-hwpr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24x8-275w-hwpr", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6383" + ], + "details": "The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6383" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eae63103-3de6-4100-8f48-2bcf9a5c91fb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2g38-fxhq-9w3p/GHSA-2g38-fxhq-9w3p.json b/advisories/unreviewed/2024/01/GHSA-2g38-fxhq-9w3p/GHSA-2g38-fxhq-9w3p.json new file mode 100644 index 00000000000..3bad9a1f04d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2g38-fxhq-9w3p/GHSA-2g38-fxhq-9w3p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g38-fxhq-9w3p", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6505" + ], + "details": "The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6505" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eca6f099-6af0-4f42-aade-ab61dd792629" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3fm4-698v-g632/GHSA-3fm4-698v-g632.json b/advisories/unreviewed/2024/01/GHSA-3fm4-698v-g632/GHSA-3fm4-698v-g632.json new file mode 100644 index 00000000000..1c7e89c5249 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3fm4-698v-g632/GHSA-3fm4-698v-g632.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fm4-698v-g632", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-51246" + ], + "details": "A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51246" + }, + { + "type": "WEB", + "url": "https://github.com/NING0121/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://gist.github.com/NING0121/25498c5326c2590423b26ace38d2cf39" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json b/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json index fd158212d4d..364465b4cc1 100644 --- a/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json +++ b/advisories/unreviewed/2024/01/GHSA-44qm-928x-6p3g/GHSA-44qm-928x-6p3g.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-4gcw-p8mg-cmch/GHSA-4gcw-p8mg-cmch.json b/advisories/unreviewed/2024/01/GHSA-4gcw-p8mg-cmch/GHSA-4gcw-p8mg-cmch.json new file mode 100644 index 00000000000..002cd64a3f5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4gcw-p8mg-cmch/GHSA-4gcw-p8mg-cmch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gcw-p8mg-cmch", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-51406" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51406" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fastdup/wordpress-fastdup-plugin-2-1-7-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json b/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json index 558e3655d47..98d53cd9a2b 100644 --- a/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json +++ b/advisories/unreviewed/2024/01/GHSA-4q33-wj3r-p79q/GHSA-4q33-wj3r-p79q.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-5f35-x73c-jq69/GHSA-5f35-x73c-jq69.json b/advisories/unreviewed/2024/01/GHSA-5f35-x73c-jq69/GHSA-5f35-x73c-jq69.json new file mode 100644 index 00000000000..ea83a88f1cc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5f35-x73c-jq69/GHSA-5f35-x73c-jq69.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f35-x73c-jq69", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-1032" + ], + "details": "The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1032" + }, + { + "type": "WEB", + "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1032" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-5977-1" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-6024-1" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-6033-1" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/03/13/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5g4j-2gfr-rxr3/GHSA-5g4j-2gfr-rxr3.json b/advisories/unreviewed/2024/01/GHSA-5g4j-2gfr-rxr3/GHSA-5g4j-2gfr-rxr3.json new file mode 100644 index 00000000000..a2a189d7233 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5g4j-2gfr-rxr3/GHSA-5g4j-2gfr-rxr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g4j-2gfr-rxr3", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-52190" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52190" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/coupon-referral-program/wordpress-coupon-referral-program-plugin-1-7-2-unauthenticated-sensitive-data-pii-coupon-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json b/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json index 246a93be21d..d0c2a2982b1 100644 --- a/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json +++ b/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rfq-95qv-rxwp", - "modified": "2024-01-02T21:30:26Z", + "modified": "2024-01-08T21:30:32Z", "published": "2024-01-02T21:30:26Z", "aliases": [ "CVE-2023-45893" ], "details": "An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json b/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json index 7fae7f5f9cf..4f44ae7393e 100644 --- a/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json +++ b/advisories/unreviewed/2024/01/GHSA-5w5c-6hmq-mgpr/GHSA-5w5c-6hmq-mgpr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-65ph-fjq3-j5hx/GHSA-65ph-fjq3-j5hx.json b/advisories/unreviewed/2024/01/GHSA-65ph-fjq3-j5hx/GHSA-65ph-fjq3-j5hx.json new file mode 100644 index 00000000000..26e3bb98dd0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-65ph-fjq3-j5hx/GHSA-65ph-fjq3-j5hx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65ph-fjq3-j5hx", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-52208" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52208" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/constant-contact-forms/wordpress-constant-contact-forms-plugin-2-4-2-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6hc7-6677-28mx/GHSA-6hc7-6677-28mx.json b/advisories/unreviewed/2024/01/GHSA-6hc7-6677-28mx/GHSA-6hc7-6677-28mx.json new file mode 100644 index 00000000000..d87e0ffd188 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6hc7-6677-28mx/GHSA-6hc7-6677-28mx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hc7-6677-28mx", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52216" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52216" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/js-css-script-optimizer/wordpress-js-css-script-optimizer-plugin-0-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6xcx-h3hh-6q6h/GHSA-6xcx-h3hh-6q6h.json b/advisories/unreviewed/2024/01/GHSA-6xcx-h3hh-6q6h/GHSA-6xcx-h3hh-6q6h.json new file mode 100644 index 00000000000..d5b25c566f7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6xcx-h3hh-6q6h/GHSA-6xcx-h3hh-6q6h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xcx-h3hh-6q6h", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6532" + ], + "details": "The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6532" + }, + { + "type": "WEB", + "url": "https://magos-securitas.com/txt/CVE-2023-6532.txt" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/05a730bc-2d72-49e3-a608-e4390b19e97f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-769h-g9v6-cwg7/GHSA-769h-g9v6-cwg7.json b/advisories/unreviewed/2024/01/GHSA-769h-g9v6-cwg7/GHSA-769h-g9v6-cwg7.json new file mode 100644 index 00000000000..39e207544dd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-769h-g9v6-cwg7/GHSA-769h-g9v6-cwg7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-769h-g9v6-cwg7", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2021-3600" + ], + "details": "It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3600" + }, + { + "type": "WEB", + "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3600" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/linus/e88b2c6e5a4d9ce30d75391e4d950da74bb2bd90" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-5003-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json b/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json new file mode 100644 index 00000000000..395d1571035 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7p5c-pch3-5mg6/GHSA-7p5c-pch3-5mg6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p5c-pch3-5mg6", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-50982" + ], + "details": "Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50982" + }, + { + "type": "WEB", + "url": "https://gitlab.studip.de/studip/studip/-/tags" + }, + { + "type": "WEB", + "url": "https://rehmeinfosec.de/labor/cve-2023-50982" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/projects/studip/files/Stud.IP/5.4/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7pjg-9jch-7gjc/GHSA-7pjg-9jch-7gjc.json b/advisories/unreviewed/2024/01/GHSA-7pjg-9jch-7gjc/GHSA-7pjg-9jch-7gjc.json new file mode 100644 index 00000000000..6bc70731fe5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7pjg-9jch-7gjc/GHSA-7pjg-9jch-7gjc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pjg-9jch-7gjc", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52196" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52196" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cpt-bootstrap-carousel/wordpress-cpt-bootstrap-carousel-plugin-1-12-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7qh3-wv79-v2r6/GHSA-7qh3-wv79-v2r6.json b/advisories/unreviewed/2024/01/GHSA-7qh3-wv79-v2r6/GHSA-7qh3-wv79-v2r6.json new file mode 100644 index 00000000000..4cc87e667b7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7qh3-wv79-v2r6/GHSA-7qh3-wv79-v2r6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qh3-wv79-v2r6", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-5235" + ], + "details": "The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow attackers with a subscriber+ account to update blog options, such as 'users_can_register' and 'default_role'. It also unserializes user input in the process, which may lead to Object Injection attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5235" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/35c9a954-37fc-4818-a71f-34aaaa0fa3db" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-835p-c6x8-xh5f/GHSA-835p-c6x8-xh5f.json b/advisories/unreviewed/2024/01/GHSA-835p-c6x8-xh5f/GHSA-835p-c6x8-xh5f.json index f13ec6b2875..89aa1582f51 100644 --- a/advisories/unreviewed/2024/01/GHSA-835p-c6x8-xh5f/GHSA-835p-c6x8-xh5f.json +++ b/advisories/unreviewed/2024/01/GHSA-835p-c6x8-xh5f/GHSA-835p-c6x8-xh5f.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-83wx-v283-85g9/GHSA-83wx-v283-85g9.json b/advisories/unreviewed/2024/01/GHSA-83wx-v283-85g9/GHSA-83wx-v283-85g9.json index 72c2160c8f0..2ba7444cde3 100644 --- a/advisories/unreviewed/2024/01/GHSA-83wx-v283-85g9/GHSA-83wx-v283-85g9.json +++ b/advisories/unreviewed/2024/01/GHSA-83wx-v283-85g9/GHSA-83wx-v283-85g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-83wx-v283-85g9", - "modified": "2024-01-04T03:30:39Z", + "modified": "2024-01-08T21:30:33Z", "published": "2024-01-04T03:30:39Z", "aliases": [ "CVE-2024-0224" ], "details": "Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T02:15:29Z" diff --git a/advisories/unreviewed/2024/01/GHSA-877p-v8mm-jqg9/GHSA-877p-v8mm-jqg9.json b/advisories/unreviewed/2024/01/GHSA-877p-v8mm-jqg9/GHSA-877p-v8mm-jqg9.json new file mode 100644 index 00000000000..d196e533dd7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-877p-v8mm-jqg9/GHSA-877p-v8mm-jqg9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-877p-v8mm-jqg9", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6627" + ], + "details": "The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6627" + }, + { + "type": "WEB", + "url": "https://wpscan.com/blog/stored-xss-fixed-in-wp-go-maps-9-0-28/" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f5687d0e-98ca-4449-98d6-7170c97c8f54" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json b/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json index 86ed55461b7..6c6d479dccd 100644 --- a/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json +++ b/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89vh-9hfj-x469", - "modified": "2024-01-02T21:30:26Z", + "modified": "2024-01-08T21:30:32Z", "published": "2024-01-02T21:30:26Z", "aliases": [ "CVE-2023-47458" ], "details": "An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8cpj-q267-9h4x/GHSA-8cpj-q267-9h4x.json b/advisories/unreviewed/2024/01/GHSA-8cpj-q267-9h4x/GHSA-8cpj-q267-9h4x.json new file mode 100644 index 00000000000..545fb70711a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8cpj-q267-9h4x/GHSA-8cpj-q267-9h4x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cpj-q267-9h4x", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6845" + ], + "details": "The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6845" + }, + { + "type": "WEB", + "url": "https://magos-securitas.com/txt/2023-6845" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cbdaf158-f277-4be4-b022-68d18dae4c55" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9243-gh96-v7h6/GHSA-9243-gh96-v7h6.json b/advisories/unreviewed/2024/01/GHSA-9243-gh96-v7h6/GHSA-9243-gh96-v7h6.json new file mode 100644 index 00000000000..ef52050d70d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9243-gh96-v7h6/GHSA-9243-gh96-v7h6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9243-gh96-v7h6", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-49961" + ], + "details": "WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49961" + }, + { + "type": "WEB", + "url": "https://www.wallix.com/support/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-95jv-pcxp-g9qj/GHSA-95jv-pcxp-g9qj.json b/advisories/unreviewed/2024/01/GHSA-95jv-pcxp-g9qj/GHSA-95jv-pcxp-g9qj.json new file mode 100644 index 00000000000..a75874a1c51 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-95jv-pcxp-g9qj/GHSA-95jv-pcxp-g9qj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95jv-pcxp-g9qj", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6529" + ], + "details": "The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6529" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c36314c1-a2c0-4816-93c9-e61f9cf7f27a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json b/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json new file mode 100644 index 00000000000..99ab1c8234e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9954-329g-42vc/GHSA-9954-329g-42vc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9954-329g-42vc", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-51408" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue affects WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce: from n/a through 1.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51408" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-optin-wheel/wordpress-wp-optin-wheel-plugin-1-4-3-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9vwj-7j5p-7q44/GHSA-9vwj-7j5p-7q44.json b/advisories/unreviewed/2024/01/GHSA-9vwj-7j5p-7q44/GHSA-9vwj-7j5p-7q44.json new file mode 100644 index 00000000000..ac35d853f58 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9vwj-7j5p-7q44/GHSA-9vwj-7j5p-7q44.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vwj-7j5p-7q44", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52213" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows Reflected XSS.This issue affects Rate Star Review – AJAX Reviews for Content, with Star Ratings: from n/a through 1.5.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rate-star-review/wordpress-rate-star-review-plugin-1-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c87c-56pw-mwgh/GHSA-c87c-56pw-mwgh.json b/advisories/unreviewed/2024/01/GHSA-c87c-56pw-mwgh/GHSA-c87c-56pw-mwgh.json index 8f0f526c41f..191c7ea5d03 100644 --- a/advisories/unreviewed/2024/01/GHSA-c87c-56pw-mwgh/GHSA-c87c-56pw-mwgh.json +++ b/advisories/unreviewed/2024/01/GHSA-c87c-56pw-mwgh/GHSA-c87c-56pw-mwgh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c87c-56pw-mwgh", - "modified": "2024-01-04T03:30:38Z", + "modified": "2024-01-08T21:30:33Z", "published": "2024-01-04T03:30:38Z", "aliases": [ "CVE-2024-0222" ], "details": "Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T02:15:28Z" diff --git a/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json b/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json index f68b3558390..d5eb5caf3df 100644 --- a/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json +++ b/advisories/unreviewed/2024/01/GHSA-cv8x-5cww-p4pf/GHSA-cv8x-5cww-p4pf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-f8j7-qgh6-xg5f/GHSA-f8j7-qgh6-xg5f.json b/advisories/unreviewed/2024/01/GHSA-f8j7-qgh6-xg5f/GHSA-f8j7-qgh6-xg5f.json new file mode 100644 index 00000000000..5787d2465e6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f8j7-qgh6-xg5f/GHSA-f8j7-qgh6-xg5f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8j7-qgh6-xg5f", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52205" + ], + "details": "Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52205" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/html5-soundcloud-player-with-playlist/wordpress-html5-soundcloud-player-plugin-2-8-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fwrh-jr8g-7mf2/GHSA-fwrh-jr8g-7mf2.json b/advisories/unreviewed/2024/01/GHSA-fwrh-jr8g-7mf2/GHSA-fwrh-jr8g-7mf2.json new file mode 100644 index 00000000000..a4cdd8422ca --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fwrh-jr8g-7mf2/GHSA-fwrh-jr8g-7mf2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwrh-jr8g-7mf2", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6555" + ], + "details": "The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6555" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/58803934-dbd3-422d-88e7-ebbc5e8c0886" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g554-v8g8-hm96/GHSA-g554-v8g8-hm96.json b/advisories/unreviewed/2024/01/GHSA-g554-v8g8-hm96/GHSA-g554-v8g8-hm96.json new file mode 100644 index 00000000000..36819115846 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g554-v8g8-hm96/GHSA-g554-v8g8-hm96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g554-v8g8-hm96", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52197" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click Protection: from n/a through 1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52197" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ads-invalid-click-protection/wordpress-ads-invalid-click-protection-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json b/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json index a0d853d665e..08eb7ce1e66 100644 --- a/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json +++ b/advisories/unreviewed/2024/01/GHSA-gf8x-c888-36h7/GHSA-gf8x-c888-36h7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-gg47-6mxg-9jcv/GHSA-gg47-6mxg-9jcv.json b/advisories/unreviewed/2024/01/GHSA-gg47-6mxg-9jcv/GHSA-gg47-6mxg-9jcv.json new file mode 100644 index 00000000000..7e8a226ba19 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gg47-6mxg-9jcv/GHSA-gg47-6mxg-9jcv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg47-6mxg-9jcv", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52200" + ], + "details": "Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: n/a.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52200" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-lite-plugin-4-0-22-cross-site-request-forgery-csrf-to-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json b/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json new file mode 100644 index 00000000000..913d137c52d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gh6x-qpj6-x25r/GHSA-gh6x-qpj6-x25r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh6x-qpj6-x25r", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-51490" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security – Malware Scanner, Login Security & Firewall: from n/a through 4.1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-4-1-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-ghcj-p98x-79p3/GHSA-ghcj-p98x-79p3.json b/advisories/unreviewed/2024/01/GHSA-ghcj-p98x-79p3/GHSA-ghcj-p98x-79p3.json new file mode 100644 index 00000000000..0aa5cea97ef --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-ghcj-p98x-79p3/GHSA-ghcj-p98x-79p3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghcj-p98x-79p3", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52202" + ], + "details": "Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52202" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/html5-mp3-player-with-mp3-folder-feedburner-playlist/wordpress-html5-mp3-player-with-folder-feedburner-plugin-2-8-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gm6c-33w6-46gc/GHSA-gm6c-33w6-46gc.json b/advisories/unreviewed/2024/01/GHSA-gm6c-33w6-46gc/GHSA-gm6c-33w6-46gc.json new file mode 100644 index 00000000000..937a475afb1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gm6c-33w6-46gc/GHSA-gm6c-33w6-46gc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm6c-33w6-46gc", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6139" + ], + "details": "The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6139" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/96396a22-f523-4c51-8b72-52be266988aa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gq65-6w6h-w9gj/GHSA-gq65-6w6h-w9gj.json b/advisories/unreviewed/2024/01/GHSA-gq65-6w6h-w9gj/GHSA-gq65-6w6h-w9gj.json new file mode 100644 index 00000000000..49bac058288 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gq65-6w6h-w9gj/GHSA-gq65-6w6h-w9gj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq65-6w6h-w9gj", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2022-45354" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45354" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/download-monitor/wordpress-download-monitor-plugin-4-7-60-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gqr9-4fcc-c9jq/GHSA-gqr9-4fcc-c9jq.json b/advisories/unreviewed/2024/01/GHSA-gqr9-4fcc-c9jq/GHSA-gqr9-4fcc-c9jq.json index 8703907b7d8..900e7f576d4 100644 --- a/advisories/unreviewed/2024/01/GHSA-gqr9-4fcc-c9jq/GHSA-gqr9-4fcc-c9jq.json +++ b/advisories/unreviewed/2024/01/GHSA-gqr9-4fcc-c9jq/GHSA-gqr9-4fcc-c9jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqr9-4fcc-c9jq", - "modified": "2024-01-04T03:30:39Z", + "modified": "2024-01-08T21:30:33Z", "published": "2024-01-04T03:30:39Z", "aliases": [ "CVE-2024-0225" ], "details": "Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T02:15:29Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gwm5-99v5-pwf9/GHSA-gwm5-99v5-pwf9.json b/advisories/unreviewed/2024/01/GHSA-gwm5-99v5-pwf9/GHSA-gwm5-99v5-pwf9.json new file mode 100644 index 00000000000..6ac6909682c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gwm5-99v5-pwf9/GHSA-gwm5-99v5-pwf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwm5-99v5-pwf9", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52204" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52204" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/randomize/wordpress-randomize-plugin-1-4-3-contributor-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hfgf-j9pj-wg8w/GHSA-hfgf-j9pj-wg8w.json b/advisories/unreviewed/2024/01/GHSA-hfgf-j9pj-wg8w/GHSA-hfgf-j9pj-wg8w.json new file mode 100644 index 00000000000..e53d7a2887d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hfgf-j9pj-wg8w/GHSA-hfgf-j9pj-wg8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfgf-j9pj-wg8w", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-51508" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & Repair: from n/a through 0.9.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51508" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/database-cleaner/wordpress-database-cleaner-plugin-0-9-8-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json b/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json index 65b5bd1bd95..32e0bd3ef06 100644 --- a/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json +++ b/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjjw-x8pv-g64q", - "modified": "2024-01-02T21:30:26Z", + "modified": "2024-01-08T21:30:32Z", "published": "2024-01-02T21:30:26Z", "aliases": [ "CVE-2023-45561" ], "details": "An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jp26-vw47-9r58/GHSA-jp26-vw47-9r58.json b/advisories/unreviewed/2024/01/GHSA-jp26-vw47-9r58/GHSA-jp26-vw47-9r58.json new file mode 100644 index 00000000000..4e61ab13d13 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jp26-vw47-9r58/GHSA-jp26-vw47-9r58.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp26-vw47-9r58", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2018-25095" + ], + "details": "The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25095" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/16cc47aa-cb31-4114-b014-7ac5fbc1d3ee" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m866-4h9x-6c44/GHSA-m866-4h9x-6c44.json b/advisories/unreviewed/2024/01/GHSA-m866-4h9x-6c44/GHSA-m866-4h9x-6c44.json new file mode 100644 index 00000000000..7ad8cecab4c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m866-4h9x-6c44/GHSA-m866-4h9x-6c44.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m866-4h9x-6c44", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6161" + ], + "details": "The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6161" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ca7b6a39-a910-4b4f-b9cc-be444ec44942" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mqv9-v5xg-xp9h/GHSA-mqv9-v5xg-xp9h.json b/advisories/unreviewed/2024/01/GHSA-mqv9-v5xg-xp9h/GHSA-mqv9-v5xg-xp9h.json new file mode 100644 index 00000000000..62a8c9ecc2c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mqv9-v5xg-xp9h/GHSA-mqv9-v5xg-xp9h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqv9-v5xg-xp9h", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-5957" + ], + "details": "The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5957" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/70f823ff-64ad-4f05-9eb3-b69b3b79dc12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p288-w88f-r2qg/GHSA-p288-w88f-r2qg.json b/advisories/unreviewed/2024/01/GHSA-p288-w88f-r2qg/GHSA-p288-w88f-r2qg.json new file mode 100644 index 00000000000..a09935a3909 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p288-w88f-r2qg/GHSA-p288-w88f-r2qg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p288-w88f-r2qg", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6141" + ], + "details": "The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6141" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/df12513b-9664-45be-8824-2924bfddf364" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json b/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json index e43d9eead36..0f66f528ac7 100644 --- a/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json +++ b/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p5jr-rfj3-98f5", - "modified": "2024-01-02T21:30:26Z", + "modified": "2024-01-08T21:30:32Z", "published": "2024-01-02T21:30:26Z", "aliases": [ "CVE-2023-45892" ], "details": "An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T21:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-p6wf-q8mw-wpwr/GHSA-p6wf-q8mw-wpwr.json b/advisories/unreviewed/2024/01/GHSA-p6wf-q8mw-wpwr/GHSA-p6wf-q8mw-wpwr.json new file mode 100644 index 00000000000..4bb96270a33 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p6wf-q8mw-wpwr/GHSA-p6wf-q8mw-wpwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6wf-q8mw-wpwr", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-52207" + ], + "details": "Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52207" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/html5-mp3-player-with-playlist/wordpress-html5-mp3-player-plugin-3-0-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pcwc-j2m8-3j5j/GHSA-pcwc-j2m8-3j5j.json b/advisories/unreviewed/2024/01/GHSA-pcwc-j2m8-3j5j/GHSA-pcwc-j2m8-3j5j.json new file mode 100644 index 00000000000..fd7e86a8cf0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pcwc-j2m8-3j5j/GHSA-pcwc-j2m8-3j5j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcwc-j2m8-3j5j", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-7218" + ], + "details": "A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-249852. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7218" + }, + { + "type": "WEB", + "url": "https://github.com/jylsec/vuldb/blob/main/TOTOLINK/N350RT/4/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249852" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249852" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pfp2-75wj-3h2f/GHSA-pfp2-75wj-3h2f.json b/advisories/unreviewed/2024/01/GHSA-pfp2-75wj-3h2f/GHSA-pfp2-75wj-3h2f.json new file mode 100644 index 00000000000..e0afcedccec --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pfp2-75wj-3h2f/GHSA-pfp2-75wj-3h2f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfp2-75wj-3h2f", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-27739" + ], + "details": "easyXDM 2.5 allows XSS via the xdm_e parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27739" + }, + { + "type": "WEB", + "url": "https://threeshield.ca/easyxdm-2.5.20.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pmx3-5c86-vxfm/GHSA-pmx3-5c86-vxfm.json b/advisories/unreviewed/2024/01/GHSA-pmx3-5c86-vxfm/GHSA-pmx3-5c86-vxfm.json new file mode 100644 index 00000000000..c3b8ca08aae --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pmx3-5c86-vxfm/GHSA-pmx3-5c86-vxfm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmx3-5c86-vxfm", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6140" + ], + "details": "The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6140" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c837eaf3-fafd-45a2-8f5e-03afb28a765b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q7rh-w25v-mpj8/GHSA-q7rh-w25v-mpj8.json b/advisories/unreviewed/2024/01/GHSA-q7rh-w25v-mpj8/GHSA-q7rh-w25v-mpj8.json new file mode 100644 index 00000000000..b39d16ad1f8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q7rh-w25v-mpj8/GHSA-q7rh-w25v-mpj8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7rh-w25v-mpj8", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6631" + ], + "details": "PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6631" + }, + { + "type": "WEB", + "url": "https://subnet.com/contact/" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-353-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q942-jjg3-5jhx/GHSA-q942-jjg3-5jhx.json b/advisories/unreviewed/2024/01/GHSA-q942-jjg3-5jhx/GHSA-q942-jjg3-5jhx.json new file mode 100644 index 00000000000..9c1733bccd0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q942-jjg3-5jhx/GHSA-q942-jjg3-5jhx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q942-jjg3-5jhx", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6528" + ], + "details": "The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6528" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/36ced447-84ea-4162-80d2-6df226cb53cb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qmm7-7fgh-3877/GHSA-qmm7-7fgh-3877.json b/advisories/unreviewed/2024/01/GHSA-qmm7-7fgh-3877/GHSA-qmm7-7fgh-3877.json new file mode 100644 index 00000000000..e50cf4012ff --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qmm7-7fgh-3877/GHSA-qmm7-7fgh-3877.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmm7-7fgh-3877", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52142" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52142" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/template-events-calendar/wordpress-events-shortcodes-for-the-events-calendar-plugin-2-3-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json b/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json index b6195fa8c2f..4dfeb9bb7d6 100644 --- a/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json +++ b/advisories/unreviewed/2024/01/GHSA-qwm2-x6hp-6h68/GHSA-qwm2-x6hp-6h68.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-r2px-vqx2-ww27/GHSA-r2px-vqx2-ww27.json b/advisories/unreviewed/2024/01/GHSA-r2px-vqx2-ww27/GHSA-r2px-vqx2-ww27.json new file mode 100644 index 00000000000..e060774f843 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r2px-vqx2-ww27/GHSA-r2px-vqx2-ww27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2px-vqx2-ww27", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52198" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52198" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/private-google-calendars/wordpress-private-google-calendars-plugin-20231125-contributor-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json b/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json new file mode 100644 index 00000000000..080b1c297a8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r67f-8hjg-55w3/GHSA-r67f-8hjg-55w3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r67f-8hjg-55w3", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52271" + ], + "details": "The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52271" + }, + { + "type": "WEB", + "url": "https://northwave-cybersecurity.com/vulnerability-notice-topaz-antifraud" + }, + { + "type": "WEB", + "url": "https://www.topazevolution.com/en/antifraud/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r7v9-5wqr-cqv8/GHSA-r7v9-5wqr-cqv8.json b/advisories/unreviewed/2024/01/GHSA-r7v9-5wqr-cqv8/GHSA-r7v9-5wqr-cqv8.json new file mode 100644 index 00000000000..62b30e9ab64 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r7v9-5wqr-cqv8/GHSA-r7v9-5wqr-cqv8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7v9-5wqr-cqv8", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52203" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52203" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cforms2/wordpress-cformsii-plugin-15-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rm8m-fq9m-823j/GHSA-rm8m-fq9m-823j.json b/advisories/unreviewed/2024/01/GHSA-rm8m-fq9m-823j/GHSA-rm8m-fq9m-823j.json new file mode 100644 index 00000000000..b579ec7b601 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-rm8m-fq9m-823j/GHSA-rm8m-fq9m-823j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm8m-fq9m-823j", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-5911" + ], + "details": "The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5911" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dde0767d-1dff-4261-adbe-1f3fdf2d9aae" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json b/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json index 322c3e92b87..7bf005d562a 100644 --- a/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json +++ b/advisories/unreviewed/2024/01/GHSA-rmpv-5qmj-3fgc/GHSA-rmpv-5qmj-3fgc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-w23w-39xh-22v5/GHSA-w23w-39xh-22v5.json b/advisories/unreviewed/2024/01/GHSA-w23w-39xh-22v5/GHSA-w23w-39xh-22v5.json new file mode 100644 index 00000000000..329db0ca3ad --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w23w-39xh-22v5/GHSA-w23w-39xh-22v5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w23w-39xh-22v5", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6750" + ], + "details": "The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6750" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fad9eefe-4552-4d20-a1fd-bb2e172ec8d7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w8x8-g534-x4rp/GHSA-w8x8-g534-x4rp.json b/advisories/unreviewed/2024/01/GHSA-w8x8-g534-x4rp/GHSA-w8x8-g534-x4rp.json index 9b69190e295..dadbf893e80 100644 --- a/advisories/unreviewed/2024/01/GHSA-w8x8-g534-x4rp/GHSA-w8x8-g534-x4rp.json +++ b/advisories/unreviewed/2024/01/GHSA-w8x8-g534-x4rp/GHSA-w8x8-g534-x4rp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8x8-g534-x4rp", - "modified": "2024-01-04T03:30:39Z", + "modified": "2024-01-08T21:30:33Z", "published": "2024-01-04T03:30:39Z", "aliases": [ "CVE-2024-0223" ], "details": "Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T02:15:28Z" diff --git a/advisories/unreviewed/2024/01/GHSA-wc7m-mx46-8xfv/GHSA-wc7m-mx46-8xfv.json b/advisories/unreviewed/2024/01/GHSA-wc7m-mx46-8xfv/GHSA-wc7m-mx46-8xfv.json new file mode 100644 index 00000000000..13cfd7bb392 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wc7m-mx46-8xfv/GHSA-wc7m-mx46-8xfv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc7m-mx46-8xfv", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52201" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52201" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ptypeconverter/wordpress-ptypeconverter-plugin-0-2-8-1-subscriber-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x8v8-8hj9-w975/GHSA-x8v8-8hj9-w975.json b/advisories/unreviewed/2024/01/GHSA-x8v8-8hj9-w975/GHSA-x8v8-8hj9-w975.json new file mode 100644 index 00000000000..3b7138b2ce2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x8v8-8hj9-w975/GHSA-x8v8-8hj9-w975.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8v8-8hj9-w975", + "modified": "2024-01-08T21:30:34Z", + "published": "2024-01-08T21:30:34Z", + "aliases": [ + "CVE-2023-52206" + ], + "details": "Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52206" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/live-composer-page-builder/wordpress-page-builder-live-composer-plugin-1-5-25-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xcwv-4qfh-f8xj/GHSA-xcwv-4qfh-f8xj.json b/advisories/unreviewed/2024/01/GHSA-xcwv-4qfh-f8xj/GHSA-xcwv-4qfh-f8xj.json new file mode 100644 index 00000000000..78355dcad26 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xcwv-4qfh-f8xj/GHSA-xcwv-4qfh-f8xj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcwv-4qfh-f8xj", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-52222" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52222" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce/wordpress-woocommerce-plugin-8-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xjh6-43fr-h892/GHSA-xjh6-43fr-h892.json b/advisories/unreviewed/2024/01/GHSA-xjh6-43fr-h892/GHSA-xjh6-43fr-h892.json new file mode 100644 index 00000000000..c6f7736cd3f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xjh6-43fr-h892/GHSA-xjh6-43fr-h892.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjh6-43fr-h892", + "modified": "2024-01-08T21:30:33Z", + "published": "2024-01-08T21:30:33Z", + "aliases": [ + "CVE-2023-6042" + ], + "details": "Any unauthenticated user may send e-mail from the site with any title or content to the admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6042" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/56a1c050-67b5-43bc-b5b6-28d9a5a59eba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T19:15:09Z" + } +} \ No newline at end of file