diff --git a/advisories/unreviewed/2023/11/GHSA-2ghr-522h-prhx/GHSA-2ghr-522h-prhx.json b/advisories/unreviewed/2023/11/GHSA-2ghr-522h-prhx/GHSA-2ghr-522h-prhx.json new file mode 100644 index 00000000000..53ed3c5c9bb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2ghr-522h-prhx/GHSA-2ghr-522h-prhx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ghr-522h-prhx", + "modified": "2023-11-10T00:30:26Z", + "published": "2023-11-10T00:30:26Z", + "aliases": [ + "CVE-2023-32579" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/forget-about-shortcode-buttons/wordpress-forget-about-shortcode-buttons-plugin-2-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4rxq-xcjw-9ww8/GHSA-4rxq-xcjw-9ww8.json b/advisories/unreviewed/2023/11/GHSA-4rxq-xcjw-9ww8/GHSA-4rxq-xcjw-9ww8.json new file mode 100644 index 00000000000..4477138c9c7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4rxq-xcjw-9ww8/GHSA-4rxq-xcjw-9ww8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rxq-xcjw-9ww8", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-32502" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pro-mime-types/wordpress-pro-mime-types-plugin-1-0-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4vhp-q3px-rx42/GHSA-4vhp-q3px-rx42.json b/advisories/unreviewed/2023/11/GHSA-4vhp-q3px-rx42/GHSA-4vhp-q3px-rx42.json new file mode 100644 index 00000000000..2c78c756120 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4vhp-q3px-rx42/GHSA-4vhp-q3px-rx42.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vhp-q3px-rx42", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-31086" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31086" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/giveasap/wordpress-simple-giveaways-plugin-2-45-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-52x8-2f4w-q8mm/GHSA-52x8-2f4w-q8mm.json b/advisories/unreviewed/2023/11/GHSA-52x8-2f4w-q8mm/GHSA-52x8-2f4w-q8mm.json index f0e265909ed..3c3900c9638 100644 --- a/advisories/unreviewed/2023/11/GHSA-52x8-2f4w-q8mm/GHSA-52x8-2f4w-q8mm.json +++ b/advisories/unreviewed/2023/11/GHSA-52x8-2f4w-q8mm/GHSA-52x8-2f4w-q8mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52x8-2f4w-q8mm", - "modified": "2023-11-03T06:36:29Z", + "modified": "2023-11-10T00:30:26Z", "published": "2023-11-03T06:36:29Z", "aliases": [ "CVE-2020-28407" ], "details": "In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -33,11 +36,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T04:15:15Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-577g-8prr-p86v/GHSA-577g-8prr-p86v.json b/advisories/unreviewed/2023/11/GHSA-577g-8prr-p86v/GHSA-577g-8prr-p86v.json new file mode 100644 index 00000000000..07870d236f2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-577g-8prr-p86v/GHSA-577g-8prr-p86v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-577g-8prr-p86v", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-32501" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32501" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vikbooking/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-6-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6436-83pc-5gxw/GHSA-6436-83pc-5gxw.json b/advisories/unreviewed/2023/11/GHSA-6436-83pc-5gxw/GHSA-6436-83pc-5gxw.json new file mode 100644 index 00000000000..7b3832e1245 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6436-83pc-5gxw/GHSA-6436-83pc-5gxw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6436-83pc-5gxw", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-36014" + ], + "details": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36014" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36014" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-10T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6j2x-75g2-gv86/GHSA-6j2x-75g2-gv86.json b/advisories/unreviewed/2023/11/GHSA-6j2x-75g2-gv86/GHSA-6j2x-75g2-gv86.json index a364e81cd4b..051422addba 100644 --- a/advisories/unreviewed/2023/11/GHSA-6j2x-75g2-gv86/GHSA-6j2x-75g2-gv86.json +++ b/advisories/unreviewed/2023/11/GHSA-6j2x-75g2-gv86/GHSA-6j2x-75g2-gv86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6j2x-75g2-gv86", - "modified": "2023-11-03T03:30:24Z", + "modified": "2023-11-10T00:30:26Z", "published": "2023-11-03T03:30:24Z", "aliases": [ "CVE-2023-46954" ], "details": "SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T03:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7236-9j44-cf2f/GHSA-7236-9j44-cf2f.json b/advisories/unreviewed/2023/11/GHSA-7236-9j44-cf2f/GHSA-7236-9j44-cf2f.json new file mode 100644 index 00000000000..eacfe615a19 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7236-9j44-cf2f/GHSA-7236-9j44-cf2f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7236-9j44-cf2f", + "modified": "2023-11-10T00:30:26Z", + "published": "2023-11-10T00:30:26Z", + "aliases": [ + "CVE-2023-32512" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32512" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-webp-avif-cdn-image-optimization-plugin-3-7-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7x7g-p6hc-7cp3/GHSA-7x7g-p6hc-7cp3.json b/advisories/unreviewed/2023/11/GHSA-7x7g-p6hc-7cp3/GHSA-7x7g-p6hc-7cp3.json index c344be797d9..072a594bf68 100644 --- a/advisories/unreviewed/2023/11/GHSA-7x7g-p6hc-7cp3/GHSA-7x7g-p6hc-7cp3.json +++ b/advisories/unreviewed/2023/11/GHSA-7x7g-p6hc-7cp3/GHSA-7x7g-p6hc-7cp3.json @@ -33,6 +33,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T01:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-837h-2mxv-3v98/GHSA-837h-2mxv-3v98.json b/advisories/unreviewed/2023/11/GHSA-837h-2mxv-3v98/GHSA-837h-2mxv-3v98.json new file mode 100644 index 00000000000..42285cf2e56 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-837h-2mxv-3v98/GHSA-837h-2mxv-3v98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-837h-2mxv-3v98", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-36024" + ], + "details": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36024" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-10T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9fvm-c82m-5q5f/GHSA-9fvm-c82m-5q5f.json b/advisories/unreviewed/2023/11/GHSA-9fvm-c82m-5q5f/GHSA-9fvm-c82m-5q5f.json new file mode 100644 index 00000000000..e676bd0acc2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9fvm-c82m-5q5f/GHSA-9fvm-c82m-5q5f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fvm-c82m-5q5f", + "modified": "2023-11-10T00:30:28Z", + "published": "2023-11-10T00:30:28Z", + "aliases": [ + "CVE-2023-31235" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/participants-database/wordpress-participants-database-plugin-2-4-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9vf9-2prf-pcq9/GHSA-9vf9-2prf-pcq9.json b/advisories/unreviewed/2023/11/GHSA-9vf9-2prf-pcq9/GHSA-9vf9-2prf-pcq9.json new file mode 100644 index 00000000000..cf1d8db87cd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9vf9-2prf-pcq9/GHSA-9vf9-2prf-pcq9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vf9-2prf-pcq9", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-31093" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31093" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/chronosly-events-calendar/wordpress-chronosly-events-calendar-plugin-2-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cxrw-jr5w-6fgv/GHSA-cxrw-jr5w-6fgv.json b/advisories/unreviewed/2023/11/GHSA-cxrw-jr5w-6fgv/GHSA-cxrw-jr5w-6fgv.json new file mode 100644 index 00000000000..fbc62e17cfc --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cxrw-jr5w-6fgv/GHSA-cxrw-jr5w-6fgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxrw-jr5w-6fgv", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2018-8863" + ], + "details": "The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-8863" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsma-18-137-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f48g-5q5h-xx63/GHSA-f48g-5q5h-xx63.json b/advisories/unreviewed/2023/11/GHSA-f48g-5q5h-xx63/GHSA-f48g-5q5h-xx63.json index e47f2e08f40..e73a369a2f1 100644 --- a/advisories/unreviewed/2023/11/GHSA-f48g-5q5h-xx63/GHSA-f48g-5q5h-xx63.json +++ b/advisories/unreviewed/2023/11/GHSA-f48g-5q5h-xx63/GHSA-f48g-5q5h-xx63.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f48g-5q5h-xx63", - "modified": "2023-11-03T06:36:30Z", + "modified": "2023-11-10T00:30:26Z", "published": "2023-11-03T06:36:30Z", "aliases": [ "CVE-2023-43982" ], "details": "Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate data via a HTTP call.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-918" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T05:15:30Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fpqf-jx9q-7w86/GHSA-fpqf-jx9q-7w86.json b/advisories/unreviewed/2023/11/GHSA-fpqf-jx9q-7w86/GHSA-fpqf-jx9q-7w86.json new file mode 100644 index 00000000000..53f0bc9d209 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fpqf-jx9q-7w86/GHSA-fpqf-jx9q-7w86.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpqf-jx9q-7w86", + "modified": "2023-11-10T00:30:26Z", + "published": "2023-11-10T00:30:26Z", + "aliases": [ + "CVE-2023-32592" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Search plugin <= 1.0.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32592" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fast-search-powered-by-solr/wordpress-sunny-search-plugin-1-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fr3j-67c2-cffx/GHSA-fr3j-67c2-cffx.json b/advisories/unreviewed/2023/11/GHSA-fr3j-67c2-cffx/GHSA-fr3j-67c2-cffx.json new file mode 100644 index 00000000000..bc72337f621 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fr3j-67c2-cffx/GHSA-fr3j-67c2-cffx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr3j-67c2-cffx", + "modified": "2023-11-10T00:30:26Z", + "published": "2023-11-10T00:30:26Z", + "aliases": [ + "CVE-2023-29975" + ], + "details": "An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29975" + }, + { + "type": "WEB", + "url": "https://www.esecforte.com/cve-2023-29975-unverified-password-changed/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g6wj-cmhj-qw7h/GHSA-g6wj-cmhj-qw7h.json b/advisories/unreviewed/2023/11/GHSA-g6wj-cmhj-qw7h/GHSA-g6wj-cmhj-qw7h.json new file mode 100644 index 00000000000..32ceefbe7c3 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g6wj-cmhj-qw7h/GHSA-g6wj-cmhj-qw7h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6wj-cmhj-qw7h", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-32093" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Criss Swaim TPG Redirect plugin <= 1.0.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32093" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tpg-redirect/wordpress-tpg-redirect-plugin-1-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g884-2qr9-vj7f/GHSA-g884-2qr9-vj7f.json b/advisories/unreviewed/2023/11/GHSA-g884-2qr9-vj7f/GHSA-g884-2qr9-vj7f.json index 6da521b615d..1ca93513798 100644 --- a/advisories/unreviewed/2023/11/GHSA-g884-2qr9-vj7f/GHSA-g884-2qr9-vj7f.json +++ b/advisories/unreviewed/2023/11/GHSA-g884-2qr9-vj7f/GHSA-g884-2qr9-vj7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g884-2qr9-vj7f", - "modified": "2023-11-03T06:36:29Z", + "modified": "2023-11-10T00:30:26Z", "published": "2023-11-03T06:36:29Z", "aliases": [ "CVE-2023-36621" ], "details": "An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -33,11 +36,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T04:15:21Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-j28c-2mmq-8j4f/GHSA-j28c-2mmq-8j4f.json b/advisories/unreviewed/2023/11/GHSA-j28c-2mmq-8j4f/GHSA-j28c-2mmq-8j4f.json new file mode 100644 index 00000000000..4ab1115f267 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j28c-2mmq-8j4f/GHSA-j28c-2mmq-8j4f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j28c-2mmq-8j4f", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-32125" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32125" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/multi-rating/wordpress-multi-rating-plugin-5-0-6-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-j6wq-57g5-j35c/GHSA-j6wq-57g5-j35c.json b/advisories/unreviewed/2023/11/GHSA-j6wq-57g5-j35c/GHSA-j6wq-57g5-j35c.json new file mode 100644 index 00000000000..e311379336f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j6wq-57g5-j35c/GHSA-j6wq-57g5-j35c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6wq-57g5-j35c", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-31088" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Faraz Quazi Floating Action Button plugin <= 1.2.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31088" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/floating-action-button/wordpress-floating-action-button-plugin-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jr92-46c3-hhcf/GHSA-jr92-46c3-hhcf.json b/advisories/unreviewed/2023/11/GHSA-jr92-46c3-hhcf/GHSA-jr92-46c3-hhcf.json index e4a39af8c59..3c2d8fa63ec 100644 --- a/advisories/unreviewed/2023/11/GHSA-jr92-46c3-hhcf/GHSA-jr92-46c3-hhcf.json +++ b/advisories/unreviewed/2023/11/GHSA-jr92-46c3-hhcf/GHSA-jr92-46c3-hhcf.json @@ -33,6 +33,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T05:15:29Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mp22-jx23-944p/GHSA-mp22-jx23-944p.json b/advisories/unreviewed/2023/11/GHSA-mp22-jx23-944p/GHSA-mp22-jx23-944p.json new file mode 100644 index 00000000000..f000663b30d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mp22-jx23-944p/GHSA-mp22-jx23-944p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp22-jx23-944p", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-32092" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0.9.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32092" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/peepso-core/wordpress-community-by-peepso-social-network-membership-registration-user-profiles-plugin-6-0-9-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-p657-7739-2grh/GHSA-p657-7739-2grh.json b/advisories/unreviewed/2023/11/GHSA-p657-7739-2grh/GHSA-p657-7739-2grh.json new file mode 100644 index 00000000000..d8dc22cb0e4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-p657-7739-2grh/GHSA-p657-7739-2grh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p657-7739-2grh", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-5543" + ], + "details": "When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5543" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2243442" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=451584" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-77795" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qpc2-222x-ppq9/GHSA-qpc2-222x-ppq9.json b/advisories/unreviewed/2023/11/GHSA-qpc2-222x-ppq9/GHSA-qpc2-222x-ppq9.json index f7a0eaddb11..22b40a03a72 100644 --- a/advisories/unreviewed/2023/11/GHSA-qpc2-222x-ppq9/GHSA-qpc2-222x-ppq9.json +++ b/advisories/unreviewed/2023/11/GHSA-qpc2-222x-ppq9/GHSA-qpc2-222x-ppq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpc2-222x-ppq9", - "modified": "2023-11-03T06:36:30Z", + "modified": "2023-11-10T00:30:26Z", "published": "2023-11-03T06:36:30Z", "aliases": [ "CVE-2023-45360" ], "details": "An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-03T05:15:30Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v8jm-8mp9-5962/GHSA-v8jm-8mp9-5962.json b/advisories/unreviewed/2023/11/GHSA-v8jm-8mp9-5962/GHSA-v8jm-8mp9-5962.json index 4146b4a0dd5..a0740228024 100644 --- a/advisories/unreviewed/2023/11/GHSA-v8jm-8mp9-5962/GHSA-v8jm-8mp9-5962.json +++ b/advisories/unreviewed/2023/11/GHSA-v8jm-8mp9-5962/GHSA-v8jm-8mp9-5962.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8jm-8mp9-5962", - "modified": "2023-11-03T06:36:30Z", + "modified": "2023-11-10T00:30:26Z", "published": "2023-11-03T06:36:30Z", "aliases": [ "CVE-2023-41914" ], "details": "SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41914" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OWKTCYZT3DXEH66QXQJYB7NI7ONDRS4M/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWKTCYZT3DXEH66QXQJYB7NI7ONDRS4M/" @@ -33,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-03T05:15:30Z" diff --git a/advisories/unreviewed/2023/11/GHSA-vrx6-28g2-g5gm/GHSA-vrx6-28g2-g5gm.json b/advisories/unreviewed/2023/11/GHSA-vrx6-28g2-g5gm/GHSA-vrx6-28g2-g5gm.json new file mode 100644 index 00000000000..bd87481d8b1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vrx6-28g2-g5gm/GHSA-vrx6-28g2-g5gm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrx6-28g2-g5gm", + "modified": "2023-11-10T00:30:27Z", + "published": "2023-11-10T00:30:27Z", + "aliases": [ + "CVE-2023-32500" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme <= 7.1.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32500" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woodmart/wordpress-woodmart-theme-7-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x327-w9wh-hfg2/GHSA-x327-w9wh-hfg2.json b/advisories/unreviewed/2023/11/GHSA-x327-w9wh-hfg2/GHSA-x327-w9wh-hfg2.json new file mode 100644 index 00000000000..3d872821aa9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x327-w9wh-hfg2/GHSA-x327-w9wh-hfg2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x327-w9wh-hfg2", + "modified": "2023-11-10T00:30:26Z", + "published": "2023-11-10T00:30:26Z", + "aliases": [ + "CVE-2023-32587" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Reactions, LLC WP Reactions Lite plugin <= 1.3.8 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-reactions-lite/wordpress-wp-reactions-lite-plugin-1-3-8-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-09T22:15:10Z" + } +} \ No newline at end of file