diff --git a/advisories/unreviewed/2022/01/GHSA-9fvj-4grr-mv9j/GHSA-9fvj-4grr-mv9j.json b/advisories/unreviewed/2022/01/GHSA-9fvj-4grr-mv9j/GHSA-9fvj-4grr-mv9j.json index 2b377175b93..b2c3908b1f0 100644 --- a/advisories/unreviewed/2022/01/GHSA-9fvj-4grr-mv9j/GHSA-9fvj-4grr-mv9j.json +++ b/advisories/unreviewed/2022/01/GHSA-9fvj-4grr-mv9j/GHSA-9fvj-4grr-mv9j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9fvj-4grr-mv9j", - "modified": "2022-01-15T00:03:22Z", + "modified": "2023-06-27T21:30:42Z", "published": "2022-01-11T00:00:57Z", "aliases": [ "CVE-2022-22265" ], "details": "An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-703", "CWE-755" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/01/GHSA-fgwx-697g-22hm/GHSA-fgwx-697g-22hm.json b/advisories/unreviewed/2022/01/GHSA-fgwx-697g-22hm/GHSA-fgwx-697g-22hm.json index b6135bc8559..3793533a195 100644 --- a/advisories/unreviewed/2022/01/GHSA-fgwx-697g-22hm/GHSA-fgwx-697g-22hm.json +++ b/advisories/unreviewed/2022/01/GHSA-fgwx-697g-22hm/GHSA-fgwx-697g-22hm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fgwx-697g-22hm", - "modified": "2022-01-27T00:03:48Z", + "modified": "2023-06-27T21:30:43Z", "published": "2022-01-20T00:01:57Z", "aliases": [ "CVE-2022-22166" ], "details": "An Improper Validation of Specified Quantity in Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause an rdp crash and thereby a Denial of Service (DoS). If a BGP update message is received over an established BGP session where a BGP SR-TE policy tunnel attribute is malformed and BGP update tracing flag is enabled, the rpd will core. This issue can happen with any BGP session as long as the previous conditions are met. This issue can not propagate as the crash occurs as soon as the malformed update is received. This issue affects Juniper Networks Junos OS: 20.4 versions prior to 20.4R3-S1; 21.1 versions prior to 21.1R2-S2, 21.1R3. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/01/GHSA-jgrp-9rqg-rqhp/GHSA-jgrp-9rqg-rqhp.json b/advisories/unreviewed/2022/01/GHSA-jgrp-9rqg-rqhp/GHSA-jgrp-9rqg-rqhp.json index 7378c28fcb4..1a185c9c88e 100644 --- a/advisories/unreviewed/2022/01/GHSA-jgrp-9rqg-rqhp/GHSA-jgrp-9rqg-rqhp.json +++ b/advisories/unreviewed/2022/01/GHSA-jgrp-9rqg-rqhp/GHSA-jgrp-9rqg-rqhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jgrp-9rqg-rqhp", - "modified": "2022-02-02T00:02:02Z", + "modified": "2023-06-27T21:30:43Z", "published": "2022-01-26T00:00:49Z", "aliases": [ "CVE-2022-23008" ], "details": "On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the \"user\" or \"admin\" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/01/GHSA-m2q7-5g93-322p/GHSA-m2q7-5g93-322p.json b/advisories/unreviewed/2022/01/GHSA-m2q7-5g93-322p/GHSA-m2q7-5g93-322p.json index af3f7b89d65..3f90a1bb835 100644 --- a/advisories/unreviewed/2022/01/GHSA-m2q7-5g93-322p/GHSA-m2q7-5g93-322p.json +++ b/advisories/unreviewed/2022/01/GHSA-m2q7-5g93-322p/GHSA-m2q7-5g93-322p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2q7-5g93-322p", - "modified": "2022-01-16T00:01:04Z", + "modified": "2023-06-27T21:30:43Z", "published": "2022-01-11T00:00:54Z", "aliases": [ "CVE-2022-22272" ], "details": "Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/01/GHSA-mf8r-2pp6-7vqp/GHSA-mf8r-2pp6-7vqp.json b/advisories/unreviewed/2022/01/GHSA-mf8r-2pp6-7vqp/GHSA-mf8r-2pp6-7vqp.json index 305a488f507..8c40abdc0da 100644 --- a/advisories/unreviewed/2022/01/GHSA-mf8r-2pp6-7vqp/GHSA-mf8r-2pp6-7vqp.json +++ b/advisories/unreviewed/2022/01/GHSA-mf8r-2pp6-7vqp/GHSA-mf8r-2pp6-7vqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf8r-2pp6-7vqp", - "modified": "2022-01-20T00:02:50Z", + "modified": "2023-06-27T21:30:43Z", "published": "2022-01-11T00:00:51Z", "aliases": [ "CVE-2022-22288" ], "details": "Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json b/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json index 2f896df36fb..4a7dbce2c1e 100644 --- a/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json +++ b/advisories/unreviewed/2022/02/GHSA-hr65-735p-72v3/GHSA-hr65-735p-72v3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-191", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-jhfm-vpj4-vj2f/GHSA-jhfm-vpj4-vj2f.json b/advisories/unreviewed/2022/02/GHSA-jhfm-vpj4-vj2f/GHSA-jhfm-vpj4-vj2f.json index 68e4e4f6386..fa367ee33b8 100644 --- a/advisories/unreviewed/2022/02/GHSA-jhfm-vpj4-vj2f/GHSA-jhfm-vpj4-vj2f.json +++ b/advisories/unreviewed/2022/02/GHSA-jhfm-vpj4-vj2f/GHSA-jhfm-vpj4-vj2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhfm-vpj4-vj2f", - "modified": "2022-02-16T00:02:06Z", + "modified": "2023-06-27T21:30:44Z", "published": "2022-02-11T00:00:50Z", "aliases": [ "CVE-2022-21825" ], "details": "An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/02/GHSA-mv97-qj5h-25f3/GHSA-mv97-qj5h-25f3.json b/advisories/unreviewed/2022/02/GHSA-mv97-qj5h-25f3/GHSA-mv97-qj5h-25f3.json index df481768de1..b8e45d8f4a0 100644 --- a/advisories/unreviewed/2022/02/GHSA-mv97-qj5h-25f3/GHSA-mv97-qj5h-25f3.json +++ b/advisories/unreviewed/2022/02/GHSA-mv97-qj5h-25f3/GHSA-mv97-qj5h-25f3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mv97-qj5h-25f3", - "modified": "2022-02-09T00:01:05Z", + "modified": "2023-06-27T21:30:43Z", "published": "2022-02-09T00:01:05Z", "aliases": [ "CVE-2022-23134" ], "details": "After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,6 +40,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", + "CWE-287", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/02/GHSA-mwwv-v58h-qcvw/GHSA-mwwv-v58h-qcvw.json b/advisories/unreviewed/2022/02/GHSA-mwwv-v58h-qcvw/GHSA-mwwv-v58h-qcvw.json index 1e9bc6e652e..9df0f7f348d 100644 --- a/advisories/unreviewed/2022/02/GHSA-mwwv-v58h-qcvw/GHSA-mwwv-v58h-qcvw.json +++ b/advisories/unreviewed/2022/02/GHSA-mwwv-v58h-qcvw/GHSA-mwwv-v58h-qcvw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mwwv-v58h-qcvw", - "modified": "2022-02-19T00:01:46Z", + "modified": "2023-06-27T21:30:44Z", "published": "2022-02-12T00:00:40Z", "aliases": [ "CVE-2022-23433" ], "details": "Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/03/GHSA-5xgr-wq7f-67xj/GHSA-5xgr-wq7f-67xj.json b/advisories/unreviewed/2022/03/GHSA-5xgr-wq7f-67xj/GHSA-5xgr-wq7f-67xj.json index 5b97b8208c7..cb935b9ed9c 100644 --- a/advisories/unreviewed/2022/03/GHSA-5xgr-wq7f-67xj/GHSA-5xgr-wq7f-67xj.json +++ b/advisories/unreviewed/2022/03/GHSA-5xgr-wq7f-67xj/GHSA-5xgr-wq7f-67xj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-1284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/03/GHSA-6w5w-27h7-6r2x/GHSA-6w5w-27h7-6r2x.json b/advisories/unreviewed/2022/03/GHSA-6w5w-27h7-6r2x/GHSA-6w5w-27h7-6r2x.json index 153082e1bbc..3c1cecac75d 100644 --- a/advisories/unreviewed/2022/03/GHSA-6w5w-27h7-6r2x/GHSA-6w5w-27h7-6r2x.json +++ b/advisories/unreviewed/2022/03/GHSA-6w5w-27h7-6r2x/GHSA-6w5w-27h7-6r2x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-1284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/03/GHSA-9hg8-8wq3-mhhg/GHSA-9hg8-8wq3-mhhg.json b/advisories/unreviewed/2022/03/GHSA-9hg8-8wq3-mhhg/GHSA-9hg8-8wq3-mhhg.json index ce2b8bf2e0f..4304322118c 100644 --- a/advisories/unreviewed/2022/03/GHSA-9hg8-8wq3-mhhg/GHSA-9hg8-8wq3-mhhg.json +++ b/advisories/unreviewed/2022/03/GHSA-9hg8-8wq3-mhhg/GHSA-9hg8-8wq3-mhhg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-1284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/03/GHSA-fj9g-qqr2-c949/GHSA-fj9g-qqr2-c949.json b/advisories/unreviewed/2022/03/GHSA-fj9g-qqr2-c949/GHSA-fj9g-qqr2-c949.json index e47fdeaf848..fd7d2df46a0 100644 --- a/advisories/unreviewed/2022/03/GHSA-fj9g-qqr2-c949/GHSA-fj9g-qqr2-c949.json +++ b/advisories/unreviewed/2022/03/GHSA-fj9g-qqr2-c949/GHSA-fj9g-qqr2-c949.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-352" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/03/GHSA-jjv8-4r6f-2mj4/GHSA-jjv8-4r6f-2mj4.json b/advisories/unreviewed/2022/03/GHSA-jjv8-4r6f-2mj4/GHSA-jjv8-4r6f-2mj4.json index 6b16e2902e4..eafeb2bc564 100644 --- a/advisories/unreviewed/2022/03/GHSA-jjv8-4r6f-2mj4/GHSA-jjv8-4r6f-2mj4.json +++ b/advisories/unreviewed/2022/03/GHSA-jjv8-4r6f-2mj4/GHSA-jjv8-4r6f-2mj4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-424", "CWE-425" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/04/GHSA-467q-fpqj-82rx/GHSA-467q-fpqj-82rx.json b/advisories/unreviewed/2022/04/GHSA-467q-fpqj-82rx/GHSA-467q-fpqj-82rx.json index 5c905f022d4..69fa5564863 100644 --- a/advisories/unreviewed/2022/04/GHSA-467q-fpqj-82rx/GHSA-467q-fpqj-82rx.json +++ b/advisories/unreviewed/2022/04/GHSA-467q-fpqj-82rx/GHSA-467q-fpqj-82rx.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-4gh9-g4rp-rqwx/GHSA-4gh9-g4rp-rqwx.json b/advisories/unreviewed/2022/04/GHSA-4gh9-g4rp-rqwx/GHSA-4gh9-g4rp-rqwx.json index 14829f80482..be1ea65a07e 100644 --- a/advisories/unreviewed/2022/04/GHSA-4gh9-g4rp-rqwx/GHSA-4gh9-g4rp-rqwx.json +++ b/advisories/unreviewed/2022/04/GHSA-4gh9-g4rp-rqwx/GHSA-4gh9-g4rp-rqwx.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-h42q-jjcq-2ff4/GHSA-h42q-jjcq-2ff4.json b/advisories/unreviewed/2022/04/GHSA-h42q-jjcq-2ff4/GHSA-h42q-jjcq-2ff4.json index 12630ef7159..9ca8e654c41 100644 --- a/advisories/unreviewed/2022/04/GHSA-h42q-jjcq-2ff4/GHSA-h42q-jjcq-2ff4.json +++ b/advisories/unreviewed/2022/04/GHSA-h42q-jjcq-2ff4/GHSA-h42q-jjcq-2ff4.json @@ -29,6 +29,7 @@ "database_specific": { "cwe_ids": [ "CWE-284", + "CWE-639", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/04/GHSA-vxc8-cmfv-782q/GHSA-vxc8-cmfv-782q.json b/advisories/unreviewed/2022/04/GHSA-vxc8-cmfv-782q/GHSA-vxc8-cmfv-782q.json index 1f093c1757d..ef3e2ce48b1 100644 --- a/advisories/unreviewed/2022/04/GHSA-vxc8-cmfv-782q/GHSA-vxc8-cmfv-782q.json +++ b/advisories/unreviewed/2022/04/GHSA-vxc8-cmfv-782q/GHSA-vxc8-cmfv-782q.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-125" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json b/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json index 2c7a68333d9..7092073b8c7 100644 --- a/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json +++ b/advisories/unreviewed/2022/04/GHSA-x568-473g-qj6x/GHSA-x568-473g-qj6x.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-2wqm-v6p6-8mqx/GHSA-2wqm-v6p6-8mqx.json b/advisories/unreviewed/2022/05/GHSA-2wqm-v6p6-8mqx/GHSA-2wqm-v6p6-8mqx.json index 2f5e4dccbbf..fcf4845c165 100644 --- a/advisories/unreviewed/2022/05/GHSA-2wqm-v6p6-8mqx/GHSA-2wqm-v6p6-8mqx.json +++ b/advisories/unreviewed/2022/05/GHSA-2wqm-v6p6-8mqx/GHSA-2wqm-v6p6-8mqx.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-8xpw-m3x3-rq75/GHSA-8xpw-m3x3-rq75.json b/advisories/unreviewed/2022/05/GHSA-8xpw-m3x3-rq75/GHSA-8xpw-m3x3-rq75.json index 6630b3b01ce..6c0ae10ea99 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xpw-m3x3-rq75/GHSA-8xpw-m3x3-rq75.json +++ b/advisories/unreviewed/2022/05/GHSA-8xpw-m3x3-rq75/GHSA-8xpw-m3x3-rq75.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-862" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-mp8h-qmxp-c39w/GHSA-mp8h-qmxp-c39w.json b/advisories/unreviewed/2022/05/GHSA-mp8h-qmxp-c39w/GHSA-mp8h-qmxp-c39w.json index cc9a7ff6366..49a56afb213 100644 --- a/advisories/unreviewed/2022/05/GHSA-mp8h-qmxp-c39w/GHSA-mp8h-qmxp-c39w.json +++ b/advisories/unreviewed/2022/05/GHSA-mp8h-qmxp-c39w/GHSA-mp8h-qmxp-c39w.json @@ -44,7 +44,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-476", + "CWE-822" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w2qp-8fj2-5g53/GHSA-w2qp-8fj2-5g53.json b/advisories/unreviewed/2022/05/GHSA-w2qp-8fj2-5g53/GHSA-w2qp-8fj2-5g53.json index 8100ed3291e..d0fec30ceaa 100644 --- a/advisories/unreviewed/2022/05/GHSA-w2qp-8fj2-5g53/GHSA-w2qp-8fj2-5g53.json +++ b/advisories/unreviewed/2022/05/GHSA-w2qp-8fj2-5g53/GHSA-w2qp-8fj2-5g53.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-664", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-fx8r-hf6c-5p46/GHSA-fx8r-hf6c-5p46.json b/advisories/unreviewed/2022/06/GHSA-fx8r-hf6c-5p46/GHSA-fx8r-hf6c-5p46.json index a20aa27af6a..a4254d5af7a 100644 --- a/advisories/unreviewed/2022/06/GHSA-fx8r-hf6c-5p46/GHSA-fx8r-hf6c-5p46.json +++ b/advisories/unreviewed/2022/06/GHSA-fx8r-hf6c-5p46/GHSA-fx8r-hf6c-5p46.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-qrhx-g8ph-h5v3/GHSA-qrhx-g8ph-h5v3.json b/advisories/unreviewed/2022/06/GHSA-qrhx-g8ph-h5v3/GHSA-qrhx-g8ph-h5v3.json index 31c5ff57044..45034c9de28 100644 --- a/advisories/unreviewed/2022/06/GHSA-qrhx-g8ph-h5v3/GHSA-qrhx-g8ph-h5v3.json +++ b/advisories/unreviewed/2022/06/GHSA-qrhx-g8ph-h5v3/GHSA-qrhx-g8ph-h5v3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/08/GHSA-fxpp-6992-65m4/GHSA-fxpp-6992-65m4.json b/advisories/unreviewed/2022/08/GHSA-fxpp-6992-65m4/GHSA-fxpp-6992-65m4.json index 38e30475331..dd5e49deb87 100644 --- a/advisories/unreviewed/2022/08/GHSA-fxpp-6992-65m4/GHSA-fxpp-6992-65m4.json +++ b/advisories/unreviewed/2022/08/GHSA-fxpp-6992-65m4/GHSA-fxpp-6992-65m4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-r3p9-xjh5-cp2m/GHSA-r3p9-xjh5-cp2m.json b/advisories/unreviewed/2022/08/GHSA-r3p9-xjh5-cp2m/GHSA-r3p9-xjh5-cp2m.json index 2e04ed4c266..d273bca3cf9 100644 --- a/advisories/unreviewed/2022/08/GHSA-r3p9-xjh5-cp2m/GHSA-r3p9-xjh5-cp2m.json +++ b/advisories/unreviewed/2022/08/GHSA-r3p9-xjh5-cp2m/GHSA-r3p9-xjh5-cp2m.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json b/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json index 31e80fb8122..68abd2cf23c 100644 --- a/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json +++ b/advisories/unreviewed/2022/09/GHSA-m864-5788-g574/GHSA-m864-5788-g574.json @@ -28,6 +28,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", + "CWE-190", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-w6wh-qr7x-h932/GHSA-w6wh-qr7x-h932.json b/advisories/unreviewed/2022/09/GHSA-w6wh-qr7x-h932/GHSA-w6wh-qr7x-h932.json index 9954ba8fba0..a9200bf2c36 100644 --- a/advisories/unreviewed/2022/09/GHSA-w6wh-qr7x-h932/GHSA-w6wh-qr7x-h932.json +++ b/advisories/unreviewed/2022/09/GHSA-w6wh-qr7x-h932/GHSA-w6wh-qr7x-h932.json @@ -32,6 +32,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-192", + "CWE-681", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-34xg-89cf-qr7j/GHSA-34xg-89cf-qr7j.json b/advisories/unreviewed/2022/10/GHSA-34xg-89cf-qr7j/GHSA-34xg-89cf-qr7j.json index b0bd518c507..fdaabda186a 100644 --- a/advisories/unreviewed/2022/10/GHSA-34xg-89cf-qr7j/GHSA-34xg-89cf-qr7j.json +++ b/advisories/unreviewed/2022/10/GHSA-34xg-89cf-qr7j/GHSA-34xg-89cf-qr7j.json @@ -28,6 +28,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", + "CWE-667", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-cp7v-6jp7-gpwm/GHSA-cp7v-6jp7-gpwm.json b/advisories/unreviewed/2022/10/GHSA-cp7v-6jp7-gpwm/GHSA-cp7v-6jp7-gpwm.json index fd69a8c6c21..60f8162bbde 100644 --- a/advisories/unreviewed/2022/10/GHSA-cp7v-6jp7-gpwm/GHSA-cp7v-6jp7-gpwm.json +++ b/advisories/unreviewed/2022/10/GHSA-cp7v-6jp7-gpwm/GHSA-cp7v-6jp7-gpwm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-9wc2-mv76-38jp/GHSA-9wc2-mv76-38jp.json b/advisories/unreviewed/2022/11/GHSA-9wc2-mv76-38jp/GHSA-9wc2-mv76-38jp.json index b922489e3b4..64230b8b32c 100644 --- a/advisories/unreviewed/2022/11/GHSA-9wc2-mv76-38jp/GHSA-9wc2-mv76-38jp.json +++ b/advisories/unreviewed/2022/11/GHSA-9wc2-mv76-38jp/GHSA-9wc2-mv76-38jp.json @@ -32,7 +32,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-305", + "CWE-307" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json b/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json index 2b6988ff09b..881d4222ac3 100644 --- a/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json +++ b/advisories/unreviewed/2022/11/GHSA-f39f-g3gv-88jq/GHSA-f39f-g3gv-88jq.json @@ -36,6 +36,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", + "CWE-117", "CWE-74" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/11/GHSA-m5r3-w5hq-w9c2/GHSA-m5r3-w5hq-w9c2.json b/advisories/unreviewed/2022/11/GHSA-m5r3-w5hq-w9c2/GHSA-m5r3-w5hq-w9c2.json index 431cf1cc749..cc0dd8ca550 100644 --- a/advisories/unreviewed/2022/11/GHSA-m5r3-w5hq-w9c2/GHSA-m5r3-w5hq-w9c2.json +++ b/advisories/unreviewed/2022/11/GHSA-m5r3-w5hq-w9c2/GHSA-m5r3-w5hq-w9c2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20", + "CWE-287" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-p6xj-9vgw-4xp9/GHSA-p6xj-9vgw-4xp9.json b/advisories/unreviewed/2022/11/GHSA-p6xj-9vgw-4xp9/GHSA-p6xj-9vgw-4xp9.json index 5663ed8c428..e23413bdd6e 100644 --- a/advisories/unreviewed/2022/11/GHSA-p6xj-9vgw-4xp9/GHSA-p6xj-9vgw-4xp9.json +++ b/advisories/unreviewed/2022/11/GHSA-p6xj-9vgw-4xp9/GHSA-p6xj-9vgw-4xp9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-444", + "CWE-603" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json b/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json index 30769ada474..199a906813a 100644 --- a/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json +++ b/advisories/unreviewed/2022/12/GHSA-86q3-6wjf-3984/GHSA-86q3-6wjf-3984.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-134", "CWE-74" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-rgw4-gxj6-8ffh/GHSA-rgw4-gxj6-8ffh.json b/advisories/unreviewed/2022/12/GHSA-rgw4-gxj6-8ffh/GHSA-rgw4-gxj6-8ffh.json index 27450c167b0..0ffb4825af1 100644 --- a/advisories/unreviewed/2022/12/GHSA-rgw4-gxj6-8ffh/GHSA-rgw4-gxj6-8ffh.json +++ b/advisories/unreviewed/2022/12/GHSA-rgw4-gxj6-8ffh/GHSA-rgw4-gxj6-8ffh.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json b/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json index d468370c3b9..a9586c4ce3b 100644 --- a/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json +++ b/advisories/unreviewed/2022/12/GHSA-x4qc-6q9c-46qw/GHSA-x4qc-6q9c-46qw.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-302" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-5rfm-q8cg-pq99/GHSA-5rfm-q8cg-pq99.json b/advisories/unreviewed/2023/01/GHSA-5rfm-q8cg-pq99/GHSA-5rfm-q8cg-pq99.json index 8240593be8d..f5bace32021 100644 --- a/advisories/unreviewed/2023/01/GHSA-5rfm-q8cg-pq99/GHSA-5rfm-q8cg-pq99.json +++ b/advisories/unreviewed/2023/01/GHSA-5rfm-q8cg-pq99/GHSA-5rfm-q8cg-pq99.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-352", "CWE-863" ], diff --git a/advisories/unreviewed/2023/06/GHSA-23qq-wph5-jwww/GHSA-23qq-wph5-jwww.json b/advisories/unreviewed/2023/06/GHSA-23qq-wph5-jwww/GHSA-23qq-wph5-jwww.json new file mode 100644 index 00000000000..82f08c2f63f --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-23qq-wph5-jwww/GHSA-23qq-wph5-jwww.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23qq-wph5-jwww", + "modified": "2023-06-27T21:30:50Z", + "published": "2023-06-27T21:30:50Z", + "aliases": [ + "CVE-2020-18416" + ], + "details": "An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18416" + }, + { + "type": "WEB", + "url": "https://github.com/dtorp06/jymusic/issues/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-2w8c-hj6v-28vw/GHSA-2w8c-hj6v-28vw.json b/advisories/unreviewed/2023/06/GHSA-2w8c-hj6v-28vw/GHSA-2w8c-hj6v-28vw.json new file mode 100644 index 00000000000..2a9e2c7414e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-2w8c-hj6v-28vw/GHSA-2w8c-hj6v-28vw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w8c-hj6v-28vw", + "modified": "2023-06-27T21:30:49Z", + "published": "2023-06-27T21:30:49Z", + "aliases": [ + "CVE-2023-25004" + ], + "details": "A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25004" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-3jf9-v55g-6wcc/GHSA-3jf9-v55g-6wcc.json b/advisories/unreviewed/2023/06/GHSA-3jf9-v55g-6wcc/GHSA-3jf9-v55g-6wcc.json index 4d301b2867e..633b9c2a490 100644 --- a/advisories/unreviewed/2023/06/GHSA-3jf9-v55g-6wcc/GHSA-3jf9-v55g-6wcc.json +++ b/advisories/unreviewed/2023/06/GHSA-3jf9-v55g-6wcc/GHSA-3jf9-v55g-6wcc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3jf9-v55g-6wcc", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20067" ], "details": "File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-5jr5-6wr3-298c/GHSA-5jr5-6wr3-298c.json b/advisories/unreviewed/2023/06/GHSA-5jr5-6wr3-298c/GHSA-5jr5-6wr3-298c.json index b047d410787..36b4488def5 100644 --- a/advisories/unreviewed/2023/06/GHSA-5jr5-6wr3-298c/GHSA-5jr5-6wr3-298c.json +++ b/advisories/unreviewed/2023/06/GHSA-5jr5-6wr3-298c/GHSA-5jr5-6wr3-298c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jr5-6wr3-298c", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20918" ], "details": "An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-764x-v9xv-4xj8/GHSA-764x-v9xv-4xj8.json b/advisories/unreviewed/2023/06/GHSA-764x-v9xv-4xj8/GHSA-764x-v9xv-4xj8.json new file mode 100644 index 00000000000..3ee5fc066a7 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-764x-v9xv-4xj8/GHSA-764x-v9xv-4xj8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-764x-v9xv-4xj8", + "modified": "2023-06-27T21:30:49Z", + "published": "2023-06-27T21:30:49Z", + "aliases": [ + "CVE-2020-18410" + ], + "details": "A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18410" + }, + { + "type": "WEB", + "url": "https://github.com/GodEpic/chaojicms/issues/6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-788j-595w-gjx9/GHSA-788j-595w-gjx9.json b/advisories/unreviewed/2023/06/GHSA-788j-595w-gjx9/GHSA-788j-595w-gjx9.json index 9dda6d2e37f..78a52ab7027 100644 --- a/advisories/unreviewed/2023/06/GHSA-788j-595w-gjx9/GHSA-788j-595w-gjx9.json +++ b/advisories/unreviewed/2023/06/GHSA-788j-595w-gjx9/GHSA-788j-595w-gjx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-788j-595w-gjx9", - "modified": "2023-06-21T15:30:21Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-21T15:30:21Z", "aliases": [ "CVE-2023-27429" diff --git a/advisories/unreviewed/2023/06/GHSA-8x43-c958-qqx4/GHSA-8x43-c958-qqx4.json b/advisories/unreviewed/2023/06/GHSA-8x43-c958-qqx4/GHSA-8x43-c958-qqx4.json index 42ee9626d42..056c3d829ee 100644 --- a/advisories/unreviewed/2023/06/GHSA-8x43-c958-qqx4/GHSA-8x43-c958-qqx4.json +++ b/advisories/unreviewed/2023/06/GHSA-8x43-c958-qqx4/GHSA-8x43-c958-qqx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8x43-c958-qqx4", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2023-34597" ], "details": "A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-964x-jm93-vwr2/GHSA-964x-jm93-vwr2.json b/advisories/unreviewed/2023/06/GHSA-964x-jm93-vwr2/GHSA-964x-jm93-vwr2.json index 6ce45a0c151..8dadafa4713 100644 --- a/advisories/unreviewed/2023/06/GHSA-964x-jm93-vwr2/GHSA-964x-jm93-vwr2.json +++ b/advisories/unreviewed/2023/06/GHSA-964x-jm93-vwr2/GHSA-964x-jm93-vwr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-964x-jm93-vwr2", - "modified": "2023-06-21T15:30:21Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-21T15:30:21Z", "aliases": [ "CVE-2023-27439" diff --git a/advisories/unreviewed/2023/06/GHSA-9q56-96jc-v96w/GHSA-9q56-96jc-v96w.json b/advisories/unreviewed/2023/06/GHSA-9q56-96jc-v96w/GHSA-9q56-96jc-v96w.json new file mode 100644 index 00000000000..33ae291076d --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-9q56-96jc-v96w/GHSA-9q56-96jc-v96w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q56-96jc-v96w", + "modified": "2023-06-27T21:30:50Z", + "published": "2023-06-27T21:30:50Z", + "aliases": [ + "CVE-2020-18409" + ], + "details": "Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18409" + }, + { + "type": "WEB", + "url": "https://github.com/xwlrbh/Catfish/issues/5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-cvvh-gx49-6x22/GHSA-cvvh-gx49-6x22.json b/advisories/unreviewed/2023/06/GHSA-cvvh-gx49-6x22/GHSA-cvvh-gx49-6x22.json index 0eaf72fd012..79f9d1e741d 100644 --- a/advisories/unreviewed/2023/06/GHSA-cvvh-gx49-6x22/GHSA-cvvh-gx49-6x22.json +++ b/advisories/unreviewed/2023/06/GHSA-cvvh-gx49-6x22/GHSA-cvvh-gx49-6x22.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvvh-gx49-6x22", - "modified": "2023-06-20T15:31:09Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:09Z", "aliases": [ "CVE-2023-34600" ], "details": "Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-cxw7-q566-ccx6/GHSA-cxw7-q566-ccx6.json b/advisories/unreviewed/2023/06/GHSA-cxw7-q566-ccx6/GHSA-cxw7-q566-ccx6.json index f8c09c9fc2a..c23d39462c8 100644 --- a/advisories/unreviewed/2023/06/GHSA-cxw7-q566-ccx6/GHSA-cxw7-q566-ccx6.json +++ b/advisories/unreviewed/2023/06/GHSA-cxw7-q566-ccx6/GHSA-cxw7-q566-ccx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cxw7-q566-ccx6", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20502" ], "details": "Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-f9wj-wv6x-9pj8/GHSA-f9wj-wv6x-9pj8.json b/advisories/unreviewed/2023/06/GHSA-f9wj-wv6x-9pj8/GHSA-f9wj-wv6x-9pj8.json new file mode 100644 index 00000000000..4d4a323d257 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-f9wj-wv6x-9pj8/GHSA-f9wj-wv6x-9pj8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9wj-wv6x-9pj8", + "modified": "2023-06-27T21:30:48Z", + "published": "2023-06-27T21:30:48Z", + "aliases": [ + "CVE-2023-23468" + ], + "details": "IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration which may allow creation of namespaces within a cluster. IBM X-Force ID: 244500.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23468" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/244500" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7005999" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-fw27-7fvf-jgxv/GHSA-fw27-7fvf-jgxv.json b/advisories/unreviewed/2023/06/GHSA-fw27-7fvf-jgxv/GHSA-fw27-7fvf-jgxv.json new file mode 100644 index 00000000000..38e05e62dae --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-fw27-7fvf-jgxv/GHSA-fw27-7fvf-jgxv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw27-7fvf-jgxv", + "modified": "2023-06-27T21:30:49Z", + "published": "2023-06-27T21:30:49Z", + "aliases": [ + "CVE-2023-29068" + ], + "details": "A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29068" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-fw3q-vjp3-89w5/GHSA-fw3q-vjp3-89w5.json b/advisories/unreviewed/2023/06/GHSA-fw3q-vjp3-89w5/GHSA-fw3q-vjp3-89w5.json index 77f65bab3b1..24cb71e50ec 100644 --- a/advisories/unreviewed/2023/06/GHSA-fw3q-vjp3-89w5/GHSA-fw3q-vjp3-89w5.json +++ b/advisories/unreviewed/2023/06/GHSA-fw3q-vjp3-89w5/GHSA-fw3q-vjp3-89w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw3q-vjp3-89w5", - "modified": "2023-06-13T09:30:19Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-13T09:30:19Z", "aliases": [ "CVE-2023-2673" diff --git a/advisories/unreviewed/2023/06/GHSA-g2c3-62p7-49qv/GHSA-g2c3-62p7-49qv.json b/advisories/unreviewed/2023/06/GHSA-g2c3-62p7-49qv/GHSA-g2c3-62p7-49qv.json new file mode 100644 index 00000000000..3959e4c80a4 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-g2c3-62p7-49qv/GHSA-g2c3-62p7-49qv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2c3-62p7-49qv", + "modified": "2023-06-27T21:30:50Z", + "published": "2023-06-27T21:30:50Z", + "aliases": [ + "CVE-2020-18414" + ], + "details": "Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via /index.php?admin-master-webset.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18414" + }, + { + "type": "WEB", + "url": "https://github.com/GodEpic/chaojicms/issues/3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-h7fv-hhvw-364h/GHSA-h7fv-hhvw-364h.json b/advisories/unreviewed/2023/06/GHSA-h7fv-hhvw-364h/GHSA-h7fv-hhvw-364h.json new file mode 100644 index 00000000000..357d2e77ed5 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-h7fv-hhvw-364h/GHSA-h7fv-hhvw-364h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7fv-hhvw-364h", + "modified": "2023-06-27T21:30:50Z", + "published": "2023-06-27T21:30:50Z", + "aliases": [ + "CVE-2020-19902" + ], + "details": "Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19902" + }, + { + "type": "WEB", + "url": "https://github.com/vedees/wcms/issues/3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-h9xp-w8f3-2qrr/GHSA-h9xp-w8f3-2qrr.json b/advisories/unreviewed/2023/06/GHSA-h9xp-w8f3-2qrr/GHSA-h9xp-w8f3-2qrr.json index 342d8c8e3c2..7d25bd3e1c9 100644 --- a/advisories/unreviewed/2023/06/GHSA-h9xp-w8f3-2qrr/GHSA-h9xp-w8f3-2qrr.json +++ b/advisories/unreviewed/2023/06/GHSA-h9xp-w8f3-2qrr/GHSA-h9xp-w8f3-2qrr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9xp-w8f3-2qrr", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20491" ], "details": "SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-hpj7-4fx3-hmfp/GHSA-hpj7-4fx3-hmfp.json b/advisories/unreviewed/2023/06/GHSA-hpj7-4fx3-hmfp/GHSA-hpj7-4fx3-hmfp.json index 1d68ead8d1c..c0b92642bb9 100644 --- a/advisories/unreviewed/2023/06/GHSA-hpj7-4fx3-hmfp/GHSA-hpj7-4fx3-hmfp.json +++ b/advisories/unreviewed/2023/06/GHSA-hpj7-4fx3-hmfp/GHSA-hpj7-4fx3-hmfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hpj7-4fx3-hmfp", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-31239" ], "details": "Stack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attacker to execute arbitrary code by having user open a specially crafted VPR file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-hxgq-2x58-pgpq/GHSA-hxgq-2x58-pgpq.json b/advisories/unreviewed/2023/06/GHSA-hxgq-2x58-pgpq/GHSA-hxgq-2x58-pgpq.json index 59566b2bd4a..cd79546bcbd 100644 --- a/advisories/unreviewed/2023/06/GHSA-hxgq-2x58-pgpq/GHSA-hxgq-2x58-pgpq.json +++ b/advisories/unreviewed/2023/06/GHSA-hxgq-2x58-pgpq/GHSA-hxgq-2x58-pgpq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxgq-2x58-pgpq", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20703" ], "details": "Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-mr5g-mvhg-7rhw/GHSA-mr5g-mvhg-7rhw.json b/advisories/unreviewed/2023/06/GHSA-mr5g-mvhg-7rhw/GHSA-mr5g-mvhg-7rhw.json new file mode 100644 index 00000000000..040fb1d7994 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-mr5g-mvhg-7rhw/GHSA-mr5g-mvhg-7rhw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr5g-mvhg-7rhw", + "modified": "2023-06-27T21:30:50Z", + "published": "2023-06-27T21:30:50Z", + "aliases": [ + "CVE-2023-30993" + ], + "details": "IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30993" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/254136" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6995221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json b/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json index e499fef3f48..2a32f2b6ea6 100644 --- a/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json +++ b/advisories/unreviewed/2023/06/GHSA-pfwq-49pr-pf8x/GHSA-pfwq-49pr-pf8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfwq-49pr-pf8x", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-30759" ], "details": "The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-r2pc-66q7-8m6r/GHSA-r2pc-66q7-8m6r.json b/advisories/unreviewed/2023/06/GHSA-r2pc-66q7-8m6r/GHSA-r2pc-66q7-8m6r.json index 699e8773839..7a4642373aa 100644 --- a/advisories/unreviewed/2023/06/GHSA-r2pc-66q7-8m6r/GHSA-r2pc-66q7-8m6r.json +++ b/advisories/unreviewed/2023/06/GHSA-r2pc-66q7-8m6r/GHSA-r2pc-66q7-8m6r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2pc-66q7-8m6r", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-32542" ], "details": "Out-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 file may lead to information disclosure and/or arbitrary code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-v3g5-6v9c-w8g3/GHSA-v3g5-6v9c-w8g3.json b/advisories/unreviewed/2023/06/GHSA-v3g5-6v9c-w8g3/GHSA-v3g5-6v9c-w8g3.json new file mode 100644 index 00000000000..dc2e38f45bd --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-v3g5-6v9c-w8g3/GHSA-v3g5-6v9c-w8g3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3g5-6v9c-w8g3", + "modified": "2023-06-27T21:30:49Z", + "published": "2023-06-27T21:30:49Z", + "aliases": [ + "CVE-2020-18413" + ], + "details": "Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18413" + }, + { + "type": "WEB", + "url": "https://github.com/GodEpic/chaojicms/issues/5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-vg7q-4h76-hx2w/GHSA-vg7q-4h76-hx2w.json b/advisories/unreviewed/2023/06/GHSA-vg7q-4h76-hx2w/GHSA-vg7q-4h76-hx2w.json new file mode 100644 index 00000000000..41e01b7256c --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-vg7q-4h76-hx2w/GHSA-vg7q-4h76-hx2w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg7q-4h76-hx2w", + "modified": "2023-06-27T21:30:48Z", + "published": "2023-06-27T21:30:48Z", + "aliases": [ + "CVE-2020-18418" + ], + "details": "A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18418" + }, + { + "type": "WEB", + "url": "https://github.com/GodEpic/Vulnerability-detection/blob/master/feifeicms/FeiFeiCMS_4.1_csrf.doc" + }, + { + "type": "WEB", + "url": "https://github.com/GodEpic/Vulnerability-detection/blob/master/feifeicms/poc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-vhgh-2x75-3pw8/GHSA-vhgh-2x75-3pw8.json b/advisories/unreviewed/2023/06/GHSA-vhgh-2x75-3pw8/GHSA-vhgh-2x75-3pw8.json new file mode 100644 index 00000000000..a7f5dc9954c --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-vhgh-2x75-3pw8/GHSA-vhgh-2x75-3pw8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhgh-2x75-3pw8", + "modified": "2023-06-27T21:30:50Z", + "published": "2023-06-27T21:30:50Z", + "aliases": [ + "CVE-2020-18404" + ], + "details": "An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18404" + }, + { + "type": "WEB", + "url": "https://github.com/source-hunter/espcms/issues/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-vwf2-f9cg-9fg8/GHSA-vwf2-f9cg-9fg8.json b/advisories/unreviewed/2023/06/GHSA-vwf2-f9cg-9fg8/GHSA-vwf2-f9cg-9fg8.json index 89912ff9765..e9b5581d8c7 100644 --- a/advisories/unreviewed/2023/06/GHSA-vwf2-f9cg-9fg8/GHSA-vwf2-f9cg-9fg8.json +++ b/advisories/unreviewed/2023/06/GHSA-vwf2-f9cg-9fg8/GHSA-vwf2-f9cg-9fg8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwf2-f9cg-9fg8", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-35857" ], "details": "In Siren Investigate before 13.2.2, session keys remain active even after logging out.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-613" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-vwr9-mg8c-jp94/GHSA-vwr9-mg8c-jp94.json b/advisories/unreviewed/2023/06/GHSA-vwr9-mg8c-jp94/GHSA-vwr9-mg8c-jp94.json index 7d4a18996b5..038b450e847 100644 --- a/advisories/unreviewed/2023/06/GHSA-vwr9-mg8c-jp94/GHSA-vwr9-mg8c-jp94.json +++ b/advisories/unreviewed/2023/06/GHSA-vwr9-mg8c-jp94/GHSA-vwr9-mg8c-jp94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwr9-mg8c-jp94", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20636" ], "details": "SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-w2fg-vh2j-wmhr/GHSA-w2fg-vh2j-wmhr.json b/advisories/unreviewed/2023/06/GHSA-w2fg-vh2j-wmhr/GHSA-w2fg-vh2j-wmhr.json index ec4be0c131c..09cd368dc28 100644 --- a/advisories/unreviewed/2023/06/GHSA-w2fg-vh2j-wmhr/GHSA-w2fg-vh2j-wmhr.json +++ b/advisories/unreviewed/2023/06/GHSA-w2fg-vh2j-wmhr/GHSA-w2fg-vh2j-wmhr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2fg-vh2j-wmhr", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-21268" ], "details": "Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-w2mw-92v8-xh4h/GHSA-w2mw-92v8-xh4h.json b/advisories/unreviewed/2023/06/GHSA-w2mw-92v8-xh4h/GHSA-w2mw-92v8-xh4h.json index 30876b5d844..c92b3e181f1 100644 --- a/advisories/unreviewed/2023/06/GHSA-w2mw-92v8-xh4h/GHSA-w2mw-92v8-xh4h.json +++ b/advisories/unreviewed/2023/06/GHSA-w2mw-92v8-xh4h/GHSA-w2mw-92v8-xh4h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2mw-92v8-xh4h", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20335" ], "details": "Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a denial of service via the editorUpdateRow function in kilo.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-w3rr-qmj4-q59x/GHSA-w3rr-qmj4-q59x.json b/advisories/unreviewed/2023/06/GHSA-w3rr-qmj4-q59x/GHSA-w3rr-qmj4-q59x.json index 6bfabfedff0..69c66715277 100644 --- a/advisories/unreviewed/2023/06/GHSA-w3rr-qmj4-q59x/GHSA-w3rr-qmj4-q59x.json +++ b/advisories/unreviewed/2023/06/GHSA-w3rr-qmj4-q59x/GHSA-w3rr-qmj4-q59x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3rr-qmj4-q59x", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-32538" ], "details": "Stack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may lead to information disclosure and/or arbitrary code execution. This vulnerability is different from CVE-2023-32273 and CVE-2023-32201.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json b/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json new file mode 100644 index 00000000000..3d55da59dee --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-w6xx-rr92-x6gv/GHSA-w6xx-rr92-x6gv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6xx-rr92-x6gv", + "modified": "2023-06-27T21:30:48Z", + "published": "2023-06-27T21:30:48Z", + "aliases": [ + "CVE-2023-22593" + ], + "details": "\nIBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22593" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/244074" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7006001" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-whpq-78mq-qcj6/GHSA-whpq-78mq-qcj6.json b/advisories/unreviewed/2023/06/GHSA-whpq-78mq-qcj6/GHSA-whpq-78mq-qcj6.json new file mode 100644 index 00000000000..05646733908 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-whpq-78mq-qcj6/GHSA-whpq-78mq-qcj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whpq-78mq-qcj6", + "modified": "2023-06-27T21:30:51Z", + "published": "2023-06-27T21:30:51Z", + "aliases": [ + "CVE-2023-3436" + ], + "details": "Xpdf 4.04 will deadlock on a PDF object stream whose \"Length\" field is itself in another object stream.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3436" + }, + { + "type": "WEB", + "url": "https://forum.xpdfreader.com/viewtopic.php?t=42618" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-833" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-wxm7-fv5m-rc6h/GHSA-wxm7-fv5m-rc6h.json b/advisories/unreviewed/2023/06/GHSA-wxm7-fv5m-rc6h/GHSA-wxm7-fv5m-rc6h.json new file mode 100644 index 00000000000..3aa7ad63964 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-wxm7-fv5m-rc6h/GHSA-wxm7-fv5m-rc6h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxm7-fv5m-rc6h", + "modified": "2023-06-27T21:30:49Z", + "published": "2023-06-27T21:30:49Z", + "aliases": [ + "CVE-2020-18406" + ], + "details": "An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-18406" + }, + { + "type": "WEB", + "url": "https://github.com/source-hunter/cmseasy/issues/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-x56c-grq3-w2x8/GHSA-x56c-grq3-w2x8.json b/advisories/unreviewed/2023/06/GHSA-x56c-grq3-w2x8/GHSA-x56c-grq3-w2x8.json index f0a29b0ce31..accff52e53c 100644 --- a/advisories/unreviewed/2023/06/GHSA-x56c-grq3-w2x8/GHSA-x56c-grq3-w2x8.json +++ b/advisories/unreviewed/2023/06/GHSA-x56c-grq3-w2x8/GHSA-x56c-grq3-w2x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x56c-grq3-w2x8", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:47Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20413" ], "details": "SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-xjf3-qfqc-g6g5/GHSA-xjf3-qfqc-g6g5.json b/advisories/unreviewed/2023/06/GHSA-xjf3-qfqc-g6g5/GHSA-xjf3-qfqc-g6g5.json index f67c3d0e31a..07a0acf87f8 100644 --- a/advisories/unreviewed/2023/06/GHSA-xjf3-qfqc-g6g5/GHSA-xjf3-qfqc-g6g5.json +++ b/advisories/unreviewed/2023/06/GHSA-xjf3-qfqc-g6g5/GHSA-xjf3-qfqc-g6g5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjf3-qfqc-g6g5", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2023-35095" diff --git a/advisories/unreviewed/2023/06/GHSA-xv2w-5rg6-j3gc/GHSA-xv2w-5rg6-j3gc.json b/advisories/unreviewed/2023/06/GHSA-xv2w-5rg6-j3gc/GHSA-xv2w-5rg6-j3gc.json index 6cc88ae3f33..9d89a9a98db 100644 --- a/advisories/unreviewed/2023/06/GHSA-xv2w-5rg6-j3gc/GHSA-xv2w-5rg6-j3gc.json +++ b/advisories/unreviewed/2023/06/GHSA-xv2w-5rg6-j3gc/GHSA-xv2w-5rg6-j3gc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xv2w-5rg6-j3gc", - "modified": "2023-06-20T15:31:08Z", + "modified": "2023-06-27T21:30:46Z", "published": "2023-06-20T15:31:08Z", "aliases": [ "CVE-2020-20070" ], "details": "Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false,