From 7fafdce406a97946f40be11d0d1009518f9015ff Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 Nov 2023 21:31:50 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9qr8-h5jr-2gmw.json | 4 ++ .../GHSA-2rrm-7h4w-qg5g.json | 11 +++-- .../GHSA-3x9m-qxj4-gff3.json | 11 +++-- .../GHSA-3xwq-m4f9-jf8w.json | 11 +++-- .../GHSA-577v-m627-qpf4.json | 11 +++-- .../GHSA-5vqr-qc3r-pv4r.json | 11 +++-- .../GHSA-67p3-vgwg-jfjf.json | 7 +-- .../GHSA-7rjj-x9r2-43h4.json | 11 +++-- .../GHSA-8jvw-g6jp-rqqp.json | 11 +++-- .../GHSA-8prx-84h6-4fr5.json | 2 +- .../GHSA-9xjj-cwg3-hjc7.json | 13 +++--- .../GHSA-g468-f3m4-727c.json | 11 +++-- .../GHSA-g5gm-qgrx-3h7c.json | 11 +++-- .../GHSA-hmf3-8cx7-g4jw.json | 11 +++-- .../GHSA-jmvp-hm64-wcvc.json | 11 +++-- .../GHSA-m9r2-v6px-98w2.json | 11 +++-- .../GHSA-mfm9-gf89-rmqf.json | 13 +++--- .../GHSA-mph8-5cmm-748x.json | 11 +++-- .../GHSA-p649-773m-qr8x.json | 11 +++-- .../GHSA-qgfp-cppw-mc67.json | 11 +++-- .../GHSA-r2hv-xh5m-g4w7.json | 13 +++--- .../GHSA-r75f-cj9v-2727.json | 11 +++-- .../GHSA-w47r-jmwx-8fq5.json | 11 +++-- .../GHSA-x7w6-3cp2-qjcv.json | 4 +- .../GHSA-39vm-62wp-46hv.json | 11 +++-- .../GHSA-3pxf-gwjv-f45v.json | 13 +++--- .../GHSA-4284-q573-745v.json | 2 +- .../GHSA-43wm-36v8-wrcq.json | 35 +++++++++++++++ .../GHSA-52gq-6r3g-qrmr.json | 39 +++++++++++++++++ .../GHSA-52rh-vv3q-8jrh.json | 35 +++++++++++++++ .../GHSA-5fvg-7q6x-mgh2.json | 38 ++++++++++++++++ .../GHSA-75mv-f5hh-c65h.json | 11 +++-- .../GHSA-782h-r93g-8gcc.json | 35 +++++++++++++++ .../GHSA-7cjp-92p9-vr97.json | 11 +++-- .../GHSA-7x3f-23vq-mrxp.json | 11 +++-- .../GHSA-89jm-mj5r-5rp8.json | 35 +++++++++++++++ .../GHSA-8rrh-9958-v272.json | 13 +++--- .../GHSA-8v7h-jhgr-2fgc.json | 11 +++-- .../GHSA-c46p-5pq2-qpcg.json | 11 +++-- .../GHSA-c8pp-vxj4-7mp3.json | 11 +++-- .../GHSA-ch98-xc2f-x3rf.json | 2 +- .../GHSA-cm77-ccvm-f7p6.json | 43 +++++++++++++++++++ .../GHSA-f3pw-mpwc-pw7v.json | 13 +++--- .../GHSA-f4hj-7928-3pr9.json | 39 +++++++++++++++++ .../GHSA-g35p-9423-7ww9.json | 11 +++-- .../GHSA-g896-hqwq-6qp3.json | 35 +++++++++++++++ .../GHSA-ggg3-qv53-5qcr.json | 35 +++++++++++++++ .../GHSA-gj94-rc7p-wwm6.json | 35 +++++++++++++++ .../GHSA-gww9-w46q-2x34.json | 9 ++-- .../GHSA-h6c7-v3fj-vggf.json | 2 +- .../GHSA-hrr6-mvh4-hgmq.json | 4 +- .../GHSA-jwj7-8489-4jqm.json | 11 +++-- .../GHSA-mh8h-8fcp-q2hp.json | 13 +++--- .../GHSA-p4vh-m995-92m8.json | 9 ++-- .../GHSA-pf76-3jj8-rpqg.json | 2 +- .../GHSA-pq78-6h8h-rcf4.json | 11 +++-- .../GHSA-q3gq-rg4m-vgrp.json | 39 +++++++++++++++++ .../GHSA-qf75-86xr-cfpw.json | 11 +++-- .../GHSA-qfx8-xprj-wvh4.json | 11 +++-- .../GHSA-qwmr-4wg7-xq78.json | 35 +++++++++++++++ .../GHSA-r8cx-47rc-5x49.json | 35 +++++++++++++++ .../GHSA-v92j-4pq6-rqx3.json | 13 +++--- .../GHSA-vr5f-vjc4-r753.json | 13 +++--- .../GHSA-vv89-229f-wqm4.json | 13 +++--- .../GHSA-wf5p-g6vw-rhxx.json | 35 +++++++++++++++ .../GHSA-x65g-79jp-p76h.json | 13 +++--- .../GHSA-xg45-v5rp-r5m2.json | 35 +++++++++++++++ .../GHSA-xmhq-fw78-wjxr.json | 11 +++-- 68 files changed, 910 insertions(+), 193 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json create mode 100644 advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-f4hj-7928-3pr9/GHSA-f4hj-7928-3pr9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-ggg3-qv53-5qcr/GHSA-ggg3-qv53-5qcr.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gj94-rc7p-wwm6/GHSA-gj94-rc7p-wwm6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q3gq-rg4m-vgrp/GHSA-q3gq-rg4m-vgrp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-qwmr-4wg7-xq78/GHSA-qwmr-4wg7-xq78.json create mode 100644 advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json create mode 100644 advisories/unreviewed/2023/11/GHSA-wf5p-g6vw-rhxx/GHSA-wf5p-g6vw-rhxx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xg45-v5rp-r5m2/GHSA-xg45-v5rp-r5m2.json diff --git a/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json b/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json index 47f60d1a8fd..228a69dc2f8 100644 --- a/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json +++ b/advisories/unreviewed/2023/02/GHSA-9qr8-h5jr-2gmw/GHSA-9qr8-h5jr-2gmw.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/11/08/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/11/08/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-2rrm-7h4w-qg5g/GHSA-2rrm-7h4w-qg5g.json b/advisories/unreviewed/2023/10/GHSA-2rrm-7h4w-qg5g/GHSA-2rrm-7h4w-qg5g.json index 6b07ab06020..32cbbb61ffa 100644 --- a/advisories/unreviewed/2023/10/GHSA-2rrm-7h4w-qg5g/GHSA-2rrm-7h4w-qg5g.json +++ b/advisories/unreviewed/2023/10/GHSA-2rrm-7h4w-qg5g/GHSA-2rrm-7h4w-qg5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2rrm-7h4w-qg5g", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5360" ], "details": "The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3x9m-qxj4-gff3/GHSA-3x9m-qxj4-gff3.json b/advisories/unreviewed/2023/10/GHSA-3x9m-qxj4-gff3/GHSA-3x9m-qxj4-gff3.json index ac014e802b1..065e062fb03 100644 --- a/advisories/unreviewed/2023/10/GHSA-3x9m-qxj4-gff3/GHSA-3x9m-qxj4-gff3.json +++ b/advisories/unreviewed/2023/10/GHSA-3x9m-qxj4-gff3/GHSA-3x9m-qxj4-gff3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x9m-qxj4-gff3", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-31212" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3xwq-m4f9-jf8w/GHSA-3xwq-m4f9-jf8w.json b/advisories/unreviewed/2023/10/GHSA-3xwq-m4f9-jf8w/GHSA-3xwq-m4f9-jf8w.json index 03c0e6a5ef1..e3654b3e0d6 100644 --- a/advisories/unreviewed/2023/10/GHSA-3xwq-m4f9-jf8w/GHSA-3xwq-m4f9-jf8w.json +++ b/advisories/unreviewed/2023/10/GHSA-3xwq-m4f9-jf8w/GHSA-3xwq-m4f9-jf8w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3xwq-m4f9-jf8w", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-24410" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-577v-m627-qpf4/GHSA-577v-m627-qpf4.json b/advisories/unreviewed/2023/10/GHSA-577v-m627-qpf4/GHSA-577v-m627-qpf4.json index 78efb6e026b..f868cc75bea 100644 --- a/advisories/unreviewed/2023/10/GHSA-577v-m627-qpf4/GHSA-577v-m627-qpf4.json +++ b/advisories/unreviewed/2023/10/GHSA-577v-m627-qpf4/GHSA-577v-m627-qpf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-577v-m627-qpf4", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-5211" ], "details": "The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5vqr-qc3r-pv4r/GHSA-5vqr-qc3r-pv4r.json b/advisories/unreviewed/2023/10/GHSA-5vqr-qc3r-pv4r/GHSA-5vqr-qc3r-pv4r.json index 9d6e9455e64..c27a07ba2e3 100644 --- a/advisories/unreviewed/2023/10/GHSA-5vqr-qc3r-pv4r/GHSA-5vqr-qc3r-pv4r.json +++ b/advisories/unreviewed/2023/10/GHSA-5vqr-qc3r-pv4r/GHSA-5vqr-qc3r-pv4r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vqr-qc3r-pv4r", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-33927" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.3.19.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json b/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json index 9af005942cf..a034630fdad 100644 --- a/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json +++ b/advisories/unreviewed/2023/10/GHSA-67p3-vgwg-jfjf/GHSA-67p3-vgwg-jfjf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67p3-vgwg-jfjf", - "modified": "2023-10-30T00:30:17Z", + "modified": "2023-11-08T21:30:33Z", "published": "2023-10-30T00:30:17Z", "aliases": [ "CVE-2023-4393" @@ -28,9 +28,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-74" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-30T00:15:39Z" diff --git a/advisories/unreviewed/2023/10/GHSA-7rjj-x9r2-43h4/GHSA-7rjj-x9r2-43h4.json b/advisories/unreviewed/2023/10/GHSA-7rjj-x9r2-43h4/GHSA-7rjj-x9r2-43h4.json index 2cc35c6d534..51f7bf4baba 100644 --- a/advisories/unreviewed/2023/10/GHSA-7rjj-x9r2-43h4/GHSA-7rjj-x9r2-43h4.json +++ b/advisories/unreviewed/2023/10/GHSA-7rjj-x9r2-43h4/GHSA-7rjj-x9r2-43h4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7rjj-x9r2-43h4", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5243" ], "details": "The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8jvw-g6jp-rqqp/GHSA-8jvw-g6jp-rqqp.json b/advisories/unreviewed/2023/10/GHSA-8jvw-g6jp-rqqp/GHSA-8jvw-g6jp-rqqp.json index d478b828140..b111a13e81f 100644 --- a/advisories/unreviewed/2023/10/GHSA-8jvw-g6jp-rqqp/GHSA-8jvw-g6jp-rqqp.json +++ b/advisories/unreviewed/2023/10/GHSA-8jvw-g6jp-rqqp/GHSA-8jvw-g6jp-rqqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8jvw-g6jp-rqqp", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-5098" ], "details": "The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string \"true\", which could lead to a variety of outcomes, including DoS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json b/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json index 4bc863cbf6c..0ad27dd7463 100644 --- a/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json +++ b/advisories/unreviewed/2023/10/GHSA-8prx-84h6-4fr5/GHSA-8prx-84h6-4fr5.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json b/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json index 5f7acffa624..764cf4c2d84 100644 --- a/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json +++ b/advisories/unreviewed/2023/10/GHSA-9xjj-cwg3-hjc7/GHSA-9xjj-cwg3-hjc7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xjj-cwg3-hjc7", - "modified": "2023-10-31T21:32:35Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T21:32:35Z", "aliases": [ "CVE-2023-46484" ], "details": "An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T21:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-g468-f3m4-727c/GHSA-g468-f3m4-727c.json b/advisories/unreviewed/2023/10/GHSA-g468-f3m4-727c/GHSA-g468-f3m4-727c.json index 8ea2779a638..75dc72cf84d 100644 --- a/advisories/unreviewed/2023/10/GHSA-g468-f3m4-727c/GHSA-g468-f3m4-727c.json +++ b/advisories/unreviewed/2023/10/GHSA-g468-f3m4-727c/GHSA-g468-f3m4-727c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g468-f3m4-727c", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5519" ], "details": "The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-g5gm-qgrx-3h7c/GHSA-g5gm-qgrx-3h7c.json b/advisories/unreviewed/2023/10/GHSA-g5gm-qgrx-3h7c/GHSA-g5gm-qgrx-3h7c.json index 390b82c44ce..14c2e750484 100644 --- a/advisories/unreviewed/2023/10/GHSA-g5gm-qgrx-3h7c/GHSA-g5gm-qgrx-3h7c.json +++ b/advisories/unreviewed/2023/10/GHSA-g5gm-qgrx-3h7c/GHSA-g5gm-qgrx-3h7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5gm-qgrx-3h7c", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5238" ], "details": "The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-hmf3-8cx7-g4jw/GHSA-hmf3-8cx7-g4jw.json b/advisories/unreviewed/2023/10/GHSA-hmf3-8cx7-g4jw/GHSA-hmf3-8cx7-g4jw.json index a204cc017b7..a6bada017e4 100644 --- a/advisories/unreviewed/2023/10/GHSA-hmf3-8cx7-g4jw/GHSA-hmf3-8cx7-g4jw.json +++ b/advisories/unreviewed/2023/10/GHSA-hmf3-8cx7-g4jw/GHSA-hmf3-8cx7-g4jw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmf3-8cx7-g4jw", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5307" ], "details": "The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,9 +34,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jmvp-hm64-wcvc/GHSA-jmvp-hm64-wcvc.json b/advisories/unreviewed/2023/10/GHSA-jmvp-hm64-wcvc/GHSA-jmvp-hm64-wcvc.json index e7221050898..3a8d0e7510c 100644 --- a/advisories/unreviewed/2023/10/GHSA-jmvp-hm64-wcvc/GHSA-jmvp-hm64-wcvc.json +++ b/advisories/unreviewed/2023/10/GHSA-jmvp-hm64-wcvc/GHSA-jmvp-hm64-wcvc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jmvp-hm64-wcvc", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5237" ], "details": "The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,9 +34,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m9r2-v6px-98w2/GHSA-m9r2-v6px-98w2.json b/advisories/unreviewed/2023/10/GHSA-m9r2-v6px-98w2/GHSA-m9r2-v6px-98w2.json index 0cc12ae4a36..4fd8149c60f 100644 --- a/advisories/unreviewed/2023/10/GHSA-m9r2-v6px-98w2/GHSA-m9r2-v6px-98w2.json +++ b/advisories/unreviewed/2023/10/GHSA-m9r2-v6px-98w2/GHSA-m9r2-v6px-98w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9r2-v6px-98w2", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-5229" ], "details": "The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json b/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json index ca258e79aca..400a11d3def 100644 --- a/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json +++ b/advisories/unreviewed/2023/10/GHSA-mfm9-gf89-rmqf/GHSA-mfm9-gf89-rmqf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfm9-gf89-rmqf", - "modified": "2023-10-31T21:32:36Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-10-31T21:32:36Z", "aliases": [ "CVE-2023-46485" ], "details": "An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T21:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-mph8-5cmm-748x/GHSA-mph8-5cmm-748x.json b/advisories/unreviewed/2023/10/GHSA-mph8-5cmm-748x/GHSA-mph8-5cmm-748x.json index a1ef8f74cab..e2f1c1b4158 100644 --- a/advisories/unreviewed/2023/10/GHSA-mph8-5cmm-748x/GHSA-mph8-5cmm-748x.json +++ b/advisories/unreviewed/2023/10/GHSA-mph8-5cmm-748x/GHSA-mph8-5cmm-748x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mph8-5cmm-748x", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-36508" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress contact-form-to-db allows SQL Injection.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.1.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-p649-773m-qr8x/GHSA-p649-773m-qr8x.json b/advisories/unreviewed/2023/10/GHSA-p649-773m-qr8x/GHSA-p649-773m-qr8x.json index 41fa423ff0d..45031162210 100644 --- a/advisories/unreviewed/2023/10/GHSA-p649-773m-qr8x/GHSA-p649-773m-qr8x.json +++ b/advisories/unreviewed/2023/10/GHSA-p649-773m-qr8x/GHSA-p649-773m-qr8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p649-773m-qr8x", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-5458" ], "details": "The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-qgfp-cppw-mc67/GHSA-qgfp-cppw-mc67.json b/advisories/unreviewed/2023/10/GHSA-qgfp-cppw-mc67/GHSA-qgfp-cppw-mc67.json index 0dfd63e4da7..920f6c73a24 100644 --- a/advisories/unreviewed/2023/10/GHSA-qgfp-cppw-mc67/GHSA-qgfp-cppw-mc67.json +++ b/advisories/unreviewed/2023/10/GHSA-qgfp-cppw-mc67/GHSA-qgfp-cppw-mc67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qgfp-cppw-mc67", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-35879" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.78.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-r2hv-xh5m-g4w7/GHSA-r2hv-xh5m-g4w7.json b/advisories/unreviewed/2023/10/GHSA-r2hv-xh5m-g4w7/GHSA-r2hv-xh5m-g4w7.json index d3c2fb4c543..3318106e7ab 100644 --- a/advisories/unreviewed/2023/10/GHSA-r2hv-xh5m-g4w7/GHSA-r2hv-xh5m-g4w7.json +++ b/advisories/unreviewed/2023/10/GHSA-r2hv-xh5m-g4w7/GHSA-r2hv-xh5m-g4w7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2hv-xh5m-g4w7", - "modified": "2023-10-31T06:30:23Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T06:30:23Z", "aliases": [ "CVE-2023-43139" ], "details": "An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and controllers/front/validation.php components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T05:15:58Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-r75f-cj9v-2727/GHSA-r75f-cj9v-2727.json b/advisories/unreviewed/2023/10/GHSA-r75f-cj9v-2727/GHSA-r75f-cj9v-2727.json index 4bd232a9862..2ee63221b1d 100644 --- a/advisories/unreviewed/2023/10/GHSA-r75f-cj9v-2727/GHSA-r75f-cj9v-2727.json +++ b/advisories/unreviewed/2023/10/GHSA-r75f-cj9v-2727/GHSA-r75f-cj9v-2727.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r75f-cj9v-2727", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-4836" ], "details": "The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,9 +34,9 @@ "cwe_ids": [ "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-w47r-jmwx-8fq5/GHSA-w47r-jmwx-8fq5.json b/advisories/unreviewed/2023/10/GHSA-w47r-jmwx-8fq5/GHSA-w47r-jmwx-8fq5.json index 0b91434a834..dbaa7c4c90a 100644 --- a/advisories/unreviewed/2023/10/GHSA-w47r-jmwx-8fq5/GHSA-w47r-jmwx-8fq5.json +++ b/advisories/unreviewed/2023/10/GHSA-w47r-jmwx-8fq5/GHSA-w47r-jmwx-8fq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w47r-jmwx-8fq5", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T21:30:34Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-37966" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This issue affects User Activity Log: from n/a through 1.6.2.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json b/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json index 40ecdae53e3..70ba9fa31ff 100644 --- a/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json +++ b/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x7w6-3cp2-qjcv", - "modified": "2023-10-20T21:31:00Z", + "modified": "2023-11-08T21:30:33Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5561" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-200" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-16T20:15:18Z" diff --git a/advisories/unreviewed/2023/11/GHSA-39vm-62wp-46hv/GHSA-39vm-62wp-46hv.json b/advisories/unreviewed/2023/11/GHSA-39vm-62wp-46hv/GHSA-39vm-62wp-46hv.json index aa8955b8215..a5945f0318b 100644 --- a/advisories/unreviewed/2023/11/GHSA-39vm-62wp-46hv/GHSA-39vm-62wp-46hv.json +++ b/advisories/unreviewed/2023/11/GHSA-39vm-62wp-46hv/GHSA-39vm-62wp-46hv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-39vm-62wp-46hv", - "modified": "2023-11-01T18:30:34Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:34Z", "aliases": [ "CVE-2023-5853" ], "details": "Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-3pxf-gwjv-f45v/GHSA-3pxf-gwjv-f45v.json b/advisories/unreviewed/2023/11/GHSA-3pxf-gwjv-f45v/GHSA-3pxf-gwjv-f45v.json index 7f43346d8b0..ebf35f86834 100644 --- a/advisories/unreviewed/2023/11/GHSA-3pxf-gwjv-f45v/GHSA-3pxf-gwjv-f45v.json +++ b/advisories/unreviewed/2023/11/GHSA-3pxf-gwjv-f45v/GHSA-3pxf-gwjv-f45v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3pxf-gwjv-f45v", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42634" ], "details": "In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4284-q573-745v/GHSA-4284-q573-745v.json b/advisories/unreviewed/2023/11/GHSA-4284-q573-745v/GHSA-4284-q573-745v.json index 4370cd82394..743b8f28c13 100644 --- a/advisories/unreviewed/2023/11/GHSA-4284-q573-745v/GHSA-4284-q573-745v.json +++ b/advisories/unreviewed/2023/11/GHSA-4284-q573-745v/GHSA-4284-q573-745v.json @@ -33,6 +33,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T03:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json b/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json new file mode 100644 index 00000000000..0d9035d9102 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-43wm-36v8-wrcq/GHSA-43wm-36v8-wrcq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43wm-36v8-wrcq", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-47223" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47223" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/basic-interactive-world-map/wordpress-basic-interactive-world-map-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json b/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json new file mode 100644 index 00000000000..9a731867b15 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-52gq-6r3g-qrmr/GHSA-52gq-6r3g-qrmr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52gq-6r3g-qrmr", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-46363" + ], + "details": "jbig2enc v0.28 was discovered to contain a SEGV via jbig2_add_page in src/jbig2enc.cc:512.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46363" + }, + { + "type": "WEB", + "url": "https://github.com/agl/jbig2enc/issues/85" + }, + { + "type": "WEB", + "url": "https://github.com/agl/jbig2enc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json b/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json new file mode 100644 index 00000000000..0731eb02e4b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-52rh-vv3q-8jrh/GHSA-52rh-vv3q-8jrh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52rh-vv3q-8jrh", + "modified": "2023-11-08T21:30:36Z", + "published": "2023-11-08T21:30:36Z", + "aliases": [ + "CVE-2023-47190" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47190" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/apollo13-framework-extensions/wordpress-apollo13-framework-extensions-plugin-1-9-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json b/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json new file mode 100644 index 00000000000..a5bf1beb6ba --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5fvg-7q6x-mgh2/GHSA-5fvg-7q6x-mgh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fvg-7q6x-mgh2", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-26221" + ], + "details": "The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with read/write access to craft malicious Analyst files. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 12.3.0, 12.4.0, and 12.5.0, Spotfire Server: versions 12.3.0, 12.4.0, and 12.5.0, and Spotfire for AWS Marketplace: version 12.5.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26221" + }, + { + "type": "WEB", + "url": "https://www.tibco.com/services/support/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-75mv-f5hh-c65h/GHSA-75mv-f5hh-c65h.json b/advisories/unreviewed/2023/11/GHSA-75mv-f5hh-c65h/GHSA-75mv-f5hh-c65h.json index b7ff27039b2..1dd3b4a7793 100644 --- a/advisories/unreviewed/2023/11/GHSA-75mv-f5hh-c65h/GHSA-75mv-f5hh-c65h.json +++ b/advisories/unreviewed/2023/11/GHSA-75mv-f5hh-c65h/GHSA-75mv-f5hh-c65h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75mv-f5hh-c65h", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5851" ], "details": "Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json b/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json new file mode 100644 index 00000000000..c489de06294 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-782h-r93g-8gcc/GHSA-782h-r93g-8gcc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-782h-r93g-8gcc", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-29974" + ], + "details": "An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29974" + }, + { + "type": "WEB", + "url": "https://www.esecforte.com/cve-2023-29974-weak-password-policy/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json b/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json index 3704b93cb67..18a7d140d6a 100644 --- a/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json +++ b/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7cjp-92p9-vr97", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5849" ], "details": "Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json b/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json index 3d5a46c1f81..e17b98da6e0 100644 --- a/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json +++ b/advisories/unreviewed/2023/11/GHSA-7x3f-23vq-mrxp/GHSA-7x3f-23vq-mrxp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7x3f-23vq-mrxp", - "modified": "2023-11-01T15:33:29Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T15:33:29Z", "aliases": [ "CVE-2023-46928" ], "details": "GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,9 +34,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json b/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json new file mode 100644 index 00000000000..cc4d8b5f408 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-89jm-mj5r-5rp8/GHSA-89jm-mj5r-5rp8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89jm-mj5r-5rp8", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-47227" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one place plugin <= 1.5.4.6 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-facebook/wordpress-social-feed-all-social-media-in-one-place-plugin-1-5-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8rrh-9958-v272/GHSA-8rrh-9958-v272.json b/advisories/unreviewed/2023/11/GHSA-8rrh-9958-v272/GHSA-8rrh-9958-v272.json index 9f2e3c5d174..427b1781f8d 100644 --- a/advisories/unreviewed/2023/11/GHSA-8rrh-9958-v272/GHSA-8rrh-9958-v272.json +++ b/advisories/unreviewed/2023/11/GHSA-8rrh-9958-v272/GHSA-8rrh-9958-v272.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rrh-9958-v272", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42631" ], "details": "In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json b/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json index d3b5865f6c4..e4365605f37 100644 --- a/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json +++ b/advisories/unreviewed/2023/11/GHSA-8v7h-jhgr-2fgc/GHSA-8v7h-jhgr-2fgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8v7h-jhgr-2fgc", - "modified": "2023-11-01T15:33:29Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T15:33:29Z", "aliases": [ "CVE-2023-46930" ], "details": "GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,9 +34,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T14:15:38Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json b/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json index 78d4bfdc8e1..07f72ef458c 100644 --- a/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json +++ b/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c46p-5pq2-qpcg", - "modified": "2023-11-01T18:30:34Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5854" ], "details": "Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-c8pp-vxj4-7mp3/GHSA-c8pp-vxj4-7mp3.json b/advisories/unreviewed/2023/11/GHSA-c8pp-vxj4-7mp3/GHSA-c8pp-vxj4-7mp3.json index f9ff85f8a62..3cc4153dd6a 100644 --- a/advisories/unreviewed/2023/11/GHSA-c8pp-vxj4-7mp3/GHSA-c8pp-vxj4-7mp3.json +++ b/advisories/unreviewed/2023/11/GHSA-c8pp-vxj4-7mp3/GHSA-c8pp-vxj4-7mp3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c8pp-vxj4-7mp3", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5480" ], "details": "Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-ch98-xc2f-x3rf/GHSA-ch98-xc2f-x3rf.json b/advisories/unreviewed/2023/11/GHSA-ch98-xc2f-x3rf/GHSA-ch98-xc2f-x3rf.json index ab86485c140..4e7ee167028 100644 --- a/advisories/unreviewed/2023/11/GHSA-ch98-xc2f-x3rf/GHSA-ch98-xc2f-x3rf.json +++ b/advisories/unreviewed/2023/11/GHSA-ch98-xc2f-x3rf/GHSA-ch98-xc2f-x3rf.json @@ -33,6 +33,6 @@ "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json b/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json new file mode 100644 index 00000000000..c3a5833f732 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cm77-ccvm-f7p6/GHSA-cm77-ccvm-f7p6.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm77-ccvm-f7p6", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-45875" + ], + "details": "An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45875" + }, + { + "type": "WEB", + "url": "https://docs.couchbase.com/server/current/release-notes/relnotes.html" + }, + { + "type": "WEB", + "url": "https://forums.couchbase.com/tags/security" + }, + { + "type": "WEB", + "url": "https://www.couchbase.com/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f3pw-mpwc-pw7v/GHSA-f3pw-mpwc-pw7v.json b/advisories/unreviewed/2023/11/GHSA-f3pw-mpwc-pw7v/GHSA-f3pw-mpwc-pw7v.json index 7b779cd5550..d9a6704c809 100644 --- a/advisories/unreviewed/2023/11/GHSA-f3pw-mpwc-pw7v/GHSA-f3pw-mpwc-pw7v.json +++ b/advisories/unreviewed/2023/11/GHSA-f3pw-mpwc-pw7v/GHSA-f3pw-mpwc-pw7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f3pw-mpwc-pw7v", - "modified": "2023-11-01T15:33:29Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T15:33:29Z", "aliases": [ "CVE-2023-46927" ], "details": "GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T15:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f4hj-7928-3pr9/GHSA-f4hj-7928-3pr9.json b/advisories/unreviewed/2023/11/GHSA-f4hj-7928-3pr9/GHSA-f4hj-7928-3pr9.json new file mode 100644 index 00000000000..aab69e0a707 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-f4hj-7928-3pr9/GHSA-f4hj-7928-3pr9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4hj-7928-3pr9", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-46362" + ], + "details": "jbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46362" + }, + { + "type": "WEB", + "url": "https://github.com/agl/jbig2enc/issues/84" + }, + { + "type": "WEB", + "url": "https://github.com/agl/jbig2enc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g35p-9423-7ww9/GHSA-g35p-9423-7ww9.json b/advisories/unreviewed/2023/11/GHSA-g35p-9423-7ww9/GHSA-g35p-9423-7ww9.json index 6778e6d3731..fdb45389665 100644 --- a/advisories/unreviewed/2023/11/GHSA-g35p-9423-7ww9/GHSA-g35p-9423-7ww9.json +++ b/advisories/unreviewed/2023/11/GHSA-g35p-9423-7ww9/GHSA-g35p-9423-7ww9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g35p-9423-7ww9", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5858" ], "details": "Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json b/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json new file mode 100644 index 00000000000..439a8428348 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g896-hqwq-6qp3/GHSA-g896-hqwq-6qp3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g896-hqwq-6qp3", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-47228" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47228" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slider-slideshow/wordpress-layer-slider-plugin-1-1-9-7-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ggg3-qv53-5qcr/GHSA-ggg3-qv53-5qcr.json b/advisories/unreviewed/2023/11/GHSA-ggg3-qv53-5qcr/GHSA-ggg3-qv53-5qcr.json new file mode 100644 index 00000000000..f31a5353f60 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ggg3-qv53-5qcr/GHSA-ggg3-qv53-5qcr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggg3-qv53-5qcr", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-47229" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/top-25-social-icons/wordpress-top-25-social-icons-plugin-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gj94-rc7p-wwm6/GHSA-gj94-rc7p-wwm6.json b/advisories/unreviewed/2023/11/GHSA-gj94-rc7p-wwm6/GHSA-gj94-rc7p-wwm6.json new file mode 100644 index 00000000000..d1723485952 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gj94-rc7p-wwm6/GHSA-gj94-rc7p-wwm6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj94-rc7p-wwm6", + "modified": "2023-11-08T21:30:36Z", + "published": "2023-11-08T21:30:36Z", + "aliases": [ + "CVE-2023-47181" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47181" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ideapush/wordpress-ideapush-plugin-8-46-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gww9-w46q-2x34/GHSA-gww9-w46q-2x34.json b/advisories/unreviewed/2023/11/GHSA-gww9-w46q-2x34/GHSA-gww9-w46q-2x34.json index d20a9f83bc7..6a80fff7abf 100644 --- a/advisories/unreviewed/2023/11/GHSA-gww9-w46q-2x34/GHSA-gww9-w46q-2x34.json +++ b/advisories/unreviewed/2023/11/GHSA-gww9-w46q-2x34/GHSA-gww9-w46q-2x34.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gww9-w46q-2x34", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5850" ], "details": "Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-h6c7-v3fj-vggf/GHSA-h6c7-v3fj-vggf.json b/advisories/unreviewed/2023/11/GHSA-h6c7-v3fj-vggf/GHSA-h6c7-v3fj-vggf.json index 98db8195f38..022db76b673 100644 --- a/advisories/unreviewed/2023/11/GHSA-h6c7-v3fj-vggf/GHSA-h6c7-v3fj-vggf.json +++ b/advisories/unreviewed/2023/11/GHSA-h6c7-v3fj-vggf/GHSA-h6c7-v3fj-vggf.json @@ -37,6 +37,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hrr6-mvh4-hgmq/GHSA-hrr6-mvh4-hgmq.json b/advisories/unreviewed/2023/11/GHSA-hrr6-mvh4-hgmq/GHSA-hrr6-mvh4-hgmq.json index 4779a93921f..0a002c127d6 100644 --- a/advisories/unreviewed/2023/11/GHSA-hrr6-mvh4-hgmq/GHSA-hrr6-mvh4-hgmq.json +++ b/advisories/unreviewed/2023/11/GHSA-hrr6-mvh4-hgmq/GHSA-hrr6-mvh4-hgmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrr6-mvh4-hgmq", - "modified": "2023-11-01T03:31:00Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T03:31:00Z", "aliases": [ "CVE-2023-2621" @@ -33,6 +33,6 @@ "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T03:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json b/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json index 1144ca5f891..371d5a6df8a 100644 --- a/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json +++ b/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwj7-8489-4jqm", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5855" ], "details": "Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-mh8h-8fcp-q2hp/GHSA-mh8h-8fcp-q2hp.json b/advisories/unreviewed/2023/11/GHSA-mh8h-8fcp-q2hp/GHSA-mh8h-8fcp-q2hp.json index c703abf7a84..5ad4ff3a5bb 100644 --- a/advisories/unreviewed/2023/11/GHSA-mh8h-8fcp-q2hp/GHSA-mh8h-8fcp-q2hp.json +++ b/advisories/unreviewed/2023/11/GHSA-mh8h-8fcp-q2hp/GHSA-mh8h-8fcp-q2hp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mh8h-8fcp-q2hp", - "modified": "2023-11-01T15:33:29Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T15:33:29Z", "aliases": [ "CVE-2023-46931" ], "details": "GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T14:15:38Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-p4vh-m995-92m8/GHSA-p4vh-m995-92m8.json b/advisories/unreviewed/2023/11/GHSA-p4vh-m995-92m8/GHSA-p4vh-m995-92m8.json index 58e4802cfa2..12feac432a4 100644 --- a/advisories/unreviewed/2023/11/GHSA-p4vh-m995-92m8/GHSA-p4vh-m995-92m8.json +++ b/advisories/unreviewed/2023/11/GHSA-p4vh-m995-92m8/GHSA-p4vh-m995-92m8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p4vh-m995-92m8", - "modified": "2023-11-01T18:30:34Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:34Z", "aliases": [ "CVE-2023-5857" ], "details": "Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-pf76-3jj8-rpqg/GHSA-pf76-3jj8-rpqg.json b/advisories/unreviewed/2023/11/GHSA-pf76-3jj8-rpqg/GHSA-pf76-3jj8-rpqg.json index 1d735bd6860..9329de1353b 100644 --- a/advisories/unreviewed/2023/11/GHSA-pf76-3jj8-rpqg/GHSA-pf76-3jj8-rpqg.json +++ b/advisories/unreviewed/2023/11/GHSA-pf76-3jj8-rpqg/GHSA-pf76-3jj8-rpqg.json @@ -33,6 +33,6 @@ "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T03:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pq78-6h8h-rcf4/GHSA-pq78-6h8h-rcf4.json b/advisories/unreviewed/2023/11/GHSA-pq78-6h8h-rcf4/GHSA-pq78-6h8h-rcf4.json index dd813ecec21..d050b806e88 100644 --- a/advisories/unreviewed/2023/11/GHSA-pq78-6h8h-rcf4/GHSA-pq78-6h8h-rcf4.json +++ b/advisories/unreviewed/2023/11/GHSA-pq78-6h8h-rcf4/GHSA-pq78-6h8h-rcf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq78-6h8h-rcf4", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5482" ], "details": "Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-q3gq-rg4m-vgrp/GHSA-q3gq-rg4m-vgrp.json b/advisories/unreviewed/2023/11/GHSA-q3gq-rg4m-vgrp/GHSA-q3gq-rg4m-vgrp.json new file mode 100644 index 00000000000..ac8b347d40e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q3gq-rg4m-vgrp/GHSA-q3gq-rg4m-vgrp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3gq-rg4m-vgrp", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-5996" + ], + "details": "Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5996" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1497859" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qf75-86xr-cfpw/GHSA-qf75-86xr-cfpw.json b/advisories/unreviewed/2023/11/GHSA-qf75-86xr-cfpw/GHSA-qf75-86xr-cfpw.json index 7003e6c2541..8790f55f237 100644 --- a/advisories/unreviewed/2023/11/GHSA-qf75-86xr-cfpw/GHSA-qf75-86xr-cfpw.json +++ b/advisories/unreviewed/2023/11/GHSA-qf75-86xr-cfpw/GHSA-qf75-86xr-cfpw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qf75-86xr-cfpw", - "modified": "2023-11-01T18:30:34Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:34Z", "aliases": [ "CVE-2023-5859" ], "details": "Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-346" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json b/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json index b5b9057da69..c91643ac27b 100644 --- a/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json +++ b/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfx8-xprj-wvh4", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5852" ], "details": "Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-qwmr-4wg7-xq78/GHSA-qwmr-4wg7-xq78.json b/advisories/unreviewed/2023/11/GHSA-qwmr-4wg7-xq78/GHSA-qwmr-4wg7-xq78.json new file mode 100644 index 00000000000..92efae0d05f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qwmr-4wg7-xq78/GHSA-qwmr-4wg7-xq78.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwmr-4wg7-xq78", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-47231" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcodes-ui/wordpress-shortcodes-ui-plugin-1-9-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json b/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json new file mode 100644 index 00000000000..2033d48ee24 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-r8cx-47rc-5x49/GHSA-r8cx-47rc-5x49.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8cx-47rc-5x49", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-47226" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Post Sliders & Post Grids plugin <= 1.0.20 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/post-slider-carousel/wordpress-post-sliders-post-grids-plugin-1-0-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v92j-4pq6-rqx3/GHSA-v92j-4pq6-rqx3.json b/advisories/unreviewed/2023/11/GHSA-v92j-4pq6-rqx3/GHSA-v92j-4pq6-rqx3.json index 77c65b41386..ea5d6e48792 100644 --- a/advisories/unreviewed/2023/11/GHSA-v92j-4pq6-rqx3/GHSA-v92j-4pq6-rqx3.json +++ b/advisories/unreviewed/2023/11/GHSA-v92j-4pq6-rqx3/GHSA-v92j-4pq6-rqx3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v92j-4pq6-rqx3", - "modified": "2023-11-01T18:30:33Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-46911" ], "details": "There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T17:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vr5f-vjc4-r753/GHSA-vr5f-vjc4-r753.json b/advisories/unreviewed/2023/11/GHSA-vr5f-vjc4-r753/GHSA-vr5f-vjc4-r753.json index 62874156e9a..de99356cf7a 100644 --- a/advisories/unreviewed/2023/11/GHSA-vr5f-vjc4-r753/GHSA-vr5f-vjc4-r753.json +++ b/advisories/unreviewed/2023/11/GHSA-vr5f-vjc4-r753/GHSA-vr5f-vjc4-r753.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vr5f-vjc4-r753", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42632" ], "details": "In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vv89-229f-wqm4/GHSA-vv89-229f-wqm4.json b/advisories/unreviewed/2023/11/GHSA-vv89-229f-wqm4/GHSA-vv89-229f-wqm4.json index 67cc84dec9f..94f4bb921b8 100644 --- a/advisories/unreviewed/2023/11/GHSA-vv89-229f-wqm4/GHSA-vv89-229f-wqm4.json +++ b/advisories/unreviewed/2023/11/GHSA-vv89-229f-wqm4/GHSA-vv89-229f-wqm4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vv89-229f-wqm4", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42640" ], "details": "In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-wf5p-g6vw-rhxx/GHSA-wf5p-g6vw-rhxx.json b/advisories/unreviewed/2023/11/GHSA-wf5p-g6vw-rhxx/GHSA-wf5p-g6vw-rhxx.json new file mode 100644 index 00000000000..d80e2c50e5e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-wf5p-g6vw-rhxx/GHSA-wf5p-g6vw-rhxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf5p-g6vw-rhxx", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-45857" + ], + "details": "An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45857" + }, + { + "type": "WEB", + "url": "https://github.com/axios/axios/issues/6006" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x65g-79jp-p76h/GHSA-x65g-79jp-p76h.json b/advisories/unreviewed/2023/11/GHSA-x65g-79jp-p76h/GHSA-x65g-79jp-p76h.json index d8cc69b6469..9ee061a7a3d 100644 --- a/advisories/unreviewed/2023/11/GHSA-x65g-79jp-p76h/GHSA-x65g-79jp-p76h.json +++ b/advisories/unreviewed/2023/11/GHSA-x65g-79jp-p76h/GHSA-x65g-79jp-p76h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x65g-79jp-p76h", - "modified": "2023-11-01T12:30:20Z", + "modified": "2023-11-08T21:30:35Z", "published": "2023-11-01T12:30:20Z", "aliases": [ "CVE-2023-42633" ], "details": "In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-11-01T10:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xg45-v5rp-r5m2/GHSA-xg45-v5rp-r5m2.json b/advisories/unreviewed/2023/11/GHSA-xg45-v5rp-r5m2/GHSA-xg45-v5rp-r5m2.json new file mode 100644 index 00000000000..b7df6025742 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xg45-v5rp-r5m2/GHSA-xg45-v5rp-r5m2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg45-v5rp-r5m2", + "modified": "2023-11-08T21:30:37Z", + "published": "2023-11-08T21:30:37Z", + "aliases": [ + "CVE-2023-0392" + ], + "details": "The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0392" + }, + { + "type": "WEB", + "url": "https://trust.okta.com/security-advisories/okta-ldap-agent-cve-2023-0392" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-428" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json b/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json index 039879e6cee..96de08f6a5d 100644 --- a/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json +++ b/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xmhq-fw78-wjxr", - "modified": "2023-11-01T18:30:34Z", + "modified": "2023-11-08T21:30:36Z", "published": "2023-11-01T18:30:34Z", "aliases": [ "CVE-2023-5856" ], "details": "Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-01T18:15:10Z"