diff --git a/advisories/unreviewed/2023/12/GHSA-mxx7-h83w-7323/GHSA-mxx7-h83w-7323.json b/advisories/unreviewed/2023/12/GHSA-mxx7-h83w-7323/GHSA-mxx7-h83w-7323.json index 7967b9df1a0..d952942ceeb 100644 --- a/advisories/unreviewed/2023/12/GHSA-mxx7-h83w-7323/GHSA-mxx7-h83w-7323.json +++ b/advisories/unreviewed/2023/12/GHSA-mxx7-h83w-7323/GHSA-mxx7-h83w-7323.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mxx7-h83w-7323", - "modified": "2023-12-29T15:30:37Z", + "modified": "2024-01-08T18:30:26Z", "published": "2023-12-29T15:30:37Z", "aliases": [ "CVE-2023-4674" diff --git a/advisories/unreviewed/2023/12/GHSA-q2h3-9c64-6vmc/GHSA-q2h3-9c64-6vmc.json b/advisories/unreviewed/2023/12/GHSA-q2h3-9c64-6vmc/GHSA-q2h3-9c64-6vmc.json index 8fec69977d9..4ca21199501 100644 --- a/advisories/unreviewed/2023/12/GHSA-q2h3-9c64-6vmc/GHSA-q2h3-9c64-6vmc.json +++ b/advisories/unreviewed/2023/12/GHSA-q2h3-9c64-6vmc/GHSA-q2h3-9c64-6vmc.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://patchwork.kernel.org/project/io-uring/patch/20231130194633.649319-2-axboe@kernel.dk/" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176405/io_uring-__io_uaddr_map-Dangerous-Multi-Page-Handling.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-28vh-7gjh-8xmq/GHSA-28vh-7gjh-8xmq.json b/advisories/unreviewed/2024/01/GHSA-28vh-7gjh-8xmq/GHSA-28vh-7gjh-8xmq.json index 53d3e046962..4c5a69658dd 100644 --- a/advisories/unreviewed/2024/01/GHSA-28vh-7gjh-8xmq/GHSA-28vh-7gjh-8xmq.json +++ b/advisories/unreviewed/2024/01/GHSA-28vh-7gjh-8xmq/GHSA-28vh-7gjh-8xmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-28vh-7gjh-8xmq", - "modified": "2024-01-01T15:30:34Z", + "modified": "2024-01-08T18:30:26Z", "published": "2024-01-01T15:30:34Z", "aliases": [ "CVE-2023-6271" ], "details": "The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-01T15:15:43Z" diff --git a/advisories/unreviewed/2024/01/GHSA-3hh9-m6jx-r3jg/GHSA-3hh9-m6jx-r3jg.json b/advisories/unreviewed/2024/01/GHSA-3hh9-m6jx-r3jg/GHSA-3hh9-m6jx-r3jg.json index 3dc7f3133dd..a97405f2bac 100644 --- a/advisories/unreviewed/2024/01/GHSA-3hh9-m6jx-r3jg/GHSA-3hh9-m6jx-r3jg.json +++ b/advisories/unreviewed/2024/01/GHSA-3hh9-m6jx-r3jg/GHSA-3hh9-m6jx-r3jg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3hh9-m6jx-r3jg", - "modified": "2024-01-01T15:30:33Z", + "modified": "2024-01-08T18:30:26Z", "published": "2024-01-01T15:30:33Z", "aliases": [ "CVE-2023-5877" ], "details": "The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-01T15:15:42Z" diff --git a/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json b/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json index 0e78b8c24bd..76d22124d1d 100644 --- a/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json +++ b/advisories/unreviewed/2024/01/GHSA-4w3j-4m96-c92x/GHSA-4w3j-4m96-c92x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-5c9f-6cwg-mhc5/GHSA-5c9f-6cwg-mhc5.json b/advisories/unreviewed/2024/01/GHSA-5c9f-6cwg-mhc5/GHSA-5c9f-6cwg-mhc5.json new file mode 100644 index 00000000000..9554f4b54ce --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5c9f-6cwg-mhc5/GHSA-5c9f-6cwg-mhc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c9f-6cwg-mhc5", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2024-21745" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laybuy Laybuy Payment Extension for WooCommerce allows Stored XSS.This issue affects Laybuy Payment Extension for WooCommerce: from n/a through 5.3.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21745" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/laybuy-gateway-for-woocommerce/wordpress-laybuy-payment-extension-for-woocommerce-plugin-5-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5vhq-6jvc-vjp4/GHSA-5vhq-6jvc-vjp4.json b/advisories/unreviewed/2024/01/GHSA-5vhq-6jvc-vjp4/GHSA-5vhq-6jvc-vjp4.json new file mode 100644 index 00000000000..bd6ff3f27f3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5vhq-6jvc-vjp4/GHSA-5vhq-6jvc-vjp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vhq-6jvc-vjp4", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2023-52215" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce: from n/a through 1.5.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52215" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-1-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-759j-vc5c-fv87/GHSA-759j-vc5c-fv87.json b/advisories/unreviewed/2024/01/GHSA-759j-vc5c-fv87/GHSA-759j-vc5c-fv87.json new file mode 100644 index 00000000000..6ee7e4e5773 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-759j-vc5c-fv87/GHSA-759j-vc5c-fv87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-759j-vc5c-fv87", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2023-52218" + ], + "details": "Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52218" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-tranzila-gateway/wordpress-woocommerce-tranzila-gateway-plugin-1-0-8-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cjqf-877p-7m3f/GHSA-cjqf-877p-7m3f.json b/advisories/unreviewed/2024/01/GHSA-cjqf-877p-7m3f/GHSA-cjqf-877p-7m3f.json new file mode 100644 index 00000000000..e55c9f9623a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cjqf-877p-7m3f/GHSA-cjqf-877p-7m3f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjqf-877p-7m3f", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2022-3328" + ], + "details": "Race condition in snap-confine's must_mkdir_and_open_with_perms()", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3328" + }, + { + "type": "WEB", + "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3328" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/notices/USN-5753-1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f2w2-g9x5-9598/GHSA-f2w2-g9x5-9598.json b/advisories/unreviewed/2024/01/GHSA-f2w2-g9x5-9598/GHSA-f2w2-g9x5-9598.json new file mode 100644 index 00000000000..6bf3c728b45 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-f2w2-g9x5-9598/GHSA-f2w2-g9x5-9598.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2w2-g9x5-9598", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2024-21744" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology Inc. Mapster WP Maps allows Stored XSS.This issue affects Mapster WP Maps: from n/a through 1.2.38.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21744" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mapster-wp-maps/wordpress-mapster-wp-maps-plugin-1-2-38-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-qxmc-p4v9-vcqq/GHSA-qxmc-p4v9-vcqq.json b/advisories/unreviewed/2024/01/GHSA-qxmc-p4v9-vcqq/GHSA-qxmc-p4v9-vcqq.json index f18a28dbfee..4376c7d66ba 100644 --- a/advisories/unreviewed/2024/01/GHSA-qxmc-p4v9-vcqq/GHSA-qxmc-p4v9-vcqq.json +++ b/advisories/unreviewed/2024/01/GHSA-qxmc-p4v9-vcqq/GHSA-qxmc-p4v9-vcqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxmc-p4v9-vcqq", - "modified": "2024-01-01T15:30:33Z", + "modified": "2024-01-08T18:30:26Z", "published": "2024-01-01T15:30:33Z", "aliases": [ "CVE-2023-6064" ], "details": "The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-532" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-01T15:15:43Z" diff --git a/advisories/unreviewed/2024/01/GHSA-r293-cvcc-7wmh/GHSA-r293-cvcc-7wmh.json b/advisories/unreviewed/2024/01/GHSA-r293-cvcc-7wmh/GHSA-r293-cvcc-7wmh.json new file mode 100644 index 00000000000..3fae00773ba --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r293-cvcc-7wmh/GHSA-r293-cvcc-7wmh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r293-cvcc-7wmh", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2023-52225" + ], + "details": "Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/taggbox-widget/wordpress-tagbox-widget-plugin-3-1-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r477-vj9r-595h/GHSA-r477-vj9r-595h.json b/advisories/unreviewed/2024/01/GHSA-r477-vj9r-595h/GHSA-r477-vj9r-595h.json new file mode 100644 index 00000000000..e86320479de --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r477-vj9r-595h/GHSA-r477-vj9r-595h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r477-vj9r-595h", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2023-52219" + ], + "details": "Deserialization of Untrusted Data vulnerability in Gecka Gecka Terms Thumbnails.This issue affects Gecka Terms Thumbnails: from n/a through 1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52219" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gecka-terms-thumbnails/wordpress-gecka-terms-thumbnails-plugin-1-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T18:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vc5m-qgwv-5c7r/GHSA-vc5m-qgwv-5c7r.json b/advisories/unreviewed/2024/01/GHSA-vc5m-qgwv-5c7r/GHSA-vc5m-qgwv-5c7r.json new file mode 100644 index 00000000000..5b66011c372 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vc5m-qgwv-5c7r/GHSA-vc5m-qgwv-5c7r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc5m-qgwv-5c7r", + "modified": "2024-01-08T18:30:29Z", + "published": "2024-01-08T18:30:29Z", + "aliases": [ + "CVE-2024-21747" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue affects WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting: from n/a through 1.12.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/erp/wordpress-wp-erp-plugin-1-12-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T17:15:08Z" + } +} \ No newline at end of file