Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-10 18:31:47 +00:00
parent cf396eb20c
commit 9704a95432
47 changed files with 1025 additions and 50 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hx3v-wmpr-r7fv",
"modified": "2022-05-24T16:55:17Z",
"modified": "2024-01-10T18:30:24Z",
"published": "2022-05-24T16:55:17Z",
"aliases": [
"CVE-2019-15830"
],
"details": "The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,13 +28,17 @@
{
"type": "WEB",
"url": "https://wordpress.org/plugins/icegram/#developers"
},
{
"type": "WEB",
"url": "https://wpvulndb.com/vulnerabilities/9440"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-08-30T14:15:00Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrh8-hwhr-wvmg",
"modified": "2022-05-24T22:00:34Z",
"modified": "2024-01-10T18:30:24Z",
"published": "2022-05-24T22:00:34Z",
"aliases": [
"CVE-2016-10962"
],
"details": "The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfjq-wx2j-m93v",
"modified": "2022-05-24T22:00:35Z",
"modified": "2024-01-10T18:30:24Z",
"published": "2022-05-24T22:00:35Z",
"aliases": [
"CVE-2016-10963"
],
"details": "The icegram plugin before 1.9.19 for WordPress has XSS.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xq4v-6896-qq49",
"modified": "2022-05-24T22:33:56Z",
"modified": "2024-01-10T18:30:24Z",
"published": "2022-05-24T22:33:56Z",
"aliases": [
"CVE-2021-36832"
],
"details": "WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin Icegram (versions <= 2.0.2) vulnerable at \"Headline\" (&message_data[16][headline]) input.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc6j-9f2x-v9w8",
"modified": "2023-12-29T21:30:45Z",
"modified": "2024-01-10T18:30:24Z",
"published": "2023-12-21T21:30:32Z",
"aliases": [
"CVE-2023-6746"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2566-fq23-672g",
"modified": "2024-01-10T18:30:27Z",
"published": "2024-01-10T18:30:27Z",
"aliases": [
"CVE-2023-49738"
],
"details": "An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49738"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1881"
}
],
"database_specific": {
"cwe_ids": [
"CWE-73"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:48Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2frf-pg6c-g93r",
"modified": "2024-01-10T18:30:28Z",
"published": "2024-01-10T18:30:28Z",
"aliases": [
"CVE-2023-51962"
],
"details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51962"
},
{
"type": "WEB",
"url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-setIptvInfo-944beaf189db4bf49f99a7a7418c7bdd"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:49Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-339f-fg4x-gwcm",
"modified": "2024-01-10T18:30:26Z",
"published": "2024-01-10T18:30:26Z",
"aliases": [
"CVE-2023-47861"
],
"details": "A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47861"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1884"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:47Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4j3v-h4q8-j269",
"modified": "2024-01-04T21:30:24Z",
"modified": "2024-01-10T18:30:26Z",
"published": "2024-01-04T21:30:24Z",
"aliases": [
"CVE-2023-51812"
],
"details": "Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-04T19:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55rm-p79h-88wj",
"modified": "2024-01-03T09:30:29Z",
"modified": "2024-01-10T18:30:24Z",
"published": "2024-01-03T09:30:29Z",
"aliases": [
"CVE-2023-6986"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59j2-44h9-8h98",
"modified": "2024-01-04T21:30:24Z",
"modified": "2024-01-10T18:30:26Z",
"published": "2024-01-04T21:30:24Z",
"aliases": [
"CVE-2023-51154"
],
"details": "Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-04T19:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cpg-h4r2-65fc",
"modified": "2024-01-04T09:30:33Z",
"modified": "2024-01-10T18:30:25Z",
"published": "2024-01-04T09:30:33Z",
"aliases": [
"CVE-2023-50082"
],
"details": "Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-04T08:15:08Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5h2w-cfc8-wwh3",
"modified": "2024-01-10T18:30:28Z",
"published": "2024-01-10T18:30:28Z",
"aliases": [
"CVE-2023-51967"
],
"details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51967"
},
{
"type": "WEB",
"url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:49Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5j7f-3j5h-cvq3",
"modified": "2024-01-10T18:30:28Z",
"published": "2024-01-10T18:30:28Z",
"aliases": [
"CVE-2023-51968"
],
"details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51968"
},
{
"type": "WEB",
"url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:49Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5w8j-whwf-384q",
"modified": "2024-01-10T18:30:28Z",
"published": "2024-01-10T18:30:28Z",
"aliases": [
"CVE-2023-51970"
],
"details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51970"
},
{
"type": "WEB",
"url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:49Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m9q-9m44-9hvq",
"modified": "2024-01-10T18:30:27Z",
"published": "2024-01-10T18:30:27Z",
"aliases": [
"CVE-2023-49589"
],
"details": "An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49589"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1896"
}
],
"database_specific": {
"cwe_ids": [
"CWE-640"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-10T16:15:48Z"
}
}
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-209"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "LOW",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More