diff --git a/advisories/unreviewed/2022/05/GHSA-hx3v-wmpr-r7fv/GHSA-hx3v-wmpr-r7fv.json b/advisories/unreviewed/2022/05/GHSA-hx3v-wmpr-r7fv/GHSA-hx3v-wmpr-r7fv.json index 2aefb4678d2..ce852911e5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-hx3v-wmpr-r7fv/GHSA-hx3v-wmpr-r7fv.json +++ b/advisories/unreviewed/2022/05/GHSA-hx3v-wmpr-r7fv/GHSA-hx3v-wmpr-r7fv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx3v-wmpr-r7fv", - "modified": "2022-05-24T16:55:17Z", + "modified": "2024-01-10T18:30:24Z", "published": "2022-05-24T16:55:17Z", "aliases": [ "CVE-2019-15830" ], "details": "The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,13 +28,17 @@ { "type": "WEB", "url": "https://wordpress.org/plugins/icegram/#developers" + }, + { + "type": "WEB", + "url": "https://wpvulndb.com/vulnerabilities/9440" } ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-08-30T14:15:00Z" diff --git a/advisories/unreviewed/2022/05/GHSA-jrh8-hwhr-wvmg/GHSA-jrh8-hwhr-wvmg.json b/advisories/unreviewed/2022/05/GHSA-jrh8-hwhr-wvmg/GHSA-jrh8-hwhr-wvmg.json index d5de66e5488..162375e40d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-jrh8-hwhr-wvmg/GHSA-jrh8-hwhr-wvmg.json +++ b/advisories/unreviewed/2022/05/GHSA-jrh8-hwhr-wvmg/GHSA-jrh8-hwhr-wvmg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrh8-hwhr-wvmg", - "modified": "2022-05-24T22:00:34Z", + "modified": "2024-01-10T18:30:24Z", "published": "2022-05-24T22:00:34Z", "aliases": [ "CVE-2016-10962" ], "details": "The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-qfjq-wx2j-m93v/GHSA-qfjq-wx2j-m93v.json b/advisories/unreviewed/2022/05/GHSA-qfjq-wx2j-m93v/GHSA-qfjq-wx2j-m93v.json index 7a8f430e83e..4c267204ffa 100644 --- a/advisories/unreviewed/2022/05/GHSA-qfjq-wx2j-m93v/GHSA-qfjq-wx2j-m93v.json +++ b/advisories/unreviewed/2022/05/GHSA-qfjq-wx2j-m93v/GHSA-qfjq-wx2j-m93v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfjq-wx2j-m93v", - "modified": "2022-05-24T22:00:35Z", + "modified": "2024-01-10T18:30:24Z", "published": "2022-05-24T22:00:35Z", "aliases": [ "CVE-2016-10963" ], "details": "The icegram plugin before 1.9.19 for WordPress has XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json b/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json index 2ef434da8cc..edcd7b69388 100644 --- a/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json +++ b/advisories/unreviewed/2022/05/GHSA-xq4v-6896-qq49/GHSA-xq4v-6896-qq49.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xq4v-6896-qq49", - "modified": "2022-05-24T22:33:56Z", + "modified": "2024-01-10T18:30:24Z", "published": "2022-05-24T22:33:56Z", "aliases": [ "CVE-2021-36832" ], "details": "WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at \"Headline\" (&message_data[16][headline]) input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/12/GHSA-fc6j-9f2x-v9w8/GHSA-fc6j-9f2x-v9w8.json b/advisories/unreviewed/2023/12/GHSA-fc6j-9f2x-v9w8/GHSA-fc6j-9f2x-v9w8.json index d2e96900cb8..74619ddd844 100644 --- a/advisories/unreviewed/2023/12/GHSA-fc6j-9f2x-v9w8/GHSA-fc6j-9f2x-v9w8.json +++ b/advisories/unreviewed/2023/12/GHSA-fc6j-9f2x-v9w8/GHSA-fc6j-9f2x-v9w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc6j-9f2x-v9w8", - "modified": "2023-12-29T21:30:45Z", + "modified": "2024-01-10T18:30:24Z", "published": "2023-12-21T21:30:32Z", "aliases": [ "CVE-2023-6746" diff --git a/advisories/unreviewed/2024/01/GHSA-2566-fq23-672g/GHSA-2566-fq23-672g.json b/advisories/unreviewed/2024/01/GHSA-2566-fq23-672g/GHSA-2566-fq23-672g.json new file mode 100644 index 00000000000..6065a0a3f3b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2566-fq23-672g/GHSA-2566-fq23-672g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2566-fq23-672g", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49738" + ], + "details": "An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49738" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1881" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2frf-pg6c-g93r/GHSA-2frf-pg6c-g93r.json b/advisories/unreviewed/2024/01/GHSA-2frf-pg6c-g93r/GHSA-2frf-pg6c-g93r.json new file mode 100644 index 00000000000..48ca7935738 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2frf-pg6c-g93r/GHSA-2frf-pg6c-g93r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2frf-pg6c-g93r", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-51962" + ], + "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51962" + }, + { + "type": "WEB", + "url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-setIptvInfo-944beaf189db4bf49f99a7a7418c7bdd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-339f-fg4x-gwcm/GHSA-339f-fg4x-gwcm.json b/advisories/unreviewed/2024/01/GHSA-339f-fg4x-gwcm/GHSA-339f-fg4x-gwcm.json new file mode 100644 index 00000000000..5fd418ce1bf --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-339f-fg4x-gwcm/GHSA-339f-fg4x-gwcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-339f-fg4x-gwcm", + "modified": "2024-01-10T18:30:26Z", + "published": "2024-01-10T18:30:26Z", + "aliases": [ + "CVE-2023-47861" + ], + "details": "A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47861" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1884" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json b/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json index 9fa7f55e2b6..435689d5434 100644 --- a/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json +++ b/advisories/unreviewed/2024/01/GHSA-4j3v-h4q8-j269/GHSA-4j3v-h4q8-j269.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j3v-h4q8-j269", - "modified": "2024-01-04T21:30:24Z", + "modified": "2024-01-10T18:30:26Z", "published": "2024-01-04T21:30:24Z", "aliases": [ "CVE-2023-51812" ], "details": "Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json b/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json index cbfef7b7228..52c2898c427 100644 --- a/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json +++ b/advisories/unreviewed/2024/01/GHSA-55rm-p79h-88wj/GHSA-55rm-p79h-88wj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55rm-p79h-88wj", - "modified": "2024-01-03T09:30:29Z", + "modified": "2024-01-10T18:30:24Z", "published": "2024-01-03T09:30:29Z", "aliases": [ "CVE-2023-6986" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-59j2-44h9-8h98/GHSA-59j2-44h9-8h98.json b/advisories/unreviewed/2024/01/GHSA-59j2-44h9-8h98/GHSA-59j2-44h9-8h98.json index be1ba5587c1..1296c43b580 100644 --- a/advisories/unreviewed/2024/01/GHSA-59j2-44h9-8h98/GHSA-59j2-44h9-8h98.json +++ b/advisories/unreviewed/2024/01/GHSA-59j2-44h9-8h98/GHSA-59j2-44h9-8h98.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59j2-44h9-8h98", - "modified": "2024-01-04T21:30:24Z", + "modified": "2024-01-10T18:30:26Z", "published": "2024-01-04T21:30:24Z", "aliases": [ "CVE-2023-51154" ], "details": "Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5cpg-h4r2-65fc/GHSA-5cpg-h4r2-65fc.json b/advisories/unreviewed/2024/01/GHSA-5cpg-h4r2-65fc/GHSA-5cpg-h4r2-65fc.json index c8d580f9d4e..d64f2131e4c 100644 --- a/advisories/unreviewed/2024/01/GHSA-5cpg-h4r2-65fc/GHSA-5cpg-h4r2-65fc.json +++ b/advisories/unreviewed/2024/01/GHSA-5cpg-h4r2-65fc/GHSA-5cpg-h4r2-65fc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5cpg-h4r2-65fc", - "modified": "2024-01-04T09:30:33Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T09:30:33Z", "aliases": [ "CVE-2023-50082" ], "details": "Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T08:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5h2w-cfc8-wwh3/GHSA-5h2w-cfc8-wwh3.json b/advisories/unreviewed/2024/01/GHSA-5h2w-cfc8-wwh3/GHSA-5h2w-cfc8-wwh3.json new file mode 100644 index 00000000000..a2d8418d3ff --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5h2w-cfc8-wwh3/GHSA-5h2w-cfc8-wwh3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h2w-cfc8-wwh3", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-51967" + ], + "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51967" + }, + { + "type": "WEB", + "url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5j7f-3j5h-cvq3/GHSA-5j7f-3j5h-cvq3.json b/advisories/unreviewed/2024/01/GHSA-5j7f-3j5h-cvq3/GHSA-5j7f-3j5h-cvq3.json new file mode 100644 index 00000000000..dc955acf871 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5j7f-3j5h-cvq3/GHSA-5j7f-3j5h-cvq3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j7f-3j5h-cvq3", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-51968" + ], + "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51968" + }, + { + "type": "WEB", + "url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5w8j-whwf-384q/GHSA-5w8j-whwf-384q.json b/advisories/unreviewed/2024/01/GHSA-5w8j-whwf-384q/GHSA-5w8j-whwf-384q.json new file mode 100644 index 00000000000..ab4eead08f9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5w8j-whwf-384q/GHSA-5w8j-whwf-384q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w8j-whwf-384q", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-51970" + ], + "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51970" + }, + { + "type": "WEB", + "url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6m9q-9m44-9hvq/GHSA-6m9q-9m44-9hvq.json b/advisories/unreviewed/2024/01/GHSA-6m9q-9m44-9hvq/GHSA-6m9q-9m44-9hvq.json new file mode 100644 index 00000000000..46cfd4889d8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6m9q-9m44-9hvq/GHSA-6m9q-9m44-9hvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m9q-9m44-9hvq", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49589" + ], + "details": "An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49589" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1896" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-74jf-25c2-5jf2/GHSA-74jf-25c2-5jf2.json b/advisories/unreviewed/2024/01/GHSA-74jf-25c2-5jf2/GHSA-74jf-25c2-5jf2.json index bd4c6fcca71..66c8fa4889c 100644 --- a/advisories/unreviewed/2024/01/GHSA-74jf-25c2-5jf2/GHSA-74jf-25c2-5jf2.json +++ b/advisories/unreviewed/2024/01/GHSA-74jf-25c2-5jf2/GHSA-74jf-25c2-5jf2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-7gq2-mc3v-cv43/GHSA-7gq2-mc3v-cv43.json b/advisories/unreviewed/2024/01/GHSA-7gq2-mc3v-cv43/GHSA-7gq2-mc3v-cv43.json index 53da632d0e1..6deb56052a6 100644 --- a/advisories/unreviewed/2024/01/GHSA-7gq2-mc3v-cv43/GHSA-7gq2-mc3v-cv43.json +++ b/advisories/unreviewed/2024/01/GHSA-7gq2-mc3v-cv43/GHSA-7gq2-mc3v-cv43.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-86rg-pf4c-5grg/GHSA-86rg-pf4c-5grg.json b/advisories/unreviewed/2024/01/GHSA-86rg-pf4c-5grg/GHSA-86rg-pf4c-5grg.json index 6ec568cd97f..90d223cae38 100644 --- a/advisories/unreviewed/2024/01/GHSA-86rg-pf4c-5grg/GHSA-86rg-pf4c-5grg.json +++ b/advisories/unreviewed/2024/01/GHSA-86rg-pf4c-5grg/GHSA-86rg-pf4c-5grg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-209" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-88ww-j9jx-rp23/GHSA-88ww-j9jx-rp23.json b/advisories/unreviewed/2024/01/GHSA-88ww-j9jx-rp23/GHSA-88ww-j9jx-rp23.json index 2f9b53c3c29..c026f2a7b6b 100644 --- a/advisories/unreviewed/2024/01/GHSA-88ww-j9jx-rp23/GHSA-88ww-j9jx-rp23.json +++ b/advisories/unreviewed/2024/01/GHSA-88ww-j9jx-rp23/GHSA-88ww-j9jx-rp23.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-8m5f-2xvp-2c8w/GHSA-8m5f-2xvp-2c8w.json b/advisories/unreviewed/2024/01/GHSA-8m5f-2xvp-2c8w/GHSA-8m5f-2xvp-2c8w.json new file mode 100644 index 00000000000..46d693bba5c --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8m5f-2xvp-2c8w/GHSA-8m5f-2xvp-2c8w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m5f-2xvp-2c8w", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-50172" + ], + "details": "A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to silently create a recovery pass code for any user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50172" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1897" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8vcc-cghx-67pj/GHSA-8vcc-cghx-67pj.json b/advisories/unreviewed/2024/01/GHSA-8vcc-cghx-67pj/GHSA-8vcc-cghx-67pj.json new file mode 100644 index 00000000000..34831967b8e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8vcc-cghx-67pj/GHSA-8vcc-cghx-67pj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vcc-cghx-67pj", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49862" + ], + "details": "An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49862" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-c68r-72rr-cx8r/GHSA-c68r-72rr-cx8r.json b/advisories/unreviewed/2024/01/GHSA-c68r-72rr-cx8r/GHSA-c68r-72rr-cx8r.json new file mode 100644 index 00000000000..52cf45b6f1f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-c68r-72rr-cx8r/GHSA-c68r-72rr-cx8r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c68r-72rr-cx8r", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-37934" + ], + "details": "An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37934" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-226" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g73p-9p76-7wm8/GHSA-g73p-9p76-7wm8.json b/advisories/unreviewed/2024/01/GHSA-g73p-9p76-7wm8/GHSA-g73p-9p76-7wm8.json new file mode 100644 index 00000000000..4c5763c0bc6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g73p-9p76-7wm8/GHSA-g73p-9p76-7wm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g73p-9p76-7wm8", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-37932" + ], + "details": "An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker to read arbitrary files from the system via sending crafted HTTP or HTTPS requests", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37932" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gh6r-r3hf-65pm/GHSA-gh6r-r3hf-65pm.json b/advisories/unreviewed/2024/01/GHSA-gh6r-r3hf-65pm/GHSA-gh6r-r3hf-65pm.json new file mode 100644 index 00000000000..343f40c76af --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gh6r-r3hf-65pm/GHSA-gh6r-r3hf-65pm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh6r-r3hf-65pm", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-51969" + ], + "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51969" + }, + { + "type": "WEB", + "url": "https://grove-laser-8ad.notion.site/Tenda-AX1803-Buffer-Overflow-in-getIptvInfo-f5918cc2828c49e78554f456bf7d4b36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gm82-j72q-3fqh/GHSA-gm82-j72q-3fqh.json b/advisories/unreviewed/2024/01/GHSA-gm82-j72q-3fqh/GHSA-gm82-j72q-3fqh.json index 79ba89c72e6..b5fd4fe3faf 100644 --- a/advisories/unreviewed/2024/01/GHSA-gm82-j72q-3fqh/GHSA-gm82-j72q-3fqh.json +++ b/advisories/unreviewed/2024/01/GHSA-gm82-j72q-3fqh/GHSA-gm82-j72q-3fqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gm82-j72q-3fqh", - "modified": "2024-01-04T09:30:33Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T09:30:33Z", "aliases": [ "CVE-2023-50630" ], "details": "Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T08:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jxch-62jx-98vm/GHSA-jxch-62jx-98vm.json b/advisories/unreviewed/2024/01/GHSA-jxch-62jx-98vm/GHSA-jxch-62jx-98vm.json new file mode 100644 index 00000000000..ba938c645d5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jxch-62jx-98vm/GHSA-jxch-62jx-98vm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxch-62jx-98vm", + "modified": "2024-01-10T18:30:26Z", + "published": "2024-01-10T18:30:26Z", + "aliases": [ + "CVE-2023-47862" + ], + "details": "A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47862" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1886" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mc9v-5c5f-p2j5/GHSA-mc9v-5c5f-p2j5.json b/advisories/unreviewed/2024/01/GHSA-mc9v-5c5f-p2j5/GHSA-mc9v-5c5f-p2j5.json new file mode 100644 index 00000000000..e1915705cc8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mc9v-5c5f-p2j5/GHSA-mc9v-5c5f-p2j5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc9v-5c5f-p2j5", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49863" + ], + "details": "An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_webpimage` parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49863" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mj36-f2x8-8hgg/GHSA-mj36-f2x8-8hgg.json b/advisories/unreviewed/2024/01/GHSA-mj36-f2x8-8hgg/GHSA-mj36-f2x8-8hgg.json index 0cd369ca9ba..679ea24d5c1 100644 --- a/advisories/unreviewed/2024/01/GHSA-mj36-f2x8-8hgg/GHSA-mj36-f2x8-8hgg.json +++ b/advisories/unreviewed/2024/01/GHSA-mj36-f2x8-8hgg/GHSA-mj36-f2x8-8hgg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mj36-f2x8-8hgg", - "modified": "2024-01-04T06:30:32Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T06:30:32Z", "aliases": [ "CVE-2023-29962" ], "details": "S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T06:15:45Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mr34-2x5p-4cw8/GHSA-mr34-2x5p-4cw8.json b/advisories/unreviewed/2024/01/GHSA-mr34-2x5p-4cw8/GHSA-mr34-2x5p-4cw8.json new file mode 100644 index 00000000000..6e7873f01c6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mr34-2x5p-4cw8/GHSA-mr34-2x5p-4cw8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr34-2x5p-4cw8", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-44250" + ], + "details": "An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44250" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mx69-f24x-8r7c/GHSA-mx69-f24x-8r7c.json b/advisories/unreviewed/2024/01/GHSA-mx69-f24x-8r7c/GHSA-mx69-f24x-8r7c.json index f68491b4240..301795afe7b 100644 --- a/advisories/unreviewed/2024/01/GHSA-mx69-f24x-8r7c/GHSA-mx69-f24x-8r7c.json +++ b/advisories/unreviewed/2024/01/GHSA-mx69-f24x-8r7c/GHSA-mx69-f24x-8r7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mx69-f24x-8r7c", - "modified": "2024-01-04T06:30:32Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T06:30:32Z", "aliases": [ "CVE-2023-6738" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-p45m-r94f-7mf2/GHSA-p45m-r94f-7mf2.json b/advisories/unreviewed/2024/01/GHSA-p45m-r94f-7mf2/GHSA-p45m-r94f-7mf2.json new file mode 100644 index 00000000000..6cb00219432 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p45m-r94f-7mf2/GHSA-p45m-r94f-7mf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p45m-r94f-7mf2", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49715" + ], + "details": "A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49715" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1885" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p88h-866g-7w72/GHSA-p88h-866g-7w72.json b/advisories/unreviewed/2024/01/GHSA-p88h-866g-7w72/GHSA-p88h-866g-7w72.json index 268528f9f6a..a4187e93430 100644 --- a/advisories/unreviewed/2024/01/GHSA-p88h-866g-7w72/GHSA-p88h-866g-7w72.json +++ b/advisories/unreviewed/2024/01/GHSA-p88h-866g-7w72/GHSA-p88h-866g-7w72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p88h-866g-7w72", - "modified": "2024-01-04T09:30:33Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T09:30:33Z", "aliases": [ "CVE-2023-52322" ], "details": "ecrire/public/assembler.php in SPIP before 4.1.3 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-04T07:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-pp66-r2h3-jcwq/GHSA-pp66-r2h3-jcwq.json b/advisories/unreviewed/2024/01/GHSA-pp66-r2h3-jcwq/GHSA-pp66-r2h3-jcwq.json new file mode 100644 index 00000000000..7d24c6c1784 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pp66-r2h3-jcwq/GHSA-pp66-r2h3-jcwq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp66-r2h3-jcwq", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-48783" + ], + "details": "An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48783" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-408" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q2qc-2pfg-hfvg/GHSA-q2qc-2pfg-hfvg.json b/advisories/unreviewed/2024/01/GHSA-q2qc-2pfg-hfvg/GHSA-q2qc-2pfg-hfvg.json new file mode 100644 index 00000000000..8d63c2adee7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q2qc-2pfg-hfvg/GHSA-q2qc-2pfg-hfvg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2qc-2pfg-hfvg", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-46712" + ], + "details": "A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46712" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-395" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json b/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json index 8eb5640dc1b..bb2ab08c961 100644 --- a/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json +++ b/advisories/unreviewed/2024/01/GHSA-r6q5-w2p8-76c4/GHSA-r6q5-w2p8-76c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6q5-w2p8-76c4", - "modified": "2024-01-04T12:30:20Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T12:30:20Z", "aliases": [ "CVE-2023-7044" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-rrxp-pgc2-x28c/GHSA-rrxp-pgc2-x28c.json b/advisories/unreviewed/2024/01/GHSA-rrxp-pgc2-x28c/GHSA-rrxp-pgc2-x28c.json index 1a9230cad9f..65509495cbb 100644 --- a/advisories/unreviewed/2024/01/GHSA-rrxp-pgc2-x28c/GHSA-rrxp-pgc2-x28c.json +++ b/advisories/unreviewed/2024/01/GHSA-rrxp-pgc2-x28c/GHSA-rrxp-pgc2-x28c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rrxp-pgc2-x28c", - "modified": "2024-01-04T06:30:32Z", + "modified": "2024-01-10T18:30:25Z", "published": "2024-01-04T06:30:32Z", "aliases": [ "CVE-2023-6498" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-v3xr-m742-g2v3/GHSA-v3xr-m742-g2v3.json b/advisories/unreviewed/2024/01/GHSA-v3xr-m742-g2v3/GHSA-v3xr-m742-g2v3.json index b3b92bf5b3b..f9a54038757 100644 --- a/advisories/unreviewed/2024/01/GHSA-v3xr-m742-g2v3/GHSA-v3xr-m742-g2v3.json +++ b/advisories/unreviewed/2024/01/GHSA-v3xr-m742-g2v3/GHSA-v3xr-m742-g2v3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json b/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json index 1c34ad0b41d..85eae2d046d 100644 --- a/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json +++ b/advisories/unreviewed/2024/01/GHSA-v4r8-6m3f-gvv4/GHSA-v4r8-6m3f-gvv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4r8-6m3f-gvv4", - "modified": "2024-01-03T09:30:33Z", + "modified": "2024-01-10T18:30:24Z", "published": "2024-01-03T09:30:33Z", "aliases": [ "CVE-2023-6747" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-v6qj-8w6x-qqf5/GHSA-v6qj-8w6x-qqf5.json b/advisories/unreviewed/2024/01/GHSA-v6qj-8w6x-qqf5/GHSA-v6qj-8w6x-qqf5.json new file mode 100644 index 00000000000..5303da5fcb5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v6qj-8w6x-qqf5/GHSA-v6qj-8w6x-qqf5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6qj-8w6x-qqf5", + "modified": "2024-01-10T18:30:26Z", + "published": "2024-01-10T18:30:26Z", + "aliases": [ + "CVE-2023-48730" + ], + "details": "A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48730" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1882" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v977-h4hm-rrff/GHSA-v977-h4hm-rrff.json b/advisories/unreviewed/2024/01/GHSA-v977-h4hm-rrff/GHSA-v977-h4hm-rrff.json new file mode 100644 index 00000000000..f6201743bbc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v977-h4hm-rrff/GHSA-v977-h4hm-rrff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v977-h4hm-rrff", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49810" + ], + "details": "A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to bruteforce users credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49810" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1898" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w876-744c-hf5g/GHSA-w876-744c-hf5g.json b/advisories/unreviewed/2024/01/GHSA-w876-744c-hf5g/GHSA-w876-744c-hf5g.json new file mode 100644 index 00000000000..cefb2098673 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w876-744c-hf5g/GHSA-w876-744c-hf5g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w876-744c-hf5g", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-29444" + ], + "details": "An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29444" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-243-03" + }, + { + "type": "WEB", + "url": "https://www.ptc.com/en/support/article/cs399528" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wfjj-3hq8-qwp2/GHSA-wfjj-3hq8-qwp2.json b/advisories/unreviewed/2024/01/GHSA-wfjj-3hq8-qwp2/GHSA-wfjj-3hq8-qwp2.json new file mode 100644 index 00000000000..f6b2315d4fd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wfjj-3hq8-qwp2/GHSA-wfjj-3hq8-qwp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfjj-3hq8-qwp2", + "modified": "2024-01-10T18:30:26Z", + "published": "2024-01-10T18:30:26Z", + "aliases": [ + "CVE-2023-47171" + ], + "details": "An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47171" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1869" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wgfw-cpjm-64v6/GHSA-wgfw-cpjm-64v6.json b/advisories/unreviewed/2024/01/GHSA-wgfw-cpjm-64v6/GHSA-wgfw-cpjm-64v6.json new file mode 100644 index 00000000000..83491a1d420 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wgfw-cpjm-64v6/GHSA-wgfw-cpjm-64v6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgfw-cpjm-64v6", + "modified": "2024-01-10T18:30:28Z", + "published": "2024-01-10T18:30:28Z", + "aliases": [ + "CVE-2023-49864" + ], + "details": "An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49864" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wj25-93rv-m5jr/GHSA-wj25-93rv-m5jr.json b/advisories/unreviewed/2024/01/GHSA-wj25-93rv-m5jr/GHSA-wj25-93rv-m5jr.json index 61cd9219f41..052e918cd8e 100644 --- a/advisories/unreviewed/2024/01/GHSA-wj25-93rv-m5jr/GHSA-wj25-93rv-m5jr.json +++ b/advisories/unreviewed/2024/01/GHSA-wj25-93rv-m5jr/GHSA-wj25-93rv-m5jr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-wqcc-qf63-c2x4/GHSA-wqcc-qf63-c2x4.json b/advisories/unreviewed/2024/01/GHSA-wqcc-qf63-c2x4/GHSA-wqcc-qf63-c2x4.json new file mode 100644 index 00000000000..2725c9a6477 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wqcc-qf63-c2x4/GHSA-wqcc-qf63-c2x4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqcc-qf63-c2x4", + "modified": "2024-01-10T18:30:27Z", + "published": "2024-01-10T18:30:27Z", + "aliases": [ + "CVE-2023-49599" + ], + "details": "An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and bruteforce the salt offline, leading to forging a legitimate password recovery code for the admin user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49599" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-331" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-wv3w-qq6q-g9j3/GHSA-wv3w-qq6q-g9j3.json b/advisories/unreviewed/2024/01/GHSA-wv3w-qq6q-g9j3/GHSA-wv3w-qq6q-g9j3.json new file mode 100644 index 00000000000..3c0923df0da --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-wv3w-qq6q-g9j3/GHSA-wv3w-qq6q-g9j3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv3w-qq6q-g9j3", + "modified": "2024-01-10T18:30:26Z", + "published": "2024-01-10T18:30:26Z", + "aliases": [ + "CVE-2023-48728" + ], + "details": "A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48728" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1883" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-10T16:15:47Z" + } +} \ No newline at end of file