diff --git a/advisories/github-reviewed/2023/11/GHSA-fccv-jmmp-qg76/GHSA-fccv-jmmp-qg76.json b/advisories/github-reviewed/2023/11/GHSA-fccv-jmmp-qg76/GHSA-fccv-jmmp-qg76.json index fb7087909ba..3a5ae4b594f 100644 --- a/advisories/github-reviewed/2023/11/GHSA-fccv-jmmp-qg76/GHSA-fccv-jmmp-qg76.json +++ b/advisories/github-reviewed/2023/11/GHSA-fccv-jmmp-qg76/GHSA-fccv-jmmp-qg76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fccv-jmmp-qg76", - "modified": "2023-12-21T22:01:39Z", + "modified": "2024-01-05T12:30:19Z", "published": "2023-11-28T18:30:23Z", "aliases": [ "CVE-2023-46589" @@ -197,6 +197,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00001.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20231214-0009/" diff --git a/advisories/unreviewed/2021/10/GHSA-gqhp-5j32-xwmm/GHSA-gqhp-5j32-xwmm.json b/advisories/unreviewed/2021/10/GHSA-gqhp-5j32-xwmm/GHSA-gqhp-5j32-xwmm.json index 772bb54991b..ead82a8a3ce 100644 --- a/advisories/unreviewed/2021/10/GHSA-gqhp-5j32-xwmm/GHSA-gqhp-5j32-xwmm.json +++ b/advisories/unreviewed/2021/10/GHSA-gqhp-5j32-xwmm/GHSA-gqhp-5j32-xwmm.json @@ -42,6 +42,10 @@ "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/july-2021-security-releases-2/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-02" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20211112-0002/" diff --git a/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json b/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json index 58a5846746c..0e207d0a6fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json +++ b/advisories/unreviewed/2022/05/GHSA-6hhj-4h22-mrmm/GHSA-6hhj-4h22-mrmm.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-02" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20210923-0001/" diff --git a/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json b/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json index 9b01a170b68..609c672cc1c 100644 --- a/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json +++ b/advisories/unreviewed/2022/05/GHSA-7r9p-c88x-w357/GHSA-7r9p-c88x-w357.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-02" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20210923-0001/" @@ -56,6 +60,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-170", "CWE-20" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json b/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json index cb4ce74bbe6..41917c4d8ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json +++ b/advisories/unreviewed/2022/05/GHSA-9mvv-4q4j-q2j8/GHSA-9mvv-4q4j-q2j8.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-02" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20210917-0003/" diff --git a/advisories/unreviewed/2022/05/GHSA-hghm-3vc3-hppj/GHSA-hghm-3vc3-hppj.json b/advisories/unreviewed/2022/05/GHSA-hghm-3vc3-hppj/GHSA-hghm-3vc3-hppj.json index cca53d1e60d..f038d3a3288 100644 --- a/advisories/unreviewed/2022/05/GHSA-hghm-3vc3-hppj/GHSA-hghm-3vc3-hppj.json +++ b/advisories/unreviewed/2022/05/GHSA-hghm-3vc3-hppj/GHSA-hghm-3vc3-hppj.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-02" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2022.html" diff --git a/advisories/unreviewed/2023/03/GHSA-v7h6-g695-5j7q/GHSA-v7h6-g695-5j7q.json b/advisories/unreviewed/2023/03/GHSA-v7h6-g695-5j7q/GHSA-v7h6-g695-5j7q.json index b52f7f5115f..4b3c7761610 100644 --- a/advisories/unreviewed/2023/03/GHSA-v7h6-g695-5j7q/GHSA-v7h6-g695-5j7q.json +++ b/advisories/unreviewed/2023/03/GHSA-v7h6-g695-5j7q/GHSA-v7h6-g695-5j7q.json @@ -29,9 +29,17 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2168631" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33LDNS6RPOPP36Z4MPWXALUQZXJCWJS2/" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-02" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-22j2-mxcq-m52p/GHSA-22j2-mxcq-m52p.json b/advisories/unreviewed/2024/01/GHSA-22j2-mxcq-m52p/GHSA-22j2-mxcq-m52p.json index 6ff08ebc7cf..d017e981544 100644 --- a/advisories/unreviewed/2024/01/GHSA-22j2-mxcq-m52p/GHSA-22j2-mxcq-m52p.json +++ b/advisories/unreviewed/2024/01/GHSA-22j2-mxcq-m52p/GHSA-22j2-mxcq-m52p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22j2-mxcq-m52p", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32874" ], "details": "In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json b/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json new file mode 100644 index 00000000000..0feddaa761a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-33rw-cjxq-8rgp/GHSA-33rw-cjxq-8rgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33rw-cjxq-8rgp", + "modified": "2024-01-05T12:30:21Z", + "published": "2024-01-05T12:30:21Z", + "aliases": [ + "CVE-2023-51538" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/awesome-support/wordpress-awesome-support-plugin-6-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4mhp-935g-p95j/GHSA-4mhp-935g-p95j.json b/advisories/unreviewed/2024/01/GHSA-4mhp-935g-p95j/GHSA-4mhp-935g-p95j.json index 5b8a0d58e7b..4302f4208e1 100644 --- a/advisories/unreviewed/2024/01/GHSA-4mhp-935g-p95j/GHSA-4mhp-935g-p95j.json +++ b/advisories/unreviewed/2024/01/GHSA-4mhp-935g-p95j/GHSA-4mhp-935g-p95j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mhp-935g-p95j", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32879" ], "details": "In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308064.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json b/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json new file mode 100644 index 00000000000..0d80b627ce2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5f2c-q448-h62x/GHSA-5f2c-q448-h62x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2c-q448-h62x", + "modified": "2024-01-05T12:30:21Z", + "published": "2024-01-05T12:30:21Z", + "aliases": [ + "CVE-2023-50991" + ], + "details": "Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50991" + }, + { + "type": "WEB", + "url": "https://github.com/ef4tless/vuln/blob/master/iot/i29/pingSet.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json b/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json new file mode 100644 index 00000000000..11492641185 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5ghg-77c4-pg6g/GHSA-5ghg-77c4-pg6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ghg-77c4-pg6g", + "modified": "2024-01-05T12:30:24Z", + "published": "2024-01-05T12:30:24Z", + "aliases": [ + "CVE-2023-51678" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/doofinder-for-woocommerce/wordpress-doofinder-wp-woocommerce-search-plugin-2-0-33-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5w6w-j982-cggq/GHSA-5w6w-j982-cggq.json b/advisories/unreviewed/2024/01/GHSA-5w6w-j982-cggq/GHSA-5w6w-j982-cggq.json new file mode 100644 index 00000000000..afd2cb08004 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5w6w-j982-cggq/GHSA-5w6w-j982-cggq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w6w-j982-cggq", + "modified": "2024-01-05T12:30:22Z", + "published": "2024-01-05T12:30:22Z", + "aliases": [ + "CVE-2023-51539" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/apollo13-framework-extensions/wordpress-apollo13-framework-extensions-plugin-1-9-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6pjw-2w28-39xc/GHSA-6pjw-2w28-39xc.json b/advisories/unreviewed/2024/01/GHSA-6pjw-2w28-39xc/GHSA-6pjw-2w28-39xc.json index e3bec160931..199e7a81356 100644 --- a/advisories/unreviewed/2024/01/GHSA-6pjw-2w28-39xc/GHSA-6pjw-2w28-39xc.json +++ b/advisories/unreviewed/2024/01/GHSA-6pjw-2w28-39xc/GHSA-6pjw-2w28-39xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6pjw-2w28-39xc", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32878" ], "details": "In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08307992.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-74pj-4459-77rw/GHSA-74pj-4459-77rw.json b/advisories/unreviewed/2024/01/GHSA-74pj-4459-77rw/GHSA-74pj-4459-77rw.json index 4b8c37f6a7f..525cfa7f637 100644 --- a/advisories/unreviewed/2024/01/GHSA-74pj-4459-77rw/GHSA-74pj-4459-77rw.json +++ b/advisories/unreviewed/2024/01/GHSA-74pj-4459-77rw/GHSA-74pj-4459-77rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74pj-4459-77rw", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32885" ], "details": "In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780685; Issue ID: ALPS07780685.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7c6f-5v4h-x27j/GHSA-7c6f-5v4h-x27j.json b/advisories/unreviewed/2024/01/GHSA-7c6f-5v4h-x27j/GHSA-7c6f-5v4h-x27j.json index a1f28b28f62..3d4b366389e 100644 --- a/advisories/unreviewed/2024/01/GHSA-7c6f-5v4h-x27j/GHSA-7c6f-5v4h-x27j.json +++ b/advisories/unreviewed/2024/01/GHSA-7c6f-5v4h-x27j/GHSA-7c6f-5v4h-x27j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7c6f-5v4h-x27j", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32872" ], "details": "In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08308607.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-7hf2-cmmw-j42p/GHSA-7hf2-cmmw-j42p.json b/advisories/unreviewed/2024/01/GHSA-7hf2-cmmw-j42p/GHSA-7hf2-cmmw-j42p.json new file mode 100644 index 00000000000..0e9023f1bb8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7hf2-cmmw-j42p/GHSA-7hf2-cmmw-j42p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hf2-cmmw-j42p", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52148" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/affiliates-manager/wordpress-affiliates-manager-plugin-2-9-30-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7jwp-9wj7-pp6x/GHSA-7jwp-9wj7-pp6x.json b/advisories/unreviewed/2024/01/GHSA-7jwp-9wj7-pp6x/GHSA-7jwp-9wj7-pp6x.json new file mode 100644 index 00000000000..b3bc00fe050 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7jwp-9wj7-pp6x/GHSA-7jwp-9wj7-pp6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jwp-9wj7-pp6x", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52151" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: from n/a through 5.1.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52151" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/uncanny-automator/wordpress-uncanny-automator-plugin-5-1-0-2-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7q5q-c932-cm9r/GHSA-7q5q-c932-cm9r.json b/advisories/unreviewed/2024/01/GHSA-7q5q-c932-cm9r/GHSA-7q5q-c932-cm9r.json index 77a3eb36bc2..aac8a3f6763 100644 --- a/advisories/unreviewed/2024/01/GHSA-7q5q-c932-cm9r/GHSA-7q5q-c932-cm9r.json +++ b/advisories/unreviewed/2024/01/GHSA-7q5q-c932-cm9r/GHSA-7q5q-c932-cm9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7q5q-c932-cm9r", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32880" ], "details": "In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308076.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8284-h6g2-x964/GHSA-8284-h6g2-x964.json b/advisories/unreviewed/2024/01/GHSA-8284-h6g2-x964/GHSA-8284-h6g2-x964.json new file mode 100644 index 00000000000..ee131221c82 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8284-h6g2-x964/GHSA-8284-h6g2-x964.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8284-h6g2-x964", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52124" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plugin for WordPress allows Stored XSS.This issue affects WP Tabs – Responsive Tabs Plugin for WordPress: from n/a through 2.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52124" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-expand-tabs-free/wordpress-wp-tabs-responsive-tabs-plugin-for-wordpress-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-8q2r-v4xp-34qq/GHSA-8q2r-v4xp-34qq.json b/advisories/unreviewed/2024/01/GHSA-8q2r-v4xp-34qq/GHSA-8q2r-v4xp-34qq.json index c574a0c8cd2..f7d7485e9d1 100644 --- a/advisories/unreviewed/2024/01/GHSA-8q2r-v4xp-34qq/GHSA-8q2r-v4xp-34qq.json +++ b/advisories/unreviewed/2024/01/GHSA-8q2r-v4xp-34qq/GHSA-8q2r-v4xp-34qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8q2r-v4xp-34qq", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32888" ], "details": "In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161830; Issue ID: MOLY01161830 (MSV-894).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8wmq-6cfj-m7w3/GHSA-8wmq-6cfj-m7w3.json b/advisories/unreviewed/2024/01/GHSA-8wmq-6cfj-m7w3/GHSA-8wmq-6cfj-m7w3.json index 6018c9ec863..98e79c905ea 100644 --- a/advisories/unreviewed/2024/01/GHSA-8wmq-6cfj-m7w3/GHSA-8wmq-6cfj-m7w3.json +++ b/advisories/unreviewed/2024/01/GHSA-8wmq-6cfj-m7w3/GHSA-8wmq-6cfj-m7w3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wmq-6cfj-m7w3", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32877" ], "details": "In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308070.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json b/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json new file mode 100644 index 00000000000..a7c1ce565a4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9frx-f993-wf86/GHSA-9frx-f993-wf86.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9frx-f993-wf86", + "modified": "2024-01-05T12:30:23Z", + "published": "2024-01-05T12:30:23Z", + "aliases": [ + "CVE-2023-51673" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from n/a through 7.0.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stylish-price-list/wordpress-stylish-price-list-plugin-7-0-17-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9gfp-mxq7-r8g5/GHSA-9gfp-mxq7-r8g5.json b/advisories/unreviewed/2024/01/GHSA-9gfp-mxq7-r8g5/GHSA-9gfp-mxq7-r8g5.json index 06dc7dc2d4d..08d29f212f1 100644 --- a/advisories/unreviewed/2024/01/GHSA-9gfp-mxq7-r8g5/GHSA-9gfp-mxq7-r8g5.json +++ b/advisories/unreviewed/2024/01/GHSA-9gfp-mxq7-r8g5/GHSA-9gfp-mxq7-r8g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9gfp-mxq7-r8g5", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32875" ], "details": "In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308607; Issue ID: ALPS08304217.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-9wr3-3xxw-mvrx/GHSA-9wr3-3xxw-mvrx.json b/advisories/unreviewed/2024/01/GHSA-9wr3-3xxw-mvrx/GHSA-9wr3-3xxw-mvrx.json new file mode 100644 index 00000000000..a052f5969bd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9wr3-3xxw-mvrx/GHSA-9wr3-3xxw-mvrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wr3-3xxw-mvrx", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52125" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly iframe allows Stored XSS.This issue affects iframe: from n/a through 4.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52125" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/iframe/wordpress-iframe-plugin-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cpmc-862m-r48v/GHSA-cpmc-862m-r48v.json b/advisories/unreviewed/2024/01/GHSA-cpmc-862m-r48v/GHSA-cpmc-862m-r48v.json new file mode 100644 index 00000000000..6f9cff01faf --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-cpmc-862m-r48v/GHSA-cpmc-862m-r48v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpmc-862m-r48v", + "modified": "2024-01-05T12:30:23Z", + "published": "2024-01-05T12:30:23Z", + "aliases": [ + "CVE-2023-51668" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Inline Image Upload for BBPress.This issue affects Inline Image Upload for BBPress: from n/a through 1.1.18.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/image-upload-for-bbpress/wordpress-inline-image-upload-for-bbpress-plugin-1-1-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-cpmr-p9r8-5m73/GHSA-cpmr-p9r8-5m73.json b/advisories/unreviewed/2024/01/GHSA-cpmr-p9r8-5m73/GHSA-cpmr-p9r8-5m73.json index 036a1e6814f..9aadf8d68b9 100644 --- a/advisories/unreviewed/2024/01/GHSA-cpmr-p9r8-5m73/GHSA-cpmr-p9r8-5m73.json +++ b/advisories/unreviewed/2024/01/GHSA-cpmr-p9r8-5m73/GHSA-cpmr-p9r8-5m73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpmr-p9r8-5m73", - "modified": "2024-01-02T03:30:31Z", + "modified": "2024-01-05T12:30:20Z", "published": "2024-01-02T03:30:31Z", "aliases": [ "CVE-2023-32890" ], "details": "In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01183647; Issue ID: MOLY01183647 (MSV-963).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-f8hf-p24c-jqvg/GHSA-f8hf-p24c-jqvg.json b/advisories/unreviewed/2024/01/GHSA-f8hf-p24c-jqvg/GHSA-f8hf-p24c-jqvg.json index 37e929112ba..d1376d2affc 100644 --- a/advisories/unreviewed/2024/01/GHSA-f8hf-p24c-jqvg/GHSA-f8hf-p24c-jqvg.json +++ b/advisories/unreviewed/2024/01/GHSA-f8hf-p24c-jqvg/GHSA-f8hf-p24c-jqvg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8hf-p24c-jqvg", - "modified": "2024-01-02T03:30:31Z", + "modified": "2024-01-05T12:30:20Z", "published": "2024-01-02T03:30:31Z", "aliases": [ "CVE-2023-32889" ], "details": "In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161825; Issue ID: MOLY01161825 (MSV-895).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-g4pv-55wx-3w8q/GHSA-g4pv-55wx-3w8q.json b/advisories/unreviewed/2024/01/GHSA-g4pv-55wx-3w8q/GHSA-g4pv-55wx-3w8q.json index c8ea35b4124..fcc0bf63cbd 100644 --- a/advisories/unreviewed/2024/01/GHSA-g4pv-55wx-3w8q/GHSA-g4pv-55wx-3w8q.json +++ b/advisories/unreviewed/2024/01/GHSA-g4pv-55wx-3w8q/GHSA-g4pv-55wx-3w8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g4pv-55wx-3w8q", - "modified": "2024-01-02T03:30:31Z", + "modified": "2024-01-05T12:30:20Z", "published": "2024-01-02T03:30:31Z", "aliases": [ "CVE-2023-32891" ], "details": "In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07933038; Issue ID: MSV-559.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gqgh-pxg9-5r2w/GHSA-gqgh-pxg9-5r2w.json b/advisories/unreviewed/2024/01/GHSA-gqgh-pxg9-5r2w/GHSA-gqgh-pxg9-5r2w.json index e90bce2312f..dd6e78fc372 100644 --- a/advisories/unreviewed/2024/01/GHSA-gqgh-pxg9-5r2w/GHSA-gqgh-pxg9-5r2w.json +++ b/advisories/unreviewed/2024/01/GHSA-gqgh-pxg9-5r2w/GHSA-gqgh-pxg9-5r2w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gqgh-pxg9-5r2w", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32881" ], "details": "In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308080.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-j534-cwfj-5vqc/GHSA-j534-cwfj-5vqc.json b/advisories/unreviewed/2024/01/GHSA-j534-cwfj-5vqc/GHSA-j534-cwfj-5vqc.json new file mode 100644 index 00000000000..df831dd3826 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-j534-cwfj-5vqc/GHSA-j534-cwfj-5vqc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j534-cwfj-5vqc", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52120" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Contact forms and much more: from n/a through 8.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52120" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nex-forms-express-wp-form-builder/wordpress-nex-forms-plugin-8-5-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jfch-7m53-3fxv/GHSA-jfch-7m53-3fxv.json b/advisories/unreviewed/2024/01/GHSA-jfch-7m53-3fxv/GHSA-jfch-7m53-3fxv.json new file mode 100644 index 00000000000..a6757ca776e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jfch-7m53-3fxv/GHSA-jfch-7m53-3fxv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfch-7m53-3fxv", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52119" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.18.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52119" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icegram/wordpress-icegram-engage-plugin-3-1-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json b/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json new file mode 100644 index 00000000000..014acd2b92d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m3fq-v9fh-gg5p/GHSA-m3fq-v9fh-gg5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3fq-v9fh-gg5p", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2022-46839" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/js-support-ticket/wordpress-js-help-desk-plugin-2-7-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m7pf-2cqc-rm4r/GHSA-m7pf-2cqc-rm4r.json b/advisories/unreviewed/2024/01/GHSA-m7pf-2cqc-rm4r/GHSA-m7pf-2cqc-rm4r.json index f508ce19f7e..e86713872d7 100644 --- a/advisories/unreviewed/2024/01/GHSA-m7pf-2cqc-rm4r/GHSA-m7pf-2cqc-rm4r.json +++ b/advisories/unreviewed/2024/01/GHSA-m7pf-2cqc-rm4r/GHSA-m7pf-2cqc-rm4r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m7pf-2cqc-rm4r", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32876" ], "details": "In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308612; Issue ID: ALPS08308612.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-mf62-7364-m8fq/GHSA-mf62-7364-m8fq.json b/advisories/unreviewed/2024/01/GHSA-mf62-7364-m8fq/GHSA-mf62-7364-m8fq.json new file mode 100644 index 00000000000..32e70b2afdc --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mf62-7364-m8fq/GHSA-mf62-7364-m8fq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf62-7364-m8fq", + "modified": "2024-01-05T12:30:21Z", + "published": "2024-01-05T12:30:21Z", + "aliases": [ + "CVE-2023-51535" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ?leanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cleantalk-spam-protect/wordpress-spam-protection-anti-spam-firewall-by-cleantalk-plugin-6-20-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mhjf-f5q6-785c/GHSA-mhjf-f5q6-785c.json b/advisories/unreviewed/2024/01/GHSA-mhjf-f5q6-785c/GHSA-mhjf-f5q6-785c.json new file mode 100644 index 00000000000..e075e77665f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mhjf-f5q6-785c/GHSA-mhjf-f5q6-785c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhjf-f5q6-785c", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52122" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52122" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-job-board/wordpress-simple-job-board-plugin-2-10-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p2v6-235w-qhfc/GHSA-p2v6-235w-qhfc.json b/advisories/unreviewed/2024/01/GHSA-p2v6-235w-qhfc/GHSA-p2v6-235w-qhfc.json index e847198b45f..725b0368d93 100644 --- a/advisories/unreviewed/2024/01/GHSA-p2v6-235w-qhfc/GHSA-p2v6-235w-qhfc.json +++ b/advisories/unreviewed/2024/01/GHSA-p2v6-235w-qhfc/GHSA-p2v6-235w-qhfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2v6-235w-qhfc", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32886" ], "details": "In Modem IMS SMS UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00730807; Issue ID: MOLY00730807.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-q4r7-vvv3-cgv4/GHSA-q4r7-vvv3-cgv4.json b/advisories/unreviewed/2024/01/GHSA-q4r7-vvv3-cgv4/GHSA-q4r7-vvv3-cgv4.json index b3d739f766b..cb608005ddf 100644 --- a/advisories/unreviewed/2024/01/GHSA-q4r7-vvv3-cgv4/GHSA-q4r7-vvv3-cgv4.json +++ b/advisories/unreviewed/2024/01/GHSA-q4r7-vvv3-cgv4/GHSA-q4r7-vvv3-cgv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q4r7-vvv3-cgv4", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32882" ], "details": "In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID: ALPS08308616.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json b/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json new file mode 100644 index 00000000000..6864e08d055 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-q6fp-96rm-r5mq/GHSA-q6fp-96rm-r5mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6fp-96rm-r5mq", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52146" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.33.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52146" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/404-solution/wordpress-404-solution-plugin-2-33-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-q6w4-3x9w-4364/GHSA-q6w4-3x9w-4364.json b/advisories/unreviewed/2024/01/GHSA-q6w4-3x9w-4364/GHSA-q6w4-3x9w-4364.json index a8222443a5e..f6fd0ed2b29 100644 --- a/advisories/unreviewed/2024/01/GHSA-q6w4-3x9w-4364/GHSA-q6w4-3x9w-4364.json +++ b/advisories/unreviewed/2024/01/GHSA-q6w4-3x9w-4364/GHSA-q6w4-3x9w-4364.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q6w4-3x9w-4364", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32884" ], "details": "In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944011; Issue ID: ALPS07944011.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-qc8f-vmgx-5jmp/GHSA-qc8f-vmgx-5jmp.json b/advisories/unreviewed/2024/01/GHSA-qc8f-vmgx-5jmp/GHSA-qc8f-vmgx-5jmp.json new file mode 100644 index 00000000000..5faac6a2003 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-qc8f-vmgx-5jmp/GHSA-qc8f-vmgx-5jmp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc8f-vmgx-5jmp", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52126" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52126" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/send-users-email/wordpress-send-users-email-plugin-1-4-3-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json b/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json new file mode 100644 index 00000000000..35e3c02e87a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-r45q-p466-5ghh/GHSA-r45q-p466-5ghh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r45q-p466-5ghh", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52121" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc. NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images.This issue affects NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images: from n/a through 1.10.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52121" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nitropack/wordpress-nitropack-plugin-1-10-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v27h-q36j-mh72/GHSA-v27h-q36j-mh72.json b/advisories/unreviewed/2024/01/GHSA-v27h-q36j-mh72/GHSA-v27h-q36j-mh72.json index d66a54e973c..e410b410c01 100644 --- a/advisories/unreviewed/2024/01/GHSA-v27h-q36j-mh72/GHSA-v27h-q36j-mh72.json +++ b/advisories/unreviewed/2024/01/GHSA-v27h-q36j-mh72/GHSA-v27h-q36j-mh72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v27h-q36j-mh72", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32887" ], "details": "In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161837; Issue ID: MOLY01161837 (MSV-892).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-119" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-w44p-fc2q-qf57/GHSA-w44p-fc2q-qf57.json b/advisories/unreviewed/2024/01/GHSA-w44p-fc2q-qf57/GHSA-w44p-fc2q-qf57.json index c408eb59499..573fd276087 100644 --- a/advisories/unreviewed/2024/01/GHSA-w44p-fc2q-qf57/GHSA-w44p-fc2q-qf57.json +++ b/advisories/unreviewed/2024/01/GHSA-w44p-fc2q-qf57/GHSA-w44p-fc2q-qf57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w44p-fc2q-qf57", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32883" ], "details": "In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08282249; Issue ID: ALPS08282249.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-w86q-6fxq-gcmr/GHSA-w86q-6fxq-gcmr.json b/advisories/unreviewed/2024/01/GHSA-w86q-6fxq-gcmr/GHSA-w86q-6fxq-gcmr.json index 318925d14b1..1a4ce8ed57f 100644 --- a/advisories/unreviewed/2024/01/GHSA-w86q-6fxq-gcmr/GHSA-w86q-6fxq-gcmr.json +++ b/advisories/unreviewed/2024/01/GHSA-w86q-6fxq-gcmr/GHSA-w86q-6fxq-gcmr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w86q-6fxq-gcmr", - "modified": "2024-01-02T03:30:30Z", + "modified": "2024-01-05T12:30:19Z", "published": "2024-01-02T03:30:30Z", "aliases": [ "CVE-2023-32831" ], "details": "In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00325055; Issue ID: MSV-868.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-330" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-02T03:15:07Z" diff --git a/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json b/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json new file mode 100644 index 00000000000..06abd29a5e0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xj5p-wxr5-6r73/GHSA-xj5p-wxr5-6r73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj5p-wxr5-6r73", + "modified": "2024-01-05T12:30:25Z", + "published": "2024-01-05T12:30:25Z", + "aliases": [ + "CVE-2023-52143" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52143" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-stripe-checkout/wordpress-wp-stripe-checkout-plugin-1-2-2-37-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-05T11:15:10Z" + } +} \ No newline at end of file