From ba7f4f071b1de4a64ad8266c200acb3c64cab4ab Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 10 Jul 2023 18:31:58 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-px4v-wj8p-cq36.json | 3 +- .../GHSA-3g24-rv7h-5xh5.json | 4 +- .../GHSA-25xc-r4x7-g46h.json | 4 ++ .../GHSA-f585-354r-gp9r.json | 4 ++ .../GHSA-77p4-47r7-prgw.json | 1 + .../GHSA-f92h-c5mh-qv8v.json | 3 +- .../GHSA-q7rw-9gg7-5wfw.json | 10 ++-- .../GHSA-3886-rc87-ccgx.json | 1 + .../GHSA-3jr6-jfqc-mjcf.json | 3 +- .../GHSA-w4h2-22wh-m6jx.json | 3 +- .../GHSA-m82q-v8rc-95v6.json | 3 +- .../GHSA-5v8j-jfmm-6x86.json | 8 +++ .../GHSA-8937-gcf5-34xq.json | 1 + .../GHSA-pcw9-xw4x-jgj3.json | 7 ++- .../GHSA-w92h-gfcv-m7wv.json | 7 ++- .../GHSA-29xr-xpp4-5783.json | 46 +++++++++++++++++ .../GHSA-2fmj-pq77-gvj7.json | 35 +++++++++++++ .../GHSA-2h4j-hwr9-94jw.json | 46 +++++++++++++++++ .../GHSA-2hf7-q8gj-r58v.json | 35 +++++++++++++ .../GHSA-2wjj-p9fg-qxjq.json | 35 +++++++++++++ .../GHSA-2xf9-j9jw-g7f7.json | 46 +++++++++++++++++ .../GHSA-32v6-f8xf-f75q.json | 35 +++++++++++++ .../GHSA-36wf-hpjh-x3fr.json | 7 ++- .../GHSA-3c6h-f6m9-jghc.json | 35 +++++++++++++ .../GHSA-3w6v-h5wr-h9rh.json | 38 ++++++++++++++ .../GHSA-3x7w-vvg2-w6r8.json | 50 +++++++++++++++++++ .../GHSA-48fj-24fp-5q3v.json | 38 ++++++++++++++ .../GHSA-4fq5-58j6-9qph.json | 46 +++++++++++++++++ .../GHSA-4jrq-9cvx-fwjx.json | 42 ++++++++++++++++ .../GHSA-4mxm-g64v-4969.json | 35 +++++++++++++ .../GHSA-4v64-w7v7-ch7f.json | 50 +++++++++++++++++++ .../GHSA-4wj9-c75j-279x.json | 38 ++++++++++++++ .../GHSA-4x7m-cpcp-9gfm.json | 10 ++-- .../GHSA-524r-w8fx-hqg3.json | 42 ++++++++++++++++ .../GHSA-5cqw-x4wx-53xw.json | 35 +++++++++++++ .../GHSA-5f9q-hg2v-3887.json | 46 +++++++++++++++++ .../GHSA-5p42-mr7p-8fjp.json | 42 ++++++++++++++++ .../GHSA-5qhm-fc96-683m.json | 35 +++++++++++++ .../GHSA-5v68-mvvf-48w9.json | 42 ++++++++++++++++ .../GHSA-5vq4-c62g-74hv.json | 42 ++++++++++++++++ .../GHSA-5vqx-g346-7f3c.json | 35 +++++++++++++ .../GHSA-638m-xxfq-rm3j.json | 9 ++-- .../GHSA-679c-fmwp-9p5j.json | 39 +++++++++++++++ .../GHSA-68p8-pp29-g967.json | 38 ++++++++++++++ .../GHSA-68xp-j24j-mvjp.json | 42 ++++++++++++++++ .../GHSA-6c2m-vp47-m6fq.json | 35 +++++++++++++ .../GHSA-6ccc-8wgj-7rf9.json | 35 +++++++++++++ .../GHSA-6g2w-257v-3c9f.json | 35 +++++++++++++ .../GHSA-6gwc-q32q-63j2.json | 35 +++++++++++++ .../GHSA-6m67-x55h-jgr8.json | 46 +++++++++++++++++ .../GHSA-6q57-hf8f-cfhp.json | 9 ++-- .../GHSA-6qq7-3hqc-p5w4.json | 50 +++++++++++++++++++ .../GHSA-6rh4-jr4q-29gx.json | 42 ++++++++++++++++ .../GHSA-6xfr-53hh-5q8h.json | 39 +++++++++++++++ .../GHSA-7278-8hvx-pp94.json | 7 ++- .../GHSA-74q4-qj6q-75qm.json | 42 ++++++++++++++++ .../GHSA-75qg-qmgw-fj6v.json | 42 ++++++++++++++++ .../GHSA-75qj-fcp3-j9w2.json | 4 ++ .../GHSA-75x2-mhj5-v895.json | 38 ++++++++++++++ .../GHSA-7f9h-g35v-jfqh.json | 4 ++ .../GHSA-7g9g-whvg-fhcj.json | 50 +++++++++++++++++++ .../GHSA-7x52-4x54-c7jw.json | 35 +++++++++++++ .../GHSA-87x2-pq76-h4qm.json | 38 ++++++++++++++ .../GHSA-8gf9-j4gp-qqf3.json | 46 +++++++++++++++++ .../GHSA-8w65-rp22-p462.json | 42 ++++++++++++++++ .../GHSA-93fm-f9mh-q37h.json | 35 +++++++++++++ .../GHSA-93qr-q6xr-pp2m.json | 42 ++++++++++++++++ .../GHSA-95jr-m2m4-mc9m.json | 46 +++++++++++++++++ .../GHSA-95vf-7jgr-4c75.json | 35 +++++++++++++ .../GHSA-9c8q-55w7-h67h.json | 50 +++++++++++++++++++ .../GHSA-9h59-37fx-qm9x.json | 38 ++++++++++++++ .../GHSA-9j85-mfj4-p8xm.json | 35 +++++++++++++ .../GHSA-9pcf-cp93-m9j2.json | 38 ++++++++++++++ .../GHSA-9x7r-76q2-9pj5.json | 38 ++++++++++++++ .../GHSA-c5gq-vxjx-fc85.json | 42 ++++++++++++++++ .../GHSA-cgrh-rp4g-xxp4.json | 38 ++++++++++++++ .../GHSA-cwmp-669c-fh3g.json | 35 +++++++++++++ .../GHSA-f26w-p752-7ggh.json | 42 ++++++++++++++++ .../GHSA-f58x-2j8x-cj9x.json | 35 +++++++++++++ .../GHSA-f5c3-v4p4-69h6.json | 35 +++++++++++++ .../GHSA-f6cm-fmx2-2v57.json | 38 ++++++++++++++ .../GHSA-fchg-567g-rpx3.json | 38 ++++++++++++++ .../GHSA-fcmj-gcwc-rvc5.json | 39 +++++++++++++++ .../GHSA-fg3g-frcw-5756.json | 2 +- .../GHSA-fgr5-j38j-744g.json | 38 ++++++++++++++ .../GHSA-fj6w-pj39-77x8.json | 35 +++++++++++++ .../GHSA-fm49-53h8-h7vg.json | 46 +++++++++++++++++ .../GHSA-fq7j-mj26-w42x.json | 46 +++++++++++++++++ .../GHSA-fwpj-frr9-2r36.json | 39 +++++++++++++++ .../GHSA-g5f9-q7v3-ff2h.json | 35 +++++++++++++ .../GHSA-g93m-hx8j-2qmq.json | 35 +++++++++++++ .../GHSA-g9xm-xhj6-2frv.json | 9 ++-- .../GHSA-gh5w-4mrm-4p4c.json | 42 ++++++++++++++++ .../GHSA-gjjc-pv92-5mx2.json | 39 +++++++++++++++ .../GHSA-gmpj-g3g5-h2rv.json | 42 ++++++++++++++++ .../GHSA-gpvv-vf7g-q8f6.json | 35 +++++++++++++ .../GHSA-grpp-v27v-jff6.json | 35 +++++++++++++ .../GHSA-gwr5-qqvh-c57m.json | 35 +++++++++++++ .../GHSA-h2j9-wrpc-7mm8.json | 42 ++++++++++++++++ .../GHSA-h9x4-5hxf-q5g6.json | 38 ++++++++++++++ .../GHSA-hgrq-rjwf-5f46.json | 9 ++-- .../GHSA-hhm4-xgvr-x3rg.json | 4 ++ .../GHSA-j24c-9hrq-7956.json | 35 +++++++++++++ .../GHSA-j5qp-ff5h-ffgc.json | 42 ++++++++++++++++ .../GHSA-j5v4-gjgv-j697.json | 42 ++++++++++++++++ .../GHSA-j6g7-53v4-8vmr.json | 42 ++++++++++++++++ .../GHSA-j8xr-8hjf-7jp2.json | 42 ++++++++++++++++ .../GHSA-j94g-69xw-xx5q.json | 39 +++++++++++++++ .../GHSA-jgmq-c4w3-2q95.json | 39 +++++++++++++++ .../GHSA-jjxm-6773-5xf7.json | 42 ++++++++++++++++ .../GHSA-jpg7-857p-mpqg.json | 4 ++ .../GHSA-jr95-pwfp-3r6q.json | 42 ++++++++++++++++ .../GHSA-jvc7-6hwc-2v88.json | 42 ++++++++++++++++ .../GHSA-jw79-3rh8-v6jv.json | 46 +++++++++++++++++ .../GHSA-m3mp-3m5h-pm9m.json | 46 +++++++++++++++++ .../GHSA-m8wc-q86f-6h3h.json | 38 ++++++++++++++ .../GHSA-m8xh-2cm5-qm87.json | 42 ++++++++++++++++ .../GHSA-m967-qhpw-m4rw.json | 35 +++++++++++++ .../GHSA-mf5c-mpv7-gxg8.json | 35 +++++++++++++ .../GHSA-mjmq-gwgm-5qhm.json | 38 ++++++++++++++ .../GHSA-mqw5-v4rf-8jvg.json | 35 +++++++++++++ .../GHSA-mvmr-rxwm-hjc9.json | 42 ++++++++++++++++ .../GHSA-mw2v-mwrw-64xm.json | 46 +++++++++++++++++ .../GHSA-p356-h5pr-gp95.json | 9 ++-- .../GHSA-p3v2-rv86-5c5f.json | 46 +++++++++++++++++ .../GHSA-p492-c975-6xjf.json | 35 +++++++++++++ .../GHSA-p7jq-h985-46gc.json | 46 +++++++++++++++++ .../GHSA-p7qc-vjp7-v8rx.json | 39 +++++++++++++++ .../GHSA-p83x-2782-8pc4.json | 42 ++++++++++++++++ .../GHSA-pr83-w226-5h5g.json | 35 +++++++++++++ .../GHSA-pvx5-h7p4-ffvx.json | 35 +++++++++++++ .../GHSA-q6g7-cf67-6822.json | 42 ++++++++++++++++ .../GHSA-q7hq-rw8g-9rh4.json | 9 ++-- .../GHSA-qw9f-547c-ppw4.json | 42 ++++++++++++++++ .../GHSA-r73w-7gww-pr94.json | 46 +++++++++++++++++ .../GHSA-rfv2-3vhx-4f5f.json | 42 ++++++++++++++++ .../GHSA-rv8p-344q-9xrj.json | 42 ++++++++++++++++ .../GHSA-rvfp-j42c-8vrc.json | 9 ++-- .../GHSA-v487-79cj-w3x8.json | 9 ++-- .../GHSA-v75c-m7vr-mvvg.json | 42 ++++++++++++++++ .../GHSA-v77x-qc2p-7878.json | 35 +++++++++++++ .../GHSA-v8fh-6gv5-c3px.json | 38 ++++++++++++++ .../GHSA-v9mp-h44v-2qrv.json | 50 +++++++++++++++++++ .../GHSA-vf3w-pp2v-hpgg.json | 35 +++++++++++++ .../GHSA-vjc2-xpc4-gph6.json | 38 ++++++++++++++ .../GHSA-vq7j-qx4g-8wh5.json | 46 +++++++++++++++++ .../GHSA-w2j3-rrx7-6wrf.json | 42 ++++++++++++++++ .../GHSA-w2m7-r572-689m.json | 38 ++++++++++++++ .../GHSA-w2pj-frh6-gjhp.json | 46 +++++++++++++++++ .../GHSA-w62c-jf7f-2m62.json | 38 ++++++++++++++ .../GHSA-wc7f-hjq2-jvv5.json | 2 +- .../GHSA-wf5c-q6vq-584r.json | 50 +++++++++++++++++++ .../GHSA-wjjh-7pqv-62xr.json | 38 ++++++++++++++ .../GHSA-x5q4-vvh5-cpgr.json | 9 ++-- .../GHSA-x682-h73h-4x67.json | 35 +++++++++++++ .../GHSA-x6p8-7f9j-2h7f.json | 9 ++-- .../GHSA-x97p-8gc6-fvc3.json | 38 ++++++++++++++ .../GHSA-xcmc-r5gr-ffh3.json | 38 ++++++++++++++ .../GHSA-xhx3-c8wc-wmrr.json | 38 ++++++++++++++ .../GHSA-xjj7-5xwp-h6p7.json | 42 ++++++++++++++++ .../GHSA-xjqq-3xrg-fh6j.json | 4 ++ .../GHSA-xmhp-p9h6-3cqm.json | 35 +++++++++++++ .../GHSA-xr8j-gg22-3pqg.json | 42 ++++++++++++++++ .../GHSA-xw92-6mmh-8cmv.json | 35 +++++++++++++ 164 files changed, 5308 insertions(+), 52 deletions(-) create mode 100644 advisories/unreviewed/2023/07/GHSA-29xr-xpp4-5783/GHSA-29xr-xpp4-5783.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2fmj-pq77-gvj7/GHSA-2fmj-pq77-gvj7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2h4j-hwr9-94jw/GHSA-2h4j-hwr9-94jw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2hf7-q8gj-r58v/GHSA-2hf7-q8gj-r58v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2wjj-p9fg-qxjq/GHSA-2wjj-p9fg-qxjq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-32v6-f8xf-f75q/GHSA-32v6-f8xf-f75q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3c6h-f6m9-jghc/GHSA-3c6h-f6m9-jghc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3w6v-h5wr-h9rh/GHSA-3w6v-h5wr-h9rh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-48fj-24fp-5q3v/GHSA-48fj-24fp-5q3v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4fq5-58j6-9qph/GHSA-4fq5-58j6-9qph.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4jrq-9cvx-fwjx/GHSA-4jrq-9cvx-fwjx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4mxm-g64v-4969/GHSA-4mxm-g64v-4969.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4wj9-c75j-279x/GHSA-4wj9-c75j-279x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-524r-w8fx-hqg3/GHSA-524r-w8fx-hqg3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5cqw-x4wx-53xw/GHSA-5cqw-x4wx-53xw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5f9q-hg2v-3887/GHSA-5f9q-hg2v-3887.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5qhm-fc96-683m/GHSA-5qhm-fc96-683m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5v68-mvvf-48w9/GHSA-5v68-mvvf-48w9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5vq4-c62g-74hv/GHSA-5vq4-c62g-74hv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5vqx-g346-7f3c/GHSA-5vqx-g346-7f3c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-679c-fmwp-9p5j/GHSA-679c-fmwp-9p5j.json create mode 100644 advisories/unreviewed/2023/07/GHSA-68p8-pp29-g967/GHSA-68p8-pp29-g967.json create mode 100644 advisories/unreviewed/2023/07/GHSA-68xp-j24j-mvjp/GHSA-68xp-j24j-mvjp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6c2m-vp47-m6fq/GHSA-6c2m-vp47-m6fq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6ccc-8wgj-7rf9/GHSA-6ccc-8wgj-7rf9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6g2w-257v-3c9f/GHSA-6g2w-257v-3c9f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6gwc-q32q-63j2/GHSA-6gwc-q32q-63j2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6m67-x55h-jgr8/GHSA-6m67-x55h-jgr8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6qq7-3hqc-p5w4/GHSA-6qq7-3hqc-p5w4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6rh4-jr4q-29gx/GHSA-6rh4-jr4q-29gx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6xfr-53hh-5q8h/GHSA-6xfr-53hh-5q8h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-75qg-qmgw-fj6v/GHSA-75qg-qmgw-fj6v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-75x2-mhj5-v895/GHSA-75x2-mhj5-v895.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7x52-4x54-c7jw/GHSA-7x52-4x54-c7jw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-87x2-pq76-h4qm/GHSA-87x2-pq76-h4qm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8w65-rp22-p462/GHSA-8w65-rp22-p462.json create mode 100644 advisories/unreviewed/2023/07/GHSA-93fm-f9mh-q37h/GHSA-93fm-f9mh-q37h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-93qr-q6xr-pp2m/GHSA-93qr-q6xr-pp2m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-95jr-m2m4-mc9m/GHSA-95jr-m2m4-mc9m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-95vf-7jgr-4c75/GHSA-95vf-7jgr-4c75.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9h59-37fx-qm9x/GHSA-9h59-37fx-qm9x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9j85-mfj4-p8xm/GHSA-9j85-mfj4-p8xm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9pcf-cp93-m9j2/GHSA-9pcf-cp93-m9j2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9x7r-76q2-9pj5/GHSA-9x7r-76q2-9pj5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-c5gq-vxjx-fc85/GHSA-c5gq-vxjx-fc85.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cgrh-rp4g-xxp4/GHSA-cgrh-rp4g-xxp4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-cwmp-669c-fh3g/GHSA-cwmp-669c-fh3g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f26w-p752-7ggh/GHSA-f26w-p752-7ggh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f58x-2j8x-cj9x/GHSA-f58x-2j8x-cj9x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f5c3-v4p4-69h6/GHSA-f5c3-v4p4-69h6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f6cm-fmx2-2v57/GHSA-f6cm-fmx2-2v57.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fchg-567g-rpx3/GHSA-fchg-567g-rpx3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fgr5-j38j-744g/GHSA-fgr5-j38j-744g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fj6w-pj39-77x8/GHSA-fj6w-pj39-77x8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fm49-53h8-h7vg/GHSA-fm49-53h8-h7vg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fq7j-mj26-w42x/GHSA-fq7j-mj26-w42x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fwpj-frr9-2r36/GHSA-fwpj-frr9-2r36.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g5f9-q7v3-ff2h/GHSA-g5f9-q7v3-ff2h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g93m-hx8j-2qmq/GHSA-g93m-hx8j-2qmq.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gh5w-4mrm-4p4c/GHSA-gh5w-4mrm-4p4c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gjjc-pv92-5mx2/GHSA-gjjc-pv92-5mx2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gmpj-g3g5-h2rv/GHSA-gmpj-g3g5-h2rv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gpvv-vf7g-q8f6/GHSA-gpvv-vf7g-q8f6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-grpp-v27v-jff6/GHSA-grpp-v27v-jff6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gwr5-qqvh-c57m/GHSA-gwr5-qqvh-c57m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h2j9-wrpc-7mm8/GHSA-h2j9-wrpc-7mm8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h9x4-5hxf-q5g6/GHSA-h9x4-5hxf-q5g6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j24c-9hrq-7956/GHSA-j24c-9hrq-7956.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j5qp-ff5h-ffgc/GHSA-j5qp-ff5h-ffgc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j5v4-gjgv-j697/GHSA-j5v4-gjgv-j697.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j6g7-53v4-8vmr/GHSA-j6g7-53v4-8vmr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j8xr-8hjf-7jp2/GHSA-j8xr-8hjf-7jp2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j94g-69xw-xx5q/GHSA-j94g-69xw-xx5q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jgmq-c4w3-2q95/GHSA-jgmq-c4w3-2q95.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jr95-pwfp-3r6q/GHSA-jr95-pwfp-3r6q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jvc7-6hwc-2v88/GHSA-jvc7-6hwc-2v88.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jw79-3rh8-v6jv/GHSA-jw79-3rh8-v6jv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m3mp-3m5h-pm9m/GHSA-m3mp-3m5h-pm9m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m8wc-q86f-6h3h/GHSA-m8wc-q86f-6h3h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m8xh-2cm5-qm87/GHSA-m8xh-2cm5-qm87.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m967-qhpw-m4rw/GHSA-m967-qhpw-m4rw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mf5c-mpv7-gxg8/GHSA-mf5c-mpv7-gxg8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mjmq-gwgm-5qhm/GHSA-mjmq-gwgm-5qhm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mqw5-v4rf-8jvg/GHSA-mqw5-v4rf-8jvg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mvmr-rxwm-hjc9/GHSA-mvmr-rxwm-hjc9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mw2v-mwrw-64xm/GHSA-mw2v-mwrw-64xm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p7jq-h985-46gc/GHSA-p7jq-h985-46gc.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p7qc-vjp7-v8rx/GHSA-p7qc-vjp7-v8rx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p83x-2782-8pc4/GHSA-p83x-2782-8pc4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pr83-w226-5h5g/GHSA-pr83-w226-5h5g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pvx5-h7p4-ffvx/GHSA-pvx5-h7p4-ffvx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q6g7-cf67-6822/GHSA-q6g7-cf67-6822.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qw9f-547c-ppw4/GHSA-qw9f-547c-ppw4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r73w-7gww-pr94/GHSA-r73w-7gww-pr94.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rfv2-3vhx-4f5f/GHSA-rfv2-3vhx-4f5f.json create mode 100644 advisories/unreviewed/2023/07/GHSA-rv8p-344q-9xrj/GHSA-rv8p-344q-9xrj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v75c-m7vr-mvvg/GHSA-v75c-m7vr-mvvg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v77x-qc2p-7878/GHSA-v77x-qc2p-7878.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v8fh-6gv5-c3px/GHSA-v8fh-6gv5-c3px.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v9mp-h44v-2qrv/GHSA-v9mp-h44v-2qrv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vf3w-pp2v-hpgg/GHSA-vf3w-pp2v-hpgg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vjc2-xpc4-gph6/GHSA-vjc2-xpc4-gph6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vq7j-qx4g-8wh5/GHSA-vq7j-qx4g-8wh5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w2j3-rrx7-6wrf/GHSA-w2j3-rrx7-6wrf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w2m7-r572-689m/GHSA-w2m7-r572-689m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w2pj-frh6-gjhp/GHSA-w2pj-frh6-gjhp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w62c-jf7f-2m62/GHSA-w62c-jf7f-2m62.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wjjh-7pqv-62xr/GHSA-wjjh-7pqv-62xr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x682-h73h-4x67/GHSA-x682-h73h-4x67.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x97p-8gc6-fvc3/GHSA-x97p-8gc6-fvc3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xcmc-r5gr-ffh3/GHSA-xcmc-r5gr-ffh3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xhx3-c8wc-wmrr/GHSA-xhx3-c8wc-wmrr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xjj7-5xwp-h6p7/GHSA-xjj7-5xwp-h6p7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xmhp-p9h6-3cqm/GHSA-xmhp-p9h6-3cqm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xr8j-gg22-3pqg/GHSA-xr8j-gg22-3pqg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xw92-6mmh-8cmv/GHSA-xw92-6mmh-8cmv.json diff --git a/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json b/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json index 28d47332a1f..1a80a1a0a96 100644 --- a/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json +++ b/advisories/unreviewed/2022/05/GHSA-px4v-wj8p-cq36/GHSA-px4v-wj8p-cq36.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-3g24-rv7h-5xh5/GHSA-3g24-rv7h-5xh5.json b/advisories/unreviewed/2022/10/GHSA-3g24-rv7h-5xh5/GHSA-3g24-rv7h-5xh5.json index 0eaf3e6d7df..9d6d8d1a33b 100644 --- a/advisories/unreviewed/2022/10/GHSA-3g24-rv7h-5xh5/GHSA-3g24-rv7h-5xh5.json +++ b/advisories/unreviewed/2022/10/GHSA-3g24-rv7h-5xh5/GHSA-3g24-rv7h-5xh5.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-601" + "CWE-601", + "CWE-74", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json b/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json index ad199b98d99..a7fe533cfcf 100644 --- a/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json +++ b/advisories/unreviewed/2022/11/GHSA-25xc-r4x7-g46h/GHSA-25xc-r4x7-g46h.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36179" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00009.html" + }, { "type": "WEB", "url": "https://yoroi.company/research/cve-advisory-full-disclosure-multiple-vulnerabilities/" diff --git a/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json b/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json index 7d27e3a1059..51c73d1fe96 100644 --- a/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json +++ b/advisories/unreviewed/2022/11/GHSA-f585-354r-gp9r/GHSA-f585-354r-gp9r.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36180" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00009.html" + }, { "type": "WEB", "url": "https://yoroi.company/research/cve-advisory-full-disclosure-multiple-vulnerabilities/" diff --git a/advisories/unreviewed/2022/12/GHSA-77p4-47r7-prgw/GHSA-77p4-47r7-prgw.json b/advisories/unreviewed/2022/12/GHSA-77p4-47r7-prgw/GHSA-77p4-47r7-prgw.json index 844f53863bc..0c7bb90f476 100644 --- a/advisories/unreviewed/2022/12/GHSA-77p4-47r7-prgw/GHSA-77p4-47r7-prgw.json +++ b/advisories/unreviewed/2022/12/GHSA-77p4-47r7-prgw/GHSA-77p4-47r7-prgw.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-f92h-c5mh-qv8v/GHSA-f92h-c5mh-qv8v.json b/advisories/unreviewed/2022/12/GHSA-f92h-c5mh-qv8v/GHSA-f92h-c5mh-qv8v.json index bee6b13d446..48292d0a793 100644 --- a/advisories/unreviewed/2022/12/GHSA-f92h-c5mh-qv8v/GHSA-f92h-c5mh-qv8v.json +++ b/advisories/unreviewed/2022/12/GHSA-f92h-c5mh-qv8v/GHSA-f92h-c5mh-qv8v.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-q7rw-9gg7-5wfw/GHSA-q7rw-9gg7-5wfw.json b/advisories/unreviewed/2022/12/GHSA-q7rw-9gg7-5wfw/GHSA-q7rw-9gg7-5wfw.json index 74d26c2bef7..956ad995b65 100644 --- a/advisories/unreviewed/2022/12/GHSA-q7rw-9gg7-5wfw/GHSA-q7rw-9gg7-5wfw.json +++ b/advisories/unreviewed/2022/12/GHSA-q7rw-9gg7-5wfw/GHSA-q7rw-9gg7-5wfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7rw-9gg7-5wfw", - "modified": "2022-12-14T00:30:23Z", + "modified": "2023-07-10T18:30:41Z", "published": "2022-12-14T00:30:23Z", "aliases": [ "CVE-2022-41653" ], "details": "Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-3886-rc87-ccgx/GHSA-3886-rc87-ccgx.json b/advisories/unreviewed/2023/01/GHSA-3886-rc87-ccgx/GHSA-3886-rc87-ccgx.json index b9c075115ec..0dc2b2ea44e 100644 --- a/advisories/unreviewed/2023/01/GHSA-3886-rc87-ccgx/GHSA-3886-rc87-ccgx.json +++ b/advisories/unreviewed/2023/01/GHSA-3886-rc87-ccgx/GHSA-3886-rc87-ccgx.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/01/GHSA-3jr6-jfqc-mjcf/GHSA-3jr6-jfqc-mjcf.json b/advisories/unreviewed/2023/01/GHSA-3jr6-jfqc-mjcf/GHSA-3jr6-jfqc-mjcf.json index 47c05542f74..01d24db5797 100644 --- a/advisories/unreviewed/2023/01/GHSA-3jr6-jfqc-mjcf/GHSA-3jr6-jfqc-mjcf.json +++ b/advisories/unreviewed/2023/01/GHSA-3jr6-jfqc-mjcf/GHSA-3jr6-jfqc-mjcf.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-822" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json b/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json index cc25b947637..83a31b6446b 100644 --- a/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json +++ b/advisories/unreviewed/2023/02/GHSA-w4h2-22wh-m6jx/GHSA-w4h2-22wh-m6jx.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/03/GHSA-m82q-v8rc-95v6/GHSA-m82q-v8rc-95v6.json b/advisories/unreviewed/2023/03/GHSA-m82q-v8rc-95v6/GHSA-m82q-v8rc-95v6.json index 28f6b2deb9f..06029ed5ce8 100644 --- a/advisories/unreviewed/2023/03/GHSA-m82q-v8rc-95v6/GHSA-m82q-v8rc-95v6.json +++ b/advisories/unreviewed/2023/03/GHSA-m82q-v8rc-95v6/GHSA-m82q-v8rc-95v6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1393", + "CWE-287" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-5v8j-jfmm-6x86/GHSA-5v8j-jfmm-6x86.json b/advisories/unreviewed/2023/04/GHSA-5v8j-jfmm-6x86/GHSA-5v8j-jfmm-6x86.json index 42525e56752..e16e652ffd9 100644 --- a/advisories/unreviewed/2023/04/GHSA-5v8j-jfmm-6x86/GHSA-5v8j-jfmm-6x86.json +++ b/advisories/unreviewed/2023/04/GHSA-5v8j-jfmm-6x86/GHSA-5v8j-jfmm-6x86.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BM6UW55CNFUTNGD5ZRKGUKKKFDJGMFHL/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LEGCEOKFJVBJ2QQ6S2H4NAEWTUERC7SB/" + }, { "type": "WEB", "url": "https://metacpan.org/dist/CPAN/changes" diff --git a/advisories/unreviewed/2023/06/GHSA-8937-gcf5-34xq/GHSA-8937-gcf5-34xq.json b/advisories/unreviewed/2023/06/GHSA-8937-gcf5-34xq/GHSA-8937-gcf5-34xq.json index 68cf80d028d..6de1e4df69e 100644 --- a/advisories/unreviewed/2023/06/GHSA-8937-gcf5-34xq/GHSA-8937-gcf5-34xq.json +++ b/advisories/unreviewed/2023/06/GHSA-8937-gcf5-34xq/GHSA-8937-gcf5-34xq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-789" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json b/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json index ea88de15f3b..cadfea8098e 100644 --- a/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json +++ b/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcw9-xw4x-jgj3", - "modified": "2023-06-23T21:30:33Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-06-23T21:30:33Z", "aliases": [ "CVE-2023-34188" ], "details": "The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-w92h-gfcv-m7wv/GHSA-w92h-gfcv-m7wv.json b/advisories/unreviewed/2023/06/GHSA-w92h-gfcv-m7wv/GHSA-w92h-gfcv-m7wv.json index 5b5577ec17e..33c9c6365a4 100644 --- a/advisories/unreviewed/2023/06/GHSA-w92h-gfcv-m7wv/GHSA-w92h-gfcv-m7wv.json +++ b/advisories/unreviewed/2023/06/GHSA-w92h-gfcv-m7wv/GHSA-w92h-gfcv-m7wv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w92h-gfcv-m7wv", - "modified": "2023-06-28T21:30:29Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2023-33570" ], "details": "Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-29xr-xpp4-5783/GHSA-29xr-xpp4-5783.json b/advisories/unreviewed/2023/07/GHSA-29xr-xpp4-5783/GHSA-29xr-xpp4-5783.json new file mode 100644 index 00000000000..6feb264b174 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-29xr-xpp4-5783/GHSA-29xr-xpp4-5783.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29xr-xpp4-5783", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3273" + ], + "details": "\nImproper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP\naddress based on missing access control.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3273" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2fmj-pq77-gvj7/GHSA-2fmj-pq77-gvj7.json b/advisories/unreviewed/2023/07/GHSA-2fmj-pq77-gvj7/GHSA-2fmj-pq77-gvj7.json new file mode 100644 index 00000000000..74454f3f8e6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2fmj-pq77-gvj7/GHSA-2fmj-pq77-gvj7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fmj-pq77-gvj7", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2023-1119" + ], + "details": "The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1119" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2e78735a-a7fc-41fe-8284-45bf451eff06" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2h4j-hwr9-94jw/GHSA-2h4j-hwr9-94jw.json b/advisories/unreviewed/2023/07/GHSA-2h4j-hwr9-94jw/GHSA-2h4j-hwr9-94jw.json new file mode 100644 index 00000000000..40bbf5422c5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2h4j-hwr9-94jw/GHSA-2h4j-hwr9-94jw.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h4j-hwr9-94jw", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3270" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3270" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2hf7-q8gj-r58v/GHSA-2hf7-q8gj-r58v.json b/advisories/unreviewed/2023/07/GHSA-2hf7-q8gj-r58v/GHSA-2hf7-q8gj-r58v.json new file mode 100644 index 00000000000..e0cfb6c21c0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2hf7-q8gj-r58v/GHSA-2hf7-q8gj-r58v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hf7-q8gj-r58v", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37706" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37706" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6903" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2wjj-p9fg-qxjq/GHSA-2wjj-p9fg-qxjq.json b/advisories/unreviewed/2023/07/GHSA-2wjj-p9fg-qxjq/GHSA-2wjj-p9fg-qxjq.json new file mode 100644 index 00000000000..f32f2f13536 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2wjj-p9fg-qxjq/GHSA-2wjj-p9fg-qxjq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wjj-p9fg-qxjq", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37707" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37707" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6904" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json b/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json new file mode 100644 index 00000000000..c62d11fcc0c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2xf9-j9jw-g7f7/GHSA-2xf9-j9jw-g7f7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xf9-j9jw-g7f7", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2021-4406" + ], + "details": "An administrator is able to execute commands as root via the alerts management dialog", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4406" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2021-4406" + }, + { + "type": "WEB", + "url": "https://www.divd.nl/DIVD-2021-00020" + }, + { + "type": "WEB", + "url": "https://www.osnexus.com/products/software-defined-storage" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-32v6-f8xf-f75q/GHSA-32v6-f8xf-f75q.json b/advisories/unreviewed/2023/07/GHSA-32v6-f8xf-f75q/GHSA-32v6-f8xf-f75q.json new file mode 100644 index 00000000000..49793a767f1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-32v6-f8xf-f75q/GHSA-32v6-f8xf-f75q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32v6-f8xf-f75q", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2023-1597" + ], + "details": "The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1597" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4eafe111-8874-4560-83ff-394abe7a803b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-36wf-hpjh-x3fr/GHSA-36wf-hpjh-x3fr.json b/advisories/unreviewed/2023/07/GHSA-36wf-hpjh-x3fr/GHSA-36wf-hpjh-x3fr.json index d5991e83c2d..d65f2ac0a33 100644 --- a/advisories/unreviewed/2023/07/GHSA-36wf-hpjh-x3fr/GHSA-36wf-hpjh-x3fr.json +++ b/advisories/unreviewed/2023/07/GHSA-36wf-hpjh-x3fr/GHSA-36wf-hpjh-x3fr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-36wf-hpjh-x3fr", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-1206" ], "details": "A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-3c6h-f6m9-jghc/GHSA-3c6h-f6m9-jghc.json b/advisories/unreviewed/2023/07/GHSA-3c6h-f6m9-jghc/GHSA-3c6h-f6m9-jghc.json new file mode 100644 index 00000000000..c829c31aea6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3c6h-f6m9-jghc/GHSA-3c6h-f6m9-jghc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c6h-f6m9-jghc", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3175" + ], + "details": "The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3175" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7643980b-eaa2-45d1-bd9d-9afae0943f43" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3w6v-h5wr-h9rh/GHSA-3w6v-h5wr-h9rh.json b/advisories/unreviewed/2023/07/GHSA-3w6v-h5wr-h9rh/GHSA-3w6v-h5wr-h9rh.json new file mode 100644 index 00000000000..ea84c64956c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3w6v-h5wr-h9rh/GHSA-3w6v-h5wr-h9rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w6v-h5wr-h9rh", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-22694" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22694" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bigcontact/wordpress-bigcontact-contact-page-plugin-1-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json b/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json new file mode 100644 index 00000000000..f529555adf0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3x7w-vvg2-w6r8/GHSA-3x7w-vvg2-w6r8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x7w-vvg2-w6r8", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2021-42082" + ], + "details": "Local users are able to execute scripts under root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42082" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2021-42082" + }, + { + "type": "WEB", + "url": "https://www.divd.nl/DIVD-2021-00020" + }, + { + "type": "WEB", + "url": "https://www.osnexus.com/products/software-defined-storage" + }, + { + "type": "WEB", + "url": "https://www.wbsec.nl/osnexus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-48fj-24fp-5q3v/GHSA-48fj-24fp-5q3v.json b/advisories/unreviewed/2023/07/GHSA-48fj-24fp-5q3v/GHSA-48fj-24fp-5q3v.json new file mode 100644 index 00000000000..576f261eab2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-48fj-24fp-5q3v/GHSA-48fj-24fp-5q3v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48fj-24fp-5q3v", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-23993" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23993" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ip-address-blocker/wordpress-lionscripts-ip-blocker-lite-plugin-11-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4fq5-58j6-9qph/GHSA-4fq5-58j6-9qph.json b/advisories/unreviewed/2023/07/GHSA-4fq5-58j6-9qph/GHSA-4fq5-58j6-9qph.json new file mode 100644 index 00000000000..a8b00b4edf2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4fq5-58j6-9qph/GHSA-4fq5-58j6-9qph.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fq5-58j6-9qph", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-35698" + ], + "details": "\nObservable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login\nattempt.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35698" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4jrq-9cvx-fwjx/GHSA-4jrq-9cvx-fwjx.json b/advisories/unreviewed/2023/07/GHSA-4jrq-9cvx-fwjx/GHSA-4jrq-9cvx-fwjx.json new file mode 100644 index 00000000000..c28442b4011 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4jrq-9cvx-fwjx/GHSA-4jrq-9cvx-fwjx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jrq-9cvx-fwjx", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-32627" + ], + "details": "A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32627" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-32627" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2212282" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4mxm-g64v-4969/GHSA-4mxm-g64v-4969.json b/advisories/unreviewed/2023/07/GHSA-4mxm-g64v-4969/GHSA-4mxm-g64v-4969.json new file mode 100644 index 00000000000..2735cd7492a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4mxm-g64v-4969/GHSA-4mxm-g64v-4969.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mxm-g64v-4969", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2529" + ], + "details": "The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2529" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4ac03907-2373-48f0-bca1-8f7073c06b18" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json b/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json new file mode 100644 index 00000000000..df7a5ce0e85 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4v64-w7v7-ch7f/GHSA-4v64-w7v7-ch7f.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v64-w7v7-ch7f", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2021-42079" + ], + "details": "An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42079" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2021-42079" + }, + { + "type": "WEB", + "url": "https://www.divd.nl/DIVD-2021-00020" + }, + { + "type": "WEB", + "url": "https://www.osnexus.com/products/software-defined-storage" + }, + { + "type": "WEB", + "url": "https://www.wbsec.nl/osnexus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4wj9-c75j-279x/GHSA-4wj9-c75j-279x.json b/advisories/unreviewed/2023/07/GHSA-4wj9-c75j-279x/GHSA-4wj9-c75j-279x.json new file mode 100644 index 00000000000..bbc02c8db9d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4wj9-c75j-279x/GHSA-4wj9-c75j-279x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wj9-c75j-279x", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-35912" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin <= 1.1.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/donations-for-woocommerce/wordpress-potent-donations-for-woocommerce-plugin-1-1-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json b/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json index 87bf18dfcc0..034d3bb5467 100644 --- a/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json +++ b/advisories/unreviewed/2023/07/GHSA-4x7m-cpcp-9gfm/GHSA-4x7m-cpcp-9gfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4x7m-cpcp-9gfm", - "modified": "2023-07-06T19:24:03Z", + "modified": "2023-07-10T18:30:41Z", "published": "2023-07-06T19:24:03Z", "aliases": [ "CVE-2022-41627" ], "details": "The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphone’s ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-311", + "CWE-319" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-524r-w8fx-hqg3/GHSA-524r-w8fx-hqg3.json b/advisories/unreviewed/2023/07/GHSA-524r-w8fx-hqg3/GHSA-524r-w8fx-hqg3.json new file mode 100644 index 00000000000..48dd230bdeb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-524r-w8fx-hqg3/GHSA-524r-w8fx-hqg3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-524r-w8fx-hqg3", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3565" + ], + "details": "Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3565" + }, + { + "type": "WEB", + "url": "https://github.com/nilsteampassnet/teampass/commit/820bb49a362a566c9038e4a3048b26d654babb0e" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/fcf46e1f-2ab6-4057-9d25-cf493ab09530" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5cqw-x4wx-53xw/GHSA-5cqw-x4wx-53xw.json b/advisories/unreviewed/2023/07/GHSA-5cqw-x4wx-53xw/GHSA-5cqw-x4wx-53xw.json new file mode 100644 index 00000000000..0c2b9f3294b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5cqw-x4wx-53xw/GHSA-5cqw-x4wx-53xw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cqw-x4wx-53xw", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3225" + ], + "details": "The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3225" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3c76d0f4-2ea8-433d-afb2-e35e45630899" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5f9q-hg2v-3887/GHSA-5f9q-hg2v-3887.json b/advisories/unreviewed/2023/07/GHSA-5f9q-hg2v-3887/GHSA-5f9q-hg2v-3887.json new file mode 100644 index 00000000000..37877b7852c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5f9q-hg2v-3887/GHSA-5f9q-hg2v-3887.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f9q-hg2v-3887", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2023-1183" + ], + "details": "A flaw was found in the Libreoffice package. An attacker can craft an odb containing a \"database/script\" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1183" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-1183" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2208506" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json b/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json new file mode 100644 index 00000000000..c386195a158 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5p42-mr7p-8fjp/GHSA-5p42-mr7p-8fjp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p42-mr7p-8fjp", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-30448" + ], + "details": "\nIBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30448" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/253437" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5qhm-fc96-683m/GHSA-5qhm-fc96-683m.json b/advisories/unreviewed/2023/07/GHSA-5qhm-fc96-683m/GHSA-5qhm-fc96-683m.json new file mode 100644 index 00000000000..e27d676c3db --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5qhm-fc96-683m/GHSA-5qhm-fc96-683m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qhm-fc96-683m", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37712" + ], + "details": "Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37712" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/fromSetIpBind" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5v68-mvvf-48w9/GHSA-5v68-mvvf-48w9.json b/advisories/unreviewed/2023/07/GHSA-5v68-mvvf-48w9/GHSA-5v68-mvvf-48w9.json new file mode 100644 index 00000000000..4cb78ab8944 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5v68-mvvf-48w9/GHSA-5v68-mvvf-48w9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v68-mvvf-48w9", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3557" + ], + "details": "A vulnerability was found in GZ Scripts Property Listing Script 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /preview.php. The manipulation of the argument page/layout/sort_by leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233351. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3557" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233351" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233351" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5vq4-c62g-74hv/GHSA-5vq4-c62g-74hv.json b/advisories/unreviewed/2023/07/GHSA-5vq4-c62g-74hv/GHSA-5vq4-c62g-74hv.json new file mode 100644 index 00000000000..8db7dd666f7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5vq4-c62g-74hv/GHSA-5vq4-c62g-74hv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vq4-c62g-74hv", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-28955" + ], + "details": "IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28955" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/251704" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7009747" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5vqx-g346-7f3c/GHSA-5vqx-g346-7f3c.json b/advisories/unreviewed/2023/07/GHSA-5vqx-g346-7f3c/GHSA-5vqx-g346-7f3c.json new file mode 100644 index 00000000000..902be73882a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5vqx-g346-7f3c/GHSA-5vqx-g346-7f3c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vqx-g346-7f3c", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37701" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37701" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6908" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json b/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json index 6bdfd560623..14df135da96 100644 --- a/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json +++ b/advisories/unreviewed/2023/07/GHSA-638m-xxfq-rm3j/GHSA-638m-xxfq-rm3j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-638m-xxfq-rm3j", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-28323" ], "details": "A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to other network attached machines.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-679c-fmwp-9p5j/GHSA-679c-fmwp-9p5j.json b/advisories/unreviewed/2023/07/GHSA-679c-fmwp-9p5j/GHSA-679c-fmwp-9p5j.json new file mode 100644 index 00000000000..3666f581e85 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-679c-fmwp-9p5j/GHSA-679c-fmwp-9p5j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-679c-fmwp-9p5j", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-36376" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36376" + }, + { + "type": "WEB", + "url": "https://medium.com/@ridheshgohil1092/cve-2023-36376-xss-on-hostel-management-system-c6891993527" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-68p8-pp29-g967/GHSA-68p8-pp29-g967.json b/advisories/unreviewed/2023/07/GHSA-68p8-pp29-g967/GHSA-68p8-pp29-g967.json new file mode 100644 index 00000000000..fe3b1deb1d0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-68p8-pp29-g967/GHSA-68p8-pp29-g967.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68p8-pp29-g967", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2853" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron allows Reflected XSS.This issue affects SelfPatron : before 2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2853" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-68xp-j24j-mvjp/GHSA-68xp-j24j-mvjp.json b/advisories/unreviewed/2023/07/GHSA-68xp-j24j-mvjp/GHSA-68xp-j24j-mvjp.json new file mode 100644 index 00000000000..39167e17b16 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-68xp-j24j-mvjp/GHSA-68xp-j24j-mvjp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68xp-j24j-mvjp", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-26590" + ], + "details": "A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26590" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-26590" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2212279" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6c2m-vp47-m6fq/GHSA-6c2m-vp47-m6fq.json b/advisories/unreviewed/2023/07/GHSA-6c2m-vp47-m6fq/GHSA-6c2m-vp47-m6fq.json new file mode 100644 index 00000000000..44882e4456a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6c2m-vp47-m6fq/GHSA-6c2m-vp47-m6fq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c2m-vp47-m6fq", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37710" + ], + "details": "Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37710" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/fromSetWirelessRepeat" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6ccc-8wgj-7rf9/GHSA-6ccc-8wgj-7rf9.json b/advisories/unreviewed/2023/07/GHSA-6ccc-8wgj-7rf9/GHSA-6ccc-8wgj-7rf9.json new file mode 100644 index 00000000000..7a350af6a2b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6ccc-8wgj-7rf9/GHSA-6ccc-8wgj-7rf9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ccc-8wgj-7rf9", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3219" + ], + "details": "The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3219" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/72d80887-0270-4987-9739-95b1a178c1fd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6g2w-257v-3c9f/GHSA-6g2w-257v-3c9f.json b/advisories/unreviewed/2023/07/GHSA-6g2w-257v-3c9f/GHSA-6g2w-257v-3c9f.json new file mode 100644 index 00000000000..bff1b448533 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6g2w-257v-3c9f/GHSA-6g2w-257v-3c9f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g2w-257v-3c9f", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-34442" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3.\n\nUsers should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34442" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/x4vy2hhbltb1xrvy1g6m8hpjgj2k7wgh" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6gwc-q32q-63j2/GHSA-6gwc-q32q-63j2.json b/advisories/unreviewed/2023/07/GHSA-6gwc-q32q-63j2/GHSA-6gwc-q32q-63j2.json new file mode 100644 index 00000000000..c8ad459a3a0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6gwc-q32q-63j2/GHSA-6gwc-q32q-63j2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gwc-q32q-63j2", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3209" + ], + "details": "The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3209" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/970735f1-24bb-441c-89b6-5a0959246d6c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6m67-x55h-jgr8/GHSA-6m67-x55h-jgr8.json b/advisories/unreviewed/2023/07/GHSA-6m67-x55h-jgr8/GHSA-6m67-x55h-jgr8.json new file mode 100644 index 00000000000..a1ad084e50f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6m67-x55h-jgr8/GHSA-6m67-x55h-jgr8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m67-x55h-jgr8", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-3578" + ], + "details": "A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3578" + }, + { + "type": "WEB", + "url": "https://github.com/nightcloudos/cve/blob/main/SSRF.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233371" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6q57-hf8f-cfhp/GHSA-6q57-hf8f-cfhp.json b/advisories/unreviewed/2023/07/GHSA-6q57-hf8f-cfhp/GHSA-6q57-hf8f-cfhp.json index b5a654ad3ec..d8542c4699a 100644 --- a/advisories/unreviewed/2023/07/GHSA-6q57-hf8f-cfhp/GHSA-6q57-hf8f-cfhp.json +++ b/advisories/unreviewed/2023/07/GHSA-6q57-hf8f-cfhp/GHSA-6q57-hf8f-cfhp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6q57-hf8f-cfhp", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-28365" ], "details": "A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-6qq7-3hqc-p5w4/GHSA-6qq7-3hqc-p5w4.json b/advisories/unreviewed/2023/07/GHSA-6qq7-3hqc-p5w4/GHSA-6qq7-3hqc-p5w4.json new file mode 100644 index 00000000000..3c1528013c2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6qq7-3hqc-p5w4/GHSA-6qq7-3hqc-p5w4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qq7-3hqc-p5w4", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3566" + ], + "details": "A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233359. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3566" + }, + { + "type": "WEB", + "url": "https://github.com/ctflearner/Vulnerability/blob/main/WALLABAG/NAME-LIMIT.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233359" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233359" + }, + { + "type": "WEB", + "url": "https://youtu.be/ouwud0PlHkE" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6rh4-jr4q-29gx/GHSA-6rh4-jr4q-29gx.json b/advisories/unreviewed/2023/07/GHSA-6rh4-jr4q-29gx/GHSA-6rh4-jr4q-29gx.json new file mode 100644 index 00000000000..3a8edd7f6e0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6rh4-jr4q-29gx/GHSA-6rh4-jr4q-29gx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rh4-jr4q-29gx", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-27867" + ], + "details": "IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27867" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/249514" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6xfr-53hh-5q8h/GHSA-6xfr-53hh-5q8h.json b/advisories/unreviewed/2023/07/GHSA-6xfr-53hh-5q8h/GHSA-6xfr-53hh-5q8h.json new file mode 100644 index 00000000000..595541ae6a9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6xfr-53hh-5q8h/GHSA-6xfr-53hh-5q8h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xfr-53hh-5q8h", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-37151" + ], + "details": "Sourcecodester Online Pizza Ordering System v1.0 allows the upload of malicious PHP files resulting in Remote Code Execution (RCE).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37151" + }, + { + "type": "WEB", + "url": "https://github.com/Trinity-SYT-SECURITY/arbitrary-file-upload-RCE/blob/main/Online%20Pizza%20Ordering%20System%201.0.md" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/51431" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7278-8hvx-pp94/GHSA-7278-8hvx-pp94.json b/advisories/unreviewed/2023/07/GHSA-7278-8hvx-pp94/GHSA-7278-8hvx-pp94.json index 6ffe52e8266..37907b5a0de 100644 --- a/advisories/unreviewed/2023/07/GHSA-7278-8hvx-pp94/GHSA-7278-8hvx-pp94.json +++ b/advisories/unreviewed/2023/07/GHSA-7278-8hvx-pp94/GHSA-7278-8hvx-pp94.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7278-8hvx-pp94", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-2908" ], "details": "A null pointer dereference issue was discovered in Libtiff's tif_dir.c file. This flaw allows an attacker to pass a crafted TIFF image file to the tiffcp utility, which triggers runtime error, causing an undefined behavior, resulting in an application crash, eventually leading to a denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json b/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json new file mode 100644 index 00000000000..06f81f93117 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-74q4-qj6q-75qm/GHSA-74q4-qj6q-75qm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74q4-qj6q-75qm", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-30445" + ], + "details": "\nIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30445" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/253357" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-75qg-qmgw-fj6v/GHSA-75qg-qmgw-fj6v.json b/advisories/unreviewed/2023/07/GHSA-75qg-qmgw-fj6v/GHSA-75qg-qmgw-fj6v.json new file mode 100644 index 00000000000..10ee5c0615e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-75qg-qmgw-fj6v/GHSA-75qg-qmgw-fj6v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75qg-qmgw-fj6v", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-28958" + ], + "details": "IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28958" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/251782" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7009747" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1236" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json b/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json index c29799b51e1..90a7c84067a 100644 --- a/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json +++ b/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5450" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5451" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-22/" diff --git a/advisories/unreviewed/2023/07/GHSA-75x2-mhj5-v895/GHSA-75x2-mhj5-v895.json b/advisories/unreviewed/2023/07/GHSA-75x2-mhj5-v895/GHSA-75x2-mhj5-v895.json new file mode 100644 index 00000000000..6ceac682663 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-75x2-mhj5-v895/GHSA-75x2-mhj5-v895.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75x2-mhj5-v895", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-22695" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22695" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-field-template/wordpress-custom-field-template-plugin-2-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7f9h-g35v-jfqh/GHSA-7f9h-g35v-jfqh.json b/advisories/unreviewed/2023/07/GHSA-7f9h-g35v-jfqh/GHSA-7f9h-g35v-jfqh.json index 6e1ae7d85df..545623de3de 100644 --- a/advisories/unreviewed/2023/07/GHSA-7f9h-g35v-jfqh/GHSA-7f9h-g35v-jfqh.json +++ b/advisories/unreviewed/2023/07/GHSA-7f9h-g35v-jfqh/GHSA-7f9h-g35v-jfqh.json @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5450" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5451" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-22/" diff --git a/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json b/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json new file mode 100644 index 00000000000..996933bc02f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7g9g-whvg-fhcj/GHSA-7g9g-whvg-fhcj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g9g-whvg-fhcj", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2021-42081" + ], + "details": "An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42081" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2021-42081" + }, + { + "type": "WEB", + "url": "https://www.divd.nl/DIVD-2021-00020" + }, + { + "type": "WEB", + "url": "https://www.osnexus.com/products/software-defined-storage" + }, + { + "type": "WEB", + "url": "https://www.wbsec.nl/osnexus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7x52-4x54-c7jw/GHSA-7x52-4x54-c7jw.json b/advisories/unreviewed/2023/07/GHSA-7x52-4x54-c7jw/GHSA-7x52-4x54-c7jw.json new file mode 100644 index 00000000000..ebdfdf88638 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7x52-4x54-c7jw/GHSA-7x52-4x54-c7jw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x52-4x54-c7jw", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3131" + ], + "details": "The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3131" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/970735f1-24bb-441c-89b6-5a0959246d6c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-87x2-pq76-h4qm/GHSA-87x2-pq76-h4qm.json b/advisories/unreviewed/2023/07/GHSA-87x2-pq76-h4qm/GHSA-87x2-pq76-h4qm.json new file mode 100644 index 00000000000..3dd1d4be2fb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-87x2-pq76-h4qm/GHSA-87x2-pq76-h4qm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87x2-pq76-h4qm", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-24405" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24405" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-7-paypal-add-on/wordpress-contact-form-7-paypal-stripe-add-on-plugin-1-9-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json b/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json new file mode 100644 index 00000000000..9fac812926e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8gf9-j4gp-qqf3/GHSA-8gf9-j4gp-qqf3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gf9-j4gp-qqf3", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-32250" + ], + "details": "A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32250" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-32250" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2208849" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-698/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8w65-rp22-p462/GHSA-8w65-rp22-p462.json b/advisories/unreviewed/2023/07/GHSA-8w65-rp22-p462/GHSA-8w65-rp22-p462.json new file mode 100644 index 00000000000..e596c1fd515 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8w65-rp22-p462/GHSA-8w65-rp22-p462.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w65-rp22-p462", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3555" + ], + "details": "A vulnerability was found in GZ Scripts PHP Vacation Rental Script 1.8. It has been classified as problematic. This affects an unknown part of the file /preview.php. The manipulation of the argument page/layout/sort_by/property_id leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233349 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3555" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233349" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-93fm-f9mh-q37h/GHSA-93fm-f9mh-q37h.json b/advisories/unreviewed/2023/07/GHSA-93fm-f9mh-q37h/GHSA-93fm-f9mh-q37h.json new file mode 100644 index 00000000000..8950aa3f45c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-93fm-f9mh-q37h/GHSA-93fm-f9mh-q37h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93fm-f9mh-q37h", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37705" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37705" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6902" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-93qr-q6xr-pp2m/GHSA-93qr-q6xr-pp2m.json b/advisories/unreviewed/2023/07/GHSA-93qr-q6xr-pp2m/GHSA-93qr-q6xr-pp2m.json new file mode 100644 index 00000000000..1db97c5a27e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-93qr-q6xr-pp2m/GHSA-93qr-q6xr-pp2m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93qr-q6xr-pp2m", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-30442" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a denial of service as the server may crash when using a specially crafted wrapper using certain options. IBM X-Force ID: 253202.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30442" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/253202" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010561" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-95jr-m2m4-mc9m/GHSA-95jr-m2m4-mc9m.json b/advisories/unreviewed/2023/07/GHSA-95jr-m2m4-mc9m/GHSA-95jr-m2m4-mc9m.json new file mode 100644 index 00000000000..85dd2d7ae4f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-95jr-m2m4-mc9m/GHSA-95jr-m2m4-mc9m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95jr-m2m4-mc9m", + "modified": "2023-07-10T18:30:46Z", + "published": "2023-07-10T18:30:46Z", + "aliases": [ + "CVE-2015-10120" + ], + "details": "A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPress. Affected is the function update_options of the file includes/WDS_Multisite_Aggregate_Options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is 49e0bbcb6ff70e561365d9e0d26426598f63ca12. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-233364.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-10120" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/wds-multisite-aggregate/commit/49e0bbcb6ff70e561365d9e0d26426598f63ca12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233364" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-95vf-7jgr-4c75/GHSA-95vf-7jgr-4c75.json b/advisories/unreviewed/2023/07/GHSA-95vf-7jgr-4c75/GHSA-95vf-7jgr-4c75.json new file mode 100644 index 00000000000..eb2512d2f68 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-95vf-7jgr-4c75/GHSA-95vf-7jgr-4c75.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95vf-7jgr-4c75", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3077" + ], + "details": "The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3077" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9480d0b5-97da-467d-98f6-71a32599a432" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json b/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json new file mode 100644 index 00000000000..d1083ebe83f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c8q-55w7-h67h", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2021-42083" + ], + "details": "An authenticated attacker is able to create alerts that trigger a stored XSS attack. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42083" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2021-42083" + }, + { + "type": "WEB", + "url": "https://www.divd.nl/DIVD-2021-00020" + }, + { + "type": "WEB", + "url": "https://www.osnexus.com/products/software-defined-storage" + }, + { + "type": "WEB", + "url": "https://www.wbsec.nl/osnexus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9h59-37fx-qm9x/GHSA-9h59-37fx-qm9x.json b/advisories/unreviewed/2023/07/GHSA-9h59-37fx-qm9x/GHSA-9h59-37fx-qm9x.json new file mode 100644 index 00000000000..ef02d9ef48e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9h59-37fx-qm9x/GHSA-9h59-37fx-qm9x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h59-37fx-qm9x", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-23897" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23897" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-mobile-url-redirect/wordpress-simple-mobile-url-redirect-plugin-1-7-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9j85-mfj4-p8xm/GHSA-9j85-mfj4-p8xm.json b/advisories/unreviewed/2023/07/GHSA-9j85-mfj4-p8xm/GHSA-9j85-mfj4-p8xm.json new file mode 100644 index 00000000000..5422a6cb28a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9j85-mfj4-p8xm/GHSA-9j85-mfj4-p8xm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j85-mfj4-p8xm", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37711" + ], + "details": "Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37711" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/saveParentControlInfo" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9pcf-cp93-m9j2/GHSA-9pcf-cp93-m9j2.json b/advisories/unreviewed/2023/07/GHSA-9pcf-cp93-m9j2/GHSA-9pcf-cp93-m9j2.json new file mode 100644 index 00000000000..7a2f5f3db53 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9pcf-cp93-m9j2/GHSA-9pcf-cp93-m9j2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pcf-cp93-m9j2", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-37392" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37392" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-dummy-content-generator/wordpress-wp-dummy-content-generator-plugin-2-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9x7r-76q2-9pj5/GHSA-9x7r-76q2-9pj5.json b/advisories/unreviewed/2023/07/GHSA-9x7r-76q2-9pj5/GHSA-9x7r-76q2-9pj5.json new file mode 100644 index 00000000000..26905839b25 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9x7r-76q2-9pj5/GHSA-9x7r-76q2-9pj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x7r-76q2-9pj5", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-28986" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager plugin <= 2.9.20 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/affiliates-manager/wordpress-affiliates-manager-plugin-2-9-20-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-c5gq-vxjx-fc85/GHSA-c5gq-vxjx-fc85.json b/advisories/unreviewed/2023/07/GHSA-c5gq-vxjx-fc85/GHSA-c5gq-vxjx-fc85.json new file mode 100644 index 00000000000..826fc09aa48 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-c5gq-vxjx-fc85/GHSA-c5gq-vxjx-fc85.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5gq-vxjx-fc85", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3560" + ], + "details": "A vulnerability, which was classified as problematic, has been found in GZ Scripts Ticket Booking Script 1.8. Affected by this issue is some unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack may be launched remotely. VDB-233354 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3560" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233354" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cgrh-rp4g-xxp4/GHSA-cgrh-rp4g-xxp4.json b/advisories/unreviewed/2023/07/GHSA-cgrh-rp4g-xxp4/GHSA-cgrh-rp4g-xxp4.json new file mode 100644 index 00000000000..71c95993645 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cgrh-rp4g-xxp4/GHSA-cgrh-rp4g-xxp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgrh-rp4g-xxp4", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-23787" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/premmerce-redirect-manager/wordpress-premmerce-redirect-manager-plugin-1-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-cwmp-669c-fh3g/GHSA-cwmp-669c-fh3g.json b/advisories/unreviewed/2023/07/GHSA-cwmp-669c-fh3g/GHSA-cwmp-669c-fh3g.json new file mode 100644 index 00000000000..293b26cf8c3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-cwmp-669c-fh3g/GHSA-cwmp-669c-fh3g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwmp-669c-fh3g", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2493" + ], + "details": "The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2493" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a9a205a4-eef9-4f30-877a-4c562930650c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f26w-p752-7ggh/GHSA-f26w-p752-7ggh.json b/advisories/unreviewed/2023/07/GHSA-f26w-p752-7ggh/GHSA-f26w-p752-7ggh.json new file mode 100644 index 00000000000..b4328390221 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f26w-p752-7ggh/GHSA-f26w-p752-7ggh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f26w-p752-7ggh", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-34318" + ], + "details": "A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34318" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-34318" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2212283" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f58x-2j8x-cj9x/GHSA-f58x-2j8x-cj9x.json b/advisories/unreviewed/2023/07/GHSA-f58x-2j8x-cj9x/GHSA-f58x-2j8x-cj9x.json new file mode 100644 index 00000000000..910e5f90213 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f58x-2j8x-cj9x/GHSA-f58x-2j8x-cj9x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f58x-2j8x-cj9x", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37704" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37704" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6901" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f5c3-v4p4-69h6/GHSA-f5c3-v4p4-69h6.json b/advisories/unreviewed/2023/07/GHSA-f5c3-v4p4-69h6/GHSA-f5c3-v4p4-69h6.json new file mode 100644 index 00000000000..a20ac455da3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f5c3-v4p4-69h6/GHSA-f5c3-v4p4-69h6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5c3-v4p4-69h6", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2635" + ], + "details": "The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2635" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/81b89613-18d0-4c13-84e3-9e2e1802fd7c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f6cm-fmx2-2v57/GHSA-f6cm-fmx2-2v57.json b/advisories/unreviewed/2023/07/GHSA-f6cm-fmx2-2v57/GHSA-f6cm-fmx2-2v57.json new file mode 100644 index 00000000000..fedbd45c954 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f6cm-fmx2-2v57/GHSA-f6cm-fmx2-2v57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6cm-fmx2-2v57", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-23348" + ], + "details": "HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23348" + }, + { + "type": "WEB", + "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105978" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fchg-567g-rpx3/GHSA-fchg-567g-rpx3.json b/advisories/unreviewed/2023/07/GHSA-fchg-567g-rpx3/GHSA-fchg-567g-rpx3.json new file mode 100644 index 00000000000..c9e2441070a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fchg-567g-rpx3/GHSA-fchg-567g-rpx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fchg-567g-rpx3", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-22673" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/website-monetization-by-magenet/wordpress-website-monetization-by-magenet-plugin-1-0-29-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json b/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json new file mode 100644 index 00000000000..d629b6b21c2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fcmj-gcwc-rvc5/GHSA-fcmj-gcwc-rvc5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcmj-gcwc-rvc5", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-36940" + ], + "details": "Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36940" + }, + { + "type": "WEB", + "url": "https://medium.com/@ridheshgohil1092/cve-2023-36940-xss-on-online-fire-reporting-system-v-1-2-1d3fa170e4d6" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fg3g-frcw-5756/GHSA-fg3g-frcw-5756.json b/advisories/unreviewed/2023/07/GHSA-fg3g-frcw-5756/GHSA-fg3g-frcw-5756.json index 84e2380571d..ff2043c44c3 100644 --- a/advisories/unreviewed/2023/07/GHSA-fg3g-frcw-5756/GHSA-fg3g-frcw-5756.json +++ b/advisories/unreviewed/2023/07/GHSA-fg3g-frcw-5756/GHSA-fg3g-frcw-5756.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-fgr5-j38j-744g/GHSA-fgr5-j38j-744g.json b/advisories/unreviewed/2023/07/GHSA-fgr5-j38j-744g/GHSA-fgr5-j38j-744g.json new file mode 100644 index 00000000000..37baf00d1d5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fgr5-j38j-744g/GHSA-fgr5-j38j-744g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgr5-j38j-744g", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-28995" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Keith Solomon Configurable Tag Cloud (CTC) plugin <= 5.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/configurable-tag-cloud-widget/wordpress-configurable-tag-cloud-plugin-5-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fj6w-pj39-77x8/GHSA-fj6w-pj39-77x8.json b/advisories/unreviewed/2023/07/GHSA-fj6w-pj39-77x8/GHSA-fj6w-pj39-77x8.json new file mode 100644 index 00000000000..6721b313706 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fj6w-pj39-77x8/GHSA-fj6w-pj39-77x8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj6w-pj39-77x8", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3129" + ], + "details": "The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3129" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5717d729-c24b-4415-bb99-fcdd259328c4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fm49-53h8-h7vg/GHSA-fm49-53h8-h7vg.json b/advisories/unreviewed/2023/07/GHSA-fm49-53h8-h7vg/GHSA-fm49-53h8-h7vg.json new file mode 100644 index 00000000000..42653c827e7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fm49-53h8-h7vg/GHSA-fm49-53h8-h7vg.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm49-53h8-h7vg", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3271" + ], + "details": "\nImproper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing\nunauthenticated endpoints.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3271" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fq7j-mj26-w42x/GHSA-fq7j-mj26-w42x.json b/advisories/unreviewed/2023/07/GHSA-fq7j-mj26-w42x/GHSA-fq7j-mj26-w42x.json new file mode 100644 index 00000000000..377ee246029 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fq7j-mj26-w42x/GHSA-fq7j-mj26-w42x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq7j-mj26-w42x", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-35699" + ], + "details": "\nCleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35699" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-313" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fwpj-frr9-2r36/GHSA-fwpj-frr9-2r36.json b/advisories/unreviewed/2023/07/GHSA-fwpj-frr9-2r36/GHSA-fwpj-frr9-2r36.json new file mode 100644 index 00000000000..2c29c4e9035 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fwpj-frr9-2r36/GHSA-fwpj-frr9-2r36.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwpj-frr9-2r36", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-36939" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36939" + }, + { + "type": "WEB", + "url": "https://medium.com/@ridheshgohil1092/cve-2023-36939-xss-online-security-guards-hiring-system-7547ee114134" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g5f9-q7v3-ff2h/GHSA-g5f9-q7v3-ff2h.json b/advisories/unreviewed/2023/07/GHSA-g5f9-q7v3-ff2h/GHSA-g5f9-q7v3-ff2h.json new file mode 100644 index 00000000000..bf9c0503a8f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g5f9-q7v3-ff2h/GHSA-g5f9-q7v3-ff2h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5f9-q7v3-ff2h", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2028" + ], + "details": "The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2028" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0f1c1f1c-acdd-4c8a-bd5e-a21f4915e69f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g93m-hx8j-2qmq/GHSA-g93m-hx8j-2qmq.json b/advisories/unreviewed/2023/07/GHSA-g93m-hx8j-2qmq/GHSA-g93m-hx8j-2qmq.json new file mode 100644 index 00000000000..0b85e1476ac --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g93m-hx8j-2qmq/GHSA-g93m-hx8j-2qmq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g93m-hx8j-2qmq", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2023-1208" + ], + "details": "This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a Remote Code Execution vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1208" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e0cc6740-866a-4a81-a93d-ff486b79b7f7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g9xm-xhj6-2frv/GHSA-g9xm-xhj6-2frv.json b/advisories/unreviewed/2023/07/GHSA-g9xm-xhj6-2frv/GHSA-g9xm-xhj6-2frv.json index 141cb65b87a..383986db9d3 100644 --- a/advisories/unreviewed/2023/07/GHSA-g9xm-xhj6-2frv/GHSA-g9xm-xhj6-2frv.json +++ b/advisories/unreviewed/2023/07/GHSA-g9xm-xhj6-2frv/GHSA-g9xm-xhj6-2frv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9xm-xhj6-2frv", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-28324" ], "details": "A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-gh5w-4mrm-4p4c/GHSA-gh5w-4mrm-4p4c.json b/advisories/unreviewed/2023/07/GHSA-gh5w-4mrm-4p4c/GHSA-gh5w-4mrm-4p4c.json new file mode 100644 index 00000000000..661c109b694 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gh5w-4mrm-4p4c/GHSA-gh5w-4mrm-4p4c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh5w-4mrm-4p4c", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-3568" + ], + "details": "Improper Input Validation in GitHub repository fossbilling/fossbilling prior to 0.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3568" + }, + { + "type": "WEB", + "url": "https://github.com/fossbilling/fossbilling/commit/f6348643d230a13427d8ab9213463dadbb68818f" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/f3782eb1-049b-4998-aac4-d9798ec1c123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gjjc-pv92-5mx2/GHSA-gjjc-pv92-5mx2.json b/advisories/unreviewed/2023/07/GHSA-gjjc-pv92-5mx2/GHSA-gjjc-pv92-5mx2.json new file mode 100644 index 00000000000..0d6cced928f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gjjc-pv92-5mx2/GHSA-gjjc-pv92-5mx2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjjc-pv92-5mx2", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-37153" + ], + "details": "KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37153" + }, + { + "type": "WEB", + "url": "https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/KodExplorer4.51.03.md" + }, + { + "type": "WEB", + "url": "https://github.com/kalcaddle/KodExplorer" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gmpj-g3g5-h2rv/GHSA-gmpj-g3g5-h2rv.json b/advisories/unreviewed/2023/07/GHSA-gmpj-g3g5-h2rv/GHSA-gmpj-g3g5-h2rv.json new file mode 100644 index 00000000000..86c39e3b62f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gmpj-g3g5-h2rv/GHSA-gmpj-g3g5-h2rv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmpj-g3g5-h2rv", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-30446" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: \n\n253361\n\n.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30446" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/253361" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gpvv-vf7g-q8f6/GHSA-gpvv-vf7g-q8f6.json b/advisories/unreviewed/2023/07/GHSA-gpvv-vf7g-q8f6/GHSA-gpvv-vf7g-q8f6.json new file mode 100644 index 00000000000..a69dfa0cea9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gpvv-vf7g-q8f6/GHSA-gpvv-vf7g-q8f6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpvv-vf7g-q8f6", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-1780" + ], + "details": "The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1780" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8176308f-f210-4109-9c88-9372415dbed3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-grpp-v27v-jff6/GHSA-grpp-v27v-jff6.json b/advisories/unreviewed/2023/07/GHSA-grpp-v27v-jff6/GHSA-grpp-v27v-jff6.json new file mode 100644 index 00000000000..a7aadeff219 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-grpp-v27v-jff6/GHSA-grpp-v27v-jff6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grpp-v27v-jff6", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2026" + ], + "details": "The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2026" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2b59f640-5568-42bb-87b7-36eb448db5be" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gwr5-qqvh-c57m/GHSA-gwr5-qqvh-c57m.json b/advisories/unreviewed/2023/07/GHSA-gwr5-qqvh-c57m/GHSA-gwr5-qqvh-c57m.json new file mode 100644 index 00000000000..0ae28402eeb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gwr5-qqvh-c57m/GHSA-gwr5-qqvh-c57m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwr5-qqvh-c57m", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3076" + ], + "details": "The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3076" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ac662436-29d7-4ea6-84e1-f9e229b44f5b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h2j9-wrpc-7mm8/GHSA-h2j9-wrpc-7mm8.json b/advisories/unreviewed/2023/07/GHSA-h2j9-wrpc-7mm8/GHSA-h2j9-wrpc-7mm8.json new file mode 100644 index 00000000000..edc6de22dd5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h2j9-wrpc-7mm8/GHSA-h2j9-wrpc-7mm8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2j9-wrpc-7mm8", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-28953" + ], + "details": "IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28953" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/251465" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7006413" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h9x4-5hxf-q5g6/GHSA-h9x4-5hxf-q5g6.json b/advisories/unreviewed/2023/07/GHSA-h9x4-5hxf-q5g6/GHSA-h9x4-5hxf-q5g6.json new file mode 100644 index 00000000000..ac0f8a35f81 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h9x4-5hxf-q5g6/GHSA-h9x4-5hxf-q5g6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9x4-5hxf-q5g6", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-29095" + ], + "details": "Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29095" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/rsvpmaker/wordpress-rsvpmaker-plugin-10-5-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hgrq-rjwf-5f46/GHSA-hgrq-rjwf-5f46.json b/advisories/unreviewed/2023/07/GHSA-hgrq-rjwf-5f46/GHSA-hgrq-rjwf-5f46.json index fa9252bc6e3..8f181777c93 100644 --- a/advisories/unreviewed/2023/07/GHSA-hgrq-rjwf-5f46/GHSA-hgrq-rjwf-5f46.json +++ b/advisories/unreviewed/2023/07/GHSA-hgrq-rjwf-5f46/GHSA-hgrq-rjwf-5f46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hgrq-rjwf-5f46", - "modified": "2023-07-03T21:30:57Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-36377" ], "details": "Buffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary code via a crafted .exe, .sys, and .dll files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json b/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json index 84bcf7ff957..2b6cb393a39 100644 --- a/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json +++ b/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5450" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5451" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-22/" diff --git a/advisories/unreviewed/2023/07/GHSA-j24c-9hrq-7956/GHSA-j24c-9hrq-7956.json b/advisories/unreviewed/2023/07/GHSA-j24c-9hrq-7956/GHSA-j24c-9hrq-7956.json new file mode 100644 index 00000000000..3efd4eda769 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j24c-9hrq-7956/GHSA-j24c-9hrq-7956.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j24c-9hrq-7956", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2709" + ], + "details": "The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2709" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2504dadb-1086-4fa9-8fc7-b93018423515" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j5qp-ff5h-ffgc/GHSA-j5qp-ff5h-ffgc.json b/advisories/unreviewed/2023/07/GHSA-j5qp-ff5h-ffgc/GHSA-j5qp-ff5h-ffgc.json new file mode 100644 index 00000000000..102d60b274c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j5qp-ff5h-ffgc/GHSA-j5qp-ff5h-ffgc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5qp-ff5h-ffgc", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3556" + ], + "details": "A vulnerability was found in GZ Scripts Car Listing Script PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /preview.php. The manipulation of the argument page/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-233350 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233350" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j5v4-gjgv-j697/GHSA-j5v4-gjgv-j697.json b/advisories/unreviewed/2023/07/GHSA-j5v4-gjgv-j697/GHSA-j5v4-gjgv-j697.json new file mode 100644 index 00000000000..a428fd3c3f0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j5v4-gjgv-j697/GHSA-j5v4-gjgv-j697.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5v4-gjgv-j697", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-30447" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30447" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/253436" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j6g7-53v4-8vmr/GHSA-j6g7-53v4-8vmr.json b/advisories/unreviewed/2023/07/GHSA-j6g7-53v4-8vmr/GHSA-j6g7-53v4-8vmr.json new file mode 100644 index 00000000000..2771e241c7f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j6g7-53v4-8vmr/GHSA-j6g7-53v4-8vmr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6g7-53v4-8vmr", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3562" + ], + "details": "A vulnerability has been found in GZ Scripts PHP CRM Platform 1.8 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-233356. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3562" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233356" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j8xr-8hjf-7jp2/GHSA-j8xr-8hjf-7jp2.json b/advisories/unreviewed/2023/07/GHSA-j8xr-8hjf-7jp2/GHSA-j8xr-8hjf-7jp2.json new file mode 100644 index 00000000000..ae749c795f7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j8xr-8hjf-7jp2/GHSA-j8xr-8hjf-7jp2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8xr-8hjf-7jp2", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-27869" + ], + "details": "IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27869" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/249517" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j94g-69xw-xx5q/GHSA-j94g-69xw-xx5q.json b/advisories/unreviewed/2023/07/GHSA-j94g-69xw-xx5q/GHSA-j94g-69xw-xx5q.json new file mode 100644 index 00000000000..9bbe7c18337 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j94g-69xw-xx5q/GHSA-j94g-69xw-xx5q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j94g-69xw-xx5q", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-36375" + ], + "details": "Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36375" + }, + { + "type": "WEB", + "url": "https://medium.com/@ridheshgohil1092/cve-2023-36375-xss-on-hostel-management-system-d654e6df26bc" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jgmq-c4w3-2q95/GHSA-jgmq-c4w3-2q95.json b/advisories/unreviewed/2023/07/GHSA-jgmq-c4w3-2q95/GHSA-jgmq-c4w3-2q95.json new file mode 100644 index 00000000000..3292b5ff179 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jgmq-c4w3-2q95/GHSA-jgmq-c4w3-2q95.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgmq-c4w3-2q95", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-36936" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36936" + }, + { + "type": "WEB", + "url": "https://medium.com/@ridheshgohil1092/cve-2023-36936-xss-online-security-guards-hiring-system-773f394f6117" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json b/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json new file mode 100644 index 00000000000..392efce2ea4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jjxm-6773-5xf7/GHSA-jjxm-6773-5xf7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjxm-6773-5xf7", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-30449" + ], + "details": "\nIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30449" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/253439" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010557" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jpg7-857p-mpqg/GHSA-jpg7-857p-mpqg.json b/advisories/unreviewed/2023/07/GHSA-jpg7-857p-mpqg/GHSA-jpg7-857p-mpqg.json index ba0a9bd81cd..3419a6cf8fa 100644 --- a/advisories/unreviewed/2023/07/GHSA-jpg7-857p-mpqg/GHSA-jpg7-857p-mpqg.json +++ b/advisories/unreviewed/2023/07/GHSA-jpg7-857p-mpqg/GHSA-jpg7-857p-mpqg.json @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5450" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5451" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-22/" diff --git a/advisories/unreviewed/2023/07/GHSA-jr95-pwfp-3r6q/GHSA-jr95-pwfp-3r6q.json b/advisories/unreviewed/2023/07/GHSA-jr95-pwfp-3r6q/GHSA-jr95-pwfp-3r6q.json new file mode 100644 index 00000000000..17d260b9c50 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jr95-pwfp-3r6q/GHSA-jr95-pwfp-3r6q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr95-pwfp-3r6q", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-30431" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow the buffer and execute arbitrary code. IBM X-Force ID: 252184.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30431" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/252184" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010565" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jvc7-6hwc-2v88/GHSA-jvc7-6hwc-2v88.json b/advisories/unreviewed/2023/07/GHSA-jvc7-6hwc-2v88/GHSA-jvc7-6hwc-2v88.json new file mode 100644 index 00000000000..3b8d9407bd0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jvc7-6hwc-2v88/GHSA-jvc7-6hwc-2v88.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvc7-6hwc-2v88", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3563" + ], + "details": "A vulnerability was found in GZ Scripts GZ E Learning Platform 1.8 and classified as problematic. This issue affects some unknown processing of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-233357 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3563" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233357" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jw79-3rh8-v6jv/GHSA-jw79-3rh8-v6jv.json b/advisories/unreviewed/2023/07/GHSA-jw79-3rh8-v6jv/GHSA-jw79-3rh8-v6jv.json new file mode 100644 index 00000000000..01264f71a48 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jw79-3rh8-v6jv/GHSA-jw79-3rh8-v6jv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw79-3rh8-v6jv", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-35696" + ], + "details": "\nUnauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated\nremote attacker to retrieve sensitive information about the device via HTTP requests.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35696" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-668" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m3mp-3m5h-pm9m/GHSA-m3mp-3m5h-pm9m.json b/advisories/unreviewed/2023/07/GHSA-m3mp-3m5h-pm9m/GHSA-m3mp-3m5h-pm9m.json new file mode 100644 index 00000000000..f4b36293731 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m3mp-3m5h-pm9m/GHSA-m3mp-3m5h-pm9m.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3mp-3m5h-pm9m", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3272" + ], + "details": "\n\n\nCleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a\nremote attacker to gather sensitive information by intercepting network traffic that is not encrypted.\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3272" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m8wc-q86f-6h3h/GHSA-m8wc-q86f-6h3h.json b/advisories/unreviewed/2023/07/GHSA-m8wc-q86f-6h3h/GHSA-m8wc-q86f-6h3h.json new file mode 100644 index 00000000000..49e0619bce2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m8wc-q86f-6h3h/GHSA-m8wc-q86f-6h3h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8wc-q86f-6h3h", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-24395" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24395" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-redirect-thank-you-page/wordpress-contact-form-7-redirect-thank-you-page-plugin-1-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m8xh-2cm5-qm87/GHSA-m8xh-2cm5-qm87.json b/advisories/unreviewed/2023/07/GHSA-m8xh-2cm5-qm87/GHSA-m8xh-2cm5-qm87.json new file mode 100644 index 00000000000..5b4862a324f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m8xh-2cm5-qm87/GHSA-m8xh-2cm5-qm87.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8xh-2cm5-qm87", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3561" + ], + "details": "A vulnerability, which was classified as problematic, was found in GZ Scripts PHP GZ Hotel Booking Script 1.8. This affects an unknown part of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-233355. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3561" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233355" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m967-qhpw-m4rw/GHSA-m967-qhpw-m4rw.json b/advisories/unreviewed/2023/07/GHSA-m967-qhpw-m4rw/GHSA-m967-qhpw-m4rw.json new file mode 100644 index 00000000000..50cecb5fc8b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m967-qhpw-m4rw/GHSA-m967-qhpw-m4rw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m967-qhpw-m4rw", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2964" + ], + "details": "The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2964" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/97aac334-5323-41bb-90f0-d180bcc9162f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mf5c-mpv7-gxg8/GHSA-mf5c-mpv7-gxg8.json b/advisories/unreviewed/2023/07/GHSA-mf5c-mpv7-gxg8/GHSA-mf5c-mpv7-gxg8.json new file mode 100644 index 00000000000..da52a440efb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mf5c-mpv7-gxg8/GHSA-mf5c-mpv7-gxg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf5c-mpv7-gxg8", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37700" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37700" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6905" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mjmq-gwgm-5qhm/GHSA-mjmq-gwgm-5qhm.json b/advisories/unreviewed/2023/07/GHSA-mjmq-gwgm-5qhm/GHSA-mjmq-gwgm-5qhm.json new file mode 100644 index 00000000000..144c6a9f984 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mjmq-gwgm-5qhm/GHSA-mjmq-gwgm-5qhm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjmq-gwgm-5qhm", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-35887" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.\n\nIn SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover \"exists/does not exist\" information about items outside the rooted tree via paths including parent navigation (\"..\") beyond the root, or involving symlinks.\n\nThis issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35887" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mqw5-v4rf-8jvg/GHSA-mqw5-v4rf-8jvg.json b/advisories/unreviewed/2023/07/GHSA-mqw5-v4rf-8jvg/GHSA-mqw5-v4rf-8jvg.json new file mode 100644 index 00000000000..be4f79b194a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mqw5-v4rf-8jvg/GHSA-mqw5-v4rf-8jvg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqw5-v4rf-8jvg", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37702" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37702" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6801" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mvmr-rxwm-hjc9/GHSA-mvmr-rxwm-hjc9.json b/advisories/unreviewed/2023/07/GHSA-mvmr-rxwm-hjc9/GHSA-mvmr-rxwm-hjc9.json new file mode 100644 index 00000000000..74942822388 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mvmr-rxwm-hjc9/GHSA-mvmr-rxwm-hjc9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvmr-rxwm-hjc9", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-29256" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29256" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/252046" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010573" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mw2v-mwrw-64xm/GHSA-mw2v-mwrw-64xm.json b/advisories/unreviewed/2023/07/GHSA-mw2v-mwrw-64xm/GHSA-mw2v-mwrw-64xm.json new file mode 100644 index 00000000000..6b20b38fb53 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mw2v-mwrw-64xm/GHSA-mw2v-mwrw-64xm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw2v-mwrw-64xm", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-3599" + ], + "details": "A vulnerability was found in SourceCodester Best Fee Management System 1.0. It has been rated as critical. Affected by this issue is the function save_user of the file admin_class.php of the component Add User Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-233450 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3599" + }, + { + "type": "WEB", + "url": "https://github.com/movonow/demo/blob/main/click_fees.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233450" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233450" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p356-h5pr-gp95/GHSA-p356-h5pr-gp95.json b/advisories/unreviewed/2023/07/GHSA-p356-h5pr-gp95/GHSA-p356-h5pr-gp95.json index 5ee3999a5ae..87231eaf41c 100644 --- a/advisories/unreviewed/2023/07/GHSA-p356-h5pr-gp95/GHSA-p356-h5pr-gp95.json +++ b/advisories/unreviewed/2023/07/GHSA-p356-h5pr-gp95/GHSA-p356-h5pr-gp95.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p356-h5pr-gp95", - "modified": "2023-07-03T21:30:57Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-36222" ], "details": "Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the comment parameter in the article function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json b/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json new file mode 100644 index 00000000000..fd4e84c67d2 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p3v2-rv86-5c5f/GHSA-p3v2-rv86-5c5f.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3v2-rv86-5c5f", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-32254" + ], + "details": "A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to execute code in the context of the kernel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32254" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-32254" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2191658" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-702/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json b/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json new file mode 100644 index 00000000000..213e40b8757 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p492-c975-6xjf", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2967" + ], + "details": "The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2967" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9afec4aa-1210-4c40-b566-64e37acf2b64" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p7jq-h985-46gc/GHSA-p7jq-h985-46gc.json b/advisories/unreviewed/2023/07/GHSA-p7jq-h985-46gc/GHSA-p7jq-h985-46gc.json new file mode 100644 index 00000000000..1c8ac7a9377 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p7jq-h985-46gc/GHSA-p7jq-h985-46gc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7jq-h985-46gc", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-3579" + ], + "details": "A vulnerability, which was classified as problematic, has been found in HadSky 7.11.8. Affected by this issue is some unknown functionality of the component User Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-233372.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3579" + }, + { + "type": "WEB", + "url": "https://github.com/nightcloudos/cve/blob/main/CSRF.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233372" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p7qc-vjp7-v8rx/GHSA-p7qc-vjp7-v8rx.json b/advisories/unreviewed/2023/07/GHSA-p7qc-vjp7-v8rx/GHSA-p7qc-vjp7-v8rx.json new file mode 100644 index 00000000000..86aa5412a37 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p7qc-vjp7-v8rx/GHSA-p7qc-vjp7-v8rx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7qc-vjp7-v8rx", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-37152" + ], + "details": "Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37152" + }, + { + "type": "WEB", + "url": "https://github.com/Trinity-SYT-SECURITY/arbitrary-file-upload-RCE/blob/main/Online%20Art%20gallery%20project%201.0.md" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/51524" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p83x-2782-8pc4/GHSA-p83x-2782-8pc4.json b/advisories/unreviewed/2023/07/GHSA-p83x-2782-8pc4/GHSA-p83x-2782-8pc4.json new file mode 100644 index 00000000000..efbab346d9e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p83x-2782-8pc4/GHSA-p83x-2782-8pc4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p83x-2782-8pc4", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-3580" + ], + "details": "Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3580" + }, + { + "type": "WEB", + "url": "https://github.com/squidex/squidex/commit/2aca7621845ce18ed4065cba8e3d0fa68aaf02bf" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/4eed53ca-06c2-43aa-aea8-c03ea5f13ce4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-167" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pr83-w226-5h5g/GHSA-pr83-w226-5h5g.json b/advisories/unreviewed/2023/07/GHSA-pr83-w226-5h5g/GHSA-pr83-w226-5h5g.json new file mode 100644 index 00000000000..fb048a5a8a9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pr83-w226-5h5g/GHSA-pr83-w226-5h5g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr83-w226-5h5g", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-37150" + ], + "details": "Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in \"/admin/index.php?page=categories\" Category item.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37150" + }, + { + "type": "WEB", + "url": "https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/Online%20Pizza%20Ordering%20System%20v1.0.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pvx5-h7p4-ffvx/GHSA-pvx5-h7p4-ffvx.json b/advisories/unreviewed/2023/07/GHSA-pvx5-h7p4-ffvx/GHSA-pvx5-h7p4-ffvx.json new file mode 100644 index 00000000000..7265e0c366f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pvx5-h7p4-ffvx/GHSA-pvx5-h7p4-ffvx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvx5-h7p4-ffvx", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2495" + ], + "details": "The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2495" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/45878983-7e9b-49c2-8f99-4c28aab24f09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q6g7-cf67-6822/GHSA-q6g7-cf67-6822.json b/advisories/unreviewed/2023/07/GHSA-q6g7-cf67-6822/GHSA-q6g7-cf67-6822.json new file mode 100644 index 00000000000..a408956f2e9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q6g7-cf67-6822/GHSA-q6g7-cf67-6822.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6g7-cf67-6822", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3559" + ], + "details": "A vulnerability classified as problematic was found in GZ Scripts PHP GZ Appointment Scheduling Script 1.8. Affected by this vulnerability is an unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be launched remotely. The identifier VDB-233353 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3559" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233353" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q7hq-rw8g-9rh4/GHSA-q7hq-rw8g-9rh4.json b/advisories/unreviewed/2023/07/GHSA-q7hq-rw8g-9rh4/GHSA-q7hq-rw8g-9rh4.json index f4a34bfa730..e9aa1f4b96f 100644 --- a/advisories/unreviewed/2023/07/GHSA-q7hq-rw8g-9rh4/GHSA-q7hq-rw8g-9rh4.json +++ b/advisories/unreviewed/2023/07/GHSA-q7hq-rw8g-9rh4/GHSA-q7hq-rw8g-9rh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7hq-rw8g-9rh4", - "modified": "2023-07-03T21:30:57Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-36223" ], "details": "Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-qw9f-547c-ppw4/GHSA-qw9f-547c-ppw4.json b/advisories/unreviewed/2023/07/GHSA-qw9f-547c-ppw4/GHSA-qw9f-547c-ppw4.json new file mode 100644 index 00000000000..9a44e2723b0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qw9f-547c-ppw4/GHSA-qw9f-547c-ppw4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw9f-547c-ppw4", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-27868" + ], + "details": "IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249516.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27868" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/249516" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r73w-7gww-pr94/GHSA-r73w-7gww-pr94.json b/advisories/unreviewed/2023/07/GHSA-r73w-7gww-pr94/GHSA-r73w-7gww-pr94.json new file mode 100644 index 00000000000..0354de906b0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r73w-7gww-pr94/GHSA-r73w-7gww-pr94.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r73w-7gww-pr94", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-35697" + ], + "details": "\nImproper Restriction of Excessive Authentication Attempts in the SICK ICR890-4\ncould allow a remote attacker to brute-force user credentials.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35697" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rfv2-3vhx-4f5f/GHSA-rfv2-3vhx-4f5f.json b/advisories/unreviewed/2023/07/GHSA-rfv2-3vhx-4f5f/GHSA-rfv2-3vhx-4f5f.json new file mode 100644 index 00000000000..69921622f76 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rfv2-3vhx-4f5f/GHSA-rfv2-3vhx-4f5f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfv2-3vhx-4f5f", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3554" + ], + "details": "A vulnerability was found in GZ Scripts GZ Forum Script 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /preview.php. The manipulation of the argument catid/topicid/topic/topic_message/free_name leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-233348. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3554" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233348" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rv8p-344q-9xrj/GHSA-rv8p-344q-9xrj.json b/advisories/unreviewed/2023/07/GHSA-rv8p-344q-9xrj/GHSA-rv8p-344q-9xrj.json new file mode 100644 index 00000000000..1071b452bd6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rv8p-344q-9xrj/GHSA-rv8p-344q-9xrj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv8p-344q-9xrj", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3564" + ], + "details": "A vulnerability was found in GZ Scripts GZ Multi Hotel Booking System 1.8. It has been classified as problematic. Affected is an unknown function of the file /index.php. The manipulation of the argument adults/children/cal_id leads to cross site scripting. It is possible to launch the attack remotely. VDB-233358 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3564" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233358" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-rvfp-j42c-8vrc/GHSA-rvfp-j42c-8vrc.json b/advisories/unreviewed/2023/07/GHSA-rvfp-j42c-8vrc/GHSA-rvfp-j42c-8vrc.json index 0686439ee3b..2f5e7ac420a 100644 --- a/advisories/unreviewed/2023/07/GHSA-rvfp-j42c-8vrc/GHSA-rvfp-j42c-8vrc.json +++ b/advisories/unreviewed/2023/07/GHSA-rvfp-j42c-8vrc/GHSA-rvfp-j42c-8vrc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rvfp-j42c-8vrc", - "modified": "2023-07-04T00:31:38Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-04T00:31:38Z", "aliases": [ "CVE-2023-22906" ], "details": "Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-v487-79cj-w3x8/GHSA-v487-79cj-w3x8.json b/advisories/unreviewed/2023/07/GHSA-v487-79cj-w3x8/GHSA-v487-79cj-w3x8.json index ba960789f13..8bcd37b0218 100644 --- a/advisories/unreviewed/2023/07/GHSA-v487-79cj-w3x8/GHSA-v487-79cj-w3x8.json +++ b/advisories/unreviewed/2023/07/GHSA-v487-79cj-w3x8/GHSA-v487-79cj-w3x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v487-79cj-w3x8", - "modified": "2023-07-05T03:30:23Z", + "modified": "2023-07-10T18:30:45Z", "published": "2023-07-05T03:30:23Z", "aliases": [ "CVE-2022-42175" ], "details": "Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other customer servers without authorization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-v75c-m7vr-mvvg/GHSA-v75c-m7vr-mvvg.json b/advisories/unreviewed/2023/07/GHSA-v75c-m7vr-mvvg/GHSA-v75c-m7vr-mvvg.json new file mode 100644 index 00000000000..94ec6a6dc9a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v75c-m7vr-mvvg/GHSA-v75c-m7vr-mvvg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v75c-m7vr-mvvg", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3558" + ], + "details": "A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-233352. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3558" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233352" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233352" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v77x-qc2p-7878/GHSA-v77x-qc2p-7878.json b/advisories/unreviewed/2023/07/GHSA-v77x-qc2p-7878/GHSA-v77x-qc2p-7878.json new file mode 100644 index 00000000000..d9508bf2a1d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v77x-qc2p-7878/GHSA-v77x-qc2p-7878.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v77x-qc2p-7878", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2796" + ], + "details": "The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2796" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e9ef793c-e5a3-4c55-beee-56b0909f7a0d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v8fh-6gv5-c3px/GHSA-v8fh-6gv5-c3px.json b/advisories/unreviewed/2023/07/GHSA-v8fh-6gv5-c3px/GHSA-v8fh-6gv5-c3px.json new file mode 100644 index 00000000000..daad3fa7f30 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v8fh-6gv5-c3px/GHSA-v8fh-6gv5-c3px.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8fh-6gv5-c3px", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-36691" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36691" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/webwinkelkeur/wordpress-webwinkelkeu-plugin-3-24-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v9mp-h44v-2qrv/GHSA-v9mp-h44v-2qrv.json b/advisories/unreviewed/2023/07/GHSA-v9mp-h44v-2qrv/GHSA-v9mp-h44v-2qrv.json new file mode 100644 index 00000000000..a811f540908 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v9mp-h44v-2qrv/GHSA-v9mp-h44v-2qrv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9mp-h44v-2qrv", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2016-15034" + ], + "details": "A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedomrss_search of the file freedomrss_search.php. The manipulation leads to sql injection. Upgrading to version 3.2-20180305 is able to address this issue. The patch is identified as 750a9b35af182950c952faf6ddfdcc50a2b25f8b. It is recommended to upgrade the affected component. VDB-233366 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-15034" + }, + { + "type": "WEB", + "url": "https://github.com/dynacase-labs/dynacase-webdesk/commit/750a9b35af182950c952faf6ddfdcc50a2b25f8b" + }, + { + "type": "WEB", + "url": "https://github.com/dynacase-labs/dynacase-webdesk/releases/tag/3.2-20180305" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233366" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233366" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vf3w-pp2v-hpgg/GHSA-vf3w-pp2v-hpgg.json b/advisories/unreviewed/2023/07/GHSA-vf3w-pp2v-hpgg/GHSA-vf3w-pp2v-hpgg.json new file mode 100644 index 00000000000..babddb584a1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vf3w-pp2v-hpgg/GHSA-vf3w-pp2v-hpgg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf3w-pp2v-hpgg", + "modified": "2023-07-10T18:30:50Z", + "published": "2023-07-10T18:30:50Z", + "aliases": [ + "CVE-2023-37703" + ], + "details": "Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37703" + }, + { + "type": "WEB", + "url": "https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/6907" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vjc2-xpc4-gph6/GHSA-vjc2-xpc4-gph6.json b/advisories/unreviewed/2023/07/GHSA-vjc2-xpc4-gph6/GHSA-vjc2-xpc4-gph6.json new file mode 100644 index 00000000000..3011e97b7f0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vjc2-xpc4-gph6/GHSA-vjc2-xpc4-gph6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjc2-xpc4-gph6", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3045" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Parking Web Report allows SQL Injection.This issue affects Parking Web Report: before 2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3045" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vq7j-qx4g-8wh5/GHSA-vq7j-qx4g-8wh5.json b/advisories/unreviewed/2023/07/GHSA-vq7j-qx4g-8wh5/GHSA-vq7j-qx4g-8wh5.json new file mode 100644 index 00000000000..d9f11254228 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vq7j-qx4g-8wh5/GHSA-vq7j-qx4g-8wh5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq7j-qx4g-8wh5", + "modified": "2023-07-10T18:30:46Z", + "published": "2023-07-10T18:30:46Z", + "aliases": [ + "CVE-2015-10119" + ], + "details": "A vulnerability, which was classified as problematic, has been found in View All Posts Page Plugin up to 0.9.0 on WordPress. This issue affects the function action_admin_notices_activation of the file view-all-posts-pages.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 0.9.1 is able to address this issue. The patch is named bf914f3a59063fa4df8fd4925ae18a5d852396d7. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-233363.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-10119" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/view-all-posts-pages/commit/bf914f3a59063fa4df8fd4925ae18a5d852396d7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233363" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w2j3-rrx7-6wrf/GHSA-w2j3-rrx7-6wrf.json b/advisories/unreviewed/2023/07/GHSA-w2j3-rrx7-6wrf/GHSA-w2j3-rrx7-6wrf.json new file mode 100644 index 00000000000..b440f67e701 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w2j3-rrx7-6wrf/GHSA-w2j3-rrx7-6wrf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2j3-rrx7-6wrf", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-23487" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23487" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/245918" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010567" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w2m7-r572-689m/GHSA-w2m7-r572-689m.json b/advisories/unreviewed/2023/07/GHSA-w2m7-r572-689m/GHSA-w2m7-r572-689m.json new file mode 100644 index 00000000000..af672ebb18f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w2m7-r572-689m/GHSA-w2m7-r572-689m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2m7-r572-689m", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2046" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection.This issue affects Vehicle Tracking System: before 8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2046" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0389" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w2pj-frh6-gjhp/GHSA-w2pj-frh6-gjhp.json b/advisories/unreviewed/2023/07/GHSA-w2pj-frh6-gjhp/GHSA-w2pj-frh6-gjhp.json new file mode 100644 index 00000000000..f6511348a4e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w2pj-frh6-gjhp/GHSA-w2pj-frh6-gjhp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2pj-frh6-gjhp", + "modified": "2023-07-10T18:30:46Z", + "published": "2023-07-10T18:30:46Z", + "aliases": [ + "CVE-2015-10121" + ], + "details": "A vulnerability has been found in Beeliked Microsite Plugin up to 1.0.1 on WordPress and classified as problematic. Affected by this vulnerability is the function embed_handler of the file beelikedmicrosite.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.0.2 is able to address this issue. The identifier of the patch is d23bafb5d05fb2636a2b78331f9d3fca152903dc. It is recommended to upgrade the affected component. The identifier VDB-233365 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-10121" + }, + { + "type": "WEB", + "url": "https://github.com/wp-plugins/beeliked-microsite/commit/d23bafb5d05fb2636a2b78331f9d3fca152903dc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.233365" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.233365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w62c-jf7f-2m62/GHSA-w62c-jf7f-2m62.json b/advisories/unreviewed/2023/07/GHSA-w62c-jf7f-2m62/GHSA-w62c-jf7f-2m62.json new file mode 100644 index 00000000000..69841fdc4f1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w62c-jf7f-2m62/GHSA-w62c-jf7f-2m62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w62c-jf7f-2m62", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-25478" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jason Rouet Weather Station plugin <= 3.8.12 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/live-weather-station/wordpress-weather-station-plugin-3-8-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wc7f-hjq2-jvv5/GHSA-wc7f-hjq2-jvv5.json b/advisories/unreviewed/2023/07/GHSA-wc7f-hjq2-jvv5/GHSA-wc7f-hjq2-jvv5.json index bf41b0f09be..821aae8d658 100644 --- a/advisories/unreviewed/2023/07/GHSA-wc7f-hjq2-jvv5/GHSA-wc7f-hjq2-jvv5.json +++ b/advisories/unreviewed/2023/07/GHSA-wc7f-hjq2-jvv5/GHSA-wc7f-hjq2-jvv5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json b/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json new file mode 100644 index 00000000000..58d54995c28 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wf5c-q6vq-584r/GHSA-wf5c-q6vq-584r.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf5c-q6vq-584r", + "modified": "2023-07-10T18:30:47Z", + "published": "2023-07-10T18:30:47Z", + "aliases": [ + "CVE-2021-42080" + ], + "details": "An attacker is able to launch a Reflected XSS attack using a crafted URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42080" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2021-42080" + }, + { + "type": "WEB", + "url": "https://www.divd.nl/DIVD-2021-00020" + }, + { + "type": "WEB", + "url": "https://www.osnexus.com/products/software-defined-storage" + }, + { + "type": "WEB", + "url": "https://www.wbsec.nl/osnexus" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wjjh-7pqv-62xr/GHSA-wjjh-7pqv-62xr.json b/advisories/unreviewed/2023/07/GHSA-wjjh-7pqv-62xr/GHSA-wjjh-7pqv-62xr.json new file mode 100644 index 00000000000..b46c5f897d7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wjjh-7pqv-62xr/GHSA-wjjh-7pqv-62xr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjjh-7pqv-62xr", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-23804" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23804" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ht-instagram/wordpress-ht-feed-plugin-1-2-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x5q4-vvh5-cpgr/GHSA-x5q4-vvh5-cpgr.json b/advisories/unreviewed/2023/07/GHSA-x5q4-vvh5-cpgr/GHSA-x5q4-vvh5-cpgr.json index 4049578dc59..d3d4f19ab4a 100644 --- a/advisories/unreviewed/2023/07/GHSA-x5q4-vvh5-cpgr/GHSA-x5q4-vvh5-cpgr.json +++ b/advisories/unreviewed/2023/07/GHSA-x5q4-vvh5-cpgr/GHSA-x5q4-vvh5-cpgr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x5q4-vvh5-cpgr", - "modified": "2023-07-01T00:30:45Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-01T00:30:45Z", "aliases": [ "CVE-2023-28364" ], "details": "An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-x682-h73h-4x67/GHSA-x682-h73h-4x67.json b/advisories/unreviewed/2023/07/GHSA-x682-h73h-4x67/GHSA-x682-h73h-4x67.json new file mode 100644 index 00000000000..8b729e6d06b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x682-h73h-4x67/GHSA-x682-h73h-4x67.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x682-h73h-4x67", + "modified": "2023-07-10T18:30:49Z", + "published": "2023-07-10T18:30:49Z", + "aliases": [ + "CVE-2023-3118" + ], + "details": "The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3118" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8a9efc8d-561a-42c6-8e61-ae5c3be581ea" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x6p8-7f9j-2h7f/GHSA-x6p8-7f9j-2h7f.json b/advisories/unreviewed/2023/07/GHSA-x6p8-7f9j-2h7f/GHSA-x6p8-7f9j-2h7f.json index fa4d536b9d6..435a988adaf 100644 --- a/advisories/unreviewed/2023/07/GHSA-x6p8-7f9j-2h7f/GHSA-x6p8-7f9j-2h7f.json +++ b/advisories/unreviewed/2023/07/GHSA-x6p8-7f9j-2h7f/GHSA-x6p8-7f9j-2h7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6p8-7f9j-2h7f", - "modified": "2023-07-03T21:30:57Z", + "modified": "2023-07-10T18:30:42Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-36162" ], "details": "Cross Site Request Forgery vulnerability in ZZCMS v.2023 alows a remote attacker to gain privileges via the add function in adminlist.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-x97p-8gc6-fvc3/GHSA-x97p-8gc6-fvc3.json b/advisories/unreviewed/2023/07/GHSA-x97p-8gc6-fvc3/GHSA-x97p-8gc6-fvc3.json new file mode 100644 index 00000000000..b04e43e333c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x97p-8gc6-fvc3/GHSA-x97p-8gc6-fvc3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x97p-8gc6-fvc3", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-23869" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/google-mobile-sitemap/wordpress-google-xml-sitemap-for-mobile-plugin-1-6-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xcmc-r5gr-ffh3/GHSA-xcmc-r5gr-ffh3.json b/advisories/unreviewed/2023/07/GHSA-xcmc-r5gr-ffh3/GHSA-xcmc-r5gr-ffh3.json new file mode 100644 index 00000000000..bc370a5615e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xcmc-r5gr-ffh3/GHSA-xcmc-r5gr-ffh3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcmc-r5gr-ffh3", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-28989" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/happy-elementor-addons/wordpress-happy-addons-for-elementor-plugin-3-8-2-cross-site-request-forgery-csrf-on-collect-data-popup?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xhx3-c8wc-wmrr/GHSA-xhx3-c8wc-wmrr.json b/advisories/unreviewed/2023/07/GHSA-xhx3-c8wc-wmrr/GHSA-xhx3-c8wc-wmrr.json new file mode 100644 index 00000000000..91bebf121d3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xhx3-c8wc-wmrr/GHSA-xhx3-c8wc-wmrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhx3-c8wc-wmrr", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2852" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection.This issue affects SelfPatron : before 2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2852" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xjj7-5xwp-h6p7/GHSA-xjj7-5xwp-h6p7.json b/advisories/unreviewed/2023/07/GHSA-xjj7-5xwp-h6p7/GHSA-xjj7-5xwp-h6p7.json new file mode 100644 index 00000000000..43f8680a78a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xjj7-5xwp-h6p7/GHSA-xjj7-5xwp-h6p7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjj7-5xwp-h6p7", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-27558" + ], + "details": "IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27558" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/249194" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7010571" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xjqq-3xrg-fh6j/GHSA-xjqq-3xrg-fh6j.json b/advisories/unreviewed/2023/07/GHSA-xjqq-3xrg-fh6j/GHSA-xjqq-3xrg-fh6j.json index 50022f77b38..902bcb396ce 100644 --- a/advisories/unreviewed/2023/07/GHSA-xjqq-3xrg-fh6j/GHSA-xjqq-3xrg-fh6j.json +++ b/advisories/unreviewed/2023/07/GHSA-xjqq-3xrg-fh6j/GHSA-xjqq-3xrg-fh6j.json @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5450" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5451" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-22/" diff --git a/advisories/unreviewed/2023/07/GHSA-xmhp-p9h6-3cqm/GHSA-xmhp-p9h6-3cqm.json b/advisories/unreviewed/2023/07/GHSA-xmhp-p9h6-3cqm/GHSA-xmhp-p9h6-3cqm.json new file mode 100644 index 00000000000..8328e402fa5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xmhp-p9h6-3cqm/GHSA-xmhp-p9h6-3cqm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmhp-p9h6-3cqm", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2578" + ], + "details": "The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2578" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4dad1c0d-bcf9-4486-bd8e-387ac8e6c892" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xr8j-gg22-3pqg/GHSA-xr8j-gg22-3pqg.json b/advisories/unreviewed/2023/07/GHSA-xr8j-gg22-3pqg/GHSA-xr8j-gg22-3pqg.json new file mode 100644 index 00000000000..0c265f4cd4f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xr8j-gg22-3pqg/GHSA-xr8j-gg22-3pqg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr8j-gg22-3pqg", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-27540" + ], + "details": "IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27540" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/248924" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7009883" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xw92-6mmh-8cmv/GHSA-xw92-6mmh-8cmv.json b/advisories/unreviewed/2023/07/GHSA-xw92-6mmh-8cmv/GHSA-xw92-6mmh-8cmv.json new file mode 100644 index 00000000000..794997b4051 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xw92-6mmh-8cmv/GHSA-xw92-6mmh-8cmv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw92-6mmh-8cmv", + "modified": "2023-07-10T18:30:48Z", + "published": "2023-07-10T18:30:48Z", + "aliases": [ + "CVE-2023-2029" + ], + "details": "The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2029" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4889ad5a-c8c4-4958-b176-64560490497b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file