From bd49eefd0510930ef2e889d35bcaabc9234424be Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 Nov 2023 18:31:47 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-fq2f-69mj-r56v.json | 4 +- .../GHSA-279q-vh9q-c9w4.json | 11 +++-- .../GHSA-42cp-342j-hw3x.json | 11 +++-- .../GHSA-4qwg-3cm6-6646.json | 13 +++--- .../GHSA-7fj6-6m8r-4v8h.json | 5 ++- .../GHSA-895w-8xj4-27h7.json | 4 +- .../GHSA-9m44-8f44-6rgm.json | 11 +++-- .../GHSA-9xm2-c28x-g93r.json | 13 +++--- .../GHSA-g55h-gq76-w8v9.json | 11 +++-- .../GHSA-grc3-9hxr-2h57.json | 13 +++--- .../GHSA-jh46-rmg6-r59w.json | 13 +++--- .../GHSA-jj8j-m6ch-fccm.json | 4 +- .../GHSA-mpxh-9vrg-gqx5.json | 4 +- .../GHSA-mrhc-jwc8-xfc6.json | 13 +++--- .../GHSA-p2rj-m2c8-2vm5.json | 11 +++-- .../GHSA-q6p3-mrgw-429v.json | 13 +++--- .../GHSA-qxp2-xrrh-x42h.json | 8 ++-- .../GHSA-v5g2-x587-cc7c.json | 11 +++-- .../GHSA-v5h3-pf54-xp87.json | 2 +- .../GHSA-v5x7-5rc8-h4m4.json | 11 +++-- .../GHSA-v8cj-3jcf-7q97.json | 4 +- .../GHSA-wx6j-ww2h-4pfw.json | 13 +++--- .../GHSA-x626-c49h-fr9m.json | 5 ++- .../GHSA-x642-vcqw-qq9v.json | 11 +++-- .../GHSA-42ff-p6q5-g8pg.json | 38 ++++++++++++++++ .../GHSA-4p2f-973w-q7mw.json | 35 +++++++++++++++ .../GHSA-583v-xw8h-qw2h.json | 38 ++++++++++++++++ .../GHSA-5j39-j89r-24vc.json | 35 +++++++++++++++ .../GHSA-663r-36fp-26m6.json | 35 +++++++++++++++ .../GHSA-68hx-hv9v-7v3w.json | 38 ++++++++++++++++ .../GHSA-8qp7-8q8f-4335.json | 38 ++++++++++++++++ .../GHSA-93jh-qvjc-gqxh.json | 35 +++++++++++++++ .../GHSA-9jpw-fc84-wc8p.json | 35 +++++++++++++++ .../GHSA-9rcv-5p26-mp8g.json | 38 ++++++++++++++++ .../GHSA-c65v-cwf9-f69v.json | 38 ++++++++++++++++ .../GHSA-fc42-2hhg-7r35.json | 35 +++++++++++++++ .../GHSA-fq88-7wmr-qmrc.json | 35 +++++++++++++++ .../GHSA-jmwm-w2rm-prv9.json | 43 +++++++++++++++++++ .../GHSA-m86c-6g87-95pq.json | 38 ++++++++++++++++ .../GHSA-mjm5-8p7x-r4cv.json | 38 ++++++++++++++++ .../GHSA-pq6w-72gr-399w.json | 35 +++++++++++++++ .../GHSA-w4wp-hvcq-c5fc.json | 35 +++++++++++++++ 42 files changed, 795 insertions(+), 86 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-42ff-p6q5-g8pg/GHSA-42ff-p6q5-g8pg.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4p2f-973w-q7mw/GHSA-4p2f-973w-q7mw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5j39-j89r-24vc/GHSA-5j39-j89r-24vc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-663r-36fp-26m6/GHSA-663r-36fp-26m6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json create mode 100644 advisories/unreviewed/2023/11/GHSA-93jh-qvjc-gqxh/GHSA-93jh-qvjc-gqxh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9rcv-5p26-mp8g/GHSA-9rcv-5p26-mp8g.json create mode 100644 advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fc42-2hhg-7r35/GHSA-fc42-2hhg-7r35.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fq88-7wmr-qmrc/GHSA-fq88-7wmr-qmrc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jmwm-w2rm-prv9/GHSA-jmwm-w2rm-prv9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-pq6w-72gr-399w/GHSA-pq6w-72gr-399w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w4wp-hvcq-c5fc/GHSA-w4wp-hvcq-c5fc.json diff --git a/advisories/unreviewed/2023/06/GHSA-fq2f-69mj-r56v/GHSA-fq2f-69mj-r56v.json b/advisories/unreviewed/2023/06/GHSA-fq2f-69mj-r56v/GHSA-fq2f-69mj-r56v.json index 160ccd1b151..c750d4e0327 100644 --- a/advisories/unreviewed/2023/06/GHSA-fq2f-69mj-r56v/GHSA-fq2f-69mj-r56v.json +++ b/advisories/unreviewed/2023/06/GHSA-fq2f-69mj-r56v/GHSA-fq2f-69mj-r56v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fq2f-69mj-r56v", - "modified": "2023-06-16T18:30:33Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-06-09T21:30:26Z", "aliases": [ "CVE-2023-27706" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-09T19:15:09Z" diff --git a/advisories/unreviewed/2023/10/GHSA-279q-vh9q-c9w4/GHSA-279q-vh9q-c9w4.json b/advisories/unreviewed/2023/10/GHSA-279q-vh9q-c9w4/GHSA-279q-vh9q-c9w4.json index b94bd12b744..28b17dd2b6c 100644 --- a/advisories/unreviewed/2023/10/GHSA-279q-vh9q-c9w4/GHSA-279q-vh9q-c9w4.json +++ b/advisories/unreviewed/2023/10/GHSA-279q-vh9q-c9w4/GHSA-279q-vh9q-c9w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-279q-vh9q-c9w4", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-4823" ], "details": "The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-42cp-342j-hw3x/GHSA-42cp-342j-hw3x.json b/advisories/unreviewed/2023/10/GHSA-42cp-342j-hw3x/GHSA-42cp-342j-hw3x.json index 271e1d8b1f6..b16686fef1b 100644 --- a/advisories/unreviewed/2023/10/GHSA-42cp-342j-hw3x/GHSA-42cp-342j-hw3x.json +++ b/advisories/unreviewed/2023/10/GHSA-42cp-342j-hw3x/GHSA-42cp-342j-hw3x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42cp-342j-hw3x", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-4390" ], "details": "The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4qwg-3cm6-6646/GHSA-4qwg-3cm6-6646.json b/advisories/unreviewed/2023/10/GHSA-4qwg-3cm6-6646/GHSA-4qwg-3cm6-6646.json index 86fd95022cd..b25e87792ec 100644 --- a/advisories/unreviewed/2023/10/GHSA-4qwg-3cm6-6646/GHSA-4qwg-3cm6-6646.json +++ b/advisories/unreviewed/2023/10/GHSA-4qwg-3cm6-6646/GHSA-4qwg-3cm6-6646.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4qwg-3cm6-6646", - "modified": "2023-10-31T12:30:24Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T12:30:24Z", "aliases": [ "CVE-2015-2968" ], "details": "LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-924" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T10:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7fj6-6m8r-4v8h/GHSA-7fj6-6m8r-4v8h.json b/advisories/unreviewed/2023/10/GHSA-7fj6-6m8r-4v8h/GHSA-7fj6-6m8r-4v8h.json index 990331008ce..86e6bbc60cf 100644 --- a/advisories/unreviewed/2023/10/GHSA-7fj6-6m8r-4v8h/GHSA-7fj6-6m8r-4v8h.json +++ b/advisories/unreviewed/2023/10/GHSA-7fj6-6m8r-4v8h/GHSA-7fj6-6m8r-4v8h.json @@ -36,11 +36,12 @@ ], "database_specific": { "cwe_ids": [ - "CWE-434" + "CWE-434", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-895w-8xj4-27h7/GHSA-895w-8xj4-27h7.json b/advisories/unreviewed/2023/10/GHSA-895w-8xj4-27h7/GHSA-895w-8xj4-27h7.json index 47fc07b155d..65102c4e284 100644 --- a/advisories/unreviewed/2023/10/GHSA-895w-8xj4-27h7/GHSA-895w-8xj4-27h7.json +++ b/advisories/unreviewed/2023/10/GHSA-895w-8xj4-27h7/GHSA-895w-8xj4-27h7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-895w-8xj4-27h7", - "modified": "2023-10-01T00:30:18Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-01T00:30:18Z", "aliases": [ "CVE-2023-43724" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-30T22:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-9m44-8f44-6rgm/GHSA-9m44-8f44-6rgm.json b/advisories/unreviewed/2023/10/GHSA-9m44-8f44-6rgm/GHSA-9m44-8f44-6rgm.json index 7f0e59c4761..5f10a01308e 100644 --- a/advisories/unreviewed/2023/10/GHSA-9m44-8f44-6rgm/GHSA-9m44-8f44-6rgm.json +++ b/advisories/unreviewed/2023/10/GHSA-9m44-8f44-6rgm/GHSA-9m44-8f44-6rgm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m44-8f44-6rgm", - "modified": "2023-10-31T03:31:22Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T03:31:22Z", "aliases": [ "CVE-2023-45899" ], "details": "An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-31T02:15:07Z" diff --git a/advisories/unreviewed/2023/10/GHSA-9xm2-c28x-g93r/GHSA-9xm2-c28x-g93r.json b/advisories/unreviewed/2023/10/GHSA-9xm2-c28x-g93r/GHSA-9xm2-c28x-g93r.json index 3762dc7fb65..4044600fb44 100644 --- a/advisories/unreviewed/2023/10/GHSA-9xm2-c28x-g93r/GHSA-9xm2-c28x-g93r.json +++ b/advisories/unreviewed/2023/10/GHSA-9xm2-c28x-g93r/GHSA-9xm2-c28x-g93r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9xm2-c28x-g93r", - "modified": "2023-10-31T12:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T12:30:23Z", "aliases": [ "CVE-2015-0897" ], "details": "LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,11 +32,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-924" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T10:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json b/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json index 518a5339053..78cdd0d7093 100644 --- a/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json +++ b/advisories/unreviewed/2023/10/GHSA-g55h-gq76-w8v9/GHSA-g55h-gq76-w8v9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g55h-gq76-w8v9", - "modified": "2023-10-31T18:31:44Z", + "modified": "2023-11-08T18:30:31Z", "published": "2023-10-31T18:31:44Z", "aliases": [ "CVE-2023-37831" ], "details": "An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T18:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-grc3-9hxr-2h57/GHSA-grc3-9hxr-2h57.json b/advisories/unreviewed/2023/10/GHSA-grc3-9hxr-2h57/GHSA-grc3-9hxr-2h57.json index dc38810bb94..bdaa257e560 100644 --- a/advisories/unreviewed/2023/10/GHSA-grc3-9hxr-2h57/GHSA-grc3-9hxr-2h57.json +++ b/advisories/unreviewed/2023/10/GHSA-grc3-9hxr-2h57/GHSA-grc3-9hxr-2h57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-grc3-9hxr-2h57", - "modified": "2023-10-31T21:32:35Z", + "modified": "2023-11-08T18:30:31Z", "published": "2023-10-31T21:32:35Z", "aliases": [ "CVE-2023-39610" ], "details": "An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T21:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jh46-rmg6-r59w/GHSA-jh46-rmg6-r59w.json b/advisories/unreviewed/2023/10/GHSA-jh46-rmg6-r59w/GHSA-jh46-rmg6-r59w.json index e1c5b16fc9e..0301111f6a1 100644 --- a/advisories/unreviewed/2023/10/GHSA-jh46-rmg6-r59w/GHSA-jh46-rmg6-r59w.json +++ b/advisories/unreviewed/2023/10/GHSA-jh46-rmg6-r59w/GHSA-jh46-rmg6-r59w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jh46-rmg6-r59w", - "modified": "2023-10-31T06:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T06:30:23Z", "aliases": [ "CVE-2023-47174" ], "details": "Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T04:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jj8j-m6ch-fccm/GHSA-jj8j-m6ch-fccm.json b/advisories/unreviewed/2023/10/GHSA-jj8j-m6ch-fccm/GHSA-jj8j-m6ch-fccm.json index e51cb9cc228..efbaf883640 100644 --- a/advisories/unreviewed/2023/10/GHSA-jj8j-m6ch-fccm/GHSA-jj8j-m6ch-fccm.json +++ b/advisories/unreviewed/2023/10/GHSA-jj8j-m6ch-fccm/GHSA-jj8j-m6ch-fccm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj8j-m6ch-fccm", - "modified": "2023-10-01T00:30:18Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-01T00:30:18Z", "aliases": [ "CVE-2023-43726" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-30T22:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-mpxh-9vrg-gqx5/GHSA-mpxh-9vrg-gqx5.json b/advisories/unreviewed/2023/10/GHSA-mpxh-9vrg-gqx5/GHSA-mpxh-9vrg-gqx5.json index 9f737b8e816..356b6756e6a 100644 --- a/advisories/unreviewed/2023/10/GHSA-mpxh-9vrg-gqx5/GHSA-mpxh-9vrg-gqx5.json +++ b/advisories/unreviewed/2023/10/GHSA-mpxh-9vrg-gqx5/GHSA-mpxh-9vrg-gqx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mpxh-9vrg-gqx5", - "modified": "2023-10-01T00:30:18Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-01T00:30:18Z", "aliases": [ "CVE-2023-43718" @@ -34,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-09-30T22:15:10Z" diff --git a/advisories/unreviewed/2023/10/GHSA-mrhc-jwc8-xfc6/GHSA-mrhc-jwc8-xfc6.json b/advisories/unreviewed/2023/10/GHSA-mrhc-jwc8-xfc6/GHSA-mrhc-jwc8-xfc6.json index 523c90bfa77..4274591a48c 100644 --- a/advisories/unreviewed/2023/10/GHSA-mrhc-jwc8-xfc6/GHSA-mrhc-jwc8-xfc6.json +++ b/advisories/unreviewed/2023/10/GHSA-mrhc-jwc8-xfc6/GHSA-mrhc-jwc8-xfc6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mrhc-jwc8-xfc6", - "modified": "2023-10-31T21:32:35Z", + "modified": "2023-11-08T18:30:31Z", "published": "2023-10-31T21:32:35Z", "aliases": [ "CVE-2023-43295" ], "details": "Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T21:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-p2rj-m2c8-2vm5/GHSA-p2rj-m2c8-2vm5.json b/advisories/unreviewed/2023/10/GHSA-p2rj-m2c8-2vm5/GHSA-p2rj-m2c8-2vm5.json index d9496c49367..b42a0372ba2 100644 --- a/advisories/unreviewed/2023/10/GHSA-p2rj-m2c8-2vm5/GHSA-p2rj-m2c8-2vm5.json +++ b/advisories/unreviewed/2023/10/GHSA-p2rj-m2c8-2vm5/GHSA-p2rj-m2c8-2vm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2rj-m2c8-2vm5", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-4251" ], "details": "The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-q6p3-mrgw-429v/GHSA-q6p3-mrgw-429v.json b/advisories/unreviewed/2023/10/GHSA-q6p3-mrgw-429v/GHSA-q6p3-mrgw-429v.json index d0aef08acc3..585f8461717 100644 --- a/advisories/unreviewed/2023/10/GHSA-q6p3-mrgw-429v/GHSA-q6p3-mrgw-429v.json +++ b/advisories/unreviewed/2023/10/GHSA-q6p3-mrgw-429v/GHSA-q6p3-mrgw-429v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q6p3-mrgw-429v", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-46993" ], "details": "In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-qxp2-xrrh-x42h/GHSA-qxp2-xrrh-x42h.json b/advisories/unreviewed/2023/10/GHSA-qxp2-xrrh-x42h/GHSA-qxp2-xrrh-x42h.json index 8f01ca53ef7..941826028f0 100644 --- a/advisories/unreviewed/2023/10/GHSA-qxp2-xrrh-x42h/GHSA-qxp2-xrrh-x42h.json +++ b/advisories/unreviewed/2023/10/GHSA-qxp2-xrrh-x42h/GHSA-qxp2-xrrh-x42h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxp2-xrrh-x42h", - "modified": "2023-10-31T06:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T06:30:23Z", "aliases": [ "CVE-2023-36263" @@ -28,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T05:15:58Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json b/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json index fab282db6f3..4426debf0f5 100644 --- a/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json +++ b/advisories/unreviewed/2023/10/GHSA-v5g2-x587-cc7c/GHSA-v5g2-x587-cc7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5g2-x587-cc7c", - "modified": "2023-10-31T15:30:24Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T15:30:24Z", "aliases": [ "CVE-2023-46992" ], "details": "TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-v5h3-pf54-xp87/GHSA-v5h3-pf54-xp87.json b/advisories/unreviewed/2023/10/GHSA-v5h3-pf54-xp87/GHSA-v5h3-pf54-xp87.json index 1eed83ac11c..d40517fca81 100644 --- a/advisories/unreviewed/2023/10/GHSA-v5h3-pf54-xp87/GHSA-v5h3-pf54-xp87.json +++ b/advisories/unreviewed/2023/10/GHSA-v5h3-pf54-xp87/GHSA-v5h3-pf54-xp87.json @@ -33,6 +33,6 @@ "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T21:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json b/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json index 519f7317731..18afa2f6dca 100644 --- a/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json +++ b/advisories/unreviewed/2023/10/GHSA-v5x7-5rc8-h4m4/GHSA-v5x7-5rc8-h4m4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5x7-5rc8-h4m4", - "modified": "2023-10-31T18:31:44Z", + "modified": "2023-11-08T18:30:31Z", "published": "2023-10-31T18:31:44Z", "aliases": [ "CVE-2023-5739" ], "details": "Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T16:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-v8cj-3jcf-7q97/GHSA-v8cj-3jcf-7q97.json b/advisories/unreviewed/2023/10/GHSA-v8cj-3jcf-7q97/GHSA-v8cj-3jcf-7q97.json index 85ce056dac1..e168ca35b88 100644 --- a/advisories/unreviewed/2023/10/GHSA-v8cj-3jcf-7q97/GHSA-v8cj-3jcf-7q97.json +++ b/advisories/unreviewed/2023/10/GHSA-v8cj-3jcf-7q97/GHSA-v8cj-3jcf-7q97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8cj-3jcf-7q97", - "modified": "2023-10-31T18:31:44Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-25T18:32:20Z", "aliases": [ "CVE-2023-23767" @@ -45,6 +45,6 @@ "severity": null, "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-25T18:17:23Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-wx6j-ww2h-4pfw/GHSA-wx6j-ww2h-4pfw.json b/advisories/unreviewed/2023/10/GHSA-wx6j-ww2h-4pfw/GHSA-wx6j-ww2h-4pfw.json index 279c0311d8d..980b0ef2a16 100644 --- a/advisories/unreviewed/2023/10/GHSA-wx6j-ww2h-4pfw/GHSA-wx6j-ww2h-4pfw.json +++ b/advisories/unreviewed/2023/10/GHSA-wx6j-ww2h-4pfw/GHSA-wx6j-ww2h-4pfw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wx6j-ww2h-4pfw", - "modified": "2023-10-31T18:31:44Z", + "modified": "2023-11-08T18:30:31Z", "published": "2023-10-31T18:31:44Z", "aliases": [ "CVE-2023-37832" ], "details": "A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,11 +28,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T18:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-x626-c49h-fr9m/GHSA-x626-c49h-fr9m.json b/advisories/unreviewed/2023/10/GHSA-x626-c49h-fr9m/GHSA-x626-c49h-fr9m.json index 2529cfe6790..4209604003b 100644 --- a/advisories/unreviewed/2023/10/GHSA-x626-c49h-fr9m/GHSA-x626-c49h-fr9m.json +++ b/advisories/unreviewed/2023/10/GHSA-x626-c49h-fr9m/GHSA-x626-c49h-fr9m.json @@ -36,11 +36,12 @@ ], "database_specific": { "cwe_ids": [ - "CWE-917" + "CWE-917", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T15:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-x642-vcqw-qq9v/GHSA-x642-vcqw-qq9v.json b/advisories/unreviewed/2023/10/GHSA-x642-vcqw-qq9v/GHSA-x642-vcqw-qq9v.json index 2e1302ccdd3..8f120a76c29 100644 --- a/advisories/unreviewed/2023/10/GHSA-x642-vcqw-qq9v/GHSA-x642-vcqw-qq9v.json +++ b/advisories/unreviewed/2023/10/GHSA-x642-vcqw-qq9v/GHSA-x642-vcqw-qq9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x642-vcqw-qq9v", - "modified": "2023-10-31T15:30:23Z", + "modified": "2023-11-08T18:30:30Z", "published": "2023-10-31T15:30:23Z", "aliases": [ "CVE-2023-4250" ], "details": "The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,9 +30,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, - "nvd_published_at": null + "nvd_published_at": "2023-10-31T14:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-42ff-p6q5-g8pg/GHSA-42ff-p6q5-g8pg.json b/advisories/unreviewed/2023/11/GHSA-42ff-p6q5-g8pg/GHSA-42ff-p6q5-g8pg.json new file mode 100644 index 00000000000..94776e368a1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-42ff-p6q5-g8pg/GHSA-42ff-p6q5-g8pg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42ff-p6q5-g8pg", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-35767" + ], + "details": "In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35767" + }, + { + "type": "WEB", + "url": "https://perforce.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4p2f-973w-q7mw/GHSA-4p2f-973w-q7mw.json b/advisories/unreviewed/2023/11/GHSA-4p2f-973w-q7mw/GHSA-4p2f-973w-q7mw.json new file mode 100644 index 00000000000..890e2622ece --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4p2f-973w-q7mw/GHSA-4p2f-973w-q7mw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p2f-973w-q7mw", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46643" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cloudnet-sync/wordpress-cloudnet360-plugin-3-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json b/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json new file mode 100644 index 00000000000..5132f361eb2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-583v-xw8h-qw2h/GHSA-583v-xw8h-qw2h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-583v-xw8h-qw2h", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-3282" + ], + "details": "A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3282" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2023-3282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5j39-j89r-24vc/GHSA-5j39-j89r-24vc.json b/advisories/unreviewed/2023/11/GHSA-5j39-j89r-24vc/GHSA-5j39-j89r-24vc.json new file mode 100644 index 00000000000..8f0b6fd8bea --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5j39-j89r-24vc/GHSA-5j39-j89r-24vc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j39-j89r-24vc", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46640" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/media-list/wordpress-medialist-plugin-1-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-663r-36fp-26m6/GHSA-663r-36fp-26m6.json b/advisories/unreviewed/2023/11/GHSA-663r-36fp-26m6/GHSA-663r-36fp-26m6.json new file mode 100644 index 00000000000..44740d42839 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-663r-36fp-26m6/GHSA-663r-36fp-26m6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-663r-36fp-26m6", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46626" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FLOWFACT WP Connector plugin <= 2.1.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46626" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/flowfact-wp-connector/wordpress-flowfact-wp-connector-plugin-2-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json b/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json new file mode 100644 index 00000000000..3f44ffaeffd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-68hx-hv9v-7v3w/GHSA-68hx-hv9v-7v3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68hx-hv9v-7v3w", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-5759" + ], + "details": "In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.  \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5759" + }, + { + "type": "WEB", + "url": "https://perforce.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json b/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json new file mode 100644 index 00000000000..03d1565bebd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8qp7-8q8f-4335/GHSA-8qp7-8q8f-4335.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qp7-8q8f-4335", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-45319" + ], + "details": "In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45319" + }, + { + "type": "WEB", + "url": "https://perforce.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-93jh-qvjc-gqxh/GHSA-93jh-qvjc-gqxh.json b/advisories/unreviewed/2023/11/GHSA-93jh-qvjc-gqxh/GHSA-93jh-qvjc-gqxh.json new file mode 100644 index 00000000000..a1f2e2bffe6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-93jh-qvjc-gqxh/GHSA-93jh-qvjc-gqxh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93jh-qvjc-gqxh", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-32298" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kathy Darling Simple User Listing plugin <= 1.9.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-user-listing/wordpress-simple-user-listing-plugin-1-9-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json b/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json new file mode 100644 index 00000000000..bf5c1277aff --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jpw-fc84-wc8p", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46621" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46621" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-avatar/wordpress-user-avatar-plugin-1-4-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9rcv-5p26-mp8g/GHSA-9rcv-5p26-mp8g.json b/advisories/unreviewed/2023/11/GHSA-9rcv-5p26-mp8g/GHSA-9rcv-5p26-mp8g.json new file mode 100644 index 00000000000..3f1bdf79083 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9rcv-5p26-mp8g/GHSA-9rcv-5p26-mp8g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rcv-5p26-mp8g", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-45849" + ], + "details": "An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45849" + }, + { + "type": "WEB", + "url": "https://perforce.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json b/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json new file mode 100644 index 00000000000..5d09722848f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-c65v-cwf9-f69v/GHSA-c65v-cwf9-f69v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c65v-cwf9-f69v", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-5760" + ], + "details": "A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5760" + }, + { + "type": "WEB", + "url": "https://support.norton.com/sp/static/external/tools/security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fc42-2hhg-7r35/GHSA-fc42-2hhg-7r35.json b/advisories/unreviewed/2023/11/GHSA-fc42-2hhg-7r35/GHSA-fc42-2hhg-7r35.json new file mode 100644 index 00000000000..9892bc9b3da --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fc42-2hhg-7r35/GHSA-fc42-2hhg-7r35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc42-2hhg-7r35", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46627" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-simple-html-sitemap/wordpress-wordpress-simple-html-sitemap-plugin-2-1-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fq88-7wmr-qmrc/GHSA-fq88-7wmr-qmrc.json b/advisories/unreviewed/2023/11/GHSA-fq88-7wmr-qmrc/GHSA-fq88-7wmr-qmrc.json new file mode 100644 index 00000000000..3aff57dc809 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fq88-7wmr-qmrc/GHSA-fq88-7wmr-qmrc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq88-7wmr-qmrc", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-47397" + ], + "details": "WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47397" + }, + { + "type": "WEB", + "url": "https://liotree.github.io/2023/webid.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jmwm-w2rm-prv9/GHSA-jmwm-w2rm-prv9.json b/advisories/unreviewed/2023/11/GHSA-jmwm-w2rm-prv9/GHSA-jmwm-w2rm-prv9.json new file mode 100644 index 00000000000..cc38ccf066d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jmwm-w2rm-prv9/GHSA-jmwm-w2rm-prv9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmwm-w2rm-prv9", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-47379" + ], + "details": "Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47379" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/commit/c6e7ea9d0abd7564a3bb23c14ad172e4ccf27a7e#diff-fac4e7e9eca69c10d074bf8c5eac7f64b018c6b4d91dcad54b340a8560049e00" + }, + { + "type": "WEB", + "url": "https://github.com/microweber/microweber/blob/master/CHANGELOG.md" + }, + { + "type": "WEB", + "url": "https://www.getastra.com/blog/security-audit/stored-xss-vulnerability/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json b/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json new file mode 100644 index 00000000000..d379aa64c2c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m86c-6g87-95pq/GHSA-m86c-6g87-95pq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m86c-6g87-95pq", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-5913" + ], + "details": "Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5913" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000023500?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json b/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json new file mode 100644 index 00000000000..af918dcc56b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mjm5-8p7x-r4cv/GHSA-mjm5-8p7x-r4cv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjm5-8p7x-r4cv", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-5136" + ], + "details": "An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5136" + }, + { + "type": "WEB", + "url": "https://www.ni.com/en/support/documentation/supplemental/23/incorrect-permission-assignment-in-the-topografix-dataplug-for-gpx.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pq6w-72gr-399w/GHSA-pq6w-72gr-399w.json b/advisories/unreviewed/2023/11/GHSA-pq6w-72gr-399w/GHSA-pq6w-72gr-399w.json new file mode 100644 index 00000000000..63f9933532a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-pq6w-72gr-399w/GHSA-pq6w-72gr-399w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq6w-72gr-399w", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46613" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <= 1.5.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-to-calendar-button/wordpress-add-to-calendar-button-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w4wp-hvcq-c5fc/GHSA-w4wp-hvcq-c5fc.json b/advisories/unreviewed/2023/11/GHSA-w4wp-hvcq-c5fc/GHSA-w4wp-hvcq-c5fc.json new file mode 100644 index 00000000000..b518d84adae --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w4wp-hvcq-c5fc/GHSA-w4wp-hvcq-c5fc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4wp-hvcq-c5fc", + "modified": "2023-11-08T18:30:31Z", + "published": "2023-11-08T18:30:31Z", + "aliases": [ + "CVE-2023-46642" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin <= 1.2.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46642" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sahu-tiktok-pixel/wordpress-sahu-tiktok-pixel-for-e-commerce-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-08T17:15:07Z" + } +} \ No newline at end of file