diff --git a/advisories/unreviewed/2022/10/GHSA-vxr6-pwvm-cf57/GHSA-vxr6-pwvm-cf57.json b/advisories/unreviewed/2022/10/GHSA-vxr6-pwvm-cf57/GHSA-vxr6-pwvm-cf57.json index 2d927f7d17a..56ae44a0715 100644 --- a/advisories/unreviewed/2022/10/GHSA-vxr6-pwvm-cf57/GHSA-vxr6-pwvm-cf57.json +++ b/advisories/unreviewed/2022/10/GHSA-vxr6-pwvm-cf57/GHSA-vxr6-pwvm-cf57.json @@ -28,6 +28,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1390", + "CWE-287", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/11/GHSA-cpwf-rj72-cfwc/GHSA-cpwf-rj72-cfwc.json b/advisories/unreviewed/2022/11/GHSA-cpwf-rj72-cfwc/GHSA-cpwf-rj72-cfwc.json index 4e616e6fe6c..b16f742a653 100644 --- a/advisories/unreviewed/2022/11/GHSA-cpwf-rj72-cfwc/GHSA-cpwf-rj72-cfwc.json +++ b/advisories/unreviewed/2022/11/GHSA-cpwf-rj72-cfwc/GHSA-cpwf-rj72-cfwc.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-416", "CWE-787" ], diff --git a/advisories/unreviewed/2022/11/GHSA-mh68-qf2j-8c5g/GHSA-mh68-qf2j-8c5g.json b/advisories/unreviewed/2022/11/GHSA-mh68-qf2j-8c5g/GHSA-mh68-qf2j-8c5g.json index 9a6f4da4074..3c569830bf0 100644 --- a/advisories/unreviewed/2022/11/GHSA-mh68-qf2j-8c5g/GHSA-mh68-qf2j-8c5g.json +++ b/advisories/unreviewed/2022/11/GHSA-mh68-qf2j-8c5g/GHSA-mh68-qf2j-8c5g.json @@ -40,6 +40,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-158", "CWE-74" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/11/GHSA-qj9h-vqcc-rfjq/GHSA-qj9h-vqcc-rfjq.json b/advisories/unreviewed/2022/11/GHSA-qj9h-vqcc-rfjq/GHSA-qj9h-vqcc-rfjq.json index acf7f7c7597..cd83f7de1f5 100644 --- a/advisories/unreviewed/2022/11/GHSA-qj9h-vqcc-rfjq/GHSA-qj9h-vqcc-rfjq.json +++ b/advisories/unreviewed/2022/11/GHSA-qj9h-vqcc-rfjq/GHSA-qj9h-vqcc-rfjq.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-4gv4-7phc-2jw7/GHSA-4gv4-7phc-2jw7.json b/advisories/unreviewed/2022/12/GHSA-4gv4-7phc-2jw7/GHSA-4gv4-7phc-2jw7.json index 66e947fa11b..11b1a2319e7 100644 --- a/advisories/unreviewed/2022/12/GHSA-4gv4-7phc-2jw7/GHSA-4gv4-7phc-2jw7.json +++ b/advisories/unreviewed/2022/12/GHSA-4gv4-7phc-2jw7/GHSA-4gv4-7phc-2jw7.json @@ -32,7 +32,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-497", + "CWE-668", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-c9cm-rvww-38hx/GHSA-c9cm-rvww-38hx.json b/advisories/unreviewed/2022/12/GHSA-c9cm-rvww-38hx/GHSA-c9cm-rvww-38hx.json index 8edeac7fe64..fd770311fc5 100644 --- a/advisories/unreviewed/2022/12/GHSA-c9cm-rvww-38hx/GHSA-c9cm-rvww-38hx.json +++ b/advisories/unreviewed/2022/12/GHSA-c9cm-rvww-38hx/GHSA-c9cm-rvww-38hx.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json b/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json index 9f5afacf9f0..3c21d261cf0 100644 --- a/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json +++ b/advisories/unreviewed/2022/12/GHSA-hcc6-fp5w-rfrr/GHSA-hcc6-fp5w-rfrr.json @@ -41,6 +41,7 @@ "database_specific": { "cwe_ids": [ "CWE-121", + "CWE-125", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-m5gg-2gxj-3qqx/GHSA-m5gg-2gxj-3qqx.json b/advisories/unreviewed/2022/12/GHSA-m5gg-2gxj-3qqx/GHSA-m5gg-2gxj-3qqx.json index 45cabc92811..18efc9fa8be 100644 --- a/advisories/unreviewed/2022/12/GHSA-m5gg-2gxj-3qqx/GHSA-m5gg-2gxj-3qqx.json +++ b/advisories/unreviewed/2022/12/GHSA-m5gg-2gxj-3qqx/GHSA-m5gg-2gxj-3qqx.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-x8v4-7grp-4rw2/GHSA-x8v4-7grp-4rw2.json b/advisories/unreviewed/2022/12/GHSA-x8v4-7grp-4rw2/GHSA-x8v4-7grp-4rw2.json index a0b083f8daa..1ac3987d3d7 100644 --- a/advisories/unreviewed/2022/12/GHSA-x8v4-7grp-4rw2/GHSA-x8v4-7grp-4rw2.json +++ b/advisories/unreviewed/2022/12/GHSA-x8v4-7grp-4rw2/GHSA-x8v4-7grp-4rw2.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-3fq4-7v27-7g49/GHSA-3fq4-7v27-7g49.json b/advisories/unreviewed/2023/01/GHSA-3fq4-7v27-7g49/GHSA-3fq4-7v27-7g49.json index 5921ba968ab..7196e2bfa76 100644 --- a/advisories/unreviewed/2023/01/GHSA-3fq4-7v27-7g49/GHSA-3fq4-7v27-7g49.json +++ b/advisories/unreviewed/2023/01/GHSA-3fq4-7v27-7g49/GHSA-3fq4-7v27-7g49.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json b/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json index e4bed4650de..ca0854c119c 100644 --- a/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json +++ b/advisories/unreviewed/2023/01/GHSA-5r4m-496r-7wqm/GHSA-5r4m-496r-7wqm.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-416" + "CWE-416", + "CWE-476" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-gfr8-qfh4-r5rc/GHSA-gfr8-qfh4-r5rc.json b/advisories/unreviewed/2023/01/GHSA-gfr8-qfh4-r5rc/GHSA-gfr8-qfh4-r5rc.json index a1f005b95e3..d8356de64ee 100644 --- a/advisories/unreviewed/2023/01/GHSA-gfr8-qfh4-r5rc/GHSA-gfr8-qfh4-r5rc.json +++ b/advisories/unreviewed/2023/01/GHSA-gfr8-qfh4-r5rc/GHSA-gfr8-qfh4-r5rc.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1188", "CWE-453" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/02/GHSA-h346-g45r-r5rw/GHSA-h346-g45r-r5rw.json b/advisories/unreviewed/2023/02/GHSA-h346-g45r-r5rw/GHSA-h346-g45r-r5rw.json index 85e66dab034..d1e8117c176 100644 --- a/advisories/unreviewed/2023/02/GHSA-h346-g45r-r5rw/GHSA-h346-g45r-r5rw.json +++ b/advisories/unreviewed/2023/02/GHSA-h346-g45r-r5rw/GHSA-h346-g45r-r5rw.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-269" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-2x7r-m54m-f2pf/GHSA-2x7r-m54m-f2pf.json b/advisories/unreviewed/2023/06/GHSA-2x7r-m54m-f2pf/GHSA-2x7r-m54m-f2pf.json new file mode 100644 index 00000000000..95691350f7b --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-2x7r-m54m-f2pf/GHSA-2x7r-m54m-f2pf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x7r-m54m-f2pf", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2877" + ], + "details": "The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2877" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/33765da5-c56e-42c1-83dd-fcaad976b402" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-2xjf-f4mq-m3q5/GHSA-2xjf-f4mq-m3q5.json b/advisories/unreviewed/2023/06/GHSA-2xjf-f4mq-m3q5/GHSA-2xjf-f4mq-m3q5.json new file mode 100644 index 00000000000..5ce0a37e63d --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-2xjf-f4mq-m3q5/GHSA-2xjf-f4mq-m3q5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xjf-f4mq-m3q5", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2624" + ], + "details": "The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2624" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dc3a841d-a95b-462e-be4b-acaa44e77264" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-3992-5mfp-43q5/GHSA-3992-5mfp-43q5.json b/advisories/unreviewed/2023/06/GHSA-3992-5mfp-43q5/GHSA-3992-5mfp-43q5.json new file mode 100644 index 00000000000..4591b4daa1e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-3992-5mfp-43q5/GHSA-3992-5mfp-43q5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3992-5mfp-43q5", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2326" + ], + "details": "The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2326" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f922695a-b803-4edf-aadc-80c79d99bebb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-3hmp-qggx-jm2c/GHSA-3hmp-qggx-jm2c.json b/advisories/unreviewed/2023/06/GHSA-3hmp-qggx-jm2c/GHSA-3hmp-qggx-jm2c.json new file mode 100644 index 00000000000..164ab1a085b --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-3hmp-qggx-jm2c/GHSA-3hmp-qggx-jm2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hmp-qggx-jm2c", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2744" + ], + "details": "The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2744" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/435da8a1-9955-46d7-a508-b5738259e731" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-3rqp-wp5p-mhrc/GHSA-3rqp-wp5p-mhrc.json b/advisories/unreviewed/2023/06/GHSA-3rqp-wp5p-mhrc/GHSA-3rqp-wp5p-mhrc.json new file mode 100644 index 00000000000..74f60bc51f0 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-3rqp-wp5p-mhrc/GHSA-3rqp-wp5p-mhrc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rqp-wp5p-mhrc", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2601" + ], + "details": "The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2601" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/57769468-3802-4985-bf5e-44ec1d59f5fd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-3x5r-c923-f923/GHSA-3x5r-c923-f923.json b/advisories/unreviewed/2023/06/GHSA-3x5r-c923-f923/GHSA-3x5r-c923-f923.json index 0e443e41757..74fbbd9b315 100644 --- a/advisories/unreviewed/2023/06/GHSA-3x5r-c923-f923/GHSA-3x5r-c923-f923.json +++ b/advisories/unreviewed/2023/06/GHSA-3x5r-c923-f923/GHSA-3x5r-c923-f923.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x5r-c923-f923", - "modified": "2023-06-23T18:30:24Z", + "modified": "2023-06-27T15:30:28Z", "published": "2023-06-23T18:30:24Z", "aliases": [ "CVE-2023-32373" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, iOS 15.7.6 and iPadOS 15.7.6, macOS Ventura 13.4, Safari 16.5, tvOS 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-433m-h5jj-8j5m/GHSA-433m-h5jj-8j5m.json b/advisories/unreviewed/2023/06/GHSA-433m-h5jj-8j5m/GHSA-433m-h5jj-8j5m.json index 8bea5799beb..06408fe8960 100644 --- a/advisories/unreviewed/2023/06/GHSA-433m-h5jj-8j5m/GHSA-433m-h5jj-8j5m.json +++ b/advisories/unreviewed/2023/06/GHSA-433m-h5jj-8j5m/GHSA-433m-h5jj-8j5m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-433m-h5jj-8j5m", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-2805" ], "details": "The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-44c7-92p2-r6w4/GHSA-44c7-92p2-r6w4.json b/advisories/unreviewed/2023/06/GHSA-44c7-92p2-r6w4/GHSA-44c7-92p2-r6w4.json index a6415b46e21..fe368649caa 100644 --- a/advisories/unreviewed/2023/06/GHSA-44c7-92p2-r6w4/GHSA-44c7-92p2-r6w4.json +++ b/advisories/unreviewed/2023/06/GHSA-44c7-92p2-r6w4/GHSA-44c7-92p2-r6w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-44c7-92p2-r6w4", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-2811" ], "details": "The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-4wgc-vg4p-9q74/GHSA-4wgc-vg4p-9q74.json b/advisories/unreviewed/2023/06/GHSA-4wgc-vg4p-9q74/GHSA-4wgc-vg4p-9q74.json new file mode 100644 index 00000000000..b78453fcd07 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-4wgc-vg4p-9q74/GHSA-4wgc-vg4p-9q74.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wgc-vg4p-9q74", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2021-30203" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-30203" + }, + { + "type": "WEB", + "url": "https://github.com/zyx0814/dzzoffice/issues/183" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json b/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json index 28e8fe40196..f249af3f6bf 100644 --- a/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json +++ b/advisories/unreviewed/2023/06/GHSA-5q9f-4pxq-x2gv/GHSA-5q9f-4pxq-x2gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q9f-4pxq-x2gv", - "modified": "2023-06-23T18:30:23Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-23T18:30:23Z", "aliases": [ "CVE-2023-28191" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. An app may be able to bypass Privacy preferences", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-5wv9-h9hr-4p52/GHSA-5wv9-h9hr-4p52.json b/advisories/unreviewed/2023/06/GHSA-5wv9-h9hr-4p52/GHSA-5wv9-h9hr-4p52.json index 1b2964c0dfd..8e21ceeb2bf 100644 --- a/advisories/unreviewed/2023/06/GHSA-5wv9-h9hr-4p52/GHSA-5wv9-h9hr-4p52.json +++ b/advisories/unreviewed/2023/06/GHSA-5wv9-h9hr-4p52/GHSA-5wv9-h9hr-4p52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wv9-h9hr-4p52", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-27992" diff --git a/advisories/unreviewed/2023/06/GHSA-638h-xgr5-q9r9/GHSA-638h-xgr5-q9r9.json b/advisories/unreviewed/2023/06/GHSA-638h-xgr5-q9r9/GHSA-638h-xgr5-q9r9.json new file mode 100644 index 00000000000..3e1d00be821 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-638h-xgr5-q9r9/GHSA-638h-xgr5-q9r9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-638h-xgr5-q9r9", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2628" + ], + "details": "The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2628" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e0741e2c-c529-4815-8744-16e01cdb0aed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-6h38-5jv9-8r57/GHSA-6h38-5jv9-8r57.json b/advisories/unreviewed/2023/06/GHSA-6h38-5jv9-8r57/GHSA-6h38-5jv9-8r57.json new file mode 100644 index 00000000000..7d3082ddfab --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-6h38-5jv9-8r57/GHSA-6h38-5jv9-8r57.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h38-5jv9-8r57", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2068" + ], + "details": "The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2068" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-6h5p-4q9x-7ch2/GHSA-6h5p-4q9x-7ch2.json b/advisories/unreviewed/2023/06/GHSA-6h5p-4q9x-7ch2/GHSA-6h5p-4q9x-7ch2.json new file mode 100644 index 00000000000..1bde3c7fa15 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-6h5p-4q9x-7ch2/GHSA-6h5p-4q9x-7ch2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h5p-4q9x-7ch2", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-35998" + ], + "details": "A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35998" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-6mq7-w565-8rf7/GHSA-6mq7-w565-8rf7.json b/advisories/unreviewed/2023/06/GHSA-6mq7-w565-8rf7/GHSA-6mq7-w565-8rf7.json index ee176fb8217..53baf3f313a 100644 --- a/advisories/unreviewed/2023/06/GHSA-6mq7-w565-8rf7/GHSA-6mq7-w565-8rf7.json +++ b/advisories/unreviewed/2023/06/GHSA-6mq7-w565-8rf7/GHSA-6mq7-w565-8rf7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mq7-w565-8rf7", - "modified": "2023-06-19T18:30:49Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T18:30:49Z", "aliases": [ "CVE-2023-3312" ], "details": "A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-78wc-m3h8-p6cc/GHSA-78wc-m3h8-p6cc.json b/advisories/unreviewed/2023/06/GHSA-78wc-m3h8-p6cc/GHSA-78wc-m3h8-p6cc.json new file mode 100644 index 00000000000..98005d68c5b --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-78wc-m3h8-p6cc/GHSA-78wc-m3h8-p6cc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78wc-m3h8-p6cc", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2592" + ], + "details": "The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2592" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d4298960-eaba-4185-a730-3e621d9680e1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-7wj9-m5hv-mcmx/GHSA-7wj9-m5hv-mcmx.json b/advisories/unreviewed/2023/06/GHSA-7wj9-m5hv-mcmx/GHSA-7wj9-m5hv-mcmx.json new file mode 100644 index 00000000000..5532f4a8ce6 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-7wj9-m5hv-mcmx/GHSA-7wj9-m5hv-mcmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wj9-m5hv-mcmx", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-36000" + ], + "details": "A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36000" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-84hr-677c-vfx6/GHSA-84hr-677c-vfx6.json b/advisories/unreviewed/2023/06/GHSA-84hr-677c-vfx6/GHSA-84hr-677c-vfx6.json index 84082226e0f..123e75d90d2 100644 --- a/advisories/unreviewed/2023/06/GHSA-84hr-677c-vfx6/GHSA-84hr-677c-vfx6.json +++ b/advisories/unreviewed/2023/06/GHSA-84hr-677c-vfx6/GHSA-84hr-677c-vfx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84hr-677c-vfx6", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-2779" ], "details": "The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-84qc-gm86-22q4/GHSA-84qc-gm86-22q4.json b/advisories/unreviewed/2023/06/GHSA-84qc-gm86-22q4/GHSA-84qc-gm86-22q4.json index aabec291c80..10eedf86328 100644 --- a/advisories/unreviewed/2023/06/GHSA-84qc-gm86-22q4/GHSA-84qc-gm86-22q4.json +++ b/advisories/unreviewed/2023/06/GHSA-84qc-gm86-22q4/GHSA-84qc-gm86-22q4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-84qc-gm86-22q4", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-35862" ], "details": "libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-8593-q8c6-2ggq/GHSA-8593-q8c6-2ggq.json b/advisories/unreviewed/2023/06/GHSA-8593-q8c6-2ggq/GHSA-8593-q8c6-2ggq.json new file mode 100644 index 00000000000..16d460888d6 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-8593-q8c6-2ggq/GHSA-8593-q8c6-2ggq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8593-q8c6-2ggq", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2178" + ], + "details": "The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2178" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e84b71f9-4208-4efb-90e8-1c778e7d2ebb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-89r6-wrjm-5xx8/GHSA-89r6-wrjm-5xx8.json b/advisories/unreviewed/2023/06/GHSA-89r6-wrjm-5xx8/GHSA-89r6-wrjm-5xx8.json new file mode 100644 index 00000000000..ebefed1e0d1 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-89r6-wrjm-5xx8/GHSA-89r6-wrjm-5xx8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89r6-wrjm-5xx8", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2842" + ], + "details": "The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2842" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0357ecc7-56f5-4843-a928-bf2d3ce75596" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-8crr-r6cj-54v5/GHSA-8crr-r6cj-54v5.json b/advisories/unreviewed/2023/06/GHSA-8crr-r6cj-54v5/GHSA-8crr-r6cj-54v5.json new file mode 100644 index 00000000000..f3ecc524e7f --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-8crr-r6cj-54v5/GHSA-8crr-r6cj-54v5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8crr-r6cj-54v5", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2711" + ], + "details": "The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2711" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/71c5b5b5-8694-4738-8e4b-8670a8d21c86" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-8j78-9w7g-w7xq/GHSA-8j78-9w7g-w7xq.json b/advisories/unreviewed/2023/06/GHSA-8j78-9w7g-w7xq/GHSA-8j78-9w7g-w7xq.json new file mode 100644 index 00000000000..f628a11a181 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-8j78-9w7g-w7xq/GHSA-8j78-9w7g-w7xq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j78-9w7g-w7xq", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-0873" + ], + "details": "The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0873" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8816d4c1-9e8e-4b6f-a36a-10a98a7ccfcd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-8jx9-g99g-q9g3/GHSA-8jx9-g99g-q9g3.json b/advisories/unreviewed/2023/06/GHSA-8jx9-g99g-q9g3/GHSA-8jx9-g99g-q9g3.json new file mode 100644 index 00000000000..2a8074c1979 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-8jx9-g99g-q9g3/GHSA-8jx9-g99g-q9g3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jx9-g99g-q9g3", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-0588" + ], + "details": "The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0588" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/84be272e-0891-461c-91ad-496b64f92f8f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-8wqh-3wxx-4342/GHSA-8wqh-3wxx-4342.json b/advisories/unreviewed/2023/06/GHSA-8wqh-3wxx-4342/GHSA-8wqh-3wxx-4342.json index 9a227d617db..bc2636d0a42 100644 --- a/advisories/unreviewed/2023/06/GHSA-8wqh-3wxx-4342/GHSA-8wqh-3wxx-4342.json +++ b/advisories/unreviewed/2023/06/GHSA-8wqh-3wxx-4342/GHSA-8wqh-3wxx-4342.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8wqh-3wxx-4342", - "modified": "2023-06-21T15:30:21Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-21T15:30:21Z", "aliases": [ "CVE-2023-33584" ], "details": "Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-9554-2wcv-jccj/GHSA-9554-2wcv-jccj.json b/advisories/unreviewed/2023/06/GHSA-9554-2wcv-jccj/GHSA-9554-2wcv-jccj.json index 42e54f11535..9c1473fc8af 100644 --- a/advisories/unreviewed/2023/06/GHSA-9554-2wcv-jccj/GHSA-9554-2wcv-jccj.json +++ b/advisories/unreviewed/2023/06/GHSA-9554-2wcv-jccj/GHSA-9554-2wcv-jccj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9554-2wcv-jccj", - "modified": "2023-06-20T09:30:23Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-35882" diff --git a/advisories/unreviewed/2023/06/GHSA-c3jj-9wrg-44g9/GHSA-c3jj-9wrg-44g9.json b/advisories/unreviewed/2023/06/GHSA-c3jj-9wrg-44g9/GHSA-c3jj-9wrg-44g9.json new file mode 100644 index 00000000000..1fd33aef82b --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-c3jj-9wrg-44g9/GHSA-c3jj-9wrg-44g9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3jj-9wrg-44g9", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2022-4115" + ], + "details": "The Editorial Calendar WordPress plugin through 3.7.12 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4115" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2b5071e1-9532-4a6c-9da4-d07932474ca4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-c72v-pj75-jmf4/GHSA-c72v-pj75-jmf4.json b/advisories/unreviewed/2023/06/GHSA-c72v-pj75-jmf4/GHSA-c72v-pj75-jmf4.json index 28a8428a66e..0b76b4d7571 100644 --- a/advisories/unreviewed/2023/06/GHSA-c72v-pj75-jmf4/GHSA-c72v-pj75-jmf4.json +++ b/advisories/unreviewed/2023/06/GHSA-c72v-pj75-jmf4/GHSA-c72v-pj75-jmf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c72v-pj75-jmf4", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-2899" ], "details": "The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-c75r-2gqr-7xhr/GHSA-c75r-2gqr-7xhr.json b/advisories/unreviewed/2023/06/GHSA-c75r-2gqr-7xhr/GHSA-c75r-2gqr-7xhr.json new file mode 100644 index 00000000000..e4f39503d43 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-c75r-2gqr-7xhr/GHSA-c75r-2gqr-7xhr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c75r-2gqr-7xhr", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2623" + ], + "details": "The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2623" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/85cc39b1-416f-4d23-84c1-fdcbffb0dda0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-chc6-rxgw-xf3r/GHSA-chc6-rxgw-xf3r.json b/advisories/unreviewed/2023/06/GHSA-chc6-rxgw-xf3r/GHSA-chc6-rxgw-xf3r.json index 95886ea5001..8d299c42fc4 100644 --- a/advisories/unreviewed/2023/06/GHSA-chc6-rxgw-xf3r/GHSA-chc6-rxgw-xf3r.json +++ b/advisories/unreviewed/2023/06/GHSA-chc6-rxgw-xf3r/GHSA-chc6-rxgw-xf3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chc6-rxgw-xf3r", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2022-47586" diff --git a/advisories/unreviewed/2023/06/GHSA-chj2-8247-g69q/GHSA-chj2-8247-g69q.json b/advisories/unreviewed/2023/06/GHSA-chj2-8247-g69q/GHSA-chj2-8247-g69q.json new file mode 100644 index 00000000000..3d89d1f1676 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-chj2-8247-g69q/GHSA-chj2-8247-g69q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chj2-8247-g69q", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-1166" + ], + "details": "The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1166" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/825eccf9-f351-4a5b-b238-9969141b94fa" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-cpq5-xxhj-mcq9/GHSA-cpq5-xxhj-mcq9.json b/advisories/unreviewed/2023/06/GHSA-cpq5-xxhj-mcq9/GHSA-cpq5-xxhj-mcq9.json index 613ccea4bb6..36bddb3c09b 100644 --- a/advisories/unreviewed/2023/06/GHSA-cpq5-xxhj-mcq9/GHSA-cpq5-xxhj-mcq9.json +++ b/advisories/unreviewed/2023/06/GHSA-cpq5-xxhj-mcq9/GHSA-cpq5-xxhj-mcq9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cpq5-xxhj-mcq9", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-34641" ], "details": "KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function window.print() which can then be used to open an unprivileged command prompt.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-cq3h-j934-fgjg/GHSA-cq3h-j934-fgjg.json b/advisories/unreviewed/2023/06/GHSA-cq3h-j934-fgjg/GHSA-cq3h-j934-fgjg.json index 3268eb870a7..6cf95142b4e 100644 --- a/advisories/unreviewed/2023/06/GHSA-cq3h-j934-fgjg/GHSA-cq3h-j934-fgjg.json +++ b/advisories/unreviewed/2023/06/GHSA-cq3h-j934-fgjg/GHSA-cq3h-j934-fgjg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq3h-j934-fgjg", - "modified": "2023-06-23T18:30:24Z", + "modified": "2023-06-27T15:30:28Z", "published": "2023-06-23T18:30:24Z", "aliases": [ "CVE-2023-32372" ], "details": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4, watchOS 9.5, tvOS 16.5. Processing an image may result in disclosure of process memory", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-f2f5-9rhp-q563/GHSA-f2f5-9rhp-q563.json b/advisories/unreviewed/2023/06/GHSA-f2f5-9rhp-q563/GHSA-f2f5-9rhp-q563.json index 635b0924a31..543f9a02091 100644 --- a/advisories/unreviewed/2023/06/GHSA-f2f5-9rhp-q563/GHSA-f2f5-9rhp-q563.json +++ b/advisories/unreviewed/2023/06/GHSA-f2f5-9rhp-q563/GHSA-f2f5-9rhp-q563.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2f5-9rhp-q563", - "modified": "2023-06-19T15:30:49Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T15:30:49Z", "aliases": [ "CVE-2022-46850" diff --git a/advisories/unreviewed/2023/06/GHSA-f8j8-g2f7-722j/GHSA-f8j8-g2f7-722j.json b/advisories/unreviewed/2023/06/GHSA-f8j8-g2f7-722j/GHSA-f8j8-g2f7-722j.json new file mode 100644 index 00000000000..c266d84c284 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-f8j8-g2f7-722j/GHSA-f8j8-g2f7-722j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8j8-g2f7-722j", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2021-30205" + ], + "details": "Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-30205" + }, + { + "type": "WEB", + "url": "https://github.com/zyx0814/dzzoffice/issues/184" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-ff3m-68vj-h86p/GHSA-ff3m-68vj-h86p.json b/advisories/unreviewed/2023/06/GHSA-ff3m-68vj-h86p/GHSA-ff3m-68vj-h86p.json new file mode 100644 index 00000000000..09f2c99bd97 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-ff3m-68vj-h86p/GHSA-ff3m-68vj-h86p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff3m-68vj-h86p", + "modified": "2023-06-27T15:30:29Z", + "published": "2023-06-27T15:30:29Z", + "aliases": [ + "CVE-2023-3432" + ], + "details": "Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3432" + }, + { + "type": "WEB", + "url": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/8ac3316f-431c-468d-87e4-3dafff2ecf51" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-fv2r-hw24-8rxj/GHSA-fv2r-hw24-8rxj.json b/advisories/unreviewed/2023/06/GHSA-fv2r-hw24-8rxj/GHSA-fv2r-hw24-8rxj.json index efc6634dc3c..c1c49a0cc7d 100644 --- a/advisories/unreviewed/2023/06/GHSA-fv2r-hw24-8rxj/GHSA-fv2r-hw24-8rxj.json +++ b/advisories/unreviewed/2023/06/GHSA-fv2r-hw24-8rxj/GHSA-fv2r-hw24-8rxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv2r-hw24-8rxj", - "modified": "2023-06-14T15:30:38Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-14T15:30:38Z", "aliases": [ "CVE-2023-34623" ], "details": "An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json b/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json new file mode 100644 index 00000000000..33f0b4c9691 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-g2r6-mg39-w7jm/GHSA-g2r6-mg39-w7jm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2r6-mg39-w7jm", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2580" + ], + "details": "The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2580" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7ee1efb1-9969-40b2-8ab2-ea427091bbd8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-g4w4-pwm7-7rv4/GHSA-g4w4-pwm7-7rv4.json b/advisories/unreviewed/2023/06/GHSA-g4w4-pwm7-7rv4/GHSA-g4w4-pwm7-7rv4.json new file mode 100644 index 00000000000..6d57a3de954 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-g4w4-pwm7-7rv4/GHSA-g4w4-pwm7-7rv4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4w4-pwm7-7rv4", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-3405" + ], + "details": "Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3405" + }, + { + "type": "WEB", + "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-3405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-gm3h-h75w-r3wg/GHSA-gm3h-h75w-r3wg.json b/advisories/unreviewed/2023/06/GHSA-gm3h-h75w-r3wg/GHSA-gm3h-h75w-r3wg.json new file mode 100644 index 00000000000..e70d9dc0a8e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-gm3h-h75w-r3wg/GHSA-gm3h-h75w-r3wg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm3h-h75w-r3wg", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2818" + ], + "details": "An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2818" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json b/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json new file mode 100644 index 00000000000..b9631ec6546 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-hmj4-2mw2-4m77/GHSA-hmj4-2mw2-4m77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmj4-2mw2-4m77", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-36002" + ], + "details": "A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36002" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json b/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json index 089e797aa0a..7ca3bdf3e77 100644 --- a/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json +++ b/advisories/unreviewed/2023/06/GHSA-j63h-wp7g-gv2g/GHSA-j63h-wp7g-gv2g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j63h-wp7g-gv2g", - "modified": "2023-06-19T06:30:42Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T06:30:42Z", "aliases": [ "CVE-2023-34642" ], "details": "KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function showDirectoryPicker() which can then be used to open an unprivileged command prompt.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-jhmf-mhgj-hjcw/GHSA-jhmf-mhgj-hjcw.json b/advisories/unreviewed/2023/06/GHSA-jhmf-mhgj-hjcw/GHSA-jhmf-mhgj-hjcw.json new file mode 100644 index 00000000000..01d331134c0 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-jhmf-mhgj-hjcw/GHSA-jhmf-mhgj-hjcw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhmf-mhgj-hjcw", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2743" + ], + "details": "The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2743" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/517c6aa4-a56d-4f13-b370-7c864dd9c7db" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-m8jv-2fwv-r87q/GHSA-m8jv-2fwv-r87q.json b/advisories/unreviewed/2023/06/GHSA-m8jv-2fwv-r87q/GHSA-m8jv-2fwv-r87q.json index 17c3c2f290e..e95d48256f6 100644 --- a/advisories/unreviewed/2023/06/GHSA-m8jv-2fwv-r87q/GHSA-m8jv-2fwv-r87q.json +++ b/advisories/unreviewed/2023/06/GHSA-m8jv-2fwv-r87q/GHSA-m8jv-2fwv-r87q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8jv-2fwv-r87q", - "modified": "2023-06-20T09:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-20T09:30:22Z", "aliases": [ "CVE-2023-35884" diff --git a/advisories/unreviewed/2023/06/GHSA-mjmv-wghg-gx7m/GHSA-mjmv-wghg-gx7m.json b/advisories/unreviewed/2023/06/GHSA-mjmv-wghg-gx7m/GHSA-mjmv-wghg-gx7m.json new file mode 100644 index 00000000000..676bc823128 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-mjmv-wghg-gx7m/GHSA-mjmv-wghg-gx7m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjmv-wghg-gx7m", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2627" + ], + "details": "The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2627" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/162d0029-2adc-4925-9985-1d5d672dbe75" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-mm26-p7j2-5frx/GHSA-mm26-p7j2-5frx.json b/advisories/unreviewed/2023/06/GHSA-mm26-p7j2-5frx/GHSA-mm26-p7j2-5frx.json new file mode 100644 index 00000000000..d766bde57f2 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-mm26-p7j2-5frx/GHSA-mm26-p7j2-5frx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm26-p7j2-5frx", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-1891" + ], + "details": "The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1891" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4e5d993f-cc20-4b5f-b4c8-c13004151828" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-mr4p-2m35-4m4g/GHSA-mr4p-2m35-4m4g.json b/advisories/unreviewed/2023/06/GHSA-mr4p-2m35-4m4g/GHSA-mr4p-2m35-4m4g.json new file mode 100644 index 00000000000..f4e1d7fc6d3 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-mr4p-2m35-4m4g/GHSA-mr4p-2m35-4m4g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr4p-2m35-4m4g", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2032" + ], + "details": "The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2032" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/17acde5d-44ea-4e77-8670-260d22e28ffe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-p2mf-q26j-3xmh/GHSA-p2mf-q26j-3xmh.json b/advisories/unreviewed/2023/06/GHSA-p2mf-q26j-3xmh/GHSA-p2mf-q26j-3xmh.json new file mode 100644 index 00000000000..35f10160bf0 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-p2mf-q26j-3xmh/GHSA-p2mf-q26j-3xmh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2mf-q26j-3xmh", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-3431" + ], + "details": "Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3431" + }, + { + "type": "WEB", + "url": "https://github.com/plantuml/plantuml/commit/fbe7fa3b25b4c887d83927cffb1009ec6cb8ab1e" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/fa741f95-b53c-4ed7-b157-e32c5145164c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-pg52-hw59-qg7q/GHSA-pg52-hw59-qg7q.json b/advisories/unreviewed/2023/06/GHSA-pg52-hw59-qg7q/GHSA-pg52-hw59-qg7q.json index 66820050ee1..314580c455f 100644 --- a/advisories/unreviewed/2023/06/GHSA-pg52-hw59-qg7q/GHSA-pg52-hw59-qg7q.json +++ b/advisories/unreviewed/2023/06/GHSA-pg52-hw59-qg7q/GHSA-pg52-hw59-qg7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pg52-hw59-qg7q", - "modified": "2023-06-20T09:30:23Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-20T09:30:23Z", "aliases": [ "CVE-2023-35878" diff --git a/advisories/unreviewed/2023/06/GHSA-pxjc-2pxw-qcpg/GHSA-pxjc-2pxw-qcpg.json b/advisories/unreviewed/2023/06/GHSA-pxjc-2pxw-qcpg/GHSA-pxjc-2pxw-qcpg.json index aba6431023c..91db23ca39e 100644 --- a/advisories/unreviewed/2023/06/GHSA-pxjc-2pxw-qcpg/GHSA-pxjc-2pxw-qcpg.json +++ b/advisories/unreviewed/2023/06/GHSA-pxjc-2pxw-qcpg/GHSA-pxjc-2pxw-qcpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pxjc-2pxw-qcpg", - "modified": "2023-06-23T18:30:24Z", + "modified": "2023-06-27T15:30:28Z", "published": "2023-06-23T18:30:24Z", "aliases": [ "CVE-2023-32387" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A remote attacker may be able to cause unexpected app termination or arbitrary code execution", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-qhhp-34vh-xjwv/GHSA-qhhp-34vh-xjwv.json b/advisories/unreviewed/2023/06/GHSA-qhhp-34vh-xjwv/GHSA-qhhp-34vh-xjwv.json new file mode 100644 index 00000000000..aa14a56635e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-qhhp-34vh-xjwv/GHSA-qhhp-34vh-xjwv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhhp-34vh-xjwv", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2996" + ], + "details": "The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2996" + }, + { + "type": "WEB", + "url": "https://jetpack.com/blog/jetpack-12-1-1-critical-security-update/" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/52d221bd-ae42-435d-a90a-60a5ae530663" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-qp4h-5pwc-hqm5/GHSA-qp4h-5pwc-hqm5.json b/advisories/unreviewed/2023/06/GHSA-qp4h-5pwc-hqm5/GHSA-qp4h-5pwc-hqm5.json new file mode 100644 index 00000000000..6fc269cd5da --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-qp4h-5pwc-hqm5/GHSA-qp4h-5pwc-hqm5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp4h-5pwc-hqm5", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2795" + ], + "details": "The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2795" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2d6ecd21-3dd4-423d-80e7-277c45080a9f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-qpmh-7vpm-353g/GHSA-qpmh-7vpm-353g.json b/advisories/unreviewed/2023/06/GHSA-qpmh-7vpm-353g/GHSA-qpmh-7vpm-353g.json new file mode 100644 index 00000000000..f1aa4cc896e --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-qpmh-7vpm-353g/GHSA-qpmh-7vpm-353g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpmh-7vpm-353g", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2605" + ], + "details": "The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2605" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/372cb940-71ba-4d19-b35a-ab15f8c2fdeb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-r5p4-j268-rh4h/GHSA-r5p4-j268-rh4h.json b/advisories/unreviewed/2023/06/GHSA-r5p4-j268-rh4h/GHSA-r5p4-j268-rh4h.json new file mode 100644 index 00000000000..1f9ee80fd70 --- /dev/null +++ b/advisories/unreviewed/2023/06/GHSA-r5p4-j268-rh4h/GHSA-r5p4-j268-rh4h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5p4-j268-rh4h", + "modified": "2023-06-27T15:30:28Z", + "published": "2023-06-27T15:30:28Z", + "aliases": [ + "CVE-2023-2482" + ], + "details": "The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2482" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c0f73781-be7e-482e-91de-ad7991ad4bd5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json b/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json index 678d5dbc80a..bfe01976648 100644 --- a/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json +++ b/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-rrgx-frfg-pmxf/GHSA-rrgx-frfg-pmxf.json b/advisories/unreviewed/2023/06/GHSA-rrgx-frfg-pmxf/GHSA-rrgx-frfg-pmxf.json index 576588e35a2..25a217b060c 100644 --- a/advisories/unreviewed/2023/06/GHSA-rrgx-frfg-pmxf/GHSA-rrgx-frfg-pmxf.json +++ b/advisories/unreviewed/2023/06/GHSA-rrgx-frfg-pmxf/GHSA-rrgx-frfg-pmxf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rrgx-frfg-pmxf", - "modified": "2023-06-19T12:30:22Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-19T12:30:22Z", "aliases": [ "CVE-2023-2812" ], "details": "The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-w4q9-8q4f-fh7h/GHSA-w4q9-8q4f-fh7h.json b/advisories/unreviewed/2023/06/GHSA-w4q9-8q4f-fh7h/GHSA-w4q9-8q4f-fh7h.json index 568771f5077..ba96721ba82 100644 --- a/advisories/unreviewed/2023/06/GHSA-w4q9-8q4f-fh7h/GHSA-w4q9-8q4f-fh7h.json +++ b/advisories/unreviewed/2023/06/GHSA-w4q9-8q4f-fh7h/GHSA-w4q9-8q4f-fh7h.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-404" + "CWE-404", + "CWE-77" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-xp6q-cm7h-qg74/GHSA-xp6q-cm7h-qg74.json b/advisories/unreviewed/2023/06/GHSA-xp6q-cm7h-qg74/GHSA-xp6q-cm7h-qg74.json index 5a89ac5c70f..9db5108e7da 100644 --- a/advisories/unreviewed/2023/06/GHSA-xp6q-cm7h-qg74/GHSA-xp6q-cm7h-qg74.json +++ b/advisories/unreviewed/2023/06/GHSA-xp6q-cm7h-qg74/GHSA-xp6q-cm7h-qg74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xp6q-cm7h-qg74", - "modified": "2023-06-20T21:30:56Z", + "modified": "2023-06-27T15:30:27Z", "published": "2023-06-20T21:30:56Z", "aliases": [ "CVE-2023-3220" ], "details": "An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [