diff --git a/advisories/unreviewed/2022/03/GHSA-49mr-vrxv-hmwg/GHSA-49mr-vrxv-hmwg.json b/advisories/unreviewed/2022/03/GHSA-49mr-vrxv-hmwg/GHSA-49mr-vrxv-hmwg.json index 4e552746b4e..62d220c99ca 100644 --- a/advisories/unreviewed/2022/03/GHSA-49mr-vrxv-hmwg/GHSA-49mr-vrxv-hmwg.json +++ b/advisories/unreviewed/2022/03/GHSA-49mr-vrxv-hmwg/GHSA-49mr-vrxv-hmwg.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/09/GHSA-4857-4q6j-xxx3/GHSA-4857-4q6j-xxx3.json b/advisories/unreviewed/2022/09/GHSA-4857-4q6j-xxx3/GHSA-4857-4q6j-xxx3.json index bda1c4172e2..71cc6110667 100644 --- a/advisories/unreviewed/2022/09/GHSA-4857-4q6j-xxx3/GHSA-4857-4q6j-xxx3.json +++ b/advisories/unreviewed/2022/09/GHSA-4857-4q6j-xxx3/GHSA-4857-4q6j-xxx3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-qhxx-93xr-42wh/GHSA-qhxx-93xr-42wh.json b/advisories/unreviewed/2022/09/GHSA-qhxx-93xr-42wh/GHSA-qhxx-93xr-42wh.json index 30979066d7d..f7862af7012 100644 --- a/advisories/unreviewed/2022/09/GHSA-qhxx-93xr-42wh/GHSA-qhxx-93xr-42wh.json +++ b/advisories/unreviewed/2022/09/GHSA-qhxx-93xr-42wh/GHSA-qhxx-93xr-42wh.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-ph6f-29xm-4m8p/GHSA-ph6f-29xm-4m8p.json b/advisories/unreviewed/2022/11/GHSA-ph6f-29xm-4m8p/GHSA-ph6f-29xm-4m8p.json index aea709e05a6..bb13ba6bc03 100644 --- a/advisories/unreviewed/2022/11/GHSA-ph6f-29xm-4m8p/GHSA-ph6f-29xm-4m8p.json +++ b/advisories/unreviewed/2022/11/GHSA-ph6f-29xm-4m8p/GHSA-ph6f-29xm-4m8p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-459" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-ph96-x94x-wg4h/GHSA-ph96-x94x-wg4h.json b/advisories/unreviewed/2022/11/GHSA-ph96-x94x-wg4h/GHSA-ph96-x94x-wg4h.json index 0c09fb24258..40545ebd25e 100644 --- a/advisories/unreviewed/2022/11/GHSA-ph96-x94x-wg4h/GHSA-ph96-x94x-wg4h.json +++ b/advisories/unreviewed/2022/11/GHSA-ph96-x94x-wg4h/GHSA-ph96-x94x-wg4h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-pmvv-r44r-j4g9/GHSA-pmvv-r44r-j4g9.json b/advisories/unreviewed/2022/11/GHSA-pmvv-r44r-j4g9/GHSA-pmvv-r44r-j4g9.json index 20b78f1b2d4..752dcdffd78 100644 --- a/advisories/unreviewed/2022/11/GHSA-pmvv-r44r-j4g9/GHSA-pmvv-r44r-j4g9.json +++ b/advisories/unreviewed/2022/11/GHSA-pmvv-r44r-j4g9/GHSA-pmvv-r44r-j4g9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-vc86-73mc-m266/GHSA-vc86-73mc-m266.json b/advisories/unreviewed/2022/11/GHSA-vc86-73mc-m266/GHSA-vc86-73mc-m266.json index 23fff0b9e57..8a58f8257bc 100644 --- a/advisories/unreviewed/2022/11/GHSA-vc86-73mc-m266/GHSA-vc86-73mc-m266.json +++ b/advisories/unreviewed/2022/11/GHSA-vc86-73mc-m266/GHSA-vc86-73mc-m266.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-672" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-9c9w-6vg7-jggq/GHSA-9c9w-6vg7-jggq.json b/advisories/unreviewed/2023/04/GHSA-9c9w-6vg7-jggq/GHSA-9c9w-6vg7-jggq.json index cc8dc6cc121..764caae89ba 100644 --- a/advisories/unreviewed/2023/04/GHSA-9c9w-6vg7-jggq/GHSA-9c9w-6vg7-jggq.json +++ b/advisories/unreviewed/2023/04/GHSA-9c9w-6vg7-jggq/GHSA-9c9w-6vg7-jggq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-441" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-f9vx-6cfw-vgpg/GHSA-f9vx-6cfw-vgpg.json b/advisories/unreviewed/2023/04/GHSA-f9vx-6cfw-vgpg/GHSA-f9vx-6cfw-vgpg.json index a65aef2f655..9bd31ca1998 100644 --- a/advisories/unreviewed/2023/04/GHSA-f9vx-6cfw-vgpg/GHSA-f9vx-6cfw-vgpg.json +++ b/advisories/unreviewed/2023/04/GHSA-f9vx-6cfw-vgpg/GHSA-f9vx-6cfw-vgpg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-248" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-r22j-494q-4pjg/GHSA-r22j-494q-4pjg.json b/advisories/unreviewed/2023/04/GHSA-r22j-494q-4pjg/GHSA-r22j-494q-4pjg.json index de548753b22..3b05a0a98af 100644 --- a/advisories/unreviewed/2023/04/GHSA-r22j-494q-4pjg/GHSA-r22j-494q-4pjg.json +++ b/advisories/unreviewed/2023/04/GHSA-r22j-494q-4pjg/GHSA-r22j-494q-4pjg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-rh2h-jqxg-h9f7/GHSA-rh2h-jqxg-h9f7.json b/advisories/unreviewed/2023/04/GHSA-rh2h-jqxg-h9f7/GHSA-rh2h-jqxg-h9f7.json index 66f26428149..1014a1361e4 100644 --- a/advisories/unreviewed/2023/04/GHSA-rh2h-jqxg-h9f7/GHSA-rh2h-jqxg-h9f7.json +++ b/advisories/unreviewed/2023/04/GHSA-rh2h-jqxg-h9f7/GHSA-rh2h-jqxg-h9f7.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-611" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-x58x-gv55-3jp9/GHSA-x58x-gv55-3jp9.json b/advisories/unreviewed/2023/04/GHSA-x58x-gv55-3jp9/GHSA-x58x-gv55-3jp9.json index fbfc3b91338..1e042837dcd 100644 --- a/advisories/unreviewed/2023/04/GHSA-x58x-gv55-3jp9/GHSA-x58x-gv55-3jp9.json +++ b/advisories/unreviewed/2023/04/GHSA-x58x-gv55-3jp9/GHSA-x58x-gv55-3jp9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json b/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json index 57c76950f21..ab690578a7a 100644 --- a/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json +++ b/advisories/unreviewed/2024/03/GHSA-2vp3-qj4j-9chv/GHSA-2vp3-qj4j-9chv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json b/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json index 73f5b9fe111..2f760d1874e 100644 --- a/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json +++ b/advisories/unreviewed/2024/03/GHSA-683m-h868-4cxr/GHSA-683m-h868-4cxr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-683m-h868-4cxr", - "modified": "2024-03-11T18:31:09Z", + "modified": "2025-02-05T21:32:33Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-1279" ], "details": "The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:17Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json b/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json index 7716f021469..711adaa8fff 100644 --- a/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json +++ b/advisories/unreviewed/2024/03/GHSA-9764-6h7c-x5rv/GHSA-9764-6h7c-x5rv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xwx4-47r6-38w7/GHSA-xwx4-47r6-38w7.json b/advisories/unreviewed/2024/03/GHSA-xwx4-47r6-38w7/GHSA-xwx4-47r6-38w7.json index 29e287d2762..221695000f1 100644 --- a/advisories/unreviewed/2024/03/GHSA-xwx4-47r6-38w7/GHSA-xwx4-47r6-38w7.json +++ b/advisories/unreviewed/2024/03/GHSA-xwx4-47r6-38w7/GHSA-xwx4-47r6-38w7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xwx4-47r6-38w7", - "modified": "2024-03-07T09:30:30Z", + "modified": "2025-02-05T21:32:33Z", "published": "2024-03-07T09:30:30Z", "aliases": [ "CVE-2024-1419" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json b/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json index adc9a4717ea..ae8aada2407 100644 --- a/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json +++ b/advisories/unreviewed/2024/04/GHSA-r4jj-84rh-4pf7/GHSA-r4jj-84rh-4pf7.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json b/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json index ecae027c508..253befbf90d 100644 --- a/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json +++ b/advisories/unreviewed/2024/05/GHSA-jxcj-3v7x-m3q6/GHSA-jxcj-3v7x-m3q6.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-122" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-9736-p97g-656h/GHSA-9736-p97g-656h.json b/advisories/unreviewed/2025/01/GHSA-9736-p97g-656h/GHSA-9736-p97g-656h.json index b323a82f876..1b5392f841a 100644 --- a/advisories/unreviewed/2025/01/GHSA-9736-p97g-656h/GHSA-9736-p97g-656h.json +++ b/advisories/unreviewed/2025/01/GHSA-9736-p97g-656h/GHSA-9736-p97g-656h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9736-p97g-656h", - "modified": "2025-01-23T12:32:34Z", + "modified": "2025-02-05T21:32:34Z", "published": "2025-01-23T12:32:34Z", "aliases": [ "CVE-2024-12043" diff --git a/advisories/unreviewed/2025/01/GHSA-rppq-5vq8-crrp/GHSA-rppq-5vq8-crrp.json b/advisories/unreviewed/2025/01/GHSA-rppq-5vq8-crrp/GHSA-rppq-5vq8-crrp.json index 633a785a28d..d72dfceaeaa 100644 --- a/advisories/unreviewed/2025/01/GHSA-rppq-5vq8-crrp/GHSA-rppq-5vq8-crrp.json +++ b/advisories/unreviewed/2025/01/GHSA-rppq-5vq8-crrp/GHSA-rppq-5vq8-crrp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rppq-5vq8-crrp", - "modified": "2025-01-24T03:30:37Z", + "modified": "2025-02-05T21:32:34Z", "published": "2025-01-24T03:30:37Z", "aliases": [ "CVE-2024-11931" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11931" }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2025/01/22/patch-release-gitlab-17-8-1-released/https://about.gitlab.com/releases/2025/01/22/patch-release-gitlab-17-8-1-released" + }, { "type": "WEB", "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480901" diff --git a/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json b/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json index 7a4aeaa5634..ca880e47d20 100644 --- a/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json +++ b/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84xh-pwc6-7g4g", - "modified": "2025-02-05T18:34:46Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-05T18:34:46Z", "aliases": [ "CVE-2025-23419" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://my.f5.com/manage/s/article/K000149173" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/05/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json b/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json index 3d59d7e4ae6..ce0561dcee1 100644 --- a/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json +++ b/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89fg-r5w5-hh2w", - "modified": "2025-02-05T12:33:07Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-05T12:33:07Z", "aliases": [ "CVE-2024-5528" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://hackerone.com/reports/2523654" }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2024/07/10/patch-release-gitlab-17-1-2-released" + }, { "type": "WEB", "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/464558" diff --git a/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json b/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json index 3060c91ff42..cb46263d8cb 100644 --- a/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json +++ b/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc57-hgv8-p56r", - "modified": "2025-02-05T15:32:25Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-05T12:33:07Z", "aliases": [ "CVE-2025-0665" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/02/05/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/05/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-f666-246m-p7mg/GHSA-f666-246m-p7mg.json b/advisories/unreviewed/2025/02/GHSA-f666-246m-p7mg/GHSA-f666-246m-p7mg.json index b6e60649449..671bd310d3a 100644 --- a/advisories/unreviewed/2025/02/GHSA-f666-246m-p7mg/GHSA-f666-246m-p7mg.json +++ b/advisories/unreviewed/2025/02/GHSA-f666-246m-p7mg/GHSA-f666-246m-p7mg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f666-246m-p7mg", - "modified": "2025-02-04T15:31:36Z", + "modified": "2025-02-05T21:32:34Z", "published": "2025-02-04T15:31:36Z", "aliases": [ "CVE-2025-1010" ], "details": "An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gg39-4c5c-pfx2/GHSA-gg39-4c5c-pfx2.json b/advisories/unreviewed/2025/02/GHSA-gg39-4c5c-pfx2/GHSA-gg39-4c5c-pfx2.json index 2e7756e86d2..84a3acecca0 100644 --- a/advisories/unreviewed/2025/02/GHSA-gg39-4c5c-pfx2/GHSA-gg39-4c5c-pfx2.json +++ b/advisories/unreviewed/2025/02/GHSA-gg39-4c5c-pfx2/GHSA-gg39-4c5c-pfx2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gg39-4c5c-pfx2", - "modified": "2025-02-04T15:31:37Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-04T15:31:37Z", "aliases": [ "CVE-2025-1019" ], "details": "The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1021" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-mx9x-fhqg-ggrp/GHSA-mx9x-fhqg-ggrp.json b/advisories/unreviewed/2025/02/GHSA-mx9x-fhqg-ggrp/GHSA-mx9x-fhqg-ggrp.json index 922faefed1a..4490c407854 100644 --- a/advisories/unreviewed/2025/02/GHSA-mx9x-fhqg-ggrp/GHSA-mx9x-fhqg-ggrp.json +++ b/advisories/unreviewed/2025/02/GHSA-mx9x-fhqg-ggrp/GHSA-mx9x-fhqg-ggrp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mx9x-fhqg-ggrp", - "modified": "2025-02-05T15:32:24Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-05T15:32:24Z", "aliases": [ "CVE-2024-2878" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://hackerone.com/reports/2416356" }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released" + }, { "type": "WEB", "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/451918" diff --git a/advisories/unreviewed/2025/02/GHSA-p9rf-jg9f-2chc/GHSA-p9rf-jg9f-2chc.json b/advisories/unreviewed/2025/02/GHSA-p9rf-jg9f-2chc/GHSA-p9rf-jg9f-2chc.json index 7aedfc20667..9b442964206 100644 --- a/advisories/unreviewed/2025/02/GHSA-p9rf-jg9f-2chc/GHSA-p9rf-jg9f-2chc.json +++ b/advisories/unreviewed/2025/02/GHSA-p9rf-jg9f-2chc/GHSA-p9rf-jg9f-2chc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p9rf-jg9f-2chc", - "modified": "2025-02-03T18:30:43Z", + "modified": "2025-02-05T21:32:34Z", "published": "2025-02-03T18:30:43Z", "aliases": [ "CVE-2024-53943" ], "details": "An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute JavaScript within the context of the current user by injecting JavaScript into the SSID field. If an administrator logs into the device, the injected script runs in their browser, executing the malicious payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T18:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json b/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json index f2c670cb995..cd22dda6c35 100644 --- a/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json +++ b/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-px4x-cjpp-hqv5", - "modified": "2025-02-05T12:33:07Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-05T12:33:07Z", "aliases": [ "CVE-2024-3976" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://hackerone.com/reports/2470939" }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2024/05/08/patch-release-gitlab-16-11-2-released" + }, { "type": "WEB", "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/457140" diff --git a/advisories/unreviewed/2025/02/GHSA-qp3j-rxh4-q4h8/GHSA-qp3j-rxh4-q4h8.json b/advisories/unreviewed/2025/02/GHSA-qp3j-rxh4-q4h8/GHSA-qp3j-rxh4-q4h8.json index 4f2441aff5a..7dbca7d6923 100644 --- a/advisories/unreviewed/2025/02/GHSA-qp3j-rxh4-q4h8/GHSA-qp3j-rxh4-q4h8.json +++ b/advisories/unreviewed/2025/02/GHSA-qp3j-rxh4-q4h8/GHSA-qp3j-rxh4-q4h8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qp3j-rxh4-q4h8", - "modified": "2025-02-04T15:31:36Z", + "modified": "2025-02-05T21:32:35Z", "published": "2025-02-04T15:31:36Z", "aliases": [ "CVE-2025-1011" ], "details": "A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v9m4-7h7v-vqrf/GHSA-v9m4-7h7v-vqrf.json b/advisories/unreviewed/2025/02/GHSA-v9m4-7h7v-vqrf/GHSA-v9m4-7h7v-vqrf.json index 737e51b24d2..df0e8f84035 100644 --- a/advisories/unreviewed/2025/02/GHSA-v9m4-7h7v-vqrf/GHSA-v9m4-7h7v-vqrf.json +++ b/advisories/unreviewed/2025/02/GHSA-v9m4-7h7v-vqrf/GHSA-v9m4-7h7v-vqrf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v9m4-7h7v-vqrf", - "modified": "2025-02-04T15:31:36Z", + "modified": "2025-02-05T21:32:34Z", "published": "2025-02-04T15:31:36Z", "aliases": [ "CVE-2025-1009" ], "details": "An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:31Z"