From 19243617e3351654db47a3bd5c2c8c512b4bf427 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Mar 2025 21:33:22 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-95rp-7qcx-wxr4.json | 1 + .../GHSA-c2x6-rvvf-2x2v.json | 2 +- .../GHSA-v8ff-vmc3-wr4m.json | 10 +++- .../GHSA-whfj-p5r5-33pr.json | 4 +- .../GHSA-9q54-pg8p-25cg.json | 11 +++-- .../GHSA-8cpf-fxr6-4wpq.json | 4 +- .../GHSA-wgjq-hm36-r7r8.json | 15 ++++-- .../GHSA-xcfg-gmff-9p95.json | 11 +++-- .../GHSA-262h-qq26-j72g.json | 8 ++-- .../GHSA-5wq8-45w5-cxgr.json | 11 +++-- .../GHSA-8q5c-h63v-v869.json | 11 +++-- .../GHSA-9j49-pw6q-fgq9.json | 4 +- .../GHSA-xmjw-8f7c-p37x.json | 11 +++-- .../GHSA-mgqc-jwxc-fx8x.json | 11 +++-- .../GHSA-x6g9-g4wf-qrf7.json | 6 ++- .../GHSA-h6q6-xxwv-mm6v.json | 4 +- .../GHSA-2xfx-2vr5-pf8q.json | 2 +- .../GHSA-4q6p-vw5p-724c.json | 29 +++++++++++ .../GHSA-52fg-w63x-36xq.json | 29 +++++++++++ .../GHSA-57m4-7g8p-fcrj.json | 3 +- .../GHSA-5fxv-x2j7-rmwm.json | 29 +++++++++++ .../GHSA-62q7-445r-42wh.json | 29 +++++++++++ .../GHSA-674w-jwj3-6mv7.json | 29 +++++++++++ .../GHSA-687p-fc47-c8ph.json | 29 +++++++++++ .../GHSA-6mxg-4m6j-9xh2.json | 29 +++++++++++ .../GHSA-7287-grhx-542x.json | 48 +++++++++++++++++++ .../GHSA-96p6-38w3-wjpv.json | 29 +++++++++++ .../GHSA-9pw8-9245-4vvr.json | 36 ++++++++++++++ .../GHSA-cv66-crjx-w6c2.json | 29 +++++++++++ .../GHSA-gg2f-r4jh-vpmh.json | 15 ++++-- .../GHSA-ghmc-58xm-mhvv.json | 36 ++++++++++++++ .../GHSA-gj36-hrrj-wvg8.json | 29 +++++++++++ .../GHSA-gj66-2xh5-rjrr.json | 29 +++++++++++ .../GHSA-gj95-rf37-g546.json | 29 +++++++++++ .../GHSA-hp5w-82fv-gq5h.json | 29 +++++++++++ .../GHSA-jv78-c3q7-mc62.json | 4 +- .../GHSA-m569-r4hr-26cw.json | 15 ++++-- .../GHSA-p7qf-r7jf-7mf3.json | 29 +++++++++++ .../GHSA-phrv-w9px-24x9.json | 29 +++++++++++ .../GHSA-q4fr-fxrh-m96v.json | 3 +- .../GHSA-qvq7-g7xm-xr5h.json | 15 ++++-- .../GHSA-rmm8-wf49-vvww.json | 29 +++++++++++ .../GHSA-vcxh-wf9c-h9vv.json | 4 +- .../GHSA-x74r-f89v-3jw9.json | 29 +++++++++++ .../GHSA-x7qp-h9pf-wpv9.json | 3 +- .../GHSA-xxp6-fq36-p8jx.json | 36 ++++++++++++++ 46 files changed, 787 insertions(+), 50 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9pw8-9245-4vvr/GHSA-9pw8-9245-4vvr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ghmc-58xm-mhvv/GHSA-ghmc-58xm-mhvv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xxp6-fq36-p8jx/GHSA-xxp6-fq36-p8jx.json diff --git a/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json b/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json index 1c4dee22eab..30affaed9c2 100644 --- a/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json +++ b/advisories/unreviewed/2023/02/GHSA-95rp-7qcx-wxr4/GHSA-95rp-7qcx-wxr4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-20", "CWE-369" ], diff --git a/advisories/unreviewed/2023/02/GHSA-c2x6-rvvf-2x2v/GHSA-c2x6-rvvf-2x2v.json b/advisories/unreviewed/2023/02/GHSA-c2x6-rvvf-2x2v/GHSA-c2x6-rvvf-2x2v.json index f5999b29856..7b99a007d4c 100644 --- a/advisories/unreviewed/2023/02/GHSA-c2x6-rvvf-2x2v/GHSA-c2x6-rvvf-2x2v.json +++ b/advisories/unreviewed/2023/02/GHSA-c2x6-rvvf-2x2v/GHSA-c2x6-rvvf-2x2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2x6-rvvf-2x2v", - "modified": "2023-02-14T21:30:30Z", + "modified": "2025-03-25T21:31:26Z", "published": "2023-02-06T21:30:29Z", "aliases": [ "CVE-2023-25016" diff --git a/advisories/unreviewed/2023/02/GHSA-v8ff-vmc3-wr4m/GHSA-v8ff-vmc3-wr4m.json b/advisories/unreviewed/2023/02/GHSA-v8ff-vmc3-wr4m/GHSA-v8ff-vmc3-wr4m.json index d08429e831f..9ffb88a45f4 100644 --- a/advisories/unreviewed/2023/02/GHSA-v8ff-vmc3-wr4m/GHSA-v8ff-vmc3-wr4m.json +++ b/advisories/unreviewed/2023/02/GHSA-v8ff-vmc3-wr4m/GHSA-v8ff-vmc3-wr4m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8ff-vmc3-wr4m", - "modified": "2023-02-13T15:30:27Z", + "modified": "2025-03-25T21:31:24Z", "published": "2023-02-04T21:30:22Z", "aliases": [ "CVE-2023-25193" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://github.com/harfbuzz/harfbuzz/blob/2822b589bc837fae6f66233e2cf2eef0f6ce8470/src/hb-ot-layout-gsubgpos.hh" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZ5M2GSAIHFPLHYJXUPQ2QDJCLWXUGO3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KWCHWSICWVZSAXP2YAXM65JC2GR53547" diff --git a/advisories/unreviewed/2023/02/GHSA-whfj-p5r5-33pr/GHSA-whfj-p5r5-33pr.json b/advisories/unreviewed/2023/02/GHSA-whfj-p5r5-33pr/GHSA-whfj-p5r5-33pr.json index bf17c0a9290..64b54bedbcb 100644 --- a/advisories/unreviewed/2023/02/GHSA-whfj-p5r5-33pr/GHSA-whfj-p5r5-33pr.json +++ b/advisories/unreviewed/2023/02/GHSA-whfj-p5r5-33pr/GHSA-whfj-p5r5-33pr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json b/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json index 3fd8ba4e918..8731897e34b 100644 --- a/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json +++ b/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9q54-pg8p-25cg", - "modified": "2024-03-28T06:30:45Z", + "modified": "2025-03-25T21:31:29Z", "published": "2024-03-28T06:30:45Z", "aliases": [ "CVE-2024-0677" ], "details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T05:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json b/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json index 0e3d58b4b2f..d93f1978daa 100644 --- a/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json +++ b/advisories/unreviewed/2024/04/GHSA-8cpf-fxr6-4wpq/GHSA-8cpf-fxr6-4wpq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wgjq-hm36-r7r8/GHSA-wgjq-hm36-r7r8.json b/advisories/unreviewed/2024/04/GHSA-wgjq-hm36-r7r8/GHSA-wgjq-hm36-r7r8.json index 849f9a7dd8c..22c2f3534e2 100644 --- a/advisories/unreviewed/2024/04/GHSA-wgjq-hm36-r7r8/GHSA-wgjq-hm36-r7r8.json +++ b/advisories/unreviewed/2024/04/GHSA-wgjq-hm36-r7r8/GHSA-wgjq-hm36-r7r8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgjq-hm36-r7r8", - "modified": "2024-04-30T18:30:33Z", + "modified": "2025-03-25T21:31:29Z", "published": "2024-04-30T18:30:33Z", "aliases": [ "CVE-2019-19752" ], "details": "nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated plans to fix this in the next image build.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-321" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T18:15:19Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xcfg-gmff-9p95/GHSA-xcfg-gmff-9p95.json b/advisories/unreviewed/2024/04/GHSA-xcfg-gmff-9p95/GHSA-xcfg-gmff-9p95.json index bcefeeeab96..48bb451b182 100644 --- a/advisories/unreviewed/2024/04/GHSA-xcfg-gmff-9p95/GHSA-xcfg-gmff-9p95.json +++ b/advisories/unreviewed/2024/04/GHSA-xcfg-gmff-9p95/GHSA-xcfg-gmff-9p95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcfg-gmff-9p95", - "modified": "2024-04-30T00:30:34Z", + "modified": "2025-03-25T21:31:29Z", "published": "2024-04-30T00:30:34Z", "aliases": [ "CVE-2024-33401" ], "details": "Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T22:15:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-262h-qq26-j72g/GHSA-262h-qq26-j72g.json b/advisories/unreviewed/2024/05/GHSA-262h-qq26-j72g/GHSA-262h-qq26-j72g.json index b8cb84c05d5..58e7d6f55aa 100644 --- a/advisories/unreviewed/2024/05/GHSA-262h-qq26-j72g/GHSA-262h-qq26-j72g.json +++ b/advisories/unreviewed/2024/05/GHSA-262h-qq26-j72g/GHSA-262h-qq26-j72g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-262h-qq26-j72g", - "modified": "2024-05-14T18:30:47Z", + "modified": "2025-03-25T21:31:30Z", "published": "2024-05-14T18:30:47Z", "aliases": [ "CVE-2024-32736" ], - "details": "A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the \"query_utask_verbose\" function within MCUDBHelper.\n", + "details": "A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the \"query_utask_verbose\" function within MCUDBHelper.", "severity": [ { "type": "CVSS_V3", @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json b/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json index 44d7b435626..9017ff2924f 100644 --- a/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json +++ b/advisories/unreviewed/2024/05/GHSA-5wq8-45w5-cxgr/GHSA-5wq8-45w5-cxgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5wq8-45w5-cxgr", - "modified": "2024-05-15T06:30:44Z", + "modified": "2025-03-25T21:31:30Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3631" ], "details": "The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json b/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json index b40350ac9f0..b4ed531d214 100644 --- a/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json +++ b/advisories/unreviewed/2024/05/GHSA-8q5c-h63v-v869/GHSA-8q5c-h63v-v869.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8q5c-h63v-v869", - "modified": "2024-05-08T06:30:48Z", + "modified": "2025-03-25T21:31:30Z", "published": "2024-05-08T06:30:48Z", "aliases": [ "CVE-2024-1076" ], "details": "The SSL Zen WordPress plugin before 4.6.0 only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T06:15:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9j49-pw6q-fgq9/GHSA-9j49-pw6q-fgq9.json b/advisories/unreviewed/2024/05/GHSA-9j49-pw6q-fgq9/GHSA-9j49-pw6q-fgq9.json index c7fa5ac1f19..81687177f6e 100644 --- a/advisories/unreviewed/2024/05/GHSA-9j49-pw6q-fgq9/GHSA-9j49-pw6q-fgq9.json +++ b/advisories/unreviewed/2024/05/GHSA-9j49-pw6q-fgq9/GHSA-9j49-pw6q-fgq9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json index 73469224f54..9c688dfd99a 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json +++ b/advisories/unreviewed/2024/05/GHSA-xmjw-8f7c-p37x/GHSA-xmjw-8f7c-p37x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmjw-8f7c-p37x", - "modified": "2024-05-02T06:30:32Z", + "modified": "2025-03-25T21:31:29Z", "published": "2024-05-02T06:30:32Z", "aliases": [ "CVE-2024-3478" ], "details": "The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T06:15:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json b/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json index f0e1bd21cba..53efc46bc33 100644 --- a/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json +++ b/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgqc-jwxc-fx8x", - "modified": "2024-06-14T06:34:49Z", + "modified": "2025-03-25T21:31:31Z", "published": "2024-06-14T06:34:49Z", "aliases": [ "CVE-2024-4480" ], "details": "The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-14T06:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json b/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json index 2102ef6430d..4ac58a7e889 100644 --- a/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json +++ b/advisories/unreviewed/2024/07/GHSA-x6g9-g4wf-qrf7/GHSA-x6g9-g4wf-qrf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x6g9-g4wf-qrf7", - "modified": "2024-08-21T15:30:49Z", + "modified": "2025-03-25T21:31:31Z", "published": "2024-07-01T21:31:14Z", "aliases": [ "CVE-2024-38474" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20240712-0001" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/01/7" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json b/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json index 4207b82b1e9..a83a00a08e8 100644 --- a/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json +++ b/advisories/unreviewed/2024/08/GHSA-h6q6-xxwv-mm6v/GHSA-h6q6-xxwv-mm6v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-2xfx-2vr5-pf8q/GHSA-2xfx-2vr5-pf8q.json b/advisories/unreviewed/2025/03/GHSA-2xfx-2vr5-pf8q/GHSA-2xfx-2vr5-pf8q.json index 16872750026..bc4206e6231 100644 --- a/advisories/unreviewed/2025/03/GHSA-2xfx-2vr5-pf8q/GHSA-2xfx-2vr5-pf8q.json +++ b/advisories/unreviewed/2025/03/GHSA-2xfx-2vr5-pf8q/GHSA-2xfx-2vr5-pf8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xfx-2vr5-pf8q", - "modified": "2025-03-15T12:32:56Z", + "modified": "2025-03-25T21:31:32Z", "published": "2025-03-15T12:32:56Z", "aliases": [ "CVE-2025-2025" diff --git a/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json b/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json new file mode 100644 index 00000000000..a5dbe8c8bc3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q6p-vw5p-724c", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27833" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27833" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708259" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json b/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json new file mode 100644 index 00000000000..f8765cb0210 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52fg-w63x-36xq", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27832" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27832" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708133" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json b/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json index 0071ea0bcdc..5e7df17acdf 100644 --- a/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json +++ b/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json b/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json new file mode 100644 index 00000000000..c78ccee8492 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fxv-x2j7-rmwm", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27830" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27830" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708241" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json b/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json new file mode 100644 index 00000000000..9aec39d0022 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62q7-445r-42wh", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27834" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27834" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708253" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json b/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json new file mode 100644 index 00000000000..0e9b5f25498 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-674w-jwj3-6mv7", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-25372" + ], + "details": "NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25372" + }, + { + "type": "WEB", + "url": "https://visionspace.com/nasa-cfs-version-aquila-software-vulnerability-assessment" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json b/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json new file mode 100644 index 00000000000..0d00dfca959 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-687p-fc47-c8ph", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2024-48818" + ], + "details": "An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48818" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/183309" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json b/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json new file mode 100644 index 00000000000..12b2c7b8b8c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mxg-4m6j-9xh2", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2025-25374" + ], + "details": "In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25374" + }, + { + "type": "WEB", + "url": "https://visionspace.com/nasa-cfs-version-aquila-software-vulnerability-assessment" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json b/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json new file mode 100644 index 00000000000..4fc1f4b120f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7287-grhx-542x", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-30741" + ], + "details": "Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30741" + }, + { + "type": "WEB", + "url": "https://fokus.cool/2025/03/25/pixelfed-vulnerability.html" + }, + { + "type": "WEB", + "url": "https://github.com/pixelfed/pixelfed/releases/tag/v0.12.5" + }, + { + "type": "WEB", + "url": "https://mastodon.social/@pixelfed/114215925957179498" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=43474425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json b/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json new file mode 100644 index 00000000000..c0fdbf0f984 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96p6-38w3-wjpv", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27836" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27836" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708192" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9pw8-9245-4vvr/GHSA-9pw8-9245-4vvr.json b/advisories/unreviewed/2025/03/GHSA-9pw8-9245-4vvr/GHSA-9pw8-9245-4vvr.json new file mode 100644 index 00000000000..df2e8453afe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9pw8-9245-4vvr/GHSA-9pw8-9245-4vvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pw8-9245-4vvr", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2025-30567" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wp01ru WP01 allows Path Traversal. This issue affects WP01: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30567" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp01/vulnerability/wordpress-wp01-2-6-2-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T19:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json b/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json new file mode 100644 index 00000000000..21178ac5429 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv66-crjx-w6c2", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2025-30118" + ], + "details": "An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by occupying the only available connection. The SSID remains broadcast at all times, increasing exposure to potential attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30118" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Audi/blob/main/README.md#finding-1---cve-2025-30118-audi-utr-susceptibility-to-dos" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json b/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json index baa928fdfbb..e50e18c1cdb 100644 --- a/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json +++ b/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gg2f-r4jh-vpmh", - "modified": "2025-03-18T15:30:48Z", + "modified": "2025-03-25T21:31:33Z", "published": "2025-03-18T15:30:48Z", "aliases": [ "CVE-2024-44313" ], "details": "TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-ghmc-58xm-mhvv/GHSA-ghmc-58xm-mhvv.json b/advisories/unreviewed/2025/03/GHSA-ghmc-58xm-mhvv/GHSA-ghmc-58xm-mhvv.json new file mode 100644 index 00000000000..6e034c3713c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ghmc-58xm-mhvv/GHSA-ghmc-58xm-mhvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghmc-58xm-mhvv", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2024-31896" + ], + "details": "IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31896" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7228971" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T19:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json b/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json new file mode 100644 index 00000000000..894128fa2cf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj36-hrrj-wvg8", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27835" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27835" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708131" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json b/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json new file mode 100644 index 00000000000..cec34010970 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj66-2xh5-rjrr", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2025-25373" + ], + "details": "The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25373" + }, + { + "type": "WEB", + "url": "https://visionspace.com/nasa-cfs-version-aquila-software-vulnerability-assessment" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json b/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json new file mode 100644 index 00000000000..4c89cdd9ff0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj95-rf37-g546", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2024-55029" + ], + "details": "NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55029" + }, + { + "type": "WEB", + "url": "https://visionspace.com/remote-code-execution-and-critical-vulnerabilities-in-nasa-fprime-v3-4-3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json b/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json new file mode 100644 index 00000000000..93912b6be25 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp5w-82fv-gq5h", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2025-25371" + ], + "details": "NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25371" + }, + { + "type": "WEB", + "url": "https://visionspace.com/nasa-cfs-version-aquila-software-vulnerability-assessment" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jv78-c3q7-mc62/GHSA-jv78-c3q7-mc62.json b/advisories/unreviewed/2025/03/GHSA-jv78-c3q7-mc62/GHSA-jv78-c3q7-mc62.json index 6d8dd7ee0e1..4d41467b655 100644 --- a/advisories/unreviewed/2025/03/GHSA-jv78-c3q7-mc62/GHSA-jv78-c3q7-mc62.json +++ b/advisories/unreviewed/2025/03/GHSA-jv78-c3q7-mc62/GHSA-jv78-c3q7-mc62.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json b/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json index 5b4c3df0170..5e9ae178091 100644 --- a/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json +++ b/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m569-r4hr-26cw", - "modified": "2025-03-18T15:30:50Z", + "modified": "2025-03-25T21:31:33Z", "published": "2025-03-18T15:30:49Z", "aliases": [ "CVE-2025-30116" ], "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It allows remote attackers to access and download recorded video footage from the SD card via port 9091. Additionally, attackers can connect to port 9092 to stream the live video feed by bypassing the challenge-response authentication mechanism. This exposes sensitive location and personal data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:02Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json b/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json new file mode 100644 index 00000000000..f31caf73f82 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7qf-r7jf-7mf3", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2024-55028" + ], + "details": "A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55028" + }, + { + "type": "WEB", + "url": "https://visionspace.com/remote-code-execution-and-critical-vulnerabilities-in-nasa-fprime-v3-4-3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json b/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json new file mode 100644 index 00000000000..82d547bb0ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phrv-w9px-24x9", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2024-55030" + ], + "details": "A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55030" + }, + { + "type": "WEB", + "url": "https://visionspace.com/remote-code-execution-and-critical-vulnerabilities-in-nasa-fprime-v3-4-3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json b/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json index 9ad7aab4a93..60596635cb4 100644 --- a/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json +++ b/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json b/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json index cb143f50082..683386a58f0 100644 --- a/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json +++ b/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvq7-g7xm-xr5h", - "modified": "2025-03-18T15:30:50Z", + "modified": "2025-03-25T21:31:33Z", "published": "2025-03-18T15:30:49Z", "aliases": [ "CVE-2025-30117" ], "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. After bypassing the device pairing, an attacker can obtain sensitive user and vehicle information through the settings interface. Remote attackers can modify power management settings, disable recording, delete stored footage, and turn off battery protection, leading to potential denial-of-service conditions and vehicle battery drainage.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:02Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json b/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json new file mode 100644 index 00000000000..2325255bafc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmm8-wf49-vvww", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27837" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27837" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708238" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vcxh-wf9c-h9vv/GHSA-vcxh-wf9c-h9vv.json b/advisories/unreviewed/2025/03/GHSA-vcxh-wf9c-h9vv/GHSA-vcxh-wf9c-h9vv.json index 506b8baab6f..5f2bfa53798 100644 --- a/advisories/unreviewed/2025/03/GHSA-vcxh-wf9c-h9vv/GHSA-vcxh-wf9c-h9vv.json +++ b/advisories/unreviewed/2025/03/GHSA-vcxh-wf9c-h9vv/GHSA-vcxh-wf9c-h9vv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-286" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json b/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json new file mode 100644 index 00000000000..a2a5acd7c4f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74r-f89v-3jw9", + "modified": "2025-03-25T21:31:34Z", + "published": "2025-03-25T21:31:34Z", + "aliases": [ + "CVE-2025-27831" + ], + "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27831" + }, + { + "type": "WEB", + "url": "https://bugs.ghostscript.com/show_bug.cgi?id=708132" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json b/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json index 1c2af5562d7..25698406782 100644 --- a/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json +++ b/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-xxp6-fq36-p8jx/GHSA-xxp6-fq36-p8jx.json b/advisories/unreviewed/2025/03/GHSA-xxp6-fq36-p8jx/GHSA-xxp6-fq36-p8jx.json new file mode 100644 index 00000000000..4bafcef2b9c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xxp6-fq36-p8jx/GHSA-xxp6-fq36-p8jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxp6-fq36-p8jx", + "modified": "2025-03-25T21:31:33Z", + "published": "2025-03-25T21:31:33Z", + "aliases": [ + "CVE-2025-28904" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free allows Blind SQL Injection. This issue affects Web Directory Free: from n/a through 1.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/web-directory-free/vulnerability/wordpress-web-directory-free-plugin-1-7-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T19:15:45Z" + } +} \ No newline at end of file