From 207f0b999e335a14a138acef8e93898db9ebac9b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Feb 2025 00:32:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3cfr-rpp6-j86f.json | 9 ++- .../GHSA-p5xj-3764-5mhh.json | 9 ++- .../GHSA-p8wc-6g47-vh8j.json | 9 ++- .../GHSA-22h9-2mpf-7588.json | 4 +- .../GHSA-c3qm-r5gp-mgpm.json | 4 +- .../GHSA-q9rx-4p5p-q33x.json | 2 +- .../GHSA-2wm5-pffj-4758.json | 4 +- .../GHSA-32hg-4wf9-hj7c.json | 4 +- .../GHSA-835r-7gv7-g577.json | 4 +- .../GHSA-cg32-2535-p88w.json | 4 +- .../GHSA-h443-pjpv-28vx.json | 4 +- .../GHSA-jg3j-pgx3-878w.json | 7 ++- .../GHSA-mrx6-rgfc-x742.json | 4 +- .../GHSA-qfcg-72h5-fvgr.json | 4 +- .../GHSA-3524-72hj-ch2v.json | 15 +++-- .../GHSA-5fvw-q4g6-wqf7.json | 4 +- .../GHSA-62rm-mh7j-gv7j.json | 4 +- .../GHSA-89jm-c34p-prg4.json | 4 +- .../GHSA-92fr-gqp9-2ww5.json | 15 +++-- .../GHSA-fx89-732f-4cfg.json | 4 +- .../GHSA-hv7f-m7x4-mc78.json | 4 +- .../GHSA-j2rw-fqcc-853m.json | 4 +- .../GHSA-rcw4-xmqq-44pv.json | 4 +- .../GHSA-35hc-25v2-p75r.json | 4 +- .../GHSA-48vf-pq83-g67j.json | 4 +- .../GHSA-55gc-5h36-66xg.json | 6 +- .../GHSA-8ppj-8m99-39pw.json | 4 +- .../GHSA-j33j-2cp2-2wjw.json | 4 +- .../GHSA-v9v3-78qq-v64f.json | 4 +- .../GHSA-x6px-gcfp-pfxj.json | 4 +- .../GHSA-x8qh-8j65-v4j9.json | 15 +++-- .../GHSA-4h7h-x876-6f32.json | 4 +- .../GHSA-546f-m7rq-7rxw.json | 4 +- .../GHSA-5f85-4xxw-8pg3.json | 4 +- .../GHSA-fj2x-3jj2-h7v4.json | 4 +- .../GHSA-wr9x-7mjm-9m78.json | 4 +- .../GHSA-h62g-2c7p-qj54.json | 11 +++- .../GHSA-j2wf-m2jr-hvfv.json | 4 +- .../GHSA-2cqv-65v5-fpv5.json | 4 +- .../GHSA-4rj9-473r-rjfw.json | 4 +- .../GHSA-qq87-cr9r-6pj4.json | 4 +- .../GHSA-rw57-2hfm-7g6c.json | 15 +++-- .../GHSA-2m7j-4ff8-h52q.json | 4 +- .../GHSA-88h9-qf46-pmjc.json | 6 +- .../GHSA-8m3x-wq27-j7c8.json | 15 +++-- .../GHSA-8w77-hpx9-8fm3.json | 4 +- .../GHSA-m7mj-xvm6-p76f.json | 15 +++-- .../GHSA-7fmh-23mr-53m8.json | 4 +- .../GHSA-7wj6-3hq7-wcjx.json | 4 +- .../GHSA-g67j-78ch-4v54.json | 4 +- .../GHSA-pggg-fp6x-7ww3.json | 15 +++-- .../GHSA-wv7q-jrq7-c9jq.json | 4 +- .../GHSA-2wf7-qf7v-598q.json | 4 +- .../GHSA-5vvm-wqc8-r5m8.json | 4 +- .../GHSA-7xh3-2pj7-gxgm.json | 4 +- .../GHSA-f9jc-68cv-wp63.json | 4 +- .../GHSA-fx5j-cg4m-877m.json | 15 +++-- .../GHSA-pm9m-75p4-7h69.json | 15 +++-- .../GHSA-3g5r-c4ph-rc9c.json | 15 +++-- .../GHSA-3m82-fj9p-m6vq.json | 56 +++++++++++++++++++ .../GHSA-7477-77gr-grm6.json | 15 +++-- .../GHSA-8x4v-xprf-rvvq.json | 52 +++++++++++++++++ .../GHSA-9xg5-c6xr-xwgc.json | 56 +++++++++++++++++++ .../GHSA-c374-r9p6-qggq.json | 15 +++-- .../GHSA-c4gr-3x85-j99f.json | 15 +++-- .../GHSA-cf42-x7h8-3v3q.json | 15 +++-- .../GHSA-cqqc-xfhc-44fm.json | 56 +++++++++++++++++++ .../GHSA-ggrr-27x3-83x5.json | 56 +++++++++++++++++++ .../GHSA-j8hh-6vg7-jqjr.json | 15 +++-- .../GHSA-v7x9-h7r5-85q2.json | 56 +++++++++++++++++++ .../GHSA-vh84-4pf4-6xwf.json | 15 +++-- .../GHSA-xcvv-3xh8-q2mj.json | 15 +++-- 72 files changed, 677 insertions(+), 133 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8x4v-xprf-rvvq/GHSA-8x4v-xprf-rvvq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cqqc-xfhc-44fm/GHSA-cqqc-xfhc-44fm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ggrr-27x3-83x5/GHSA-ggrr-27x3-83x5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json diff --git a/advisories/unreviewed/2022/05/GHSA-3cfr-rpp6-j86f/GHSA-3cfr-rpp6-j86f.json b/advisories/unreviewed/2022/05/GHSA-3cfr-rpp6-j86f/GHSA-3cfr-rpp6-j86f.json index bb7ff0cc741..1ee3e858496 100644 --- a/advisories/unreviewed/2022/05/GHSA-3cfr-rpp6-j86f/GHSA-3cfr-rpp6-j86f.json +++ b/advisories/unreviewed/2022/05/GHSA-3cfr-rpp6-j86f/GHSA-3cfr-rpp6-j86f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3cfr-rpp6-j86f", - "modified": "2022-05-13T01:06:46Z", + "modified": "2025-02-11T00:31:20Z", "published": "2022-05-13T01:06:46Z", "aliases": [ "CVE-2012-2034" ], "details": "Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-p5xj-3764-5mhh/GHSA-p5xj-3764-5mhh.json b/advisories/unreviewed/2022/05/GHSA-p5xj-3764-5mhh/GHSA-p5xj-3764-5mhh.json index c7951a56aba..6ef5ad8f433 100644 --- a/advisories/unreviewed/2022/05/GHSA-p5xj-3764-5mhh/GHSA-p5xj-3764-5mhh.json +++ b/advisories/unreviewed/2022/05/GHSA-p5xj-3764-5mhh/GHSA-p5xj-3764-5mhh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5xj-3764-5mhh", - "modified": "2022-05-14T02:15:25Z", + "modified": "2025-02-11T00:31:20Z", "published": "2022-05-14T02:15:25Z", "aliases": [ "CVE-2012-0754" ], "details": "Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json b/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json index 2cabcc72714..e194b0d2fab 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json +++ b/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p8wc-6g47-vh8j", - "modified": "2025-01-22T18:31:47Z", + "modified": "2025-02-11T00:31:20Z", "published": "2022-05-14T01:02:48Z", "aliases": [ "CVE-2015-1635" ], "details": "HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka \"HTTP.sys Remote Code Execution Vulnerability.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/04/GHSA-22h9-2mpf-7588/GHSA-22h9-2mpf-7588.json b/advisories/unreviewed/2023/04/GHSA-22h9-2mpf-7588/GHSA-22h9-2mpf-7588.json index d29abd8090f..1573520f8f9 100644 --- a/advisories/unreviewed/2023/04/GHSA-22h9-2mpf-7588/GHSA-22h9-2mpf-7588.json +++ b/advisories/unreviewed/2023/04/GHSA-22h9-2mpf-7588/GHSA-22h9-2mpf-7588.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-c3qm-r5gp-mgpm/GHSA-c3qm-r5gp-mgpm.json b/advisories/unreviewed/2023/04/GHSA-c3qm-r5gp-mgpm/GHSA-c3qm-r5gp-mgpm.json index be087011f4b..f20fc89fe4d 100644 --- a/advisories/unreviewed/2023/04/GHSA-c3qm-r5gp-mgpm/GHSA-c3qm-r5gp-mgpm.json +++ b/advisories/unreviewed/2023/04/GHSA-c3qm-r5gp-mgpm/GHSA-c3qm-r5gp-mgpm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-535" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json b/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json index f7ffa8f6914..79bdfcb3810 100644 --- a/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json +++ b/advisories/unreviewed/2024/02/GHSA-q9rx-4p5p-q33x/GHSA-q9rx-4p5p-q33x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q9rx-4p5p-q33x", - "modified": "2025-01-28T18:31:20Z", + "modified": "2025-02-11T00:31:24Z", "published": "2024-02-22T00:31:01Z", "aliases": [ "CVE-2024-0446" diff --git a/advisories/unreviewed/2024/03/GHSA-2wm5-pffj-4758/GHSA-2wm5-pffj-4758.json b/advisories/unreviewed/2024/03/GHSA-2wm5-pffj-4758/GHSA-2wm5-pffj-4758.json index dd1daa924ff..a268da38fcb 100644 --- a/advisories/unreviewed/2024/03/GHSA-2wm5-pffj-4758/GHSA-2wm5-pffj-4758.json +++ b/advisories/unreviewed/2024/03/GHSA-2wm5-pffj-4758/GHSA-2wm5-pffj-4758.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-32hg-4wf9-hj7c/GHSA-32hg-4wf9-hj7c.json b/advisories/unreviewed/2024/03/GHSA-32hg-4wf9-hj7c/GHSA-32hg-4wf9-hj7c.json index 42263fc7433..a2980bea1af 100644 --- a/advisories/unreviewed/2024/03/GHSA-32hg-4wf9-hj7c/GHSA-32hg-4wf9-hj7c.json +++ b/advisories/unreviewed/2024/03/GHSA-32hg-4wf9-hj7c/GHSA-32hg-4wf9-hj7c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-835r-7gv7-g577/GHSA-835r-7gv7-g577.json b/advisories/unreviewed/2024/03/GHSA-835r-7gv7-g577/GHSA-835r-7gv7-g577.json index 669ac12a9d2..70e423b1d1d 100644 --- a/advisories/unreviewed/2024/03/GHSA-835r-7gv7-g577/GHSA-835r-7gv7-g577.json +++ b/advisories/unreviewed/2024/03/GHSA-835r-7gv7-g577/GHSA-835r-7gv7-g577.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-cg32-2535-p88w/GHSA-cg32-2535-p88w.json b/advisories/unreviewed/2024/03/GHSA-cg32-2535-p88w/GHSA-cg32-2535-p88w.json index bc7a685ac29..c576cd11219 100644 --- a/advisories/unreviewed/2024/03/GHSA-cg32-2535-p88w/GHSA-cg32-2535-p88w.json +++ b/advisories/unreviewed/2024/03/GHSA-cg32-2535-p88w/GHSA-cg32-2535-p88w.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cg32-2535-p88w", - "modified": "2024-03-05T03:30:31Z", + "modified": "2025-02-11T00:31:25Z", "published": "2024-03-05T03:30:31Z", "aliases": [ "CVE-2024-21815" ], - "details": "\nInsufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. \n\nThis issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.\n\n\n\n", + "details": "Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. \n\nThis issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-h443-pjpv-28vx/GHSA-h443-pjpv-28vx.json b/advisories/unreviewed/2024/03/GHSA-h443-pjpv-28vx/GHSA-h443-pjpv-28vx.json index 0107587b6bd..9bacb713b6d 100644 --- a/advisories/unreviewed/2024/03/GHSA-h443-pjpv-28vx/GHSA-h443-pjpv-28vx.json +++ b/advisories/unreviewed/2024/03/GHSA-h443-pjpv-28vx/GHSA-h443-pjpv-28vx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-jg3j-pgx3-878w/GHSA-jg3j-pgx3-878w.json b/advisories/unreviewed/2024/03/GHSA-jg3j-pgx3-878w/GHSA-jg3j-pgx3-878w.json index f6249948789..3255089f555 100644 --- a/advisories/unreviewed/2024/03/GHSA-jg3j-pgx3-878w/GHSA-jg3j-pgx3-878w.json +++ b/advisories/unreviewed/2024/03/GHSA-jg3j-pgx3-878w/GHSA-jg3j-pgx3-878w.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jg3j-pgx3-878w", - "modified": "2024-03-05T03:30:31Z", + "modified": "2025-02-11T00:31:25Z", "published": "2024-03-05T03:30:31Z", "aliases": [ "CVE-2024-21838" ], - "details": "\nImproper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. \n\nThis issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.\n\n\n\n", + "details": "Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. \n\nThis issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-mrx6-rgfc-x742/GHSA-mrx6-rgfc-x742.json b/advisories/unreviewed/2024/03/GHSA-mrx6-rgfc-x742/GHSA-mrx6-rgfc-x742.json index 2381b043997..a52e414eb33 100644 --- a/advisories/unreviewed/2024/03/GHSA-mrx6-rgfc-x742/GHSA-mrx6-rgfc-x742.json +++ b/advisories/unreviewed/2024/03/GHSA-mrx6-rgfc-x742/GHSA-mrx6-rgfc-x742.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qfcg-72h5-fvgr/GHSA-qfcg-72h5-fvgr.json b/advisories/unreviewed/2024/03/GHSA-qfcg-72h5-fvgr/GHSA-qfcg-72h5-fvgr.json index 8f30970798e..9b97eec2fb3 100644 --- a/advisories/unreviewed/2024/03/GHSA-qfcg-72h5-fvgr/GHSA-qfcg-72h5-fvgr.json +++ b/advisories/unreviewed/2024/03/GHSA-qfcg-72h5-fvgr/GHSA-qfcg-72h5-fvgr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3524-72hj-ch2v/GHSA-3524-72hj-ch2v.json b/advisories/unreviewed/2024/04/GHSA-3524-72hj-ch2v/GHSA-3524-72hj-ch2v.json index 1926ea95db0..4f203484d80 100644 --- a/advisories/unreviewed/2024/04/GHSA-3524-72hj-ch2v/GHSA-3524-72hj-ch2v.json +++ b/advisories/unreviewed/2024/04/GHSA-3524-72hj-ch2v/GHSA-3524-72hj-ch2v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3524-72hj-ch2v", - "modified": "2024-04-10T21:30:33Z", + "modified": "2025-02-11T00:31:31Z", "published": "2024-04-10T21:30:33Z", "aliases": [ "CVE-2024-29502" ], "details": "An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json b/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json index 33e6b156217..17984457bf9 100644 --- a/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json +++ b/advisories/unreviewed/2024/04/GHSA-5fvw-q4g6-wqf7/GHSA-5fvw-q4g6-wqf7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5fvw-q4g6-wqf7", - "modified": "2024-04-23T15:30:34Z", + "modified": "2025-02-11T00:31:33Z", "published": "2024-04-18T12:30:29Z", "aliases": [ "CVE-2024-29003" ], - "details": "The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction. ", + "details": "The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json b/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json index bac90c8a6d0..0c1ea60156c 100644 --- a/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json +++ b/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-89jm-c34p-prg4/GHSA-89jm-c34p-prg4.json b/advisories/unreviewed/2024/04/GHSA-89jm-c34p-prg4/GHSA-89jm-c34p-prg4.json index edb1b3ba9de..ef5aa0c8453 100644 --- a/advisories/unreviewed/2024/04/GHSA-89jm-c34p-prg4/GHSA-89jm-c34p-prg4.json +++ b/advisories/unreviewed/2024/04/GHSA-89jm-c34p-prg4/GHSA-89jm-c34p-prg4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-89jm-c34p-prg4", - "modified": "2024-04-18T09:30:44Z", + "modified": "2025-02-11T00:31:33Z", "published": "2024-04-18T09:30:44Z", "aliases": [ "CVE-2024-29001" ], - "details": "A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited. ", + "details": "A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-92fr-gqp9-2ww5/GHSA-92fr-gqp9-2ww5.json b/advisories/unreviewed/2024/04/GHSA-92fr-gqp9-2ww5/GHSA-92fr-gqp9-2ww5.json index 319f14bb319..b4e38e2cb0c 100644 --- a/advisories/unreviewed/2024/04/GHSA-92fr-gqp9-2ww5/GHSA-92fr-gqp9-2ww5.json +++ b/advisories/unreviewed/2024/04/GHSA-92fr-gqp9-2ww5/GHSA-92fr-gqp9-2ww5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92fr-gqp9-2ww5", - "modified": "2024-04-29T18:30:44Z", + "modified": "2025-02-11T00:31:34Z", "published": "2024-04-29T18:30:44Z", "aliases": [ "CVE-2024-32268" ], "details": "An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-241" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T16:15:35Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fx89-732f-4cfg/GHSA-fx89-732f-4cfg.json b/advisories/unreviewed/2024/04/GHSA-fx89-732f-4cfg/GHSA-fx89-732f-4cfg.json index 34193532056..f6ddf9fc3df 100644 --- a/advisories/unreviewed/2024/04/GHSA-fx89-732f-4cfg/GHSA-fx89-732f-4cfg.json +++ b/advisories/unreviewed/2024/04/GHSA-fx89-732f-4cfg/GHSA-fx89-732f-4cfg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json b/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json index d8ced86cb6c..f405821faec 100644 --- a/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json +++ b/advisories/unreviewed/2024/04/GHSA-hv7f-m7x4-mc78/GHSA-hv7f-m7x4-mc78.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-j2rw-fqcc-853m/GHSA-j2rw-fqcc-853m.json b/advisories/unreviewed/2024/04/GHSA-j2rw-fqcc-853m/GHSA-j2rw-fqcc-853m.json index 1f88ed563e9..1dfb89fb33a 100644 --- a/advisories/unreviewed/2024/04/GHSA-j2rw-fqcc-853m/GHSA-j2rw-fqcc-853m.json +++ b/advisories/unreviewed/2024/04/GHSA-j2rw-fqcc-853m/GHSA-j2rw-fqcc-853m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rcw4-xmqq-44pv/GHSA-rcw4-xmqq-44pv.json b/advisories/unreviewed/2024/04/GHSA-rcw4-xmqq-44pv/GHSA-rcw4-xmqq-44pv.json index 4f47f9a6f5b..f643f3169a9 100644 --- a/advisories/unreviewed/2024/04/GHSA-rcw4-xmqq-44pv/GHSA-rcw4-xmqq-44pv.json +++ b/advisories/unreviewed/2024/04/GHSA-rcw4-xmqq-44pv/GHSA-rcw4-xmqq-44pv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rcw4-xmqq-44pv", - "modified": "2024-04-17T18:31:36Z", + "modified": "2025-02-11T00:31:32Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-28073" ], - "details": "SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.\n", + "details": "SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-35hc-25v2-p75r/GHSA-35hc-25v2-p75r.json b/advisories/unreviewed/2024/05/GHSA-35hc-25v2-p75r/GHSA-35hc-25v2-p75r.json index d1fcb932b81..b073ef17491 100644 --- a/advisories/unreviewed/2024/05/GHSA-35hc-25v2-p75r/GHSA-35hc-25v2-p75r.json +++ b/advisories/unreviewed/2024/05/GHSA-35hc-25v2-p75r/GHSA-35hc-25v2-p75r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-35hc-25v2-p75r", - "modified": "2024-05-20T21:31:09Z", + "modified": "2025-02-11T00:31:36Z", "published": "2024-05-20T21:31:09Z", "aliases": [ "CVE-2024-29000" ], - "details": "The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability. ", + "details": "The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-48vf-pq83-g67j/GHSA-48vf-pq83-g67j.json b/advisories/unreviewed/2024/05/GHSA-48vf-pq83-g67j/GHSA-48vf-pq83-g67j.json index 02589190e86..953f63228a8 100644 --- a/advisories/unreviewed/2024/05/GHSA-48vf-pq83-g67j/GHSA-48vf-pq83-g67j.json +++ b/advisories/unreviewed/2024/05/GHSA-48vf-pq83-g67j/GHSA-48vf-pq83-g67j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-48vf-pq83-g67j", - "modified": "2024-05-14T15:32:52Z", + "modified": "2025-02-11T00:31:36Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-23473" ], - "details": "The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. \n\nWe thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities. ", + "details": "The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. \n\nWe thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-55gc-5h36-66xg/GHSA-55gc-5h36-66xg.json b/advisories/unreviewed/2024/05/GHSA-55gc-5h36-66xg/GHSA-55gc-5h36-66xg.json index 55aa7ff4f0e..63c4275608f 100644 --- a/advisories/unreviewed/2024/05/GHSA-55gc-5h36-66xg/GHSA-55gc-5h36-66xg.json +++ b/advisories/unreviewed/2024/05/GHSA-55gc-5h36-66xg/GHSA-55gc-5h36-66xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55gc-5h36-66xg", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-02-11T00:31:34Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3606" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8ppj-8m99-39pw/GHSA-8ppj-8m99-39pw.json b/advisories/unreviewed/2024/05/GHSA-8ppj-8m99-39pw/GHSA-8ppj-8m99-39pw.json index 6df9fa0080e..415e0da27e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-8ppj-8m99-39pw/GHSA-8ppj-8m99-39pw.json +++ b/advisories/unreviewed/2024/05/GHSA-8ppj-8m99-39pw/GHSA-8ppj-8m99-39pw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8ppj-8m99-39pw", - "modified": "2024-05-14T15:32:53Z", + "modified": "2025-02-11T00:31:36Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-28075" ], - "details": "The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. \n\nWe thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities. ", + "details": "The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. \n\nWe thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json b/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json index 9be626d24fa..b6a5822b367 100644 --- a/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json +++ b/advisories/unreviewed/2024/05/GHSA-j33j-2cp2-2wjw/GHSA-j33j-2cp2-2wjw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json b/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json index b1c16fa28e6..fe71a9639fe 100644 --- a/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json +++ b/advisories/unreviewed/2024/05/GHSA-v9v3-78qq-v64f/GHSA-v9v3-78qq-v64f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json b/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json index 5c7145986ae..32b2f6631b7 100644 --- a/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json +++ b/advisories/unreviewed/2024/05/GHSA-x6px-gcfp-pfxj/GHSA-x6px-gcfp-pfxj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json b/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json index c00575084dc..0382b340c04 100644 --- a/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json +++ b/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8qh-8j65-v4j9", - "modified": "2024-08-20T06:31:36Z", + "modified": "2025-02-11T00:31:36Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-26306" ], "details": "iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in \"Everlasting ROBOT: the Marvin Attack\" by Hubert Kario.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-385" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:08:51Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4h7h-x876-6f32/GHSA-4h7h-x876-6f32.json b/advisories/unreviewed/2024/06/GHSA-4h7h-x876-6f32/GHSA-4h7h-x876-6f32.json index 35efe86d99d..a96fc38afea 100644 --- a/advisories/unreviewed/2024/06/GHSA-4h7h-x876-6f32/GHSA-4h7h-x876-6f32.json +++ b/advisories/unreviewed/2024/06/GHSA-4h7h-x876-6f32/GHSA-4h7h-x876-6f32.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-546f-m7rq-7rxw/GHSA-546f-m7rq-7rxw.json b/advisories/unreviewed/2024/06/GHSA-546f-m7rq-7rxw/GHSA-546f-m7rq-7rxw.json index 9f926d92e7c..41c1a7e6a96 100644 --- a/advisories/unreviewed/2024/06/GHSA-546f-m7rq-7rxw/GHSA-546f-m7rq-7rxw.json +++ b/advisories/unreviewed/2024/06/GHSA-546f-m7rq-7rxw/GHSA-546f-m7rq-7rxw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-5f85-4xxw-8pg3/GHSA-5f85-4xxw-8pg3.json b/advisories/unreviewed/2024/06/GHSA-5f85-4xxw-8pg3/GHSA-5f85-4xxw-8pg3.json index eaa2ef4f7d9..bc5a697cdf8 100644 --- a/advisories/unreviewed/2024/06/GHSA-5f85-4xxw-8pg3/GHSA-5f85-4xxw-8pg3.json +++ b/advisories/unreviewed/2024/06/GHSA-5f85-4xxw-8pg3/GHSA-5f85-4xxw-8pg3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-fj2x-3jj2-h7v4/GHSA-fj2x-3jj2-h7v4.json b/advisories/unreviewed/2024/06/GHSA-fj2x-3jj2-h7v4/GHSA-fj2x-3jj2-h7v4.json index d6bfd607328..673eb50ee21 100644 --- a/advisories/unreviewed/2024/06/GHSA-fj2x-3jj2-h7v4/GHSA-fj2x-3jj2-h7v4.json +++ b/advisories/unreviewed/2024/06/GHSA-fj2x-3jj2-h7v4/GHSA-fj2x-3jj2-h7v4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-wr9x-7mjm-9m78/GHSA-wr9x-7mjm-9m78.json b/advisories/unreviewed/2024/06/GHSA-wr9x-7mjm-9m78/GHSA-wr9x-7mjm-9m78.json index 5a042098814..c7bd0e91ebf 100644 --- a/advisories/unreviewed/2024/06/GHSA-wr9x-7mjm-9m78/GHSA-wr9x-7mjm-9m78.json +++ b/advisories/unreviewed/2024/06/GHSA-wr9x-7mjm-9m78/GHSA-wr9x-7mjm-9m78.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-h62g-2c7p-qj54/GHSA-h62g-2c7p-qj54.json b/advisories/unreviewed/2024/07/GHSA-h62g-2c7p-qj54/GHSA-h62g-2c7p-qj54.json index 14ddbffb4b6..0ef8cb475b8 100644 --- a/advisories/unreviewed/2024/07/GHSA-h62g-2c7p-qj54/GHSA-h62g-2c7p-qj54.json +++ b/advisories/unreviewed/2024/07/GHSA-h62g-2c7p-qj54/GHSA-h62g-2c7p-qj54.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h62g-2c7p-qj54", - "modified": "2024-07-09T03:31:44Z", + "modified": "2025-02-11T00:31:42Z", "published": "2024-07-09T03:31:44Z", "aliases": [ "CVE-2024-34786" ], "details": "UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio.\n\nThis vulnerability is fixed in UniFi iOS app 10.15.2 and later.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T02:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json b/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json index 4b63b22e25b..597ec2e916f 100644 --- a/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json +++ b/advisories/unreviewed/2024/07/GHSA-j2wf-m2jr-hvfv/GHSA-j2wf-m2jr-hvfv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-2cqv-65v5-fpv5/GHSA-2cqv-65v5-fpv5.json b/advisories/unreviewed/2024/10/GHSA-2cqv-65v5-fpv5/GHSA-2cqv-65v5-fpv5.json index 4102083936f..3715bc8c3c0 100644 --- a/advisories/unreviewed/2024/10/GHSA-2cqv-65v5-fpv5/GHSA-2cqv-65v5-fpv5.json +++ b/advisories/unreviewed/2024/10/GHSA-2cqv-65v5-fpv5/GHSA-2cqv-65v5-fpv5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-280" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json b/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json index 02c472d1670..1531a5732cd 100644 --- a/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json +++ b/advisories/unreviewed/2024/10/GHSA-4rj9-473r-rjfw/GHSA-4rj9-473r-rjfw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-544" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json b/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json index 6ad081a9cbf..9782db640e2 100644 --- a/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json +++ b/advisories/unreviewed/2024/10/GHSA-qq87-cr9r-6pj4/GHSA-qq87-cr9r-6pj4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-444" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-rw57-2hfm-7g6c/GHSA-rw57-2hfm-7g6c.json b/advisories/unreviewed/2024/10/GHSA-rw57-2hfm-7g6c/GHSA-rw57-2hfm-7g6c.json index eca0d7d7b5f..9996412ad1d 100644 --- a/advisories/unreviewed/2024/10/GHSA-rw57-2hfm-7g6c/GHSA-rw57-2hfm-7g6c.json +++ b/advisories/unreviewed/2024/10/GHSA-rw57-2hfm-7g6c/GHSA-rw57-2hfm-7g6c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rw57-2hfm-7g6c", - "modified": "2024-10-09T18:31:42Z", + "modified": "2025-02-11T00:31:42Z", "published": "2024-10-09T18:31:42Z", "aliases": [ "CVE-2024-42988" ], "details": "Lack of access control in ChallengeSolves (/api/v1/challenges//solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-09T17:15:16Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2m7j-4ff8-h52q/GHSA-2m7j-4ff8-h52q.json b/advisories/unreviewed/2024/11/GHSA-2m7j-4ff8-h52q/GHSA-2m7j-4ff8-h52q.json index 86cc8b5b529..74126e7d6e9 100644 --- a/advisories/unreviewed/2024/11/GHSA-2m7j-4ff8-h52q/GHSA-2m7j-4ff8-h52q.json +++ b/advisories/unreviewed/2024/11/GHSA-2m7j-4ff8-h52q/GHSA-2m7j-4ff8-h52q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json b/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json index 4b94269488a..1ba941c60a1 100644 --- a/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json +++ b/advisories/unreviewed/2024/11/GHSA-88h9-qf46-pmjc/GHSA-88h9-qf46-pmjc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88h9-qf46-pmjc", - "modified": "2024-11-26T12:41:37Z", + "modified": "2025-02-11T00:31:43Z", "published": "2024-11-26T12:41:37Z", "aliases": [ "CVE-2024-38830" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json b/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json index 756d11a95ef..3049151dc22 100644 --- a/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json +++ b/advisories/unreviewed/2024/11/GHSA-8m3x-wq27-j7c8/GHSA-8m3x-wq27-j7c8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8m3x-wq27-j7c8", - "modified": "2024-11-07T21:31:43Z", + "modified": "2025-02-11T00:31:42Z", "published": "2024-11-07T21:31:43Z", "aliases": [ "CVE-2019-20462" ], "details": "An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password of the Wi-Fi access point that the device used.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T21:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json b/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json index b6f145608b7..8d80a2e3317 100644 --- a/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json +++ b/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-86" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json b/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json index b758221870c..74357626148 100644 --- a/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json +++ b/advisories/unreviewed/2024/11/GHSA-m7mj-xvm6-p76f/GHSA-m7mj-xvm6-p76f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m7mj-xvm6-p76f", - "modified": "2024-11-08T00:30:45Z", + "modified": "2025-02-11T00:31:42Z", "published": "2024-11-08T00:30:45Z", "aliases": [ "CVE-2024-36062" ], "details": "The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-07T22:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7fmh-23mr-53m8/GHSA-7fmh-23mr-53m8.json b/advisories/unreviewed/2024/12/GHSA-7fmh-23mr-53m8/GHSA-7fmh-23mr-53m8.json index d3e3c7cfb7a..4d0ec6d968d 100644 --- a/advisories/unreviewed/2024/12/GHSA-7fmh-23mr-53m8/GHSA-7fmh-23mr-53m8.json +++ b/advisories/unreviewed/2024/12/GHSA-7fmh-23mr-53m8/GHSA-7fmh-23mr-53m8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-7wj6-3hq7-wcjx/GHSA-7wj6-3hq7-wcjx.json b/advisories/unreviewed/2024/12/GHSA-7wj6-3hq7-wcjx/GHSA-7wj6-3hq7-wcjx.json index 1696df79971..912272be859 100644 --- a/advisories/unreviewed/2024/12/GHSA-7wj6-3hq7-wcjx/GHSA-7wj6-3hq7-wcjx.json +++ b/advisories/unreviewed/2024/12/GHSA-7wj6-3hq7-wcjx/GHSA-7wj6-3hq7-wcjx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-g67j-78ch-4v54/GHSA-g67j-78ch-4v54.json b/advisories/unreviewed/2024/12/GHSA-g67j-78ch-4v54/GHSA-g67j-78ch-4v54.json index d2bb84cbb01..dd971ed056b 100644 --- a/advisories/unreviewed/2024/12/GHSA-g67j-78ch-4v54/GHSA-g67j-78ch-4v54.json +++ b/advisories/unreviewed/2024/12/GHSA-g67j-78ch-4v54/GHSA-g67j-78ch-4v54.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-pggg-fp6x-7ww3/GHSA-pggg-fp6x-7ww3.json b/advisories/unreviewed/2024/12/GHSA-pggg-fp6x-7ww3/GHSA-pggg-fp6x-7ww3.json index a4874e4b0dc..0eab8102cd3 100644 --- a/advisories/unreviewed/2024/12/GHSA-pggg-fp6x-7ww3/GHSA-pggg-fp6x-7ww3.json +++ b/advisories/unreviewed/2024/12/GHSA-pggg-fp6x-7ww3/GHSA-pggg-fp6x-7ww3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pggg-fp6x-7ww3", - "modified": "2024-12-18T06:30:49Z", + "modified": "2025-02-11T00:31:47Z", "published": "2024-12-18T06:30:49Z", "aliases": [ "CVE-2024-56169" ], "details": "A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. This can be employed as a fallback in case a new fetch fails or yields incorrect files. However, the product currently uses its cache merely as a bandwidth saving tool (because fetching is performed through deltas). If a fetch fails midway or yields incorrect files, there is no viable fallback. This leads to incomplete route origin validation data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-354" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-18T05:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wv7q-jrq7-c9jq/GHSA-wv7q-jrq7-c9jq.json b/advisories/unreviewed/2024/12/GHSA-wv7q-jrq7-c9jq/GHSA-wv7q-jrq7-c9jq.json index a67a21957e0..c36b14d8fb6 100644 --- a/advisories/unreviewed/2024/12/GHSA-wv7q-jrq7-c9jq/GHSA-wv7q-jrq7-c9jq.json +++ b/advisories/unreviewed/2024/12/GHSA-wv7q-jrq7-c9jq/GHSA-wv7q-jrq7-c9jq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2wf7-qf7v-598q/GHSA-2wf7-qf7v-598q.json b/advisories/unreviewed/2025/01/GHSA-2wf7-qf7v-598q/GHSA-2wf7-qf7v-598q.json index 305ea68498d..ab2cf9d66b6 100644 --- a/advisories/unreviewed/2025/01/GHSA-2wf7-qf7v-598q/GHSA-2wf7-qf7v-598q.json +++ b/advisories/unreviewed/2025/01/GHSA-2wf7-qf7v-598q/GHSA-2wf7-qf7v-598q.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1104" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5vvm-wqc8-r5m8/GHSA-5vvm-wqc8-r5m8.json b/advisories/unreviewed/2025/01/GHSA-5vvm-wqc8-r5m8/GHSA-5vvm-wqc8-r5m8.json index e6b21407561..2869d2f24a8 100644 --- a/advisories/unreviewed/2025/01/GHSA-5vvm-wqc8-r5m8/GHSA-5vvm-wqc8-r5m8.json +++ b/advisories/unreviewed/2025/01/GHSA-5vvm-wqc8-r5m8/GHSA-5vvm-wqc8-r5m8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7xh3-2pj7-gxgm/GHSA-7xh3-2pj7-gxgm.json b/advisories/unreviewed/2025/01/GHSA-7xh3-2pj7-gxgm/GHSA-7xh3-2pj7-gxgm.json index 00000cf7e7d..fe246004f2f 100644 --- a/advisories/unreviewed/2025/01/GHSA-7xh3-2pj7-gxgm/GHSA-7xh3-2pj7-gxgm.json +++ b/advisories/unreviewed/2025/01/GHSA-7xh3-2pj7-gxgm/GHSA-7xh3-2pj7-gxgm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1104" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-f9jc-68cv-wp63/GHSA-f9jc-68cv-wp63.json b/advisories/unreviewed/2025/01/GHSA-f9jc-68cv-wp63/GHSA-f9jc-68cv-wp63.json index 10adddd6881..5c83b785fbd 100644 --- a/advisories/unreviewed/2025/01/GHSA-f9jc-68cv-wp63/GHSA-f9jc-68cv-wp63.json +++ b/advisories/unreviewed/2025/01/GHSA-f9jc-68cv-wp63/GHSA-f9jc-68cv-wp63.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1104" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fx5j-cg4m-877m/GHSA-fx5j-cg4m-877m.json b/advisories/unreviewed/2025/01/GHSA-fx5j-cg4m-877m/GHSA-fx5j-cg4m-877m.json index ed242c48ef7..5201fe2a586 100644 --- a/advisories/unreviewed/2025/01/GHSA-fx5j-cg4m-877m/GHSA-fx5j-cg4m-877m.json +++ b/advisories/unreviewed/2025/01/GHSA-fx5j-cg4m-877m/GHSA-fx5j-cg4m-877m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fx5j-cg4m-877m", - "modified": "2025-01-22T00:33:35Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-01-22T00:33:35Z", "aliases": [ "CVE-2024-24444" ], "details": "Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-775" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-pm9m-75p4-7h69/GHSA-pm9m-75p4-7h69.json b/advisories/unreviewed/2025/01/GHSA-pm9m-75p4-7h69/GHSA-pm9m-75p4-7h69.json index 511e75ea937..f821a26aace 100644 --- a/advisories/unreviewed/2025/01/GHSA-pm9m-75p4-7h69/GHSA-pm9m-75p4-7h69.json +++ b/advisories/unreviewed/2025/01/GHSA-pm9m-75p4-7h69/GHSA-pm9m-75p4-7h69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pm9m-75p4-7h69", - "modified": "2025-01-30T00:31:04Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-01-30T00:31:04Z", "aliases": [ "CVE-2024-54852" ], "details": "When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-90" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-29T22:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3g5r-c4ph-rc9c/GHSA-3g5r-c4ph-rc9c.json b/advisories/unreviewed/2025/02/GHSA-3g5r-c4ph-rc9c/GHSA-3g5r-c4ph-rc9c.json index 82a1a725299..6c111d9119a 100644 --- a/advisories/unreviewed/2025/02/GHSA-3g5r-c4ph-rc9c/GHSA-3g5r-c4ph-rc9c.json +++ b/advisories/unreviewed/2025/02/GHSA-3g5r-c4ph-rc9c/GHSA-3g5r-c4ph-rc9c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3g5r-c4ph-rc9c", - "modified": "2025-02-10T18:30:47Z", + "modified": "2025-02-11T00:31:48Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-57409" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T18:15:33Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json b/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json new file mode 100644 index 00000000000..b3c198621a5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m82-fj9p-m6vq", + "modified": "2025-02-11T00:31:53Z", + "published": "2025-02-11T00:31:52Z", + "aliases": [ + "CVE-2025-1163" + ], + "details": "A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerability affects the function login of the component Authentication. The manipulation of the argument username leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1163" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/J0hnFFFF/j0hn_upload_three/blob/main/binary1.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295066" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295066" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T00:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7477-77gr-grm6/GHSA-7477-77gr-grm6.json b/advisories/unreviewed/2025/02/GHSA-7477-77gr-grm6/GHSA-7477-77gr-grm6.json index 6a9a74205df..4aa38935675 100644 --- a/advisories/unreviewed/2025/02/GHSA-7477-77gr-grm6/GHSA-7477-77gr-grm6.json +++ b/advisories/unreviewed/2025/02/GHSA-7477-77gr-grm6/GHSA-7477-77gr-grm6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7477-77gr-grm6", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-11T00:31:48Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2024-57609" ], "details": "An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-8x4v-xprf-rvvq/GHSA-8x4v-xprf-rvvq.json b/advisories/unreviewed/2025/02/GHSA-8x4v-xprf-rvvq/GHSA-8x4v-xprf-rvvq.json new file mode 100644 index 00000000000..26316b5a608 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8x4v-xprf-rvvq/GHSA-8x4v-xprf-rvvq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x4v-xprf-rvvq", + "modified": "2025-02-11T00:31:51Z", + "published": "2025-02-11T00:31:51Z", + "aliases": [ + "CVE-2025-1158" + ], + "details": "A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the argument safetyGroupId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1158" + }, + { + "type": "WEB", + "url": "https://github.com/Rain1er/report/blob/main/CDG/addPolicyToSafetyGroup.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295062" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295062" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.493644" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json b/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json new file mode 100644 index 00000000000..f393dcd0204 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xg5-c6xr-xwgc", + "modified": "2025-02-11T00:31:53Z", + "published": "2025-02-11T00:31:53Z", + "aliases": [ + "CVE-2025-1164" + ], + "details": "A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1164" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/J0hnFFFF/j0hn_upload_four/blob/main/binary2.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T00:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c374-r9p6-qggq/GHSA-c374-r9p6-qggq.json b/advisories/unreviewed/2025/02/GHSA-c374-r9p6-qggq/GHSA-c374-r9p6-qggq.json index 14f70c25c8d..2e3d1ef59b2 100644 --- a/advisories/unreviewed/2025/02/GHSA-c374-r9p6-qggq/GHSA-c374-r9p6-qggq.json +++ b/advisories/unreviewed/2025/02/GHSA-c374-r9p6-qggq/GHSA-c374-r9p6-qggq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c374-r9p6-qggq", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2024-25883" ], "details": "The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-682" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c4gr-3x85-j99f/GHSA-c4gr-3x85-j99f.json b/advisories/unreviewed/2025/02/GHSA-c4gr-3x85-j99f/GHSA-c4gr-3x85-j99f.json index eee6d598eb5..c8e9d1d6999 100644 --- a/advisories/unreviewed/2025/02/GHSA-c4gr-3x85-j99f/GHSA-c4gr-3x85-j99f.json +++ b/advisories/unreviewed/2025/02/GHSA-c4gr-3x85-j99f/GHSA-c4gr-3x85-j99f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c4gr-3x85-j99f", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2024-55241" ], "details": "An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:38Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cf42-x7h8-3v3q/GHSA-cf42-x7h8-3v3q.json b/advisories/unreviewed/2025/02/GHSA-cf42-x7h8-3v3q/GHSA-cf42-x7h8-3v3q.json index ee5fd1b3a3a..f347f8a262c 100644 --- a/advisories/unreviewed/2025/02/GHSA-cf42-x7h8-3v3q/GHSA-cf42-x7h8-3v3q.json +++ b/advisories/unreviewed/2025/02/GHSA-cf42-x7h8-3v3q/GHSA-cf42-x7h8-3v3q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cf42-x7h8-3v3q", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2024-57392" ], "details": "Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cqqc-xfhc-44fm/GHSA-cqqc-xfhc-44fm.json b/advisories/unreviewed/2025/02/GHSA-cqqc-xfhc-44fm/GHSA-cqqc-xfhc-44fm.json new file mode 100644 index 00000000000..e3b8ddd0693 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cqqc-xfhc-44fm/GHSA-cqqc-xfhc-44fm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqqc-xfhc-44fm", + "modified": "2025-02-11T00:31:51Z", + "published": "2025-02-11T00:31:51Z", + "aliases": [ + "CVE-2025-1159" + ], + "details": "A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academic-calendar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1159" + }, + { + "type": "WEB", + "url": "https://github.com/KhukuriRimal/Vulnerabilities/blob/main/Stored%20Cross%20Site%20Scripting-%20Teachers%20Account%20Takeover%20Possibility.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295063" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295063" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.493687" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T22:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ggrr-27x3-83x5/GHSA-ggrr-27x3-83x5.json b/advisories/unreviewed/2025/02/GHSA-ggrr-27x3-83x5/GHSA-ggrr-27x3-83x5.json new file mode 100644 index 00000000000..ecb873a95e5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ggrr-27x3-83x5/GHSA-ggrr-27x3-83x5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggrr-27x3-83x5", + "modified": "2025-02-11T00:31:52Z", + "published": "2025-02-11T00:31:52Z", + "aliases": [ + "CVE-2025-1160" + ], + "details": "A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of default credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1160" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jmx0hxq/0e9cde14b6e9190a7451cd72d7b23bfd" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295064" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295064" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.493860" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j8hh-6vg7-jqjr/GHSA-j8hh-6vg7-jqjr.json b/advisories/unreviewed/2025/02/GHSA-j8hh-6vg7-jqjr/GHSA-j8hh-6vg7-jqjr.json index 57d4f35e5c1..8c7e38e0ecc 100644 --- a/advisories/unreviewed/2025/02/GHSA-j8hh-6vg7-jqjr/GHSA-j8hh-6vg7-jqjr.json +++ b/advisories/unreviewed/2025/02/GHSA-j8hh-6vg7-jqjr/GHSA-j8hh-6vg7-jqjr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j8hh-6vg7-jqjr", - "modified": "2025-02-10T18:30:47Z", + "modified": "2025-02-11T00:31:48Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-57408" ], "details": "An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T18:15:33Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json b/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json new file mode 100644 index 00000000000..f0d9e07af3c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7x9-h7r5-85q2", + "modified": "2025-02-11T00:31:52Z", + "published": "2025-02-11T00:31:52Z", + "aliases": [ + "CVE-2025-1162" + ], + "details": "A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\\_parse/load\\_user-profile.php. The manipulation of the argument userhash leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1162" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/J0hnFFFF/j0hn_upload_two/blob/main/web1.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295065" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295065" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-10T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vh84-4pf4-6xwf/GHSA-vh84-4pf4-6xwf.json b/advisories/unreviewed/2025/02/GHSA-vh84-4pf4-6xwf/GHSA-vh84-4pf4-6xwf.json index 7b19fb90dfb..aad430c260d 100644 --- a/advisories/unreviewed/2025/02/GHSA-vh84-4pf4-6xwf/GHSA-vh84-4pf4-6xwf.json +++ b/advisories/unreviewed/2025/02/GHSA-vh84-4pf4-6xwf/GHSA-vh84-4pf4-6xwf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vh84-4pf4-6xwf", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2024-48589" ], "details": "Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xcvv-3xh8-q2mj/GHSA-xcvv-3xh8-q2mj.json b/advisories/unreviewed/2025/02/GHSA-xcvv-3xh8-q2mj/GHSA-xcvv-3xh8-q2mj.json index 7cb0a7d618c..205c68b54a0 100644 --- a/advisories/unreviewed/2025/02/GHSA-xcvv-3xh8-q2mj/GHSA-xcvv-3xh8-q2mj.json +++ b/advisories/unreviewed/2025/02/GHSA-xcvv-3xh8-q2mj/GHSA-xcvv-3xh8-q2mj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcvv-3xh8-q2mj", - "modified": "2025-02-07T03:32:02Z", + "modified": "2025-02-11T00:31:47Z", "published": "2025-02-07T03:32:02Z", "aliases": [ "CVE-2020-36085" ], "details": "Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and Last Name in Apply For This Job Form.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T22:15:33Z"