diff --git a/advisories/unreviewed/2022/01/GHSA-4g73-3mxf-j47w/GHSA-4g73-3mxf-j47w.json b/advisories/unreviewed/2022/01/GHSA-4g73-3mxf-j47w/GHSA-4g73-3mxf-j47w.json index 7cfc03e57b5..7ceeb6439e5 100644 --- a/advisories/unreviewed/2022/01/GHSA-4g73-3mxf-j47w/GHSA-4g73-3mxf-j47w.json +++ b/advisories/unreviewed/2022/01/GHSA-4g73-3mxf-j47w/GHSA-4g73-3mxf-j47w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4g73-3mxf-j47w", - "modified": "2022-01-20T00:02:14Z", + "modified": "2025-03-12T21:31:26Z", "published": "2022-01-14T00:02:17Z", "aliases": [ "CVE-2022-23131" ], "details": "In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/02/GHSA-g86r-9849-44wq/GHSA-g86r-9849-44wq.json b/advisories/unreviewed/2023/02/GHSA-g86r-9849-44wq/GHSA-g86r-9849-44wq.json index b885d004352..cd2b09401a8 100644 --- a/advisories/unreviewed/2023/02/GHSA-g86r-9849-44wq/GHSA-g86r-9849-44wq.json +++ b/advisories/unreviewed/2023/02/GHSA-g86r-9849-44wq/GHSA-g86r-9849-44wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g86r-9849-44wq", - "modified": "2023-03-03T18:30:27Z", + "modified": "2025-03-12T21:31:27Z", "published": "2023-02-23T21:30:16Z", "aliases": [ "CVE-2023-0597" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/linus/97e3d26b5e5f371b3ee223d94dd123e6c442ba80" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/07/28/1" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/07/28/1" diff --git a/advisories/unreviewed/2023/02/GHSA-pf7g-97vv-qmrr/GHSA-pf7g-97vv-qmrr.json b/advisories/unreviewed/2023/02/GHSA-pf7g-97vv-qmrr/GHSA-pf7g-97vv-qmrr.json index 8d19a6ab4d7..95c9b8f3676 100644 --- a/advisories/unreviewed/2023/02/GHSA-pf7g-97vv-qmrr/GHSA-pf7g-97vv-qmrr.json +++ b/advisories/unreviewed/2023/02/GHSA-pf7g-97vv-qmrr/GHSA-pf7g-97vv-qmrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf7g-97vv-qmrr", - "modified": "2023-03-03T18:30:27Z", + "modified": "2025-03-12T21:31:27Z", "published": "2023-02-23T21:30:17Z", "aliases": [ "CVE-2022-3219" diff --git a/advisories/unreviewed/2024/04/GHSA-2cpq-fw2c-xjfv/GHSA-2cpq-fw2c-xjfv.json b/advisories/unreviewed/2024/04/GHSA-2cpq-fw2c-xjfv/GHSA-2cpq-fw2c-xjfv.json index 9b85402d786..0a58b4d5a4d 100644 --- a/advisories/unreviewed/2024/04/GHSA-2cpq-fw2c-xjfv/GHSA-2cpq-fw2c-xjfv.json +++ b/advisories/unreviewed/2024/04/GHSA-2cpq-fw2c-xjfv/GHSA-2cpq-fw2c-xjfv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2cpq-fw2c-xjfv", - "modified": "2024-04-10T21:30:34Z", + "modified": "2025-03-12T21:31:27Z", "published": "2024-04-10T21:30:34Z", "aliases": [ "CVE-2024-31430" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-4r7g-8pjm-hmjc/GHSA-4r7g-8pjm-hmjc.json b/advisories/unreviewed/2024/04/GHSA-4r7g-8pjm-hmjc/GHSA-4r7g-8pjm-hmjc.json index 998302cb2d3..e28bbbc2daa 100644 --- a/advisories/unreviewed/2024/04/GHSA-4r7g-8pjm-hmjc/GHSA-4r7g-8pjm-hmjc.json +++ b/advisories/unreviewed/2024/04/GHSA-4r7g-8pjm-hmjc/GHSA-4r7g-8pjm-hmjc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4r7g-8pjm-hmjc", - "modified": "2024-04-15T09:30:54Z", + "modified": "2025-03-12T21:31:28Z", "published": "2024-04-15T09:30:54Z", "aliases": [ "CVE-2024-32125" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-8p8h-55m5-85pr/GHSA-8p8h-55m5-85pr.json b/advisories/unreviewed/2024/04/GHSA-8p8h-55m5-85pr/GHSA-8p8h-55m5-85pr.json index f8b94152558..646ad6b2743 100644 --- a/advisories/unreviewed/2024/04/GHSA-8p8h-55m5-85pr/GHSA-8p8h-55m5-85pr.json +++ b/advisories/unreviewed/2024/04/GHSA-8p8h-55m5-85pr/GHSA-8p8h-55m5-85pr.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-987j-g759-4rq3/GHSA-987j-g759-4rq3.json b/advisories/unreviewed/2024/04/GHSA-987j-g759-4rq3/GHSA-987j-g759-4rq3.json index a0fe64b7b29..b1289a0b5bb 100644 --- a/advisories/unreviewed/2024/04/GHSA-987j-g759-4rq3/GHSA-987j-g759-4rq3.json +++ b/advisories/unreviewed/2024/04/GHSA-987j-g759-4rq3/GHSA-987j-g759-4rq3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-987j-g759-4rq3", - "modified": "2024-04-24T18:30:33Z", + "modified": "2025-03-12T21:31:28Z", "published": "2024-04-24T18:30:33Z", "aliases": [ "CVE-2023-51405" ], - "details": "Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.\n\n", + "details": "Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-ffg5-77xm-p7h2/GHSA-ffg5-77xm-p7h2.json b/advisories/unreviewed/2024/04/GHSA-ffg5-77xm-p7h2/GHSA-ffg5-77xm-p7h2.json index d0f0adc73cb..4c4856d55ec 100644 --- a/advisories/unreviewed/2024/04/GHSA-ffg5-77xm-p7h2/GHSA-ffg5-77xm-p7h2.json +++ b/advisories/unreviewed/2024/04/GHSA-ffg5-77xm-p7h2/GHSA-ffg5-77xm-p7h2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ffg5-77xm-p7h2", - "modified": "2024-04-18T09:30:45Z", + "modified": "2025-03-12T21:31:28Z", "published": "2024-04-18T09:30:45Z", "aliases": [ "CVE-2024-32598" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-v43f-6mhr-gwc4/GHSA-v43f-6mhr-gwc4.json b/advisories/unreviewed/2024/04/GHSA-v43f-6mhr-gwc4/GHSA-v43f-6mhr-gwc4.json index d0fd34d97be..842b3c6ef6f 100644 --- a/advisories/unreviewed/2024/04/GHSA-v43f-6mhr-gwc4/GHSA-v43f-6mhr-gwc4.json +++ b/advisories/unreviewed/2024/04/GHSA-v43f-6mhr-gwc4/GHSA-v43f-6mhr-gwc4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v43f-6mhr-gwc4", - "modified": "2024-04-18T12:30:30Z", + "modified": "2025-03-12T21:31:28Z", "published": "2024-04-18T12:30:30Z", "aliases": [ "CVE-2024-32576" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json b/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json index c8216415db8..c65ec9a6801 100644 --- a/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json +++ b/advisories/unreviewed/2024/04/GHSA-v4qv-r5g6-wxrp/GHSA-v4qv-r5g6-wxrp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-h5p6-2x4v-9wqh/GHSA-h5p6-2x4v-9wqh.json b/advisories/unreviewed/2025/02/GHSA-h5p6-2x4v-9wqh/GHSA-h5p6-2x4v-9wqh.json index 898f5f66fcc..742539c9f73 100644 --- a/advisories/unreviewed/2025/02/GHSA-h5p6-2x4v-9wqh/GHSA-h5p6-2x4v-9wqh.json +++ b/advisories/unreviewed/2025/02/GHSA-h5p6-2x4v-9wqh/GHSA-h5p6-2x4v-9wqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h5p6-2x4v-9wqh", - "modified": "2025-02-21T18:31:15Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-02-21T18:31:15Z", "aliases": [ "CVE-2024-55159" ], "details": "GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T18:15:18Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jrq6-48vf-qc9h/GHSA-jrq6-48vf-qc9h.json b/advisories/unreviewed/2025/02/GHSA-jrq6-48vf-qc9h/GHSA-jrq6-48vf-qc9h.json index 62507436c39..542b9e4ab2a 100644 --- a/advisories/unreviewed/2025/02/GHSA-jrq6-48vf-qc9h/GHSA-jrq6-48vf-qc9h.json +++ b/advisories/unreviewed/2025/02/GHSA-jrq6-48vf-qc9h/GHSA-jrq6-48vf-qc9h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jrq6-48vf-qc9h", - "modified": "2025-02-14T00:30:45Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-02-14T00:30:45Z", "aliases": [ "CVE-2025-22961" ], "details": "A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access Control (CWE-284). Unauthenticated attackers can directly access sensitive database backup files (snapshot_users.db) via publicly exposed URLs (/logs/devcfg/snapshot/ and /logs/devcfg/user/). Exploiting this vulnerability allows retrieval of sensitive user data, including login credentials, potentially leading to full system compromise.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json b/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json index 2a6cbc518e7..25175077c8f 100644 --- a/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json +++ b/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pq8f-mw6x-f2j2", - "modified": "2025-02-26T18:30:38Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-02-26T18:30:38Z", "aliases": [ "CVE-2025-25462" ], "details": "A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-26T16:15:16Z" diff --git a/advisories/unreviewed/2025/03/GHSA-29qq-gf32-fj2m/GHSA-29qq-gf32-fj2m.json b/advisories/unreviewed/2025/03/GHSA-29qq-gf32-fj2m/GHSA-29qq-gf32-fj2m.json index 1190fdb6e05..14668653d5d 100644 --- a/advisories/unreviewed/2025/03/GHSA-29qq-gf32-fj2m/GHSA-29qq-gf32-fj2m.json +++ b/advisories/unreviewed/2025/03/GHSA-29qq-gf32-fj2m/GHSA-29qq-gf32-fj2m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-29qq-gf32-fj2m", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-12T21:31:29Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2025-26695" ], "details": "When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json index baa7f5b85d5..7187eab78d5 100644 --- a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json +++ b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2j99-5q75-3f57", - "modified": "2025-03-11T21:30:34Z", + "modified": "2025-03-12T21:31:29Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2025-24201" ], "details": "An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T18:15:30Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3j25-3c73-vg7p/GHSA-3j25-3c73-vg7p.json b/advisories/unreviewed/2025/03/GHSA-3j25-3c73-vg7p/GHSA-3j25-3c73-vg7p.json index e4672924330..156c847cf17 100644 --- a/advisories/unreviewed/2025/03/GHSA-3j25-3c73-vg7p/GHSA-3j25-3c73-vg7p.json +++ b/advisories/unreviewed/2025/03/GHSA-3j25-3c73-vg7p/GHSA-3j25-3c73-vg7p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3j25-3c73-vg7p", - "modified": "2025-03-10T15:30:47Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-03-10T15:30:47Z", "aliases": [ "CVE-2025-25615" ], "details": "Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T14:15:24Z" diff --git a/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json b/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json index 905120a95ef..4cc02597485 100644 --- a/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json +++ b/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42rw-qp74-jqxj", - "modified": "2025-03-10T15:30:47Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-03-10T15:30:47Z", "aliases": [ "CVE-2024-57492" ], "details": "An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1262" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T14:15:24Z" diff --git a/advisories/unreviewed/2025/03/GHSA-48hh-v7xg-xpgq/GHSA-48hh-v7xg-xpgq.json b/advisories/unreviewed/2025/03/GHSA-48hh-v7xg-xpgq/GHSA-48hh-v7xg-xpgq.json index 70fe1dfee39..200263b375a 100644 --- a/advisories/unreviewed/2025/03/GHSA-48hh-v7xg-xpgq/GHSA-48hh-v7xg-xpgq.json +++ b/advisories/unreviewed/2025/03/GHSA-48hh-v7xg-xpgq/GHSA-48hh-v7xg-xpgq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48hh-v7xg-xpgq", - "modified": "2025-03-10T15:30:48Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-03-10T15:30:47Z", "aliases": [ "CVE-2025-25616" ], "details": "Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T14:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4gx3-p432-m8m7/GHSA-4gx3-p432-m8m7.json b/advisories/unreviewed/2025/03/GHSA-4gx3-p432-m8m7/GHSA-4gx3-p432-m8m7.json new file mode 100644 index 00000000000..9564209247b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4gx3-p432-m8m7/GHSA-4gx3-p432-m8m7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gx3-p432-m8m7", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2025-0118" + ], + "details": "A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device.\n\nThis issue does not apply to the GlobalProtect app on other (non-Windows) platforms.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0118" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-618" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8g77-54rh-46hx/GHSA-8g77-54rh-46hx.json b/advisories/unreviewed/2025/03/GHSA-8g77-54rh-46hx/GHSA-8g77-54rh-46hx.json new file mode 100644 index 00000000000..cef04ef3540 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8g77-54rh-46hx/GHSA-8g77-54rh-46hx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g77-54rh-46hx", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2025-25975" + ], + "details": "An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25975" + }, + { + "type": "WEB", + "url": "https://github.com/jonschlinkert/parse-git-config/issues/14" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T19:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9qjm-v45h-7fxq/GHSA-9qjm-v45h-7fxq.json b/advisories/unreviewed/2025/03/GHSA-9qjm-v45h-7fxq/GHSA-9qjm-v45h-7fxq.json index 0672997ebf1..501020d8a6c 100644 --- a/advisories/unreviewed/2025/03/GHSA-9qjm-v45h-7fxq/GHSA-9qjm-v45h-7fxq.json +++ b/advisories/unreviewed/2025/03/GHSA-9qjm-v45h-7fxq/GHSA-9qjm-v45h-7fxq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9qjm-v45h-7fxq", - "modified": "2025-03-10T18:31:56Z", + "modified": "2025-03-12T21:31:28Z", "published": "2025-03-10T18:31:56Z", "aliases": [ "CVE-2025-25940" ], "details": "VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T16:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json b/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json index b33afd2203f..b3bdb0bee09 100644 --- a/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json +++ b/advisories/unreviewed/2025/03/GHSA-c3wj-2vf4-295m/GHSA-c3wj-2vf4-295m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c3wj-2vf4-295m", - "modified": "2025-03-12T18:32:53Z", + "modified": "2025-03-12T21:31:29Z", "published": "2025-03-12T18:32:53Z", "aliases": [ "CVE-2025-25683" ], "details": "AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.2.0 and 3.2.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T17:15:49Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c93v-4qmp-8w98/GHSA-c93v-4qmp-8w98.json b/advisories/unreviewed/2025/03/GHSA-c93v-4qmp-8w98/GHSA-c93v-4qmp-8w98.json new file mode 100644 index 00000000000..bf0db4b5587 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c93v-4qmp-8w98/GHSA-c93v-4qmp-8w98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c93v-4qmp-8w98", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2025-0116" + ], + "details": "A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenance mode.\n\nThis issue does not apply to Cloud NGFWs or Prisma Access software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0116" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json b/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json index 421fa081664..dc49bf9edb0 100644 --- a/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json +++ b/advisories/unreviewed/2025/03/GHSA-j3vw-gxh2-3r2w/GHSA-j3vw-gxh2-3r2w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3vw-gxh2-3r2w", - "modified": "2025-03-12T18:32:53Z", + "modified": "2025-03-12T21:31:29Z", "published": "2025-03-12T18:32:53Z", "aliases": [ "CVE-2024-34398" ], "details": "An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T17:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j695-2cjc-466g/GHSA-j695-2cjc-466g.json b/advisories/unreviewed/2025/03/GHSA-j695-2cjc-466g/GHSA-j695-2cjc-466g.json new file mode 100644 index 00000000000..c7bb1d5bb91 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j695-2cjc-466g/GHSA-j695-2cjc-466g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j695-2cjc-466g", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2024-26290" + ], + "details": "Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before 2024.6.0; Avid NEXIS F-series: before 2024.6.0; Avid NEXIS PRO+: before 2024.6.0; System Director Appliance (SDA+): before 2024.6.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26290" + }, + { + "type": "WEB", + "url": "https://kb.avid.com/pkb/articles/troubleshooting/en239659" + }, + { + "type": "WEB", + "url": "https://www.drive-byte.de/en/blog/avid-nexis-agent-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mqw3-crqw-fq73/GHSA-mqw3-crqw-fq73.json b/advisories/unreviewed/2025/03/GHSA-mqw3-crqw-fq73/GHSA-mqw3-crqw-fq73.json new file mode 100644 index 00000000000..6174f9fe9d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mqw3-crqw-fq73/GHSA-mqw3-crqw-fq73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqw3-crqw-fq73", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2025-0115" + ], + "details": "A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files.\n\nThis issue does not affect Cloud NGFW or Prisma Access.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0115" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p6rm-v297-gpf4/GHSA-p6rm-v297-gpf4.json b/advisories/unreviewed/2025/03/GHSA-p6rm-v297-gpf4/GHSA-p6rm-v297-gpf4.json new file mode 100644 index 00000000000..50905a1637a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p6rm-v297-gpf4/GHSA-p6rm-v297-gpf4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6rm-v297-gpf4", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2025-0114" + ], + "details": "A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the GlobalProtect gateway.\n\nThis issue does not apply to Cloud NGFWs or Prisma Access software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0114" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0114" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vhjm-w3vw-g6jw/GHSA-vhjm-w3vw-g6jw.json b/advisories/unreviewed/2025/03/GHSA-vhjm-w3vw-g6jw/GHSA-vhjm-w3vw-g6jw.json new file mode 100644 index 00000000000..e1fc5aab33d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vhjm-w3vw-g6jw/GHSA-vhjm-w3vw-g6jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhjm-w3vw-g6jw", + "modified": "2025-03-12T21:31:29Z", + "published": "2025-03-12T21:31:29Z", + "aliases": [ + "CVE-2025-0117" + ], + "details": "A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\\SYSTEM.\n\nGlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0117" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-807" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json b/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json index 64276f72ca6..f1e9340eb1f 100644 --- a/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json +++ b/advisories/unreviewed/2025/03/GHSA-wjvr-8c9r-fgmc/GHSA-wjvr-8c9r-fgmc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjvr-8c9r-fgmc", - "modified": "2025-03-12T18:32:53Z", + "modified": "2025-03-12T21:31:29Z", "published": "2025-03-12T18:32:53Z", "aliases": [ "CVE-2025-25774" ], "details": "An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-691" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T17:15:49Z"