diff --git a/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json b/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json new file mode 100644 index 00000000000..ba1252e2f26 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3gvf-4425-jjq6/GHSA-3gvf-4425-jjq6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gvf-4425-jjq6", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-2738" + ], + "details": "A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/manage-scdetails.php. The manipulation of the argument namesc leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2738" + }, + { + "type": "WEB", + "url": "https://github.com/X-X-007/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300760" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300760" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522931" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3j69-7qgr-69pj/GHSA-3j69-7qgr-69pj.json b/advisories/unreviewed/2025/03/GHSA-3j69-7qgr-69pj/GHSA-3j69-7qgr-69pj.json new file mode 100644 index 00000000000..17a12e6ccae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3j69-7qgr-69pj/GHSA-3j69-7qgr-69pj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j69-7qgr-69pj", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-2739" + ], + "details": "A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-services.php. The manipulation of the argument sertitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2739" + }, + { + "type": "WEB", + "url": "https://github.com/silent1189/Phpgurukul-Old-Age-Home-Management-System-V1.0-SQL-injection/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300761" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300761" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.523400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json b/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json new file mode 100644 index 00000000000..53bc1e434f6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3pjj-2f8w-vhh5/GHSA-3pjj-2f8w-vhh5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pjj-2f8w-vhh5", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-12769" + ], + "details": "The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12769" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/02b5c1a8-cf2a-4378-bfda-84d841d88a18" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json b/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json new file mode 100644 index 00000000000..b79bc9014ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4878-3496-cr5j/GHSA-4878-3496-cr5j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4878-3496-cr5j", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2024-13618" + ], + "details": "The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13618" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d6a78233-3f23-4da4-9bc0-1439cde20a30" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4p64-jp2f-4r7g/GHSA-4p64-jp2f-4r7g.json b/advisories/unreviewed/2025/03/GHSA-4p64-jp2f-4r7g/GHSA-4p64-jp2f-4r7g.json new file mode 100644 index 00000000000..269ef2e9db2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4p64-jp2f-4r7g/GHSA-4p64-jp2f-4r7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p64-jp2f-4r7g", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-8313" + ], + "details": "An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8313" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json b/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json new file mode 100644 index 00000000000..c9b999b5390 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5pwg-63cp-76fj/GHSA-5pwg-63cp-76fj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pwg-63cp-76fj", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2024-13863" + ], + "details": "The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13863" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a6161595-0934-4baa-9da6-73792f4b87fd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json b/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json new file mode 100644 index 00000000000..a6000117369 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5wqh-pcq3-r3px/GHSA-5wqh-pcq3-r3px.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wqh-pcq3-r3px", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2024-9770" + ], + "details": "The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9770" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d31f8713-b807-4ac4-8897-7d62a93bb2db" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json b/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json new file mode 100644 index 00000000000..5c8d72ad73b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-673g-crrq-7x55/GHSA-673g-crrq-7x55.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-673g-crrq-7x55", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-1798" + ], + "details": "The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1798" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c5c30191-857c-419c-9096-d1fe14d34eaa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6m83-456q-vvpj/GHSA-6m83-456q-vvpj.json b/advisories/unreviewed/2025/03/GHSA-6m83-456q-vvpj/GHSA-6m83-456q-vvpj.json new file mode 100644 index 00000000000..84ba1f2bc2b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6m83-456q-vvpj/GHSA-6m83-456q-vvpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m83-456q-vvpj", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2024-44903" + ], + "details": "SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44903" + }, + { + "type": "WEB", + "url": "https://www.artresilia.com/cve-2024-44903-sql-injection-vulnerability-in-horizon-information-portal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json b/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json new file mode 100644 index 00000000000..f65ad85cd09 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qrv-h235-q5x7", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-13123" + ], + "details": "The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13123" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/417178de-17ff-438c-a36c-b90db6486a46" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json b/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json new file mode 100644 index 00000000000..c6e8e8665ff --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vr9-h9pm-5frx", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10105" + ], + "details": "The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10105" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4477db12-26e9-4c6d-8b71-f3f6a0d19813" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json b/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json new file mode 100644 index 00000000000..17ce5b74c9b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7635-mr68-26j6/GHSA-7635-mr68-26j6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7635-mr68-26j6", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-13118" + ], + "details": "The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13118" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eba6f98e-b931-4f02-b190-ca855a674839" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json b/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json new file mode 100644 index 00000000000..711a92dd44b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76c9-635j-h2r5", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10566" + ], + "details": "The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10566" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a98a7f11-4c01-4b91-8adc-465beefa310a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-76fv-m4gp-q47j/GHSA-76fv-m4gp-q47j.json b/advisories/unreviewed/2025/03/GHSA-76fv-m4gp-q47j/GHSA-76fv-m4gp-q47j.json new file mode 100644 index 00000000000..67da4a6a6c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-76fv-m4gp-q47j/GHSA-76fv-m4gp-q47j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76fv-m4gp-q47j", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-27809" + ], + "details": "Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27809" + }, + { + "type": "WEB", + "url": "https://github.com/Mbed-TLS/mbedtls/releases" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-03-1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7gr8-h8hp-7wvc/GHSA-7gr8-h8hp-7wvc.json b/advisories/unreviewed/2025/03/GHSA-7gr8-h8hp-7wvc/GHSA-7gr8-h8hp-7wvc.json new file mode 100644 index 00000000000..246d46817ed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7gr8-h8hp-7wvc/GHSA-7gr8-h8hp-7wvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gr8-h8hp-7wvc", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-10207" + ], + "details": "A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to force the web server to request arbitrary URLs.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10207" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7jv5-hfjx-c9xp/GHSA-7jv5-hfjx-c9xp.json b/advisories/unreviewed/2025/03/GHSA-7jv5-hfjx-c9xp/GHSA-7jv5-hfjx-c9xp.json new file mode 100644 index 00000000000..c747090e17e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7jv5-hfjx-c9xp/GHSA-7jv5-hfjx-c9xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jv5-hfjx-c9xp", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10210" + ], + "details": "An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10210" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json b/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json new file mode 100644 index 00000000000..3386e29fdb2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8jxr-w3j2-x85w/GHSA-8jxr-w3j2-x85w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jxr-w3j2-x85w", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-0717" + ], + "details": "To exploit the vulnerability, it is necessary:", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0717" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/31f734fc-d474-46b3-98eb-04761cab8878" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json b/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json new file mode 100644 index 00000000000..a17e1f54559 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wr6-crxg-xffx", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2025-2735" + ], + "details": "A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-services.php. The manipulation of the argument sertitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2735" + }, + { + "type": "WEB", + "url": "https://github.com/0xabandon/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300757" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300757" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json b/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json new file mode 100644 index 00000000000..ab2c0086718 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c993-hrcm-4cp8", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10472" + ], + "details": "The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10472" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d79e5c05-26d0-4223-891f-42ac9fb6ef6e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json b/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json new file mode 100644 index 00000000000..fa83bb8fc5b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cw73-w3vc-7g28/GHSA-cw73-w3vc-7g28.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw73-w3vc-7g28", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-12109" + ], + "details": "The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12109" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2eca2f88-c843-4794-8cd9-46f17c92753a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json b/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json new file mode 100644 index 00000000000..aae9efbe16a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f32g-h75h-7vgp/GHSA-f32g-h75h-7vgp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f32g-h75h-7vgp", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-13617" + ], + "details": "The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13617" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8d6dd979-21ef-4d14-9c42-bbd1d7b65c53" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json b/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json new file mode 100644 index 00000000000..2528a2a778a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffm9-v534-h8c2", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10703" + ], + "details": "The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10703" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5601ac03-09e4-4b4e-b03e-98323bd36dba" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json b/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json new file mode 100644 index 00000000000..1c2d231ce0f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fg5v-3r25-5f95/GHSA-fg5v-3r25-5f95.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg5v-3r25-5f95", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-12682" + ], + "details": "The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12682" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/79d0a139-0fb3-4a4b-ac33-80cbc6cb3831" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fq2h-hwcv-889h/GHSA-fq2h-hwcv-889h.json b/advisories/unreviewed/2025/03/GHSA-fq2h-hwcv-889h/GHSA-fq2h-hwcv-889h.json new file mode 100644 index 00000000000..1ac486bb165 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fq2h-hwcv-889h/GHSA-fq2h-hwcv-889h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq2h-hwcv-889h", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-45480" + ], + "details": "An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45480" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fx3r-h88c-jrgc/GHSA-fx3r-h88c-jrgc.json b/advisories/unreviewed/2025/03/GHSA-fx3r-h88c-jrgc/GHSA-fx3r-h88c-jrgc.json new file mode 100644 index 00000000000..de4e12a3dc7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fx3r-h88c-jrgc/GHSA-fx3r-h88c-jrgc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx3r-h88c-jrgc", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-2224" + ], + "details": "The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated attackers to update the post_status of any post to 'publish'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2224" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/directorist/trunk/includes/classes/class-add-listing.php#L912" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/directorist/trunk/includes/classes/class-add-listing.php#L942" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/directorist/trunk/includes/classes/class-add-listing.php#L960" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3260639" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/684e6a97-b884-4d25-99f1-81c2a43f1239?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g336-gpg3-r725/GHSA-g336-gpg3-r725.json b/advisories/unreviewed/2025/03/GHSA-g336-gpg3-r725/GHSA-g336-gpg3-r725.json new file mode 100644 index 00000000000..fac55ddaa2d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g336-gpg3-r725/GHSA-g336-gpg3-r725.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g336-gpg3-r725", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-10206" + ], + "details": "A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10206" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json b/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json new file mode 100644 index 00000000000..40fa4ac39bb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfmx-hgrp-xwrv", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2025-2731" + ], + "details": "A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2731" + }, + { + "type": "WEB", + "url": "https://github.com/Qwen11/CVE_store/blob/main/H3C/vulnerability%20Information_3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300751" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300751" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.520497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T04:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json b/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json new file mode 100644 index 00000000000..4e9ea5bf6d4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqcv-v7gm-vw94", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10638" + ], + "details": "The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10638" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/32a7a778-2211-45b4-bdc2-528f27b7d4fe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json b/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json new file mode 100644 index 00000000000..69c12e47414 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxwf-3xjr-jjqf", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2025-2732" + ], + "details": "A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2732" + }, + { + "type": "WEB", + "url": "https://github.com/Qwen11/CVE_store/blob/main/H3C/vulnerability%20Information_4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300752" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300752" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.520499" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T04:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json b/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json new file mode 100644 index 00000000000..f09a6b343ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h2gq-85xh-8c3c/GHSA-h2gq-85xh-8c3c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2gq-85xh-8c3c", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10679" + ], + "details": "The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10679" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/001391eb-f181-441d-b777-d9ce098ba143" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h76m-8w3j-mgpm/GHSA-h76m-8w3j-mgpm.json b/advisories/unreviewed/2025/03/GHSA-h76m-8w3j-mgpm/GHSA-h76m-8w3j-mgpm.json new file mode 100644 index 00000000000..e235c482321 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h76m-8w3j-mgpm/GHSA-h76m-8w3j-mgpm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h76m-8w3j-mgpm", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2025-2733" + ], + "details": "A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown part of the file app/tool/python_execute.py of the component Prompt Handler. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2733" + }, + { + "type": "WEB", + "url": "https://magnificent-dill-351.notion.site/Command-Execution-in-Openmanus-2025-3-13-1b6c693918ed80b2826ef6bb385693fa" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300753" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300753" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.520426" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h948-gjv3-7gpc/GHSA-h948-gjv3-7gpc.json b/advisories/unreviewed/2025/03/GHSA-h948-gjv3-7gpc/GHSA-h948-gjv3-7gpc.json new file mode 100644 index 00000000000..f9bfe2744e2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h948-gjv3-7gpc/GHSA-h948-gjv3-7gpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h948-gjv3-7gpc", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-8315" + ], + "details": "An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8315" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json b/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json new file mode 100644 index 00000000000..0dd1dc99cb6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrqr-gcfr-cq9h", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2025-2734" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2734" + }, + { + "type": "WEB", + "url": "https://github.com/0xabandon/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300756" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300756" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522265" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jh98-qr76-24j7/GHSA-jh98-qr76-24j7.json b/advisories/unreviewed/2025/03/GHSA-jh98-qr76-24j7/GHSA-jh98-qr76-24j7.json new file mode 100644 index 00000000000..41d8a9bda8b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jh98-qr76-24j7/GHSA-jh98-qr76-24j7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh98-qr76-24j7", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-8314" + ], + "details": "An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8314" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-303" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json b/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json new file mode 100644 index 00000000000..46435019e33 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv5x-w5jr-8gvf", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-11272" + ], + "details": "The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11272" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d7a76794-bc7d-42d6-9e7d-d7b845a7f461" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxc9-9wjf-5v8p/GHSA-jxc9-9wjf-5v8p.json b/advisories/unreviewed/2025/03/GHSA-jxc9-9wjf-5v8p/GHSA-jxc9-9wjf-5v8p.json new file mode 100644 index 00000000000..2c78867cdba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxc9-9wjf-5v8p/GHSA-jxc9-9wjf-5v8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxc9-9wjf-5v8p", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-45482" + ], + "details": "An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a trusted remote server to execute malicious commands.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45482" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mhcg-8f2w-mrwx/GHSA-mhcg-8f2w-mrwx.json b/advisories/unreviewed/2025/03/GHSA-mhcg-8f2w-mrwx/GHSA-mhcg-8f2w-mrwx.json new file mode 100644 index 00000000000..f5c3c72c771 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mhcg-8f2w-mrwx/GHSA-mhcg-8f2w-mrwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhcg-8f2w-mrwx", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-45483" + ], + "details": "A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical attacker to alter the boot configuration of the operating system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45483" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json b/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json new file mode 100644 index 00000000000..e72ddcd1cbb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf92-gxmq-pgwp", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2025-2736" + ], + "details": "A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2736" + }, + { + "type": "WEB", + "url": "https://github.com/404heihei/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300758" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300758" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522881" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json b/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json new file mode 100644 index 00000000000..bff109a403c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q27q-f4wr-gh4j", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10554" + ], + "details": "The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10554" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7c15b082-caa5-4cf2-9986-2eb519dcb7c5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json b/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json new file mode 100644 index 00000000000..4a369497aee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgrj-c4rv-c2r5", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-11273" + ], + "details": "The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11273" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d1049a83-1298-4c8c-aeac-0055110d38fb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json b/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json new file mode 100644 index 00000000000..f86c66192ca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq4f-w524-x6mg", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10565" + ], + "details": "The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10565" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4ef05302-a6ca-4816-ab0d-a4e3bf7a5e22" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json b/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json new file mode 100644 index 00000000000..4f1fdb2c76a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqq7-68c5-p37w", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-13122" + ], + "details": "The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13122" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/512721cb-e544-4d26-87ca-43d83e77f8e4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qwrg-rgf8-83h9/GHSA-qwrg-rgf8-83h9.json b/advisories/unreviewed/2025/03/GHSA-qwrg-rgf8-83h9/GHSA-qwrg-rgf8-83h9.json new file mode 100644 index 00000000000..55aa2c5884e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qwrg-rgf8-83h9/GHSA-qwrg-rgf8-83h9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwrg-rgf8-83h9", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-45481" + ], + "details": "An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate as another legitimate user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45481" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-791" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json b/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json new file mode 100644 index 00000000000..fdc60e5bf78 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rgxv-4464-wf8w/GHSA-rgxv-4464-wf8w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgxv-4464-wf8w", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-1452" + ], + "details": "The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1452" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/47365daf-7ef5-471a-ab0e-f6d1b40ca56c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vcm5-f2fj-78jh/GHSA-vcm5-f2fj-78jh.json b/advisories/unreviewed/2025/03/GHSA-vcm5-f2fj-78jh/GHSA-vcm5-f2fj-78jh.json new file mode 100644 index 00000000000..a7417a0e64a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vcm5-f2fj-78jh/GHSA-vcm5-f2fj-78jh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcm5-f2fj-78jh", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-10208" + ], + "details": "An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10208" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vr87-63px-9cxx/GHSA-vr87-63px-9cxx.json b/advisories/unreviewed/2025/03/GHSA-vr87-63px-9cxx/GHSA-vr87-63px-9cxx.json new file mode 100644 index 00000000000..c1d45ad233d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vr87-63px-9cxx/GHSA-vr87-63px-9cxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr87-63px-9cxx", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-45484" + ], + "details": "An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 may allow an unauthenticated adjacent attacker to per-form Denial-of-Service (DoS) attacks against the product.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45484" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vvqm-mmw4-qwg5/GHSA-vvqm-mmw4-qwg5.json b/advisories/unreviewed/2025/03/GHSA-vvqm-mmw4-qwg5/GHSA-vvqm-mmw4-qwg5.json new file mode 100644 index 00000000000..2b4670ed478 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vvqm-mmw4-qwg5/GHSA-vvqm-mmw4-qwg5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqm-mmw4-qwg5", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-27810" + ], + "details": "Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27810" + }, + { + "type": "WEB", + "url": "https://github.com/Mbed-TLS/mbedtls/releases" + }, + { + "type": "WEB", + "url": "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2025-03-2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json b/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json new file mode 100644 index 00000000000..74981ce8872 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w523-c69w-6x53/GHSA-w523-c69w-6x53.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w523-c69w-6x53", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-10560" + ], + "details": "The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10560" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/80298c89-544d-4894-a837-253f5f26cf42" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json b/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json new file mode 100644 index 00000000000..8c90c6ae811 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wj74-fcp9-vrxp/GHSA-wj74-fcp9-vrxp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj74-fcp9-vrxp", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-2737" + ], + "details": "A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2737" + }, + { + "type": "WEB", + "url": "https://github.com/X-X-007/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300759" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300759" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.522898" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wmh4-fxpw-j7v4/GHSA-wmh4-fxpw-j7v4.json b/advisories/unreviewed/2025/03/GHSA-wmh4-fxpw-j7v4/GHSA-wmh4-fxpw-j7v4.json new file mode 100644 index 00000000000..c0539333c7f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wmh4-fxpw-j7v4/GHSA-wmh4-fxpw-j7v4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmh4-fxpw-j7v4", + "modified": "2025-03-25T06:30:28Z", + "published": "2025-03-25T06:30:28Z", + "aliases": [ + "CVE-2025-0845" + ], + "details": "The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0845" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/lms-learning-management-system-education-lms-wordpress-theme/7867581" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39ea4627-66b2-42a6-913e-04c708491b8d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json b/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json new file mode 100644 index 00000000000..c97487f7ac7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wwgv-3xwq-6qmc/GHSA-wwgv-3xwq-6qmc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwgv-3xwq-6qmc", + "modified": "2025-03-25T06:30:27Z", + "published": "2025-03-25T06:30:27Z", + "aliases": [ + "CVE-2024-11503" + ], + "details": "The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11503" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/25592b6c-b9ab-4d9e-b314-091594ce9189" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T06:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xr74-5p74-mh9w/GHSA-xr74-5p74-mh9w.json b/advisories/unreviewed/2025/03/GHSA-xr74-5p74-mh9w/GHSA-xr74-5p74-mh9w.json new file mode 100644 index 00000000000..d1711eee83d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xr74-5p74-mh9w/GHSA-xr74-5p74-mh9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr74-5p74-mh9w", + "modified": "2025-03-25T06:30:26Z", + "published": "2025-03-25T06:30:26Z", + "aliases": [ + "CVE-2024-10209" + ], + "details": "An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10209" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P015-77573c08.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T05:15:38Z" + } +} \ No newline at end of file