From 29659fa6745a30fcea554c434f4609cc1d46d421 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 19 Mar 2025 18:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2mmc-97mx-9r37.json | 4 +- .../GHSA-4mgq-9qgw-ghcx.json | 2 +- .../GHSA-4qc8-v4xw-jxxp.json | 2 +- .../GHSA-5547-g9w2-52xj.json | 14 ++++++- .../GHSA-ch75-4hc2-84c6.json | 6 ++- .../GHSA-cq97-3wpv-2v7v.json | 4 +- .../GHSA-fgmx-p46q-37q8.json | 4 +- .../GHSA-g89m-r2gh-92r6.json | 4 +- .../GHSA-mq7p-rx5g-55hm.json | 4 +- .../GHSA-p96j-jhf9-2vrr.json | 2 +- .../GHSA-pm9g-2hv5-xfp2.json | 4 +- .../GHSA-vwqq-p7w6-hwg3.json | 6 ++- .../GHSA-88gp-69jr-39m4.json | 6 ++- .../GHSA-wmgh-44xh-27j6.json | 2 +- .../GHSA-4974-7pgr-4grv.json | 4 +- .../GHSA-cf5h-fpjr-xpm5.json | 4 +- .../GHSA-6f82-qgq9-9h8f.json | 4 +- .../GHSA-7f7v-jf43-h9pw.json | 4 +- .../GHSA-c56c-8vvg-gr68.json | 4 +- .../GHSA-c8gp-pfr5-2mm3.json | 4 +- .../GHSA-f5x9-85f3-f3r4.json | 4 +- .../GHSA-g754-37wh-7wv7.json | 4 +- .../GHSA-vr5f-v75p-g4qw.json | 4 +- .../GHSA-45p8-xp39-q9qf.json | 4 +- .../GHSA-h4r9-mgj3-f327.json | 4 +- .../GHSA-pfjp-fv5p-fjx7.json | 11 +++-- .../GHSA-wr2q-44mp-hgqr.json | 4 +- .../GHSA-xcgj-mj4r-37f5.json | 4 +- .../GHSA-9w72-8p6g-p73f.json | 4 +- .../GHSA-q7c5-j4r5-8whv.json | 11 +++-- .../GHSA-qr35-h6w8-mx66.json | 6 ++- .../GHSA-3c78-wrg5-fqxr.json | 4 +- .../GHSA-4m39-8ph2-44fq.json | 4 +- .../GHSA-gwjv-qxvj-5x3w.json | 6 ++- .../GHSA-3jj9-9269-99m2.json | 4 +- .../GHSA-c7v6-r97x-ppjq.json | 4 +- .../GHSA-hj89-h95x-jw36.json | 4 +- .../GHSA-j3pw-x73p-86xf.json | 15 +++++-- .../GHSA-pqvj-7wmm-mjvv.json | 4 +- .../GHSA-3q47-272x-vrfj.json | 4 +- .../GHSA-5h7r-mv43-gm2c.json | 4 +- .../GHSA-wjg2-c55h-phf5.json | 4 +- .../GHSA-94mm-6r76-6pgh.json | 4 +- .../GHSA-27r4-945x-jq67.json | 1 + .../GHSA-7pvp-q2m7-p3xg.json | 2 +- .../GHSA-2hwf-vrcf-2q7m.json | 2 +- .../GHSA-44m6-q7g6-5vp6.json | 36 +++++++++++++++++ .../GHSA-mx5v-hjgf-32j4.json | 6 ++- .../GHSA-rf6c-m595-cvc8.json | 1 + .../GHSA-2x3g-rr4w-4qrp.json | 29 ++++++++++++++ .../GHSA-368g-gpf5-m486.json | 29 ++++++++++++++ .../GHSA-5wv6-ghm3-w7wv.json | 36 +++++++++++++++++ .../GHSA-627p-vx8v-8v2c.json | 36 +++++++++++++++++ .../GHSA-6mx4-qxhj-cjh2.json | 36 +++++++++++++++++ .../GHSA-6xv7-g282-fw95.json | 29 ++++++++++++++ .../GHSA-78h5-wgcx-mjqr.json | 36 +++++++++++++++++ .../GHSA-8vw4-jqcw-6334.json | 29 ++++++++++++++ .../GHSA-9r24-mxpp-867q.json | 36 +++++++++++++++++ .../GHSA-c392-wrgw-jjfw.json | 40 +++++++++++++++++++ .../GHSA-hqgf-xpw9-m8hc.json | 36 +++++++++++++++++ .../GHSA-pgr6-fqc8-qxpf.json | 36 +++++++++++++++++ .../GHSA-pj87-jxwm-9w7p.json | 36 +++++++++++++++++ .../GHSA-pwcr-fjcv-q783.json | 33 +++++++++++++++ .../GHSA-r985-fv8x-vqj3.json | 36 +++++++++++++++++ .../GHSA-x74m-qjm8-4mfg.json | 36 +++++++++++++++++ .../GHSA-xgrc-mq5c-7xjc.json | 36 +++++++++++++++++ .../GHSA-xxrg-mg63-qfpj.json | 29 ++++++++++++++ 67 files changed, 812 insertions(+), 59 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-44m6-q7g6-5vp6/GHSA-44m6-q7g6-5vp6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2x3g-rr4w-4qrp/GHSA-2x3g-rr4w-4qrp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5wv6-ghm3-w7wv/GHSA-5wv6-ghm3-w7wv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-627p-vx8v-8v2c/GHSA-627p-vx8v-8v2c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6mx4-qxhj-cjh2/GHSA-6mx4-qxhj-cjh2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6xv7-g282-fw95/GHSA-6xv7-g282-fw95.json create mode 100644 advisories/unreviewed/2025/03/GHSA-78h5-wgcx-mjqr/GHSA-78h5-wgcx-mjqr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9r24-mxpp-867q/GHSA-9r24-mxpp-867q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c392-wrgw-jjfw/GHSA-c392-wrgw-jjfw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hqgf-xpw9-m8hc/GHSA-hqgf-xpw9-m8hc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pgr6-fqc8-qxpf/GHSA-pgr6-fqc8-qxpf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pj87-jxwm-9w7p/GHSA-pj87-jxwm-9w7p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r985-fv8x-vqj3/GHSA-r985-fv8x-vqj3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x74m-qjm8-4mfg/GHSA-x74m-qjm8-4mfg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xgrc-mq5c-7xjc/GHSA-xgrc-mq5c-7xjc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json diff --git a/advisories/unreviewed/2023/02/GHSA-2mmc-97mx-9r37/GHSA-2mmc-97mx-9r37.json b/advisories/unreviewed/2023/02/GHSA-2mmc-97mx-9r37/GHSA-2mmc-97mx-9r37.json index 10c4a43b974..68a02e6bfe7 100644 --- a/advisories/unreviewed/2023/02/GHSA-2mmc-97mx-9r37/GHSA-2mmc-97mx-9r37.json +++ b/advisories/unreviewed/2023/02/GHSA-2mmc-97mx-9r37/GHSA-2mmc-97mx-9r37.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-4mgq-9qgw-ghcx/GHSA-4mgq-9qgw-ghcx.json b/advisories/unreviewed/2023/02/GHSA-4mgq-9qgw-ghcx/GHSA-4mgq-9qgw-ghcx.json index 3653e1f30ff..ad3facbf8b6 100644 --- a/advisories/unreviewed/2023/02/GHSA-4mgq-9qgw-ghcx/GHSA-4mgq-9qgw-ghcx.json +++ b/advisories/unreviewed/2023/02/GHSA-4mgq-9qgw-ghcx/GHSA-4mgq-9qgw-ghcx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mgq-9qgw-ghcx", - "modified": "2023-02-28T21:30:17Z", + "modified": "2025-03-19T18:30:37Z", "published": "2023-02-17T00:30:28Z", "aliases": [ "CVE-2020-12413" diff --git a/advisories/unreviewed/2023/02/GHSA-4qc8-v4xw-jxxp/GHSA-4qc8-v4xw-jxxp.json b/advisories/unreviewed/2023/02/GHSA-4qc8-v4xw-jxxp/GHSA-4qc8-v4xw-jxxp.json index 8243edcd471..1f395dcdcd6 100644 --- a/advisories/unreviewed/2023/02/GHSA-4qc8-v4xw-jxxp/GHSA-4qc8-v4xw-jxxp.json +++ b/advisories/unreviewed/2023/02/GHSA-4qc8-v4xw-jxxp/GHSA-4qc8-v4xw-jxxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qc8-v4xw-jxxp", - "modified": "2023-02-23T06:30:18Z", + "modified": "2025-03-19T18:30:36Z", "published": "2023-02-15T21:30:28Z", "aliases": [ "CVE-2022-45546" diff --git a/advisories/unreviewed/2023/02/GHSA-5547-g9w2-52xj/GHSA-5547-g9w2-52xj.json b/advisories/unreviewed/2023/02/GHSA-5547-g9w2-52xj/GHSA-5547-g9w2-52xj.json index 7aee886972d..e525e9d550e 100644 --- a/advisories/unreviewed/2023/02/GHSA-5547-g9w2-52xj/GHSA-5547-g9w2-52xj.json +++ b/advisories/unreviewed/2023/02/GHSA-5547-g9w2-52xj/GHSA-5547-g9w2-52xj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5547-g9w2-52xj", - "modified": "2023-02-24T21:30:19Z", + "modified": "2025-03-19T18:30:35Z", "published": "2023-02-15T18:30:19Z", "aliases": [ "CVE-2023-0361" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00015.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFIA3X4IZ3CW7SRQ2UHNHNPMRIAWF2FI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS4KVDOG6QTALWHC2QE4Y7VPDRMLTRWQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z634YBXAJ5VLDI62IOPBVP5K6YFHAWCY" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFIA3X4IZ3CW7SRQ2UHNHNPMRIAWF2FI" diff --git a/advisories/unreviewed/2023/02/GHSA-ch75-4hc2-84c6/GHSA-ch75-4hc2-84c6.json b/advisories/unreviewed/2023/02/GHSA-ch75-4hc2-84c6/GHSA-ch75-4hc2-84c6.json index cdc04db33bd..7416fd3e9e0 100644 --- a/advisories/unreviewed/2023/02/GHSA-ch75-4hc2-84c6/GHSA-ch75-4hc2-84c6.json +++ b/advisories/unreviewed/2023/02/GHSA-ch75-4hc2-84c6/GHSA-ch75-4hc2-84c6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch75-4hc2-84c6", - "modified": "2023-02-23T06:30:18Z", + "modified": "2025-03-19T18:30:36Z", "published": "2023-02-15T21:30:27Z", "aliases": [ "CVE-2022-45543" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45543" }, + { + "type": "WEB", + "url": "https://srpopty.github.io/2023/02/15/Vulnerability-Discuz-X3.4-Reflected-XSS-%28CVE-2022-45543%29" + }, { "type": "WEB", "url": "https://srpopty.github.io/2023/02/15/Vulnerability-Discuz-X3.4-Reflected-XSS-(CVE-2022-45543)" diff --git a/advisories/unreviewed/2023/02/GHSA-cq97-3wpv-2v7v/GHSA-cq97-3wpv-2v7v.json b/advisories/unreviewed/2023/02/GHSA-cq97-3wpv-2v7v/GHSA-cq97-3wpv-2v7v.json index 744cc86d730..aa65e30adfc 100644 --- a/advisories/unreviewed/2023/02/GHSA-cq97-3wpv-2v7v/GHSA-cq97-3wpv-2v7v.json +++ b/advisories/unreviewed/2023/02/GHSA-cq97-3wpv-2v7v/GHSA-cq97-3wpv-2v7v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-fgmx-p46q-37q8/GHSA-fgmx-p46q-37q8.json b/advisories/unreviewed/2023/02/GHSA-fgmx-p46q-37q8/GHSA-fgmx-p46q-37q8.json index 142dee01934..44c2a1ae8d9 100644 --- a/advisories/unreviewed/2023/02/GHSA-fgmx-p46q-37q8/GHSA-fgmx-p46q-37q8.json +++ b/advisories/unreviewed/2023/02/GHSA-fgmx-p46q-37q8/GHSA-fgmx-p46q-37q8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-g89m-r2gh-92r6/GHSA-g89m-r2gh-92r6.json b/advisories/unreviewed/2023/02/GHSA-g89m-r2gh-92r6/GHSA-g89m-r2gh-92r6.json index c9996c3f593..ef448cc9487 100644 --- a/advisories/unreviewed/2023/02/GHSA-g89m-r2gh-92r6/GHSA-g89m-r2gh-92r6.json +++ b/advisories/unreviewed/2023/02/GHSA-g89m-r2gh-92r6/GHSA-g89m-r2gh-92r6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-942" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-mq7p-rx5g-55hm/GHSA-mq7p-rx5g-55hm.json b/advisories/unreviewed/2023/02/GHSA-mq7p-rx5g-55hm/GHSA-mq7p-rx5g-55hm.json index 30576542133..1c0b53c0e9f 100644 --- a/advisories/unreviewed/2023/02/GHSA-mq7p-rx5g-55hm/GHSA-mq7p-rx5g-55hm.json +++ b/advisories/unreviewed/2023/02/GHSA-mq7p-rx5g-55hm/GHSA-mq7p-rx5g-55hm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-p96j-jhf9-2vrr/GHSA-p96j-jhf9-2vrr.json b/advisories/unreviewed/2023/02/GHSA-p96j-jhf9-2vrr/GHSA-p96j-jhf9-2vrr.json index 775ebe33b87..fe9d146e547 100644 --- a/advisories/unreviewed/2023/02/GHSA-p96j-jhf9-2vrr/GHSA-p96j-jhf9-2vrr.json +++ b/advisories/unreviewed/2023/02/GHSA-p96j-jhf9-2vrr/GHSA-p96j-jhf9-2vrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p96j-jhf9-2vrr", - "modified": "2023-02-23T18:31:05Z", + "modified": "2025-03-19T18:30:34Z", "published": "2023-02-15T03:30:47Z", "aliases": [ "CVE-2023-22368" diff --git a/advisories/unreviewed/2023/02/GHSA-pm9g-2hv5-xfp2/GHSA-pm9g-2hv5-xfp2.json b/advisories/unreviewed/2023/02/GHSA-pm9g-2hv5-xfp2/GHSA-pm9g-2hv5-xfp2.json index 86649b30fa0..1737af06cfc 100644 --- a/advisories/unreviewed/2023/02/GHSA-pm9g-2hv5-xfp2/GHSA-pm9g-2hv5-xfp2.json +++ b/advisories/unreviewed/2023/02/GHSA-pm9g-2hv5-xfp2/GHSA-pm9g-2hv5-xfp2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-vwqq-p7w6-hwg3/GHSA-vwqq-p7w6-hwg3.json b/advisories/unreviewed/2023/02/GHSA-vwqq-p7w6-hwg3/GHSA-vwqq-p7w6-hwg3.json index 7abbb319c8a..1a1884dd789 100644 --- a/advisories/unreviewed/2023/02/GHSA-vwqq-p7w6-hwg3/GHSA-vwqq-p7w6-hwg3.json +++ b/advisories/unreviewed/2023/02/GHSA-vwqq-p7w6-hwg3/GHSA-vwqq-p7w6-hwg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwqq-p7w6-hwg3", - "modified": "2023-02-27T15:30:19Z", + "modified": "2025-03-19T18:30:37Z", "published": "2023-02-16T21:30:24Z", "aliases": [ "CVE-2023-22380" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22380" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.7/admin/release-notes#3.7.6" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.7/admin/release-notes#3.7.6" diff --git a/advisories/unreviewed/2023/04/GHSA-88gp-69jr-39m4/GHSA-88gp-69jr-39m4.json b/advisories/unreviewed/2023/04/GHSA-88gp-69jr-39m4/GHSA-88gp-69jr-39m4.json index c307e49b8bf..f7c9c0c53b7 100644 --- a/advisories/unreviewed/2023/04/GHSA-88gp-69jr-39m4/GHSA-88gp-69jr-39m4.json +++ b/advisories/unreviewed/2023/04/GHSA-88gp-69jr-39m4/GHSA-88gp-69jr-39m4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88gp-69jr-39m4", - "modified": "2023-04-13T21:30:27Z", + "modified": "2025-03-19T18:30:38Z", "published": "2023-04-10T03:30:16Z", "aliases": [ "CVE-2023-30456" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-754" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json b/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json index d78be7b7a80..cd0409acbb6 100644 --- a/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json +++ b/advisories/unreviewed/2023/07/GHSA-wmgh-44xh-27j6/GHSA-wmgh-44xh-27j6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wmgh-44xh-27j6", - "modified": "2024-04-04T05:33:06Z", + "modified": "2025-03-19T18:30:35Z", "published": "2023-07-06T19:24:09Z", "aliases": [ "CVE-2023-23462" diff --git a/advisories/unreviewed/2024/02/GHSA-4974-7pgr-4grv/GHSA-4974-7pgr-4grv.json b/advisories/unreviewed/2024/02/GHSA-4974-7pgr-4grv/GHSA-4974-7pgr-4grv.json index bc7b05acbaa..5e8df241f58 100644 --- a/advisories/unreviewed/2024/02/GHSA-4974-7pgr-4grv/GHSA-4974-7pgr-4grv.json +++ b/advisories/unreviewed/2024/02/GHSA-4974-7pgr-4grv/GHSA-4974-7pgr-4grv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json b/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json index e924821d188..abd6db4be04 100644 --- a/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json +++ b/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json b/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json index deb2c7ee024..fc77580f1c7 100644 --- a/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json +++ b/advisories/unreviewed/2024/03/GHSA-6f82-qgq9-9h8f/GHSA-6f82-qgq9-9h8f.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7f7v-jf43-h9pw/GHSA-7f7v-jf43-h9pw.json b/advisories/unreviewed/2024/03/GHSA-7f7v-jf43-h9pw/GHSA-7f7v-jf43-h9pw.json index 82f37a41cbd..6aba752fa48 100644 --- a/advisories/unreviewed/2024/03/GHSA-7f7v-jf43-h9pw/GHSA-7f7v-jf43-h9pw.json +++ b/advisories/unreviewed/2024/03/GHSA-7f7v-jf43-h9pw/GHSA-7f7v-jf43-h9pw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c56c-8vvg-gr68/GHSA-c56c-8vvg-gr68.json b/advisories/unreviewed/2024/03/GHSA-c56c-8vvg-gr68/GHSA-c56c-8vvg-gr68.json index 96c9ce4cd05..3657e0d2b01 100644 --- a/advisories/unreviewed/2024/03/GHSA-c56c-8vvg-gr68/GHSA-c56c-8vvg-gr68.json +++ b/advisories/unreviewed/2024/03/GHSA-c56c-8vvg-gr68/GHSA-c56c-8vvg-gr68.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json b/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json index 46753eb4f2f..5494872ce96 100644 --- a/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json +++ b/advisories/unreviewed/2024/03/GHSA-c8gp-pfr5-2mm3/GHSA-c8gp-pfr5-2mm3.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-908" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-f5x9-85f3-f3r4/GHSA-f5x9-85f3-f3r4.json b/advisories/unreviewed/2024/03/GHSA-f5x9-85f3-f3r4/GHSA-f5x9-85f3-f3r4.json index 6cd5f493649..eb3dd8c45cc 100644 --- a/advisories/unreviewed/2024/03/GHSA-f5x9-85f3-f3r4/GHSA-f5x9-85f3-f3r4.json +++ b/advisories/unreviewed/2024/03/GHSA-f5x9-85f3-f3r4/GHSA-f5x9-85f3-f3r4.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json b/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json index ae932a0956f..0fcf2657237 100644 --- a/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json +++ b/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json b/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json index f29e98b66ab..b0334f4d584 100644 --- a/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json +++ b/advisories/unreviewed/2024/03/GHSA-vr5f-v75p-g4qw/GHSA-vr5f-v75p-g4qw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-45p8-xp39-q9qf/GHSA-45p8-xp39-q9qf.json b/advisories/unreviewed/2024/04/GHSA-45p8-xp39-q9qf/GHSA-45p8-xp39-q9qf.json index dba5bae8271..467573f3441 100644 --- a/advisories/unreviewed/2024/04/GHSA-45p8-xp39-q9qf/GHSA-45p8-xp39-q9qf.json +++ b/advisories/unreviewed/2024/04/GHSA-45p8-xp39-q9qf/GHSA-45p8-xp39-q9qf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-45p8-xp39-q9qf", - "modified": "2024-04-15T09:30:54Z", + "modified": "2025-03-19T18:30:42Z", "published": "2024-04-15T09:30:54Z", "aliases": [ "CVE-2024-32139" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-h4r9-mgj3-f327/GHSA-h4r9-mgj3-f327.json b/advisories/unreviewed/2024/04/GHSA-h4r9-mgj3-f327/GHSA-h4r9-mgj3-f327.json index 0ee65fcd370..3b326a8a29c 100644 --- a/advisories/unreviewed/2024/04/GHSA-h4r9-mgj3-f327/GHSA-h4r9-mgj3-f327.json +++ b/advisories/unreviewed/2024/04/GHSA-h4r9-mgj3-f327/GHSA-h4r9-mgj3-f327.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json b/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json index 1ffc4dac170..21934707e19 100644 --- a/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json +++ b/advisories/unreviewed/2024/04/GHSA-pfjp-fv5p-fjx7/GHSA-pfjp-fv5p-fjx7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pfjp-fv5p-fjx7", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-19T18:30:42Z", "published": "2024-04-04T12:30:58Z", "aliases": [ "CVE-2024-26809" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: release elements in clone only from destroy path\n\nClone already always provides a current view of the lookup table, use it\nto destroy the set, otherwise it is possible to destroy elements twice.\n\nThis fix requires:\n\n 212ed75dc5fb (\"netfilter: nf_tables: integrate pipapo into commit protocol\")\n\nwhich came after:\n\n 9827a0e6e23b (\"netfilter: nft_set_pipapo: release elements in clone from abort path\").", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wr2q-44mp-hgqr/GHSA-wr2q-44mp-hgqr.json b/advisories/unreviewed/2024/04/GHSA-wr2q-44mp-hgqr/GHSA-wr2q-44mp-hgqr.json index 5aaac5d8fd5..48fa2b4a629 100644 --- a/advisories/unreviewed/2024/04/GHSA-wr2q-44mp-hgqr/GHSA-wr2q-44mp-hgqr.json +++ b/advisories/unreviewed/2024/04/GHSA-wr2q-44mp-hgqr/GHSA-wr2q-44mp-hgqr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-611" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xcgj-mj4r-37f5/GHSA-xcgj-mj4r-37f5.json b/advisories/unreviewed/2024/04/GHSA-xcgj-mj4r-37f5/GHSA-xcgj-mj4r-37f5.json index e457d395a3c..59eaf27ef1c 100644 --- a/advisories/unreviewed/2024/04/GHSA-xcgj-mj4r-37f5/GHSA-xcgj-mj4r-37f5.json +++ b/advisories/unreviewed/2024/04/GHSA-xcgj-mj4r-37f5/GHSA-xcgj-mj4r-37f5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xcgj-mj4r-37f5", - "modified": "2024-04-18T12:30:31Z", + "modified": "2025-03-19T18:30:42Z", "published": "2024-04-18T12:30:31Z", "aliases": [ "CVE-2024-32602" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.3.1.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.3.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-9w72-8p6g-p73f/GHSA-9w72-8p6g-p73f.json b/advisories/unreviewed/2024/06/GHSA-9w72-8p6g-p73f/GHSA-9w72-8p6g-p73f.json index 37928555a6b..ab0ccb522ed 100644 --- a/advisories/unreviewed/2024/06/GHSA-9w72-8p6g-p73f/GHSA-9w72-8p6g-p73f.json +++ b/advisories/unreviewed/2024/06/GHSA-9w72-8p6g-p73f/GHSA-9w72-8p6g-p73f.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json b/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json index 4a3de967500..8f6b983e73c 100644 --- a/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json +++ b/advisories/unreviewed/2024/06/GHSA-q7c5-j4r5-8whv/GHSA-q7c5-j4r5-8whv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7c5-j4r5-8whv", - "modified": "2024-06-03T15:31:00Z", + "modified": "2025-03-19T18:30:42Z", "published": "2024-06-03T15:31:00Z", "aliases": [ "CVE-2024-36729" ], "details": "TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6 with a sufficiently long reboot_type key.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T14:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qr35-h6w8-mx66/GHSA-qr35-h6w8-mx66.json b/advisories/unreviewed/2024/06/GHSA-qr35-h6w8-mx66/GHSA-qr35-h6w8-mx66.json index 03ea85e5b98..41914ea52fc 100644 --- a/advisories/unreviewed/2024/06/GHSA-qr35-h6w8-mx66/GHSA-qr35-h6w8-mx66.json +++ b/advisories/unreviewed/2024/06/GHSA-qr35-h6w8-mx66/GHSA-qr35-h6w8-mx66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr35-h6w8-mx66", - "modified": "2024-06-27T21:32:08Z", + "modified": "2025-03-19T18:30:43Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-22260" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-3c78-wrg5-fqxr/GHSA-3c78-wrg5-fqxr.json b/advisories/unreviewed/2024/07/GHSA-3c78-wrg5-fqxr/GHSA-3c78-wrg5-fqxr.json index c4d53c77fd5..fe44d5da15c 100644 --- a/advisories/unreviewed/2024/07/GHSA-3c78-wrg5-fqxr/GHSA-3c78-wrg5-fqxr.json +++ b/advisories/unreviewed/2024/07/GHSA-3c78-wrg5-fqxr/GHSA-3c78-wrg5-fqxr.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-4m39-8ph2-44fq/GHSA-4m39-8ph2-44fq.json b/advisories/unreviewed/2024/07/GHSA-4m39-8ph2-44fq/GHSA-4m39-8ph2-44fq.json index 335c0ff5612..4524f672fc1 100644 --- a/advisories/unreviewed/2024/07/GHSA-4m39-8ph2-44fq/GHSA-4m39-8ph2-44fq.json +++ b/advisories/unreviewed/2024/07/GHSA-4m39-8ph2-44fq/GHSA-4m39-8ph2-44fq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-266" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-gwjv-qxvj-5x3w/GHSA-gwjv-qxvj-5x3w.json b/advisories/unreviewed/2024/07/GHSA-gwjv-qxvj-5x3w/GHSA-gwjv-qxvj-5x3w.json index 070585dea6f..2b2aa273d52 100644 --- a/advisories/unreviewed/2024/07/GHSA-gwjv-qxvj-5x3w/GHSA-gwjv-qxvj-5x3w.json +++ b/advisories/unreviewed/2024/07/GHSA-gwjv-qxvj-5x3w/GHSA-gwjv-qxvj-5x3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gwjv-qxvj-5x3w", - "modified": "2024-07-12T18:31:46Z", + "modified": "2025-03-19T18:30:43Z", "published": "2024-07-09T18:30:53Z", "aliases": [ "CVE-2024-5652" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json b/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json index b1132ecab2d..b017100884b 100644 --- a/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json +++ b/advisories/unreviewed/2024/08/GHSA-3jj9-9269-99m2/GHSA-3jj9-9269-99m2.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-367" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json b/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json index 3c0ba70b201..9b77b215970 100644 --- a/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json +++ b/advisories/unreviewed/2024/08/GHSA-c7v6-r97x-ppjq/GHSA-c7v6-r97x-ppjq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json b/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json index cbf4c6fe371..11677f8baa2 100644 --- a/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json +++ b/advisories/unreviewed/2024/08/GHSA-hj89-h95x-jw36/GHSA-hj89-h95x-jw36.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json b/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json index d80716fd810..41979f71dbc 100644 --- a/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json +++ b/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3pw-x73p-86xf", - "modified": "2024-08-07T06:31:10Z", + "modified": "2025-03-19T18:30:45Z", "published": "2024-08-07T06:31:10Z", "aliases": [ "CVE-2024-3973" ], "details": "The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T06:16:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json b/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json index c3321adea29..95c97379107 100644 --- a/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json +++ b/advisories/unreviewed/2024/08/GHSA-pqvj-7wmm-mjvv/GHSA-pqvj-7wmm-mjvv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-474" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json b/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json index 94816b09d13..91cf6036c44 100644 --- a/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json +++ b/advisories/unreviewed/2024/09/GHSA-3q47-272x-vrfj/GHSA-3q47-272x-vrfj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json b/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json index e85053c9270..f5fe77ad684 100644 --- a/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json +++ b/advisories/unreviewed/2024/09/GHSA-5h7r-mv43-gm2c/GHSA-5h7r-mv43-gm2c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json b/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json index 16145d2b77b..fc2b0175efc 100644 --- a/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json +++ b/advisories/unreviewed/2024/09/GHSA-wjg2-c55h-phf5/GHSA-wjg2-c55h-phf5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json b/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json index 4cdb552ae7e..81b0a969c36 100644 --- a/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json +++ b/advisories/unreviewed/2024/10/GHSA-94mm-6r76-6pgh/GHSA-94mm-6r76-6pgh.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json b/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json index 0c0e3ed2d2d..1a04345400f 100644 --- a/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json +++ b/advisories/unreviewed/2024/11/GHSA-27r4-945x-jq67/GHSA-27r4-945x-jq67.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json b/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json index 449939990dd..3c44dc985fa 100644 --- a/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json +++ b/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pvp-q2m7-p3xg", - "modified": "2024-12-13T15:30:41Z", + "modified": "2025-03-19T18:30:47Z", "published": "2024-12-13T15:30:41Z", "aliases": [ "CVE-2023-38475" diff --git a/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json b/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json index da7435550ec..e592badb659 100644 --- a/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json +++ b/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hwf-vrcf-2q7m", - "modified": "2025-01-15T18:30:57Z", + "modified": "2025-03-19T18:30:48Z", "published": "2025-01-15T18:30:57Z", "aliases": [ "CVE-2025-22759" diff --git a/advisories/unreviewed/2025/01/GHSA-44m6-q7g6-5vp6/GHSA-44m6-q7g6-5vp6.json b/advisories/unreviewed/2025/01/GHSA-44m6-q7g6-5vp6/GHSA-44m6-q7g6-5vp6.json new file mode 100644 index 00000000000..6f841a8d8da --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-44m6-q7g6-5vp6/GHSA-44m6-q7g6-5vp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44m6-q7g6-5vp6", + "modified": "2025-03-19T18:30:48Z", + "published": "2025-01-14T15:30:54Z", + "aliases": [ + "CVE-2024-47571" + ], + "details": "An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47571" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-672" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-14T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json index 65dcab5dd92..ea0a4412b48 100644 --- a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json +++ b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mx5v-hjgf-32j4", - "modified": "2025-02-18T21:32:29Z", + "modified": "2025-03-19T18:30:49Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24102" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json b/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json index a7c7dd246eb..adf0595450d 100644 --- a/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json +++ b/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json @@ -46,6 +46,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-2x3g-rr4w-4qrp/GHSA-2x3g-rr4w-4qrp.json b/advisories/unreviewed/2025/03/GHSA-2x3g-rr4w-4qrp/GHSA-2x3g-rr4w-4qrp.json new file mode 100644 index 00000000000..f60cc6412c7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2x3g-rr4w-4qrp/GHSA-2x3g-rr4w-4qrp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x3g-rr4w-4qrp", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-30197" + ], + "details": "Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30197" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-03-19/#SECURITY-3511" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json b/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json new file mode 100644 index 00000000000..62cc8313f0f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-368g-gpf5-m486", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-29137" + ], + "details": "Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29137" + }, + { + "type": "WEB", + "url": "https://github.com/Raining-101/IOT_cve/blob/main/tenda-ac7form_fast_setting_wifi_set%20timeZone.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5wv6-ghm3-w7wv/GHSA-5wv6-ghm3-w7wv.json b/advisories/unreviewed/2025/03/GHSA-5wv6-ghm3-w7wv/GHSA-5wv6-ghm3-w7wv.json new file mode 100644 index 00000000000..9cee8c4c175 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5wv6-ghm3-w7wv/GHSA-5wv6-ghm3-w7wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wv6-ghm3-w7wv", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2024-53969" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53969" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-627p-vx8v-8v2c/GHSA-627p-vx8v-8v2c.json b/advisories/unreviewed/2025/03/GHSA-627p-vx8v-8v2c/GHSA-627p-vx8v-8v2c.json new file mode 100644 index 00000000000..adf7e83ef8f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-627p-vx8v-8v2c/GHSA-627p-vx8v-8v2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-627p-vx8v-8v2c", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-26486" + ], + "details": "Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash \nWith Insufficient Computational Effort, Use of Weak Hash, Use of a \nOne-Way Hash with a Predictable Salt vulnerability in Beta80 Life 1st \nallows an \nAttacker to Bruteforce User\nPasswords or find a collision to gain access to a target application using BETA80\n“Life 1st Identity Manager” as a service for authentication.This issue affects Life 1st: 1.5.2.14234.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26486" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2025-26486" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mx4-qxhj-cjh2/GHSA-6mx4-qxhj-cjh2.json b/advisories/unreviewed/2025/03/GHSA-6mx4-qxhj-cjh2/GHSA-6mx4-qxhj-cjh2.json new file mode 100644 index 00000000000..44d90a6b4a5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6mx4-qxhj-cjh2/GHSA-6mx4-qxhj-cjh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mx4-qxhj-cjh2", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-26485" + ], + "details": "The Exposure of Sensitive Information to an Unauthorized Actor \nvulnerability impacting Beta80 Life 1st Identity Manager allows User \nEnumeration using Authentication Rest APIs. Affected: Life 1st version \n1.5.2.14234. Different error messages are returned to failed authentication attempts \nin case of the usage of a wrong password or a non existent user. \n\n\nThis issue affects Life 1st: 1.5.2.14234.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26485" + }, + { + "type": "WEB", + "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2025-26485" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6xv7-g282-fw95/GHSA-6xv7-g282-fw95.json b/advisories/unreviewed/2025/03/GHSA-6xv7-g282-fw95/GHSA-6xv7-g282-fw95.json new file mode 100644 index 00000000000..f1f509ff328 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6xv7-g282-fw95/GHSA-6xv7-g282-fw95.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xv7-g282-fw95", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-29401" + ], + "details": "An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29401" + }, + { + "type": "WEB", + "url": "https://github.com/bGl1o/emlogpro/blob/main/emlog%20pro2.5.7-getshell.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-78h5-wgcx-mjqr/GHSA-78h5-wgcx-mjqr.json b/advisories/unreviewed/2025/03/GHSA-78h5-wgcx-mjqr/GHSA-78h5-wgcx-mjqr.json new file mode 100644 index 00000000000..a0457db7e62 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78h5-wgcx-mjqr/GHSA-78h5-wgcx-mjqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78h5-wgcx-mjqr", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2024-53967" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53967" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json b/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json new file mode 100644 index 00000000000..524bfe99202 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vw4-jqcw-6334", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2025-29118" + ], + "details": "Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29118" + }, + { + "type": "WEB", + "url": "https://github.com/Raining-101/IOT_cve/blob/main/tenda-ac8_sub_47D878.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9r24-mxpp-867q/GHSA-9r24-mxpp-867q.json b/advisories/unreviewed/2025/03/GHSA-9r24-mxpp-867q/GHSA-9r24-mxpp-867q.json new file mode 100644 index 00000000000..ac3efa3e2cc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9r24-mxpp-867q/GHSA-9r24-mxpp-867q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r24-mxpp-867q", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-23382" + ], + "details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.c", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23382" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-uk/000291028/dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c392-wrgw-jjfw/GHSA-c392-wrgw-jjfw.json b/advisories/unreviewed/2025/03/GHSA-c392-wrgw-jjfw/GHSA-c392-wrgw-jjfw.json new file mode 100644 index 00000000000..2d46c42629b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c392-wrgw-jjfw/GHSA-c392-wrgw-jjfw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c392-wrgw-jjfw", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2024-25132" + ], + "details": "A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a ClusterSync.hiveinternal.openshift.io/v1alpha1 resource is also created, the hive hibernation controller will enter the reconciliation loop leading to a panic when accessing a non-existing field in the ClusterDeployment’s status section, resulting in a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25132" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-25132" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2260371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hqgf-xpw9-m8hc/GHSA-hqgf-xpw9-m8hc.json b/advisories/unreviewed/2025/03/GHSA-hqgf-xpw9-m8hc/GHSA-hqgf-xpw9-m8hc.json new file mode 100644 index 00000000000..c1153e1dffb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hqgf-xpw9-m8hc/GHSA-hqgf-xpw9-m8hc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgf-xpw9-m8hc", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2025-0431" + ], + "details": "Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0431" + }, + { + "type": "WEB", + "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2025-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-790" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pgr6-fqc8-qxpf/GHSA-pgr6-fqc8-qxpf.json b/advisories/unreviewed/2025/03/GHSA-pgr6-fqc8-qxpf/GHSA-pgr6-fqc8-qxpf.json new file mode 100644 index 00000000000..4c4a8e08061 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pgr6-fqc8-qxpf/GHSA-pgr6-fqc8-qxpf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgr6-fqc8-qxpf", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2024-53970" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53970" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pj87-jxwm-9w7p/GHSA-pj87-jxwm-9w7p.json b/advisories/unreviewed/2025/03/GHSA-pj87-jxwm-9w7p/GHSA-pj87-jxwm-9w7p.json new file mode 100644 index 00000000000..c7d644226e1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pj87-jxwm-9w7p/GHSA-pj87-jxwm-9w7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj87-jxwm-9w7p", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-26475" + ], + "details": "Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers running during daemon restarts, reducing attack exposure, preventing accidental misconfigurations, and ensuring security controls remain active.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26475" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-uk/000291028/dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json b/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json new file mode 100644 index 00000000000..49f3ba78a18 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwcr-fjcv-q783", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2025-29405" + ], + "details": "An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29405" + }, + { + "type": "WEB", + "url": "https://gist.github.com/bGl1o/19a141ee6e899884fa85f3a52898bcc6" + }, + { + "type": "WEB", + "url": "https://github.com/bGl1o/emlogpro/blob/main/emlog%20pro2.5.7-getshell-2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r985-fv8x-vqj3/GHSA-r985-fv8x-vqj3.json b/advisories/unreviewed/2025/03/GHSA-r985-fv8x-vqj3/GHSA-r985-fv8x-vqj3.json new file mode 100644 index 00000000000..8fcb5999ec5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r985-fv8x-vqj3/GHSA-r985-fv8x-vqj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r985-fv8x-vqj3", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-2324" + ], + "details": "Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2324" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-2324-March-18-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x74m-qjm8-4mfg/GHSA-x74m-qjm8-4mfg.json b/advisories/unreviewed/2025/03/GHSA-x74m-qjm8-4mfg/GHSA-x74m-qjm8-4mfg.json new file mode 100644 index 00000000000..c85e7bea135 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x74m-qjm8-4mfg/GHSA-x74m-qjm8-4mfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x74m-qjm8-4mfg", + "modified": "2025-03-19T18:30:52Z", + "published": "2025-03-19T18:30:52Z", + "aliases": [ + "CVE-2024-53968" + ], + "details": "Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53968" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb24-69.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xgrc-mq5c-7xjc/GHSA-xgrc-mq5c-7xjc.json b/advisories/unreviewed/2025/03/GHSA-xgrc-mq5c-7xjc/GHSA-xgrc-mq5c-7xjc.json new file mode 100644 index 00000000000..f432cf29490 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xgrc-mq5c-7xjc/GHSA-xgrc-mq5c-7xjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgrc-mq5c-7xjc", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-1758" + ], + "details": "Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects:\n\n* LoadMaster: 7.2.40.0 and above\n\n* ECS: All versions\n\n* Multi-Tenancy: 7.1.35.4 and above", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1758" + }, + { + "type": "WEB", + "url": "https://docs.progress.com/bundle/release-notes_loadmaster-7-2-61-1/page/Security-Updates.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json b/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json new file mode 100644 index 00000000000..e12e6c3e852 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxrg-mg63-qfpj", + "modified": "2025-03-19T18:30:51Z", + "published": "2025-03-19T18:30:51Z", + "aliases": [ + "CVE-2025-30196" + ], + "details": "Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30196" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-03-19/#SECURITY-3529" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T16:15:33Z" + } +} \ No newline at end of file