From 2cab9355085485880ceab84ccec35d38c141bbd4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 29 Mar 2025 00:33:00 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3q8j-579q-jx44.json | 11 +++-- .../GHSA-3qwx-q6x9-637h.json | 4 +- .../GHSA-3rhh-97v9-2g42.json | 4 +- .../GHSA-c537-pf3w-23p5.json | 4 +- .../GHSA-h33h-98m4-q487.json | 4 +- .../GHSA-v5qp-mx94-j49v.json | 4 +- .../GHSA-v9pp-cc53-25hp.json | 4 +- .../GHSA-w2f4-229h-cwc2.json | 4 +- .../GHSA-5w28-7mvj-3c7j.json | 15 +++++-- .../GHSA-5xcj-6x8h-ff6h.json | 11 +++-- .../GHSA-7537-7q22-h2h7.json | 4 +- .../GHSA-76hh-9ghf-c266.json | 4 +- .../GHSA-7hgq-9c4p-6wjc.json | 4 +- .../GHSA-c23g-g2cr-qgh6.json | 4 +- .../GHSA-f6mw-hgw7-8wr3.json | 11 +++-- .../GHSA-q43x-m6x8-fxgx.json | 11 +++-- .../GHSA-r98v-pm7j-85j5.json | 15 +++++-- .../GHSA-v72q-pr3v-f552.json | 4 +- .../GHSA-xp9q-8p95-j7cm.json | 4 +- .../GHSA-6pfx-3rw7-5c4g.json | 15 +++++-- .../GHSA-cmxf-xmv7-xjq8.json | 6 ++- .../GHSA-fh3p-6j2p-f5qv.json | 15 +++++-- .../GHSA-h335-p3x8-932g.json | 11 +++-- .../GHSA-p6gp-c388-p4cr.json | 4 +- .../GHSA-q3p5-hqpp-3phh.json | 4 +- .../GHSA-v98m-62r5-hvcm.json | 4 +- .../GHSA-w74w-xq97-pg62.json | 4 +- .../GHSA-wg7v-w4x5-xvmx.json | 4 +- .../GHSA-3563-pvjf-xg5g.json | 11 +++-- .../GHSA-3cw9-m9j6-m7jf.json | 6 ++- .../GHSA-56m5-6v25-whgm.json | 11 +++-- .../GHSA-6fj9-cq25-9x7h.json | 11 +++-- .../GHSA-cc7f-xj8f-c4mm.json | 11 +++-- .../GHSA-f487-f23r-hjx6.json | 10 ++++- .../GHSA-fhf8-hvgj-q5vh.json | 4 +- .../GHSA-j2g5-g9wr-mrff.json | 6 ++- .../GHSA-mwgq-3h9h-3q6g.json | 6 ++- .../GHSA-58pq-phhq-59vj.json | 4 +- .../GHSA-9hrm-g973-phrr.json | 4 +- .../GHSA-mv5f-f7c2-2pg5.json | 4 +- .../GHSA-wfrc-c4v4-fvxm.json | 4 +- .../GHSA-87f6-7cww-rh98.json | 6 ++- .../GHSA-3x9w-fg96-5j98.json | 6 ++- .../GHSA-j2r5-qpjf-gcfc.json | 6 ++- .../GHSA-24cf-848g-762c.json | 29 ++++++++++++++ .../GHSA-42g5-mrm4-477g.json | 40 +++++++++++++++++++ .../GHSA-4r7f-8mqg-24xx.json | 29 ++++++++++++++ .../GHSA-6hp9-7gg3-wp75.json | 36 +++++++++++++++++ .../GHSA-7q69-vmcq-34w9.json | 29 ++++++++++++++ .../GHSA-9qpf-q9v6-4q5c.json | 29 ++++++++++++++ .../GHSA-9vqf-q6g6-hpj7.json | 36 +++++++++++++++++ .../GHSA-c928-5v6m-vm5h.json | 33 +++++++++++++++ .../GHSA-gc26-wqwp-qr8c.json | 33 +++++++++++++++ .../GHSA-gfhv-5rqh-7qx3.json | 29 ++++++++++++++ .../GHSA-mhwj-vqr2-3j7m.json | 29 ++++++++++++++ .../GHSA-p6w3-x67f-q79q.json | 36 +++++++++++++++++ .../GHSA-p736-g6pg-hjhw.json | 29 ++++++++++++++ .../GHSA-pg7r-jpxf-59rr.json | 40 +++++++++++++++++++ .../GHSA-r5wr-v3gv-93m3.json | 36 +++++++++++++++++ .../GHSA-rjwx-2xjg-q573.json | 40 +++++++++++++++++++ .../GHSA-rwcm-vvj8-qgg5.json | 29 ++++++++++++++ .../GHSA-wwp5-7982-8x96.json | 36 +++++++++++++++++ 62 files changed, 827 insertions(+), 74 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-24cf-848g-762c/GHSA-24cf-848g-762c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-42g5-mrm4-477g/GHSA-42g5-mrm4-477g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hp9-7gg3-wp75/GHSA-6hp9-7gg3-wp75.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9qpf-q9v6-4q5c/GHSA-9qpf-q9v6-4q5c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vqf-q6g6-hpj7/GHSA-9vqf-q6g6-hpj7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gc26-wqwp-qr8c/GHSA-gc26-wqwp-qr8c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p6w3-x67f-q79q/GHSA-p6w3-x67f-q79q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pg7r-jpxf-59rr/GHSA-pg7r-jpxf-59rr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r5wr-v3gv-93m3/GHSA-r5wr-v3gv-93m3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rjwx-2xjg-q573/GHSA-rjwx-2xjg-q573.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wwp5-7982-8x96/GHSA-wwp5-7982-8x96.json diff --git a/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json b/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json index 13fde0a7317..2fe4b395c70 100644 --- a/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json +++ b/advisories/unreviewed/2024/02/GHSA-3q8j-579q-jx44/GHSA-3q8j-579q-jx44.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q8j-579q-jx44", - "modified": "2024-08-26T21:30:31Z", + "modified": "2025-03-29T00:31:28Z", "published": "2024-02-15T06:31:36Z", "aliases": [ "CVE-2022-23090" ], "details": "The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case.\n\nAn attacker may cause the reference count to overflow, leading to a use after free (UAF).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T06:15:45Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json b/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json index eef6e192fa5..db83921980d 100644 --- a/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json +++ b/advisories/unreviewed/2024/02/GHSA-3qwx-q6x9-637h/GHSA-3qwx-q6x9-637h.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json b/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json index d667a4253c8..3dcc9b69849 100644 --- a/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json +++ b/advisories/unreviewed/2024/02/GHSA-3rhh-97v9-2g42/GHSA-3rhh-97v9-2g42.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-441" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json b/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json index a2cbde5f8bb..1b73c4c93eb 100644 --- a/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json +++ b/advisories/unreviewed/2024/02/GHSA-c537-pf3w-23p5/GHSA-c537-pf3w-23p5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-841" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h33h-98m4-q487/GHSA-h33h-98m4-q487.json b/advisories/unreviewed/2024/02/GHSA-h33h-98m4-q487/GHSA-h33h-98m4-q487.json index 201ec3c9feb..8fb9be9c4fb 100644 --- a/advisories/unreviewed/2024/02/GHSA-h33h-98m4-q487/GHSA-h33h-98m4-q487.json +++ b/advisories/unreviewed/2024/02/GHSA-h33h-98m4-q487/GHSA-h33h-98m4-q487.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json index e7787ead8cc..a95ed42fe79 100644 --- a/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json +++ b/advisories/unreviewed/2024/02/GHSA-v5qp-mx94-j49v/GHSA-v5qp-mx94-j49v.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-617" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-v9pp-cc53-25hp/GHSA-v9pp-cc53-25hp.json b/advisories/unreviewed/2024/02/GHSA-v9pp-cc53-25hp/GHSA-v9pp-cc53-25hp.json index fecce06ac06..e6d0b1a69ae 100644 --- a/advisories/unreviewed/2024/02/GHSA-v9pp-cc53-25hp/GHSA-v9pp-cc53-25hp.json +++ b/advisories/unreviewed/2024/02/GHSA-v9pp-cc53-25hp/GHSA-v9pp-cc53-25hp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w2f4-229h-cwc2/GHSA-w2f4-229h-cwc2.json b/advisories/unreviewed/2024/02/GHSA-w2f4-229h-cwc2/GHSA-w2f4-229h-cwc2.json index 58494050eac..601dda13b8a 100644 --- a/advisories/unreviewed/2024/02/GHSA-w2f4-229h-cwc2/GHSA-w2f4-229h-cwc2.json +++ b/advisories/unreviewed/2024/02/GHSA-w2f4-229h-cwc2/GHSA-w2f4-229h-cwc2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5w28-7mvj-3c7j/GHSA-5w28-7mvj-3c7j.json b/advisories/unreviewed/2024/03/GHSA-5w28-7mvj-3c7j/GHSA-5w28-7mvj-3c7j.json index af31d8615c3..c70221ff38d 100644 --- a/advisories/unreviewed/2024/03/GHSA-5w28-7mvj-3c7j/GHSA-5w28-7mvj-3c7j.json +++ b/advisories/unreviewed/2024/03/GHSA-5w28-7mvj-3c7j/GHSA-5w28-7mvj-3c7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5w28-7mvj-3c7j", - "modified": "2024-03-24T03:30:44Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-03-24T03:30:44Z", "aliases": [ "CVE-2020-36827" ], "details": "The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-791" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-24T01:15:45Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json b/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json index 9cd7e8ee521..b02163d0000 100644 --- a/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json +++ b/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5xcj-6x8h-ff6h", - "modified": "2024-03-11T18:31:09Z", + "modified": "2025-03-29T00:31:29Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-1487" ], "details": "The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:18Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json b/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json index 0833c5ccbba..49028065b5a 100644 --- a/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json +++ b/advisories/unreviewed/2024/03/GHSA-7537-7q22-h2h7/GHSA-7537-7q22-h2h7.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-76hh-9ghf-c266/GHSA-76hh-9ghf-c266.json b/advisories/unreviewed/2024/03/GHSA-76hh-9ghf-c266/GHSA-76hh-9ghf-c266.json index 363c331818c..81d2b618940 100644 --- a/advisories/unreviewed/2024/03/GHSA-76hh-9ghf-c266/GHSA-76hh-9ghf-c266.json +++ b/advisories/unreviewed/2024/03/GHSA-76hh-9ghf-c266/GHSA-76hh-9ghf-c266.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-450" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json b/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json index 3e6461eaa83..42f903422d7 100644 --- a/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json +++ b/advisories/unreviewed/2024/03/GHSA-7hgq-9c4p-6wjc/GHSA-7hgq-9c4p-6wjc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json b/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json index d66b3501ab2..f09964b736d 100644 --- a/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json +++ b/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-f6mw-hgw7-8wr3/GHSA-f6mw-hgw7-8wr3.json b/advisories/unreviewed/2024/03/GHSA-f6mw-hgw7-8wr3/GHSA-f6mw-hgw7-8wr3.json index 8cc42c16c07..e9c87f1bae6 100644 --- a/advisories/unreviewed/2024/03/GHSA-f6mw-hgw7-8wr3/GHSA-f6mw-hgw7-8wr3.json +++ b/advisories/unreviewed/2024/03/GHSA-f6mw-hgw7-8wr3/GHSA-f6mw-hgw7-8wr3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f6mw-hgw7-8wr3", - "modified": "2024-03-15T15:30:44Z", + "modified": "2025-03-29T00:31:29Z", "published": "2024-03-15T15:30:44Z", "aliases": [ "CVE-2024-28319" ], "details": "gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T15:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json b/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json index 2a57cf2026a..158b68b3ee0 100644 --- a/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json +++ b/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q43x-m6x8-fxgx", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-03-28T03:30:58Z", "aliases": [ "CVE-2024-28006" ], "details": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to view device information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T01:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-r98v-pm7j-85j5/GHSA-r98v-pm7j-85j5.json b/advisories/unreviewed/2024/03/GHSA-r98v-pm7j-85j5/GHSA-r98v-pm7j-85j5.json index 09cf9069dae..b6029a2d303 100644 --- a/advisories/unreviewed/2024/03/GHSA-r98v-pm7j-85j5/GHSA-r98v-pm7j-85j5.json +++ b/advisories/unreviewed/2024/03/GHSA-r98v-pm7j-85j5/GHSA-r98v-pm7j-85j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r98v-pm7j-85j5", - "modified": "2024-03-22T15:31:07Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-03-22T15:31:07Z", "aliases": [ "CVE-2024-29865" ], "details": "Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T15:15:15Z" diff --git a/advisories/unreviewed/2024/03/GHSA-v72q-pr3v-f552/GHSA-v72q-pr3v-f552.json b/advisories/unreviewed/2024/03/GHSA-v72q-pr3v-f552/GHSA-v72q-pr3v-f552.json index d2210b66757..bfeabab12c1 100644 --- a/advisories/unreviewed/2024/03/GHSA-v72q-pr3v-f552/GHSA-v72q-pr3v-f552.json +++ b/advisories/unreviewed/2024/03/GHSA-v72q-pr3v-f552/GHSA-v72q-pr3v-f552.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-277" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xp9q-8p95-j7cm/GHSA-xp9q-8p95-j7cm.json b/advisories/unreviewed/2024/03/GHSA-xp9q-8p95-j7cm/GHSA-xp9q-8p95-j7cm.json index ad3f6796696..e668f17345a 100644 --- a/advisories/unreviewed/2024/03/GHSA-xp9q-8p95-j7cm/GHSA-xp9q-8p95-j7cm.json +++ b/advisories/unreviewed/2024/03/GHSA-xp9q-8p95-j7cm/GHSA-xp9q-8p95-j7cm.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json b/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json index 9f08cfb4987..53523ac9c8c 100644 --- a/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json +++ b/advisories/unreviewed/2024/04/GHSA-6pfx-3rw7-5c4g/GHSA-6pfx-3rw7-5c4g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6pfx-3rw7-5c4g", - "modified": "2024-04-05T21:32:42Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-04-05T21:32:42Z", "aliases": [ "CVE-2024-29738" ], "details": "In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json index 0c802438bae..86963f698e8 100644 --- a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json +++ b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmxf-xmv7-xjq8", - "modified": "2025-03-17T15:31:37Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2024-26656" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/22f665ecfd1225afa1309ace623157d12bb9bb0c" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e13f88e01ae7e28a7e831bf5c2409c4748e0a60" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/af054a5fb24a144f99895afce9519d709891894c" diff --git a/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json b/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json index ea93af97c61..ef1f17a2050 100644 --- a/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json +++ b/advisories/unreviewed/2024/04/GHSA-fh3p-6j2p-f5qv/GHSA-fh3p-6j2p-f5qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fh3p-6j2p-f5qv", - "modified": "2024-04-03T00:30:55Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-04-03T00:30:55Z", "aliases": [ "CVE-2024-29434" ], "details": "An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T22:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json b/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json index d43412fea3e..2528f98a6e4 100644 --- a/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json +++ b/advisories/unreviewed/2024/04/GHSA-h335-p3x8-932g/GHSA-h335-p3x8-932g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h335-p3x8-932g", - "modified": "2024-04-26T06:30:35Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-04-26T06:30:35Z", "aliases": [ "CVE-2024-2439" ], "details": "The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-26T05:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json index 3145c083d1f..afa3be11009 100644 --- a/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json +++ b/advisories/unreviewed/2024/04/GHSA-p6gp-c388-p4cr/GHSA-p6gp-c388-p4cr.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q3p5-hqpp-3phh/GHSA-q3p5-hqpp-3phh.json b/advisories/unreviewed/2024/04/GHSA-q3p5-hqpp-3phh/GHSA-q3p5-hqpp-3phh.json index d4f390b5fc4..f8185a30b16 100644 --- a/advisories/unreviewed/2024/04/GHSA-q3p5-hqpp-3phh/GHSA-q3p5-hqpp-3phh.json +++ b/advisories/unreviewed/2024/04/GHSA-q3p5-hqpp-3phh/GHSA-q3p5-hqpp-3phh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json b/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json index 3f957930f31..0e40d5513e6 100644 --- a/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json +++ b/advisories/unreviewed/2024/04/GHSA-v98m-62r5-hvcm/GHSA-v98m-62r5-hvcm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json b/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json index 1abb4b614c3..cd84ab9ff51 100644 --- a/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json +++ b/advisories/unreviewed/2024/04/GHSA-w74w-xq97-pg62/GHSA-w74w-xq97-pg62.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json b/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json index a516c06c941..b8a9d58713b 100644 --- a/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json +++ b/advisories/unreviewed/2024/04/GHSA-wg7v-w4x5-xvmx/GHSA-wg7v-w4x5-xvmx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-250" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json b/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json index 88abbd89a52..de16c42f022 100644 --- a/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json +++ b/advisories/unreviewed/2024/05/GHSA-3563-pvjf-xg5g/GHSA-3563-pvjf-xg5g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3563-pvjf-xg5g", - "modified": "2024-05-14T18:30:52Z", + "modified": "2025-03-29T00:31:31Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3582" ], "details": "The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:41:54Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3cw9-m9j6-m7jf/GHSA-3cw9-m9j6-m7jf.json b/advisories/unreviewed/2024/05/GHSA-3cw9-m9j6-m7jf/GHSA-3cw9-m9j6-m7jf.json index e26ef57b20e..4b833be9b82 100644 --- a/advisories/unreviewed/2024/05/GHSA-3cw9-m9j6-m7jf/GHSA-3cw9-m9j6-m7jf.json +++ b/advisories/unreviewed/2024/05/GHSA-3cw9-m9j6-m7jf/GHSA-3cw9-m9j6-m7jf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3cw9-m9j6-m7jf", - "modified": "2024-06-10T18:31:03Z", + "modified": "2025-03-29T00:31:32Z", "published": "2024-05-20T12:30:27Z", "aliases": [ "CVE-2024-35949" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35949" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9dff3e36ea89e8003516841c27c45af562b6ef44" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/e03418abde871314e1a3a550f4c8afb7b89cb273" diff --git a/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json b/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json index 7d4f219ef68..d25f96812b9 100644 --- a/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json +++ b/advisories/unreviewed/2024/05/GHSA-56m5-6v25-whgm/GHSA-56m5-6v25-whgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-56m5-6v25-whgm", - "modified": "2024-05-15T06:30:44Z", + "modified": "2025-03-29T00:31:31Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3822" ], "details": "The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json b/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json index 1d9d6187e76..a6dbd457d31 100644 --- a/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json +++ b/advisories/unreviewed/2024/05/GHSA-6fj9-cq25-9x7h/GHSA-6fj9-cq25-9x7h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6fj9-cq25-9x7h", - "modified": "2024-05-21T06:30:51Z", + "modified": "2025-03-29T00:31:31Z", "published": "2024-05-21T06:30:51Z", "aliases": [ "CVE-2024-4061" ], "details": "The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T06:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json b/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json index e8e3978dea1..07d55c43f27 100644 --- a/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json +++ b/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cc7f-xj8f-c4mm", - "modified": "2024-05-14T15:32:55Z", + "modified": "2025-03-29T00:31:31Z", "published": "2024-05-14T15:32:55Z", "aliases": [ "CVE-2024-31810" ], "details": "TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-259" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:25:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json b/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json index a0eeb24950f..08598a0e8b3 100644 --- a/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json +++ b/advisories/unreviewed/2024/05/GHSA-f487-f23r-hjx6/GHSA-f487-f23r-hjx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f487-f23r-hjx6", - "modified": "2024-05-01T15:30:36Z", + "modified": "2025-03-29T00:31:30Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27056" @@ -14,6 +14,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27056" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35afffaddbe8d310dc61659da0b1a337b0d0addc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4903303f25f48b5a1e34e6324c7fae9ccd6b959a" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/78f65fbf421a61894c14a1b91fe2fb4437b3fe5f" diff --git a/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json b/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json index c2904a5893d..8ce8dd5cc5c 100644 --- a/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json +++ b/advisories/unreviewed/2024/05/GHSA-fhf8-hvgj-q5vh/GHSA-fhf8-hvgj-q5vh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j2g5-g9wr-mrff/GHSA-j2g5-g9wr-mrff.json b/advisories/unreviewed/2024/05/GHSA-j2g5-g9wr-mrff/GHSA-j2g5-g9wr-mrff.json index 8b46a4ea201..8d8ad5287d3 100644 --- a/advisories/unreviewed/2024/05/GHSA-j2g5-g9wr-mrff/GHSA-j2g5-g9wr-mrff.json +++ b/advisories/unreviewed/2024/05/GHSA-j2g5-g9wr-mrff/GHSA-j2g5-g9wr-mrff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2g5-g9wr-mrff", - "modified": "2024-12-30T18:30:40Z", + "modified": "2025-03-29T00:31:31Z", "published": "2024-05-19T09:34:46Z", "aliases": [ "CVE-2024-35866" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/58acd1f497162e7d282077f816faa519487be045" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4a60d360d9114b5085701a3702a0102b0d6d846" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json b/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json index 9d8f1c40f24..0d27a86cea6 100644 --- a/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json +++ b/advisories/unreviewed/2024/05/GHSA-mwgq-3h9h-3q6g/GHSA-mwgq-3h9h-3q6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mwgq-3h9h-3q6g", - "modified": "2025-02-03T18:30:37Z", + "modified": "2025-03-29T00:31:32Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52857" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/96312a251d4dcee5d36e32edba3002bfde0ddd9c" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a12bd675100531f9fb4508fd4430dd1632325a0e" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b0b0d811eac6b4c52cb9ad632fa6384cf48869e7" diff --git a/advisories/unreviewed/2024/06/GHSA-58pq-phhq-59vj/GHSA-58pq-phhq-59vj.json b/advisories/unreviewed/2024/06/GHSA-58pq-phhq-59vj/GHSA-58pq-phhq-59vj.json index 933e5ea3185..f42b80e9cc8 100644 --- a/advisories/unreviewed/2024/06/GHSA-58pq-phhq-59vj/GHSA-58pq-phhq-59vj.json +++ b/advisories/unreviewed/2024/06/GHSA-58pq-phhq-59vj/GHSA-58pq-phhq-59vj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-73" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json b/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json index 5fd8be674c0..67f35b79f24 100644 --- a/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json +++ b/advisories/unreviewed/2024/06/GHSA-9hrm-g973-phrr/GHSA-9hrm-g973-phrr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json b/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json index 53e4a127e2e..ba8455c806c 100644 --- a/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json +++ b/advisories/unreviewed/2024/06/GHSA-mv5f-f7c2-2pg5/GHSA-mv5f-f7c2-2pg5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json b/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json index 7fdbc5eea45..bfe1686ecd3 100644 --- a/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json +++ b/advisories/unreviewed/2024/06/GHSA-wfrc-c4v4-fvxm/GHSA-wfrc-c4v4-fvxm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-87f6-7cww-rh98/GHSA-87f6-7cww-rh98.json b/advisories/unreviewed/2024/07/GHSA-87f6-7cww-rh98/GHSA-87f6-7cww-rh98.json index f97c8fd9924..2a89c4d2b8a 100644 --- a/advisories/unreviewed/2024/07/GHSA-87f6-7cww-rh98/GHSA-87f6-7cww-rh98.json +++ b/advisories/unreviewed/2024/07/GHSA-87f6-7cww-rh98/GHSA-87f6-7cww-rh98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87f6-7cww-rh98", - "modified": "2024-12-02T09:39:11Z", + "modified": "2025-03-29T00:31:33Z", "published": "2024-07-30T09:32:01Z", "aliases": [ "CVE-2024-42129" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3b62888307ae44b68512d3f7735c26a4c8e45b51" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/618c6ce83471ab4f7ac744d27b9d03af173bc141" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/efc347b9efee1c2b081f5281d33be4559fa50a16" diff --git a/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json b/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json index b5740915724..f58d3c8d619 100644 --- a/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json +++ b/advisories/unreviewed/2024/10/GHSA-3x9w-fg96-5j98/GHSA-3x9w-fg96-5j98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x9w-fg96-5j98", - "modified": "2024-10-22T18:32:10Z", + "modified": "2025-03-29T00:31:33Z", "published": "2024-10-21T15:32:27Z", "aliases": [ "CVE-2024-47753" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/35cc704622b3a9bc02a4755d5ba80238eee3cdc2" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e0713c79cf5d0b549fa855e230ade1ff83c27d7" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b113bc7c0e83b32f4dd2d291a2b6c4803e0a2c44" diff --git a/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json b/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json index 69194facbde..e120efa7068 100644 --- a/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json +++ b/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2r5-qpjf-gcfc", - "modified": "2025-03-06T15:34:38Z", + "modified": "2025-03-29T00:31:33Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53209" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3051a77a09dfe3022aa012071346937fdf059033" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f306c651feab2f3689185f60b94e72b573255db" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/84353386762a0a16dd444ead76c012e167d89b41" diff --git a/advisories/unreviewed/2025/03/GHSA-24cf-848g-762c/GHSA-24cf-848g-762c.json b/advisories/unreviewed/2025/03/GHSA-24cf-848g-762c/GHSA-24cf-848g-762c.json new file mode 100644 index 00000000000..d4100a2c306 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-24cf-848g-762c/GHSA-24cf-848g-762c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24cf-848g-762c", + "modified": "2025-03-29T00:31:34Z", + "published": "2025-03-29T00:31:34Z", + "aliases": [ + "CVE-2025-28094" + ], + "details": "shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28094" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/echzollcdlmllgqo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-42g5-mrm4-477g/GHSA-42g5-mrm4-477g.json b/advisories/unreviewed/2025/03/GHSA-42g5-mrm4-477g/GHSA-42g5-mrm4-477g.json new file mode 100644 index 00000000000..d7e34415d7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-42g5-mrm4-477g/GHSA-42g5-mrm4-477g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42g5-mrm4-477g", + "modified": "2025-03-29T00:31:33Z", + "published": "2025-03-29T00:31:33Z", + "aliases": [ + "CVE-2024-58129" + ], + "details": "In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58129" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/commit/09a43870e733f79ffa33753ddc7bce3cbb5a5647" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/releases/tag/v2.4.193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json b/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json new file mode 100644 index 00000000000..aa81ea7a64e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r7f-8mqg-24xx", + "modified": "2025-03-29T00:31:35Z", + "published": "2025-03-29T00:31:35Z", + "aliases": [ + "CVE-2025-28097" + ], + "details": "OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28097" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/oqi6pyv26gci6465" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hp9-7gg3-wp75/GHSA-6hp9-7gg3-wp75.json b/advisories/unreviewed/2025/03/GHSA-6hp9-7gg3-wp75/GHSA-6hp9-7gg3-wp75.json new file mode 100644 index 00000000000..4c7e7badc18 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hp9-7gg3-wp75/GHSA-6hp9-7gg3-wp75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hp9-7gg3-wp75", + "modified": "2025-03-29T00:31:36Z", + "published": "2025-03-29T00:31:36Z", + "aliases": [ + "CVE-2024-7577" + ], + "details": "IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7577" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7185020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-29T00:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json b/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json new file mode 100644 index 00000000000..a6ffdcbf3f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7q69-vmcq-34w9/GHSA-7q69-vmcq-34w9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q69-vmcq-34w9", + "modified": "2025-03-29T00:31:34Z", + "published": "2025-03-29T00:31:34Z", + "aliases": [ + "CVE-2025-28090" + ], + "details": "maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28090" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/xo5w1euakvtgenex" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9qpf-q9v6-4q5c/GHSA-9qpf-q9v6-4q5c.json b/advisories/unreviewed/2025/03/GHSA-9qpf-q9v6-4q5c/GHSA-9qpf-q9v6-4q5c.json new file mode 100644 index 00000000000..8e3c35b8bf5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9qpf-q9v6-4q5c/GHSA-9qpf-q9v6-4q5c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qpf-q9v6-4q5c", + "modified": "2025-03-29T00:31:35Z", + "published": "2025-03-29T00:31:35Z", + "aliases": [ + "CVE-2025-28096" + ], + "details": "OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28096" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/oqi6pyv26gci6465" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vqf-q6g6-hpj7/GHSA-9vqf-q6g6-hpj7.json b/advisories/unreviewed/2025/03/GHSA-9vqf-q6g6-hpj7/GHSA-9vqf-q6g6-hpj7.json new file mode 100644 index 00000000000..312f577a544 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9vqf-q6g6-hpj7/GHSA-9vqf-q6g6-hpj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vqf-q6g6-hpj7", + "modified": "2025-03-29T00:31:35Z", + "published": "2025-03-29T00:31:35Z", + "aliases": [ + "CVE-2024-43186" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43186" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7184980" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-29T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json b/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json new file mode 100644 index 00000000000..540e33a9bf9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c928-5v6m-vm5h/GHSA-c928-5v6m-vm5h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c928-5v6m-vm5h", + "modified": "2025-03-29T00:31:34Z", + "published": "2025-03-29T00:31:34Z", + "aliases": [ + "CVE-2025-28089" + ], + "details": "maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28089" + }, + { + "type": "WEB", + "url": "https://github.com/magicblack/maccms10/releases/tag/v2025.1000.4047" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/wzer7qxh0vwrf6zq" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gc26-wqwp-qr8c/GHSA-gc26-wqwp-qr8c.json b/advisories/unreviewed/2025/03/GHSA-gc26-wqwp-qr8c/GHSA-gc26-wqwp-qr8c.json new file mode 100644 index 00000000000..7c869b3b8f2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gc26-wqwp-qr8c/GHSA-gc26-wqwp-qr8c.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc26-wqwp-qr8c", + "modified": "2025-03-29T00:31:33Z", + "published": "2025-03-29T00:31:33Z", + "aliases": [ + "CVE-2025-25579" + ], + "details": "TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25579" + }, + { + "type": "WEB", + "url": "https://gist.github.com/regainer27/0abf6f56eae3fa2826d2551e22c2ace3" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/totolink_A3002R_remote_command_exec" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json b/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json new file mode 100644 index 00000000000..4908cc6490e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gfhv-5rqh-7qx3/GHSA-gfhv-5rqh-7qx3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfhv-5rqh-7qx3", + "modified": "2025-03-29T00:31:34Z", + "published": "2025-03-29T00:31:34Z", + "aliases": [ + "CVE-2025-28093" + ], + "details": "ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28093" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/he2hb8ic8an8h07f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json b/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json new file mode 100644 index 00000000000..2ac2be6dfc7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mhwj-vqr2-3j7m/GHSA-mhwj-vqr2-3j7m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhwj-vqr2-3j7m", + "modified": "2025-03-29T00:31:33Z", + "published": "2025-03-29T00:31:33Z", + "aliases": [ + "CVE-2025-28087" + ], + "details": "Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28087" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/vxhdpdeavzvtvdqq" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p6w3-x67f-q79q/GHSA-p6w3-x67f-q79q.json b/advisories/unreviewed/2025/03/GHSA-p6w3-x67f-q79q/GHSA-p6w3-x67f-q79q.json new file mode 100644 index 00000000000..edb69a20206 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p6w3-x67f-q79q/GHSA-p6w3-x67f-q79q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6w3-x67f-q79q", + "modified": "2025-03-29T00:31:36Z", + "published": "2025-03-29T00:31:36Z", + "aliases": [ + "CVE-2024-51477" + ], + "details": "IBM InfoSphere Information Server 11.7 \n\ncould allow an authenticated to obtain sensitive username information due to an observable response discrepancy.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51477" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7185058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-29T00:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json b/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json new file mode 100644 index 00000000000..f430e2db45d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p736-g6pg-hjhw/GHSA-p736-g6pg-hjhw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p736-g6pg-hjhw", + "modified": "2025-03-29T00:31:34Z", + "published": "2025-03-29T00:31:34Z", + "aliases": [ + "CVE-2025-28092" + ], + "details": "ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28092" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/stggvmlxs9ewqlvu" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pg7r-jpxf-59rr/GHSA-pg7r-jpxf-59rr.json b/advisories/unreviewed/2025/03/GHSA-pg7r-jpxf-59rr/GHSA-pg7r-jpxf-59rr.json new file mode 100644 index 00000000000..1457083bec8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pg7r-jpxf-59rr/GHSA-pg7r-jpxf-59rr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg7r-jpxf-59rr", + "modified": "2025-03-29T00:31:33Z", + "published": "2025-03-29T00:31:33Z", + "aliases": [ + "CVE-2024-58128" + ], + "details": "In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58128" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/commit/33a1eb66408e16a7535b2bae48303efd9501a26a" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/releases/tag/v2.4.193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r5wr-v3gv-93m3/GHSA-r5wr-v3gv-93m3.json b/advisories/unreviewed/2025/03/GHSA-r5wr-v3gv-93m3/GHSA-r5wr-v3gv-93m3.json new file mode 100644 index 00000000000..c9efea54626 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r5wr-v3gv-93m3/GHSA-r5wr-v3gv-93m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5wr-v3gv-93m3", + "modified": "2025-03-29T00:31:35Z", + "published": "2025-03-29T00:31:35Z", + "aliases": [ + "CVE-2025-2782" + ], + "details": "The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.\n\n\n\nThis issue affects Terminal Services Agent: from 12.0 through 12.10.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2782" + }, + { + "type": "WEB", + "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rjwx-2xjg-q573/GHSA-rjwx-2xjg-q573.json b/advisories/unreviewed/2025/03/GHSA-rjwx-2xjg-q573/GHSA-rjwx-2xjg-q573.json new file mode 100644 index 00000000000..c8694996710 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rjwx-2xjg-q573/GHSA-rjwx-2xjg-q573.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjwx-2xjg-q573", + "modified": "2025-03-29T00:31:33Z", + "published": "2025-03-29T00:31:33Z", + "aliases": [ + "CVE-2024-58130" + ], + "details": "In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58130" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/commit/f08a2eaec25f0212c22b225c0b654bd60d089ef9" + }, + { + "type": "WEB", + "url": "https://github.com/MISP/MISP/releases/tag/v2.4.193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json b/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json new file mode 100644 index 00000000000..388f70e951b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rwcm-vvj8-qgg5/GHSA-rwcm-vvj8-qgg5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwcm-vvj8-qgg5", + "modified": "2025-03-29T00:31:34Z", + "published": "2025-03-29T00:31:34Z", + "aliases": [ + "CVE-2025-28091" + ], + "details": "maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28091" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/ax55rxv4u3our1ic" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wwp5-7982-8x96/GHSA-wwp5-7982-8x96.json b/advisories/unreviewed/2025/03/GHSA-wwp5-7982-8x96/GHSA-wwp5-7982-8x96.json new file mode 100644 index 00000000000..1ecc0328fbb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wwp5-7982-8x96/GHSA-wwp5-7982-8x96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwp5-7982-8x96", + "modified": "2025-03-29T00:31:35Z", + "published": "2025-03-29T00:31:35Z", + "aliases": [ + "CVE-2025-2781" + ], + "details": "The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.\n\n\n\nThis issue affects Mobile VPN with SSL Client: from 11.0 through 12.11.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2781" + }, + { + "type": "WEB", + "url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T23:15:18Z" + } +} \ No newline at end of file