diff --git a/advisories/unreviewed/2022/05/GHSA-5qm4-cm2h-3cgf/GHSA-5qm4-cm2h-3cgf.json b/advisories/unreviewed/2022/05/GHSA-5qm4-cm2h-3cgf/GHSA-5qm4-cm2h-3cgf.json index 48cc0187b58..99a83c0a195 100644 --- a/advisories/unreviewed/2022/05/GHSA-5qm4-cm2h-3cgf/GHSA-5qm4-cm2h-3cgf.json +++ b/advisories/unreviewed/2022/05/GHSA-5qm4-cm2h-3cgf/GHSA-5qm4-cm2h-3cgf.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-522" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-6qxv-37xg-xg4w/GHSA-6qxv-37xg-xg4w.json b/advisories/unreviewed/2023/06/GHSA-6qxv-37xg-xg4w/GHSA-6qxv-37xg-xg4w.json index 4a0ee2fe3ed..34144c80791 100644 --- a/advisories/unreviewed/2023/06/GHSA-6qxv-37xg-xg4w/GHSA-6qxv-37xg-xg4w.json +++ b/advisories/unreviewed/2023/06/GHSA-6qxv-37xg-xg4w/GHSA-6qxv-37xg-xg4w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-h6j7-2w2f-q5rm/GHSA-h6j7-2w2f-q5rm.json b/advisories/unreviewed/2023/06/GHSA-h6j7-2w2f-q5rm/GHSA-h6j7-2w2f-q5rm.json index bffdb0d409e..7fe8d4f61aa 100644 --- a/advisories/unreviewed/2023/06/GHSA-h6j7-2w2f-q5rm/GHSA-h6j7-2w2f-q5rm.json +++ b/advisories/unreviewed/2023/06/GHSA-h6j7-2w2f-q5rm/GHSA-h6j7-2w2f-q5rm.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5mr2-xg52-9g99/GHSA-5mr2-xg52-9g99.json b/advisories/unreviewed/2024/05/GHSA-5mr2-xg52-9g99/GHSA-5mr2-xg52-9g99.json index 2daf541c0b0..249c56294ad 100644 --- a/advisories/unreviewed/2024/05/GHSA-5mr2-xg52-9g99/GHSA-5mr2-xg52-9g99.json +++ b/advisories/unreviewed/2024/05/GHSA-5mr2-xg52-9g99/GHSA-5mr2-xg52-9g99.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-345" + "CWE-345", + "CWE-346" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-66rh-m5r2-4gx2/GHSA-66rh-m5r2-4gx2.json b/advisories/unreviewed/2024/05/GHSA-66rh-m5r2-4gx2/GHSA-66rh-m5r2-4gx2.json index 67cc2ee3187..c830ffafe6a 100644 --- a/advisories/unreviewed/2024/05/GHSA-66rh-m5r2-4gx2/GHSA-66rh-m5r2-4gx2.json +++ b/advisories/unreviewed/2024/05/GHSA-66rh-m5r2-4gx2/GHSA-66rh-m5r2-4gx2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-68jf-3wjw-q37v/GHSA-68jf-3wjw-q37v.json b/advisories/unreviewed/2024/05/GHSA-68jf-3wjw-q37v/GHSA-68jf-3wjw-q37v.json index 0b0d4eb0047..979ba72e010 100644 --- a/advisories/unreviewed/2024/05/GHSA-68jf-3wjw-q37v/GHSA-68jf-3wjw-q37v.json +++ b/advisories/unreviewed/2024/05/GHSA-68jf-3wjw-q37v/GHSA-68jf-3wjw-q37v.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-fphw-hp4w-p8m4/GHSA-fphw-hp4w-p8m4.json b/advisories/unreviewed/2024/05/GHSA-fphw-hp4w-p8m4/GHSA-fphw-hp4w-p8m4.json index b3a1808147e..6b6e5e9bfe7 100644 --- a/advisories/unreviewed/2024/05/GHSA-fphw-hp4w-p8m4/GHSA-fphw-hp4w-p8m4.json +++ b/advisories/unreviewed/2024/05/GHSA-fphw-hp4w-p8m4/GHSA-fphw-hp4w-p8m4.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-pq3r-x8gq-g8xm/GHSA-pq3r-x8gq-g8xm.json b/advisories/unreviewed/2024/05/GHSA-pq3r-x8gq-g8xm/GHSA-pq3r-x8gq-g8xm.json index 3a3b1b2fb7f..807140ebe11 100644 --- a/advisories/unreviewed/2024/05/GHSA-pq3r-x8gq-g8xm/GHSA-pq3r-x8gq-g8xm.json +++ b/advisories/unreviewed/2024/05/GHSA-pq3r-x8gq-g8xm/GHSA-pq3r-x8gq-g8xm.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-r955-pv6h-62wj/GHSA-r955-pv6h-62wj.json b/advisories/unreviewed/2024/05/GHSA-r955-pv6h-62wj/GHSA-r955-pv6h-62wj.json index 4d1dba2c20c..0fd44009726 100644 --- a/advisories/unreviewed/2024/05/GHSA-r955-pv6h-62wj/GHSA-r955-pv6h-62wj.json +++ b/advisories/unreviewed/2024/05/GHSA-r955-pv6h-62wj/GHSA-r955-pv6h-62wj.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-v43g-f5c4-v4jm/GHSA-v43g-f5c4-v4jm.json b/advisories/unreviewed/2024/11/GHSA-v43g-f5c4-v4jm/GHSA-v43g-f5c4-v4jm.json index 3dff0a8b38d..be413fb86a4 100644 --- a/advisories/unreviewed/2024/11/GHSA-v43g-f5c4-v4jm/GHSA-v43g-f5c4-v4jm.json +++ b/advisories/unreviewed/2024/11/GHSA-v43g-f5c4-v4jm/GHSA-v43g-f5c4-v4jm.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-vqfj-mm88-89m5/GHSA-vqfj-mm88-89m5.json b/advisories/unreviewed/2024/11/GHSA-vqfj-mm88-89m5/GHSA-vqfj-mm88-89m5.json index 39df35669e6..9add4b94506 100644 --- a/advisories/unreviewed/2024/11/GHSA-vqfj-mm88-89m5/GHSA-vqfj-mm88-89m5.json +++ b/advisories/unreviewed/2024/11/GHSA-vqfj-mm88-89m5/GHSA-vqfj-mm88-89m5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-4545-q8rv-g7f9/GHSA-4545-q8rv-g7f9.json b/advisories/unreviewed/2024/12/GHSA-4545-q8rv-g7f9/GHSA-4545-q8rv-g7f9.json index c803d9c901c..ccc1cdddf64 100644 --- a/advisories/unreviewed/2024/12/GHSA-4545-q8rv-g7f9/GHSA-4545-q8rv-g7f9.json +++ b/advisories/unreviewed/2024/12/GHSA-4545-q8rv-g7f9/GHSA-4545-q8rv-g7f9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-866w-76w7-m942/GHSA-866w-76w7-m942.json b/advisories/unreviewed/2024/12/GHSA-866w-76w7-m942/GHSA-866w-76w7-m942.json index 31183cbd44c..03c616136f8 100644 --- a/advisories/unreviewed/2024/12/GHSA-866w-76w7-m942/GHSA-866w-76w7-m942.json +++ b/advisories/unreviewed/2024/12/GHSA-866w-76w7-m942/GHSA-866w-76w7-m942.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-9qcv-f3w6-jhh5/GHSA-9qcv-f3w6-jhh5.json b/advisories/unreviewed/2024/12/GHSA-9qcv-f3w6-jhh5/GHSA-9qcv-f3w6-jhh5.json index ee190a17909..c08441a2b6d 100644 --- a/advisories/unreviewed/2024/12/GHSA-9qcv-f3w6-jhh5/GHSA-9qcv-f3w6-jhh5.json +++ b/advisories/unreviewed/2024/12/GHSA-9qcv-f3w6-jhh5/GHSA-9qcv-f3w6-jhh5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json b/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json index cd2d4a0050a..b886de1b868 100644 --- a/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json +++ b/advisories/unreviewed/2024/12/GHSA-m5hx-8765-fjpm/GHSA-m5hx-8765-fjpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5hx-8765-fjpm", - "modified": "2024-12-12T03:33:00Z", + "modified": "2025-01-03T18:30:33Z", "published": "2024-12-08T00:31:20Z", "aliases": [ "CVE-2024-53473" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/nilsonLazarin/WeGIA/commit/3998672f1b86db58eab2808a640903d73b37bd2d" }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/blob/main/CVE-2024-53473/README.md" + }, { "type": "WEB", "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-53473" diff --git a/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json b/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json new file mode 100644 index 00000000000..f2e8ff6fdc0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63xr-9hmx-v966", + "modified": "2025-01-03T18:30:34Z", + "published": "2025-01-03T18:30:34Z", + "aliases": [ + "CVE-2024-35365" + ], + "details": "FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35365" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/ced5c5fdb8634d39ca9472a2026b2d2fea16c4e5" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/d7d4ea8055b75c4a9f9bbcff31d21423" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/fftools/ffmpeg_mux_init.c#L886" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json b/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json new file mode 100644 index 00000000000..d99f24fefbb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g48-x687-vqf9", + "modified": "2025-01-03T18:30:34Z", + "published": "2025-01-03T18:30:34Z", + "aliases": [ + "CVE-2025-0195" + ], + "details": "A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0195" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Masamuneee/1ac717728823d58ef365a418c8f39810" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290132" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290132" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json b/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json new file mode 100644 index 00000000000..cc483ffafca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h735-q6rm-hjcj", + "modified": "2025-01-03T18:30:34Z", + "published": "2025-01-03T18:30:34Z", + "aliases": [ + "CVE-2024-55507" + ], + "details": "An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55507" + }, + { + "type": "WEB", + "url": "https://github.com/CV1523/CVEs/blob/main/CVE-2024-55507.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json b/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json new file mode 100644 index 00000000000..b51baa79f67 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqm8-c3rv-5vpf", + "modified": "2025-01-03T18:30:34Z", + "published": "2025-01-03T18:30:34Z", + "aliases": [ + "CVE-2024-36613" + ], + "details": "FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36613" + }, + { + "type": "WEB", + "url": "https://github.com/ffmpeg/ffmpeg/commit/50d8e4f27398fd5778485a827d7a2817921f8540" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/0f4d90ef87553f772f888223085ac806" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/blob/n6.1.1/libavformat/dxa.c#L125" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T18:15:15Z" + } +} \ No newline at end of file