diff --git a/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json b/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json index 9f9d8b20afa..026353fa9b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json +++ b/advisories/unreviewed/2022/05/GHSA-4w4w-866c-5vgg/GHSA-4w4w-866c-5vgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4w4w-866c-5vgg", - "modified": "2022-05-17T01:57:47Z", + "modified": "2025-01-22T18:31:47Z", "published": "2022-05-17T01:57:47Z", "aliases": [ "CVE-2015-2291" diff --git a/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json b/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json index 879590ab195..2cabcc72714 100644 --- a/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json +++ b/advisories/unreviewed/2022/05/GHSA-p8wc-6g47-vh8j/GHSA-p8wc-6g47-vh8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8wc-6g47-vh8j", - "modified": "2022-05-14T01:02:48Z", + "modified": "2025-01-22T18:31:47Z", "published": "2022-05-14T01:02:48Z", "aliases": [ "CVE-2015-1635" diff --git a/advisories/unreviewed/2022/08/GHSA-3rq3-j32x-vjg4/GHSA-3rq3-j32x-vjg4.json b/advisories/unreviewed/2022/08/GHSA-3rq3-j32x-vjg4/GHSA-3rq3-j32x-vjg4.json index 9485bb6b38f..dcc18dededd 100644 --- a/advisories/unreviewed/2022/08/GHSA-3rq3-j32x-vjg4/GHSA-3rq3-j32x-vjg4.json +++ b/advisories/unreviewed/2022/08/GHSA-3rq3-j32x-vjg4/GHSA-3rq3-j32x-vjg4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3rq3-j32x-vjg4", - "modified": "2022-09-01T00:00:24Z", + "modified": "2025-01-22T18:31:47Z", "published": "2022-08-26T00:03:35Z", "aliases": [ "CVE-2022-32427" diff --git a/advisories/unreviewed/2023/01/GHSA-88v2-p2r7-rvpx/GHSA-88v2-p2r7-rvpx.json b/advisories/unreviewed/2023/01/GHSA-88v2-p2r7-rvpx/GHSA-88v2-p2r7-rvpx.json index d333bd630d2..673fc8edceb 100644 --- a/advisories/unreviewed/2023/01/GHSA-88v2-p2r7-rvpx/GHSA-88v2-p2r7-rvpx.json +++ b/advisories/unreviewed/2023/01/GHSA-88v2-p2r7-rvpx/GHSA-88v2-p2r7-rvpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88v2-p2r7-rvpx", - "modified": "2023-01-24T21:30:29Z", + "modified": "2025-01-22T18:31:48Z", "published": "2023-01-17T18:30:43Z", "aliases": [ "CVE-2018-14628" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230223-0008" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/11/28/4" diff --git a/advisories/unreviewed/2023/10/GHSA-65rf-4p7c-6rj9/GHSA-65rf-4p7c-6rj9.json b/advisories/unreviewed/2023/10/GHSA-65rf-4p7c-6rj9/GHSA-65rf-4p7c-6rj9.json index 4b20c79d1b3..03f9dadff1a 100644 --- a/advisories/unreviewed/2023/10/GHSA-65rf-4p7c-6rj9/GHSA-65rf-4p7c-6rj9.json +++ b/advisories/unreviewed/2023/10/GHSA-65rf-4p7c-6rj9/GHSA-65rf-4p7c-6rj9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65rf-4p7c-6rj9", - "modified": "2023-11-26T03:30:28Z", + "modified": "2025-01-22T18:31:48Z", "published": "2023-10-18T00:31:41Z", "aliases": [ "CVE-2023-22084" diff --git a/advisories/unreviewed/2024/02/GHSA-6r87-mg59-2prc/GHSA-6r87-mg59-2prc.json b/advisories/unreviewed/2024/02/GHSA-6r87-mg59-2prc/GHSA-6r87-mg59-2prc.json index 5918e19e0ee..76de71810de 100644 --- a/advisories/unreviewed/2024/02/GHSA-6r87-mg59-2prc/GHSA-6r87-mg59-2prc.json +++ b/advisories/unreviewed/2024/02/GHSA-6r87-mg59-2prc/GHSA-6r87-mg59-2prc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r87-mg59-2prc", - "modified": "2024-02-29T03:33:17Z", + "modified": "2025-01-22T18:31:48Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-1390" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6r9x-2rjm-v9rw/GHSA-6r9x-2rjm-v9rw.json b/advisories/unreviewed/2024/02/GHSA-6r9x-2rjm-v9rw/GHSA-6r9x-2rjm-v9rw.json index 6a540275ed0..fb26c7d762f 100644 --- a/advisories/unreviewed/2024/02/GHSA-6r9x-2rjm-v9rw/GHSA-6r9x-2rjm-v9rw.json +++ b/advisories/unreviewed/2024/02/GHSA-6r9x-2rjm-v9rw/GHSA-6r9x-2rjm-v9rw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6r9x-2rjm-v9rw", - "modified": "2024-02-29T03:33:17Z", + "modified": "2025-01-22T18:31:48Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-1408" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-78jh-rw4h-46r3/GHSA-78jh-rw4h-46r3.json b/advisories/unreviewed/2024/02/GHSA-78jh-rw4h-46r3/GHSA-78jh-rw4h-46r3.json index e781990ce6b..5e341b41fb0 100644 --- a/advisories/unreviewed/2024/02/GHSA-78jh-rw4h-46r3/GHSA-78jh-rw4h-46r3.json +++ b/advisories/unreviewed/2024/02/GHSA-78jh-rw4h-46r3/GHSA-78jh-rw4h-46r3.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-825" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-cr5c-88vg-3gjr/GHSA-cr5c-88vg-3gjr.json b/advisories/unreviewed/2024/02/GHSA-cr5c-88vg-3gjr/GHSA-cr5c-88vg-3gjr.json index b0a52a48485..e2843945862 100644 --- a/advisories/unreviewed/2024/02/GHSA-cr5c-88vg-3gjr/GHSA-cr5c-88vg-3gjr.json +++ b/advisories/unreviewed/2024/02/GHSA-cr5c-88vg-3gjr/GHSA-cr5c-88vg-3gjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr5c-88vg-3gjr", - "modified": "2024-02-29T06:30:32Z", + "modified": "2025-01-22T18:31:48Z", "published": "2024-02-29T06:30:32Z", "aliases": [ "CVE-2023-51529" diff --git a/advisories/unreviewed/2024/02/GHSA-jvjm-ff59-qpgj/GHSA-jvjm-ff59-qpgj.json b/advisories/unreviewed/2024/02/GHSA-jvjm-ff59-qpgj/GHSA-jvjm-ff59-qpgj.json index 03f30c22f12..92dabc7e051 100644 --- a/advisories/unreviewed/2024/02/GHSA-jvjm-ff59-qpgj/GHSA-jvjm-ff59-qpgj.json +++ b/advisories/unreviewed/2024/02/GHSA-jvjm-ff59-qpgj/GHSA-jvjm-ff59-qpgj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvjm-ff59-qpgj", - "modified": "2024-02-29T03:33:17Z", + "modified": "2025-01-22T18:31:48Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-1570" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-qq82-99vq-37qp/GHSA-qq82-99vq-37qp.json b/advisories/unreviewed/2024/02/GHSA-qq82-99vq-37qp/GHSA-qq82-99vq-37qp.json index 97a478de789..f5a81fbff0a 100644 --- a/advisories/unreviewed/2024/02/GHSA-qq82-99vq-37qp/GHSA-qq82-99vq-37qp.json +++ b/advisories/unreviewed/2024/02/GHSA-qq82-99vq-37qp/GHSA-qq82-99vq-37qp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq82-99vq-37qp", - "modified": "2024-02-29T03:33:17Z", + "modified": "2025-01-22T18:31:48Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-1519" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-25pp-6h88-3wpx/GHSA-25pp-6h88-3wpx.json b/advisories/unreviewed/2024/03/GHSA-25pp-6h88-3wpx/GHSA-25pp-6h88-3wpx.json index 16e22d9b888..4d1f95512b0 100644 --- a/advisories/unreviewed/2024/03/GHSA-25pp-6h88-3wpx/GHSA-25pp-6h88-3wpx.json +++ b/advisories/unreviewed/2024/03/GHSA-25pp-6h88-3wpx/GHSA-25pp-6h88-3wpx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2wh2-rrfv-xm6m/GHSA-2wh2-rrfv-xm6m.json b/advisories/unreviewed/2024/03/GHSA-2wh2-rrfv-xm6m/GHSA-2wh2-rrfv-xm6m.json index 4ee17fa33e9..b10fdb951da 100644 --- a/advisories/unreviewed/2024/03/GHSA-2wh2-rrfv-xm6m/GHSA-2wh2-rrfv-xm6m.json +++ b/advisories/unreviewed/2024/03/GHSA-2wh2-rrfv-xm6m/GHSA-2wh2-rrfv-xm6m.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-4phr-gh22-r9hw/GHSA-4phr-gh22-r9hw.json b/advisories/unreviewed/2024/03/GHSA-4phr-gh22-r9hw/GHSA-4phr-gh22-r9hw.json index 7d36b9c5b13..c974d811bd1 100644 --- a/advisories/unreviewed/2024/03/GHSA-4phr-gh22-r9hw/GHSA-4phr-gh22-r9hw.json +++ b/advisories/unreviewed/2024/03/GHSA-4phr-gh22-r9hw/GHSA-4phr-gh22-r9hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4phr-gh22-r9hw", - "modified": "2024-03-13T00:31:21Z", + "modified": "2025-01-22T18:31:49Z", "published": "2024-03-13T00:31:21Z", "aliases": [ "CVE-2024-24101" ], "details": "Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T22:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5494-m8hp-j85p/GHSA-5494-m8hp-j85p.json b/advisories/unreviewed/2024/03/GHSA-5494-m8hp-j85p/GHSA-5494-m8hp-j85p.json index 01441435700..2ae763d60ab 100644 --- a/advisories/unreviewed/2024/03/GHSA-5494-m8hp-j85p/GHSA-5494-m8hp-j85p.json +++ b/advisories/unreviewed/2024/03/GHSA-5494-m8hp-j85p/GHSA-5494-m8hp-j85p.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-7766-vp76-r5pj/GHSA-7766-vp76-r5pj.json b/advisories/unreviewed/2024/03/GHSA-7766-vp76-r5pj/GHSA-7766-vp76-r5pj.json index 6f3298fdc9c..0ed015f0d1b 100644 --- a/advisories/unreviewed/2024/03/GHSA-7766-vp76-r5pj/GHSA-7766-vp76-r5pj.json +++ b/advisories/unreviewed/2024/03/GHSA-7766-vp76-r5pj/GHSA-7766-vp76-r5pj.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-8g82-8886-q7xh/GHSA-8g82-8886-q7xh.json b/advisories/unreviewed/2024/03/GHSA-8g82-8886-q7xh/GHSA-8g82-8886-q7xh.json index e6f374aeea8..0f0cac4402b 100644 --- a/advisories/unreviewed/2024/03/GHSA-8g82-8886-q7xh/GHSA-8g82-8886-q7xh.json +++ b/advisories/unreviewed/2024/03/GHSA-8g82-8886-q7xh/GHSA-8g82-8886-q7xh.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-c8h5-49j5-398q/GHSA-c8h5-49j5-398q.json b/advisories/unreviewed/2024/03/GHSA-c8h5-49j5-398q/GHSA-c8h5-49j5-398q.json index d915b29d702..8ca5572d00f 100644 --- a/advisories/unreviewed/2024/03/GHSA-c8h5-49j5-398q/GHSA-c8h5-49j5-398q.json +++ b/advisories/unreviewed/2024/03/GHSA-c8h5-49j5-398q/GHSA-c8h5-49j5-398q.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-c97h-q9gp-6xq2/GHSA-c97h-q9gp-6xq2.json b/advisories/unreviewed/2024/03/GHSA-c97h-q9gp-6xq2/GHSA-c97h-q9gp-6xq2.json index acf867a718c..51733c3936f 100644 --- a/advisories/unreviewed/2024/03/GHSA-c97h-q9gp-6xq2/GHSA-c97h-q9gp-6xq2.json +++ b/advisories/unreviewed/2024/03/GHSA-c97h-q9gp-6xq2/GHSA-c97h-q9gp-6xq2.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-chjp-q8w3-cj2w/GHSA-chjp-q8w3-cj2w.json b/advisories/unreviewed/2024/03/GHSA-chjp-q8w3-cj2w/GHSA-chjp-q8w3-cj2w.json index ee151edbb15..590889aa54f 100644 --- a/advisories/unreviewed/2024/03/GHSA-chjp-q8w3-cj2w/GHSA-chjp-q8w3-cj2w.json +++ b/advisories/unreviewed/2024/03/GHSA-chjp-q8w3-cj2w/GHSA-chjp-q8w3-cj2w.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-cpvw-pm4w-xwgm/GHSA-cpvw-pm4w-xwgm.json b/advisories/unreviewed/2024/03/GHSA-cpvw-pm4w-xwgm/GHSA-cpvw-pm4w-xwgm.json index 88a5b2c6e11..b0bbe4998fe 100644 --- a/advisories/unreviewed/2024/03/GHSA-cpvw-pm4w-xwgm/GHSA-cpvw-pm4w-xwgm.json +++ b/advisories/unreviewed/2024/03/GHSA-cpvw-pm4w-xwgm/GHSA-cpvw-pm4w-xwgm.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-fv6c-jjp9-hj5r/GHSA-fv6c-jjp9-hj5r.json b/advisories/unreviewed/2024/03/GHSA-fv6c-jjp9-hj5r/GHSA-fv6c-jjp9-hj5r.json index bb317d8a594..ebdd64e5929 100644 --- a/advisories/unreviewed/2024/03/GHSA-fv6c-jjp9-hj5r/GHSA-fv6c-jjp9-hj5r.json +++ b/advisories/unreviewed/2024/03/GHSA-fv6c-jjp9-hj5r/GHSA-fv6c-jjp9-hj5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv6c-jjp9-hj5r", - "modified": "2024-03-13T00:31:22Z", + "modified": "2025-01-22T18:31:49Z", "published": "2024-03-13T00:31:22Z", "aliases": [ "CVE-2024-1397" @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gjp2-jvrj-5pr5/GHSA-gjp2-jvrj-5pr5.json b/advisories/unreviewed/2024/03/GHSA-gjp2-jvrj-5pr5/GHSA-gjp2-jvrj-5pr5.json index 0a1fb51ea9d..279b9288443 100644 --- a/advisories/unreviewed/2024/03/GHSA-gjp2-jvrj-5pr5/GHSA-gjp2-jvrj-5pr5.json +++ b/advisories/unreviewed/2024/03/GHSA-gjp2-jvrj-5pr5/GHSA-gjp2-jvrj-5pr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjp2-jvrj-5pr5", - "modified": "2024-03-13T00:31:23Z", + "modified": "2025-01-22T18:31:49Z", "published": "2024-03-13T00:31:23Z", "aliases": [ "CVE-2024-1421" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hqfx-hf4r-r274/GHSA-hqfx-hf4r-r274.json b/advisories/unreviewed/2024/03/GHSA-hqfx-hf4r-r274/GHSA-hqfx-hf4r-r274.json index c0ea57749e1..1ac5e5a4a87 100644 --- a/advisories/unreviewed/2024/03/GHSA-hqfx-hf4r-r274/GHSA-hqfx-hf4r-r274.json +++ b/advisories/unreviewed/2024/03/GHSA-hqfx-hf4r-r274/GHSA-hqfx-hf4r-r274.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-jh55-qq58-48ph/GHSA-jh55-qq58-48ph.json b/advisories/unreviewed/2024/03/GHSA-jh55-qq58-48ph/GHSA-jh55-qq58-48ph.json index 044aa0dbc7b..c7c6034a8c9 100644 --- a/advisories/unreviewed/2024/03/GHSA-jh55-qq58-48ph/GHSA-jh55-qq58-48ph.json +++ b/advisories/unreviewed/2024/03/GHSA-jh55-qq58-48ph/GHSA-jh55-qq58-48ph.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json b/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json index cb74929b451..9305749b2ed 100644 --- a/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json +++ b/advisories/unreviewed/2024/03/GHSA-m22v-j3fw-2m27/GHSA-m22v-j3fw-2m27.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-pg9x-738h-qgq2/GHSA-pg9x-738h-qgq2.json b/advisories/unreviewed/2024/03/GHSA-pg9x-738h-qgq2/GHSA-pg9x-738h-qgq2.json index 6c4e9240387..efa25d2950d 100644 --- a/advisories/unreviewed/2024/03/GHSA-pg9x-738h-qgq2/GHSA-pg9x-738h-qgq2.json +++ b/advisories/unreviewed/2024/03/GHSA-pg9x-738h-qgq2/GHSA-pg9x-738h-qgq2.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-vp22-34fw-hj88/GHSA-vp22-34fw-hj88.json b/advisories/unreviewed/2024/03/GHSA-vp22-34fw-hj88/GHSA-vp22-34fw-hj88.json index 00d27c82c47..08d9c1f1749 100644 --- a/advisories/unreviewed/2024/03/GHSA-vp22-34fw-hj88/GHSA-vp22-34fw-hj88.json +++ b/advisories/unreviewed/2024/03/GHSA-vp22-34fw-hj88/GHSA-vp22-34fw-hj88.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-x4wm-g2rr-c6j2/GHSA-x4wm-g2rr-c6j2.json b/advisories/unreviewed/2024/03/GHSA-x4wm-g2rr-c6j2/GHSA-x4wm-g2rr-c6j2.json index 2f659c2d182..05d01d7067e 100644 --- a/advisories/unreviewed/2024/03/GHSA-x4wm-g2rr-c6j2/GHSA-x4wm-g2rr-c6j2.json +++ b/advisories/unreviewed/2024/03/GHSA-x4wm-g2rr-c6j2/GHSA-x4wm-g2rr-c6j2.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json b/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json index 3bf043d9ec8..18984bdba04 100644 --- a/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json +++ b/advisories/unreviewed/2024/04/GHSA-33g4-2m49-x49h/GHSA-33g4-2m49-x49h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33g4-2m49-x49h", - "modified": "2024-04-09T21:31:56Z", + "modified": "2025-01-22T18:31:50Z", "published": "2024-04-09T21:31:56Z", "aliases": [ "CVE-2023-6967" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json b/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json index cbc55ada8b8..7c9996c7dcd 100644 --- a/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json +++ b/advisories/unreviewed/2024/04/GHSA-4gm7-w93h-8x3c/GHSA-4gm7-w93h-8x3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gm7-w93h-8x3c", - "modified": "2024-04-09T21:31:59Z", + "modified": "2025-01-22T18:31:50Z", "published": "2024-04-09T21:31:59Z", "aliases": [ "CVE-2024-1974" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json b/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json index 2a9154fefa6..ca726d9ae11 100644 --- a/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json +++ b/advisories/unreviewed/2024/04/GHSA-4h68-4rgv-j269/GHSA-4h68-4rgv-j269.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h68-4rgv-j269", - "modified": "2024-04-09T21:31:56Z", + "modified": "2025-01-22T18:31:50Z", "published": "2024-04-09T21:31:56Z", "aliases": [ "CVE-2023-6965" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json b/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json index 60f6aa99f6f..0a72aef87cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json +++ b/advisories/unreviewed/2024/04/GHSA-55c4-h3q7-f6wp/GHSA-55c4-h3q7-f6wp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-401", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json b/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json index 6057f55c630..4fef0e4fd36 100644 --- a/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json +++ b/advisories/unreviewed/2024/04/GHSA-h28q-32f7-jxrv/GHSA-h28q-32f7-jxrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h28q-32f7-jxrv", - "modified": "2024-04-09T21:31:57Z", + "modified": "2025-01-22T18:31:50Z", "published": "2024-04-09T21:31:57Z", "aliases": [ "CVE-2024-1412" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2cvr-cjfw-9xmv/GHSA-2cvr-cjfw-9xmv.json b/advisories/unreviewed/2024/05/GHSA-2cvr-cjfw-9xmv/GHSA-2cvr-cjfw-9xmv.json index 3f2d81113ca..a16439f013d 100644 --- a/advisories/unreviewed/2024/05/GHSA-2cvr-cjfw-9xmv/GHSA-2cvr-cjfw-9xmv.json +++ b/advisories/unreviewed/2024/05/GHSA-2cvr-cjfw-9xmv/GHSA-2cvr-cjfw-9xmv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json b/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json index 014d5b3a684..d8c93df8541 100644 --- a/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json +++ b/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36cp-x9pq-r87w", - "modified": "2024-05-14T18:31:05Z", + "modified": "2025-01-22T18:31:51Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4774" ], "details": "The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-482j-rhmj-w9w6/GHSA-482j-rhmj-w9w6.json b/advisories/unreviewed/2024/05/GHSA-482j-rhmj-w9w6/GHSA-482j-rhmj-w9w6.json index 582a9e9f3fa..d0aa22be921 100644 --- a/advisories/unreviewed/2024/05/GHSA-482j-rhmj-w9w6/GHSA-482j-rhmj-w9w6.json +++ b/advisories/unreviewed/2024/05/GHSA-482j-rhmj-w9w6/GHSA-482j-rhmj-w9w6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-482j-rhmj-w9w6", - "modified": "2024-05-16T12:30:21Z", + "modified": "2025-01-22T18:31:51Z", "published": "2024-05-16T12:30:21Z", "aliases": [ "CVE-2024-4352" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q4ff-pq82-jv6g/GHSA-q4ff-pq82-jv6g.json b/advisories/unreviewed/2024/05/GHSA-q4ff-pq82-jv6g/GHSA-q4ff-pq82-jv6g.json index 3dcd580950b..d4d7ef03ffe 100644 --- a/advisories/unreviewed/2024/05/GHSA-q4ff-pq82-jv6g/GHSA-q4ff-pq82-jv6g.json +++ b/advisories/unreviewed/2024/05/GHSA-q4ff-pq82-jv6g/GHSA-q4ff-pq82-jv6g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qchj-32cr-96w5/GHSA-qchj-32cr-96w5.json b/advisories/unreviewed/2024/05/GHSA-qchj-32cr-96w5/GHSA-qchj-32cr-96w5.json index ff837535273..5bfd1e88d92 100644 --- a/advisories/unreviewed/2024/05/GHSA-qchj-32cr-96w5/GHSA-qchj-32cr-96w5.json +++ b/advisories/unreviewed/2024/05/GHSA-qchj-32cr-96w5/GHSA-qchj-32cr-96w5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qchj-32cr-96w5", - "modified": "2024-06-10T18:31:01Z", + "modified": "2025-01-22T18:31:51Z", "published": "2024-05-14T18:31:06Z", "aliases": [ "CVE-2024-4777" ], "details": "Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:16Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3r23-64c4-mj87/GHSA-3r23-64c4-mj87.json b/advisories/unreviewed/2024/08/GHSA-3r23-64c4-mj87/GHSA-3r23-64c4-mj87.json index 1c022e72fe4..6a1f44ceca9 100644 --- a/advisories/unreviewed/2024/08/GHSA-3r23-64c4-mj87/GHSA-3r23-64c4-mj87.json +++ b/advisories/unreviewed/2024/08/GHSA-3r23-64c4-mj87/GHSA-3r23-64c4-mj87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r23-64c4-mj87", - "modified": "2024-08-20T21:30:31Z", + "modified": "2025-01-22T18:31:52Z", "published": "2024-08-14T15:31:19Z", "aliases": [ "CVE-2024-7347" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://my.f5.com/manage/s/article/K000140529" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/08/14/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-j7r2-qxwx-hpfm/GHSA-j7r2-qxwx-hpfm.json b/advisories/unreviewed/2024/10/GHSA-j7r2-qxwx-hpfm/GHSA-j7r2-qxwx-hpfm.json index 80da0aaf9fb..5c4498b44b8 100644 --- a/advisories/unreviewed/2024/10/GHSA-j7r2-qxwx-hpfm/GHSA-j7r2-qxwx-hpfm.json +++ b/advisories/unreviewed/2024/10/GHSA-j7r2-qxwx-hpfm/GHSA-j7r2-qxwx-hpfm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json b/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json index 0990efef5f0..d63bc2bec2f 100644 --- a/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json +++ b/advisories/unreviewed/2024/12/GHSA-xvwr-jcvg-47ph/GHSA-xvwr-jcvg-47ph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvwr-jcvg-47ph", - "modified": "2024-12-06T15:31:20Z", + "modified": "2025-01-22T18:31:52Z", "published": "2024-12-06T15:31:20Z", "aliases": [ "CVE-2024-53808" diff --git a/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json b/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json index 330f0ab4a49..b8720829e0d 100644 --- a/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json +++ b/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-25qq-8gc4-fhg4", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49735" ], "details": "In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json b/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json index 5a7932c8924..975aa60b80d 100644 --- a/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json +++ b/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-26h2-xpj3-3r9v", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-22T18:31:53Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57161" ], "details": "07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T16:15:32Z" diff --git a/advisories/unreviewed/2025/01/GHSA-29pr-qcmc-49q6/GHSA-29pr-qcmc-49q6.json b/advisories/unreviewed/2025/01/GHSA-29pr-qcmc-49q6/GHSA-29pr-qcmc-49q6.json index 5dd35fabbeb..f7f90eb1931 100644 --- a/advisories/unreviewed/2025/01/GHSA-29pr-qcmc-49q6/GHSA-29pr-qcmc-49q6.json +++ b/advisories/unreviewed/2025/01/GHSA-29pr-qcmc-49q6/GHSA-29pr-qcmc-49q6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-29pr-qcmc-49q6", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-34730" ], "details": "In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json b/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json index acb173f2f5f..ff3f45abf67 100644 --- a/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json +++ b/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gqx-rmcg-8rp8", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2023-40108" ], "details": "In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2gwp-84r9-4mgj/GHSA-2gwp-84r9-4mgj.json b/advisories/unreviewed/2025/01/GHSA-2gwp-84r9-4mgj/GHSA-2gwp-84r9-4mgj.json index e3ce0b6d0a9..99c6cc006ef 100644 --- a/advisories/unreviewed/2025/01/GHSA-2gwp-84r9-4mgj/GHSA-2gwp-84r9-4mgj.json +++ b/advisories/unreviewed/2025/01/GHSA-2gwp-84r9-4mgj/GHSA-2gwp-84r9-4mgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gwp-84r9-4mgj", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49734" ], "details": "In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2x48-7h28-gfqr/GHSA-2x48-7h28-gfqr.json b/advisories/unreviewed/2025/01/GHSA-2x48-7h28-gfqr/GHSA-2x48-7h28-gfqr.json index 1d5334bc734..92e72866821 100644 --- a/advisories/unreviewed/2025/01/GHSA-2x48-7h28-gfqr/GHSA-2x48-7h28-gfqr.json +++ b/advisories/unreviewed/2025/01/GHSA-2x48-7h28-gfqr/GHSA-2x48-7h28-gfqr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2x48-7h28-gfqr", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-43095" ], "details": "In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json b/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json index df7bb4a085b..e4491f81465 100644 --- a/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json +++ b/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fr5-hr7q-wjm9", - "modified": "2025-01-22T15:32:36Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T15:32:36Z", "aliases": [ "CVE-2025-23697" diff --git a/advisories/unreviewed/2025/01/GHSA-4fxh-5h9v-cw8q/GHSA-4fxh-5h9v-cw8q.json b/advisories/unreviewed/2025/01/GHSA-4fxh-5h9v-cw8q/GHSA-4fxh-5h9v-cw8q.json index 683c903a375..89b3fd043a8 100644 --- a/advisories/unreviewed/2025/01/GHSA-4fxh-5h9v-cw8q/GHSA-4fxh-5h9v-cw8q.json +++ b/advisories/unreviewed/2025/01/GHSA-4fxh-5h9v-cw8q/GHSA-4fxh-5h9v-cw8q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-4r8j-mw5f-9g2j/GHSA-4r8j-mw5f-9g2j.json b/advisories/unreviewed/2025/01/GHSA-4r8j-mw5f-9g2j/GHSA-4r8j-mw5f-9g2j.json new file mode 100644 index 00000000000..fcb88f7750d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4r8j-mw5f-9g2j/GHSA-4r8j-mw5f-9g2j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r8j-mw5f-9g2j", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2023-37777" + ], + "details": "Synnefo Internet Management Software 2023 was discovered to contain a SQL injection vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37777" + }, + { + "type": "WEB", + "url": "https://infosecwriteups.com/how-i-discovered-a-critical-vulnerability-in-an-internet-service-providers-software-56c6cc00f338" + }, + { + "type": "WEB", + "url": "https://synnefoims.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json index 7774fda1a9c..6360b1a42c9 100644 --- a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json +++ b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xpw-6594-8f5m", - "modified": "2025-01-22T15:32:34Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2025-0395" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001" + }, + { + "type": "WEB", + "url": "https://sourceware.org/pipermail/libc-announce/2025/000044.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2025/01/22/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-54pj-vxrg-8r9x/GHSA-54pj-vxrg-8r9x.json b/advisories/unreviewed/2025/01/GHSA-54pj-vxrg-8r9x/GHSA-54pj-vxrg-8r9x.json index db36e9ea556..bfe3fc19dee 100644 --- a/advisories/unreviewed/2025/01/GHSA-54pj-vxrg-8r9x/GHSA-54pj-vxrg-8r9x.json +++ b/advisories/unreviewed/2025/01/GHSA-54pj-vxrg-8r9x/GHSA-54pj-vxrg-8r9x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-54pj-vxrg-8r9x", - "modified": "2025-01-16T21:31:02Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-16T21:31:02Z", "aliases": [ "CVE-2024-57583" ], "details": "Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T21:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-572q-86rr-5vgq/GHSA-572q-86rr-5vgq.json b/advisories/unreviewed/2025/01/GHSA-572q-86rr-5vgq/GHSA-572q-86rr-5vgq.json new file mode 100644 index 00000000000..f8be3fcf944 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-572q-86rr-5vgq/GHSA-572q-86rr-5vgq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-572q-86rr-5vgq", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2024-55488" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55488" + }, + { + "type": "WEB", + "url": "https://www.nccgroup.com/us/research-blog/technical-advisory-cross-site-scripting-in-umbraco-rich-text-display" + }, + { + "type": "WEB", + "url": "http://umbraco.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-597x-9gj9-7q4x/GHSA-597x-9gj9-7q4x.json b/advisories/unreviewed/2025/01/GHSA-597x-9gj9-7q4x/GHSA-597x-9gj9-7q4x.json new file mode 100644 index 00000000000..d9aa4f6f8c2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-597x-9gj9-7q4x/GHSA-597x-9gj9-7q4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-597x-9gj9-7q4x", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-0638" + ], + "details": "The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0638" + }, + { + "type": "WEB", + "url": "https://www.nlnetlabs.nl/downloads/routinator/CVE-2025-0638.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json b/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json index 1d83bcdcfd1..1de44704848 100644 --- a/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json +++ b/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json b/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json index 451745638b8..0d7c38f0b10 100644 --- a/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json +++ b/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5rjv-47jf-7h66", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-43763" ], "details": "In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json b/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json new file mode 100644 index 00000000000..93c03c50d73 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xmq-mwgg-pjp2", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2024-24429" + ], + "details": "A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24429" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6j5q-p9xp-3cc6/GHSA-6j5q-p9xp-3cc6.json b/advisories/unreviewed/2025/01/GHSA-6j5q-p9xp-3cc6/GHSA-6j5q-p9xp-3cc6.json new file mode 100644 index 00000000000..b66e2b5142c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6j5q-p9xp-3cc6/GHSA-6j5q-p9xp-3cc6.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j5q-p9xp-3cc6", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-20128" + ], + "details": "A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\n\nThis vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.\nFor a description of this vulnerability, see the .\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20128" + }, + { + "type": "WEB", + "url": "https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120", + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json b/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json index c9ed2205fb2..fe5ba6ac7af 100644 --- a/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json +++ b/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6xh4-6995-ppc6", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-43765" ], "details": "In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1021" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-748w-f5ch-qpr7/GHSA-748w-f5ch-qpr7.json b/advisories/unreviewed/2025/01/GHSA-748w-f5ch-qpr7/GHSA-748w-f5ch-qpr7.json index 6368b466ade..a328caeaf65 100644 --- a/advisories/unreviewed/2025/01/GHSA-748w-f5ch-qpr7/GHSA-748w-f5ch-qpr7.json +++ b/advisories/unreviewed/2025/01/GHSA-748w-f5ch-qpr7/GHSA-748w-f5ch-qpr7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-76jr-jjjp-x84r/GHSA-76jr-jjjp-x84r.json b/advisories/unreviewed/2025/01/GHSA-76jr-jjjp-x84r/GHSA-76jr-jjjp-x84r.json index 81ab61b9af4..00da3c11147 100644 --- a/advisories/unreviewed/2025/01/GHSA-76jr-jjjp-x84r/GHSA-76jr-jjjp-x84r.json +++ b/advisories/unreviewed/2025/01/GHSA-76jr-jjjp-x84r/GHSA-76jr-jjjp-x84r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-7qcq-8wf4-8jh5/GHSA-7qcq-8wf4-8jh5.json b/advisories/unreviewed/2025/01/GHSA-7qcq-8wf4-8jh5/GHSA-7qcq-8wf4-8jh5.json index 0c6fc128152..d13031f8d58 100644 --- a/advisories/unreviewed/2025/01/GHSA-7qcq-8wf4-8jh5/GHSA-7qcq-8wf4-8jh5.json +++ b/advisories/unreviewed/2025/01/GHSA-7qcq-8wf4-8jh5/GHSA-7qcq-8wf4-8jh5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-828p-x24m-mvw6/GHSA-828p-x24m-mvw6.json b/advisories/unreviewed/2025/01/GHSA-828p-x24m-mvw6/GHSA-828p-x24m-mvw6.json new file mode 100644 index 00000000000..32ed7889992 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-828p-x24m-mvw6/GHSA-828p-x24m-mvw6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-828p-x24m-mvw6", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2024-42012" + ], + "details": "GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's Blocky password and from there impersonate that local user.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42012" + }, + { + "type": "WEB", + "url": "https://www.blockyforveeam.com/en/security-bulletin-2024-06-25" + }, + { + "type": "WEB", + "url": "https://www.graudata.com/en/products/protection-against-ransomware/blocky-for-veeam" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8m34-ghfg-xxc2/GHSA-8m34-ghfg-xxc2.json b/advisories/unreviewed/2025/01/GHSA-8m34-ghfg-xxc2/GHSA-8m34-ghfg-xxc2.json new file mode 100644 index 00000000000..b2c8a464d60 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8m34-ghfg-xxc2/GHSA-8m34-ghfg-xxc2.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m34-ghfg-xxc2", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-20156" + ], + "details": "A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device.\n\nThis vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20156" + }, + { + "type": "WEB", + "url": "https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-274", + "CWE-276" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-969g-rq57-c79h/GHSA-969g-rq57-c79h.json b/advisories/unreviewed/2025/01/GHSA-969g-rq57-c79h/GHSA-969g-rq57-c79h.json new file mode 100644 index 00000000000..8ba06fe4352 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-969g-rq57-c79h/GHSA-969g-rq57-c79h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-969g-rq57-c79h", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:56Z", + "aliases": [ + "CVE-2025-24401" + ], + "details": "Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24401" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3062" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json b/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json index 1b49065c028..272dee85a75 100644 --- a/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json +++ b/advisories/unreviewed/2025/01/GHSA-96qq-4jq4-p5hw/GHSA-96qq-4jq4-p5hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96qq-4jq4-p5hw", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-49733" ], "details": "In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-96xr-637g-3x8c/GHSA-96xr-637g-3x8c.json b/advisories/unreviewed/2025/01/GHSA-96xr-637g-3x8c/GHSA-96xr-637g-3x8c.json new file mode 100644 index 00000000000..77e62787bbb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-96xr-637g-3x8c/GHSA-96xr-637g-3x8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96xr-637g-3x8c", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2024-31903" + ], + "details": "IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31903" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7172233" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9g4q-mq35-ffg3/GHSA-9g4q-mq35-ffg3.json b/advisories/unreviewed/2025/01/GHSA-9g4q-mq35-ffg3/GHSA-9g4q-mq35-ffg3.json new file mode 100644 index 00000000000..62c3d25403c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9g4q-mq35-ffg3/GHSA-9g4q-mq35-ffg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g4q-mq35-ffg3", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:56Z", + "aliases": [ + "CVE-2025-0651" + ], + "details": "Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.\n\nUser with a low system privileges  can create a set of symlinks inside the C:\\ProgramData\\Cloudflare\\warp-diag-partials folder. After triggering the 'Reset all settings\" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user.\nThis issue affects WARP: before 2024.12.492.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:U/V:X/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0651" + }, + { + "type": "WEB", + "url": "https://developers.cloudflare.com/warp-client" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c6cm-6jvv-fff6/GHSA-c6cm-6jvv-fff6.json b/advisories/unreviewed/2025/01/GHSA-c6cm-6jvv-fff6/GHSA-c6cm-6jvv-fff6.json index 140385e0c65..80c38f2610e 100644 --- a/advisories/unreviewed/2025/01/GHSA-c6cm-6jvv-fff6/GHSA-c6cm-6jvv-fff6.json +++ b/advisories/unreviewed/2025/01/GHSA-c6cm-6jvv-fff6/GHSA-c6cm-6jvv-fff6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c6cm-6jvv-fff6", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57775" ], "details": "JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cw79-pg42-cfvq/GHSA-cw79-pg42-cfvq.json b/advisories/unreviewed/2025/01/GHSA-cw79-pg42-cfvq/GHSA-cw79-pg42-cfvq.json index 9fc3829e383..01211f67e18 100644 --- a/advisories/unreviewed/2025/01/GHSA-cw79-pg42-cfvq/GHSA-cw79-pg42-cfvq.json +++ b/advisories/unreviewed/2025/01/GHSA-cw79-pg42-cfvq/GHSA-cw79-pg42-cfvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cw79-pg42-cfvq", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-43096" ], "details": "In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f49h-cqg6-cgcc/GHSA-f49h-cqg6-cgcc.json b/advisories/unreviewed/2025/01/GHSA-f49h-cqg6-cgcc/GHSA-f49h-cqg6-cgcc.json new file mode 100644 index 00000000000..daf3c6bae45 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f49h-cqg6-cgcc/GHSA-f49h-cqg6-cgcc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f49h-cqg6-cgcc", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2024-42013" + ], + "details": "In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows administrative or debugging privileges can patch a binary in memory or on disk to bypass the password login requirement and gain full access to all functions of the program.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42013" + }, + { + "type": "WEB", + "url": "https://www.blockyforveeam.com/en/security-bulletin-2024-06-25" + }, + { + "type": "WEB", + "url": "https://www.graudata.com/en/products/protection-against-ransomware/blocky-for-veeam" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fcgm-cf56-frhw/GHSA-fcgm-cf56-frhw.json b/advisories/unreviewed/2025/01/GHSA-fcgm-cf56-frhw/GHSA-fcgm-cf56-frhw.json index 2a834de4c52..510a45c1a77 100644 --- a/advisories/unreviewed/2025/01/GHSA-fcgm-cf56-frhw/GHSA-fcgm-cf56-frhw.json +++ b/advisories/unreviewed/2025/01/GHSA-fcgm-cf56-frhw/GHSA-fcgm-cf56-frhw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fcgm-cf56-frhw", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-49732" ], "details": "In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fmr8-mp5m-r98h/GHSA-fmr8-mp5m-r98h.json b/advisories/unreviewed/2025/01/GHSA-fmr8-mp5m-r98h/GHSA-fmr8-mp5m-r98h.json index 74ac798af52..388548e18d1 100644 --- a/advisories/unreviewed/2025/01/GHSA-fmr8-mp5m-r98h/GHSA-fmr8-mp5m-r98h.json +++ b/advisories/unreviewed/2025/01/GHSA-fmr8-mp5m-r98h/GHSA-fmr8-mp5m-r98h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fpw7-8gjc-jwqj/GHSA-fpw7-8gjc-jwqj.json b/advisories/unreviewed/2025/01/GHSA-fpw7-8gjc-jwqj/GHSA-fpw7-8gjc-jwqj.json new file mode 100644 index 00000000000..e8f033cc0d8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fpw7-8gjc-jwqj/GHSA-fpw7-8gjc-jwqj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpw7-8gjc-jwqj", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-24400" + ], + "details": "Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24400" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3485" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json b/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json index 65a06b2559d..00ff89405ee 100644 --- a/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json +++ b/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fq6x-64vf-73q4", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-43770" ], "details": "In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gp8p-49gr-jv8j/GHSA-gp8p-49gr-jv8j.json b/advisories/unreviewed/2025/01/GHSA-gp8p-49gr-jv8j/GHSA-gp8p-49gr-jv8j.json new file mode 100644 index 00000000000..e3afd38a07d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gp8p-49gr-jv8j/GHSA-gp8p-49gr-jv8j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp8p-49gr-jv8j", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:56Z", + "aliases": [ + "CVE-2025-24403" + ], + "details": "A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24403" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3094" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json b/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json index 1d9e9237d57..b13eec2fc85 100644 --- a/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json +++ b/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-gxvq-f5q4-6g92/GHSA-gxvq-f5q4-6g92.json b/advisories/unreviewed/2025/01/GHSA-gxvq-f5q4-6g92/GHSA-gxvq-f5q4-6g92.json new file mode 100644 index 00000000000..fc4d16dc4d1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gxvq-f5q4-6g92/GHSA-gxvq-f5q4-6g92.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxvq-f5q4-6g92", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-20165" + ], + "details": "A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition.\n\nThis vulnerability is due to improper memory handling for certain SIP requests. An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system. A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20165" + }, + { + "type": "WEB", + "url": "https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-sip-dos-mSySbrmt" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476", + "CWE-789" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h79v-x5rx-hc8c/GHSA-h79v-x5rx-hc8c.json b/advisories/unreviewed/2025/01/GHSA-h79v-x5rx-hc8c/GHSA-h79v-x5rx-hc8c.json index bfd002058b3..146c04ce87d 100644 --- a/advisories/unreviewed/2025/01/GHSA-h79v-x5rx-hc8c/GHSA-h79v-x5rx-hc8c.json +++ b/advisories/unreviewed/2025/01/GHSA-h79v-x5rx-hc8c/GHSA-h79v-x5rx-hc8c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h79v-x5rx-hc8c", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57770" ], "details": "JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hqhr-2wm6-h7fv/GHSA-hqhr-2wm6-h7fv.json b/advisories/unreviewed/2025/01/GHSA-hqhr-2wm6-h7fv/GHSA-hqhr-2wm6-h7fv.json index 9079326891f..c3fe466d1de 100644 --- a/advisories/unreviewed/2025/01/GHSA-hqhr-2wm6-h7fv/GHSA-hqhr-2wm6-h7fv.json +++ b/advisories/unreviewed/2025/01/GHSA-hqhr-2wm6-h7fv/GHSA-hqhr-2wm6-h7fv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hqhr-2wm6-h7fv", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57769" ], "details": "JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j67w-4gh2-w3jq/GHSA-j67w-4gh2-w3jq.json b/advisories/unreviewed/2025/01/GHSA-j67w-4gh2-w3jq/GHSA-j67w-4gh2-w3jq.json index 4d7ed4676e2..e6f799ecdf7 100644 --- a/advisories/unreviewed/2025/01/GHSA-j67w-4gh2-w3jq/GHSA-j67w-4gh2-w3jq.json +++ b/advisories/unreviewed/2025/01/GHSA-j67w-4gh2-w3jq/GHSA-j67w-4gh2-w3jq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j67w-4gh2-w3jq", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2023-40132" ], "details": "In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jh93-vvqf-mfqc/GHSA-jh93-vvqf-mfqc.json b/advisories/unreviewed/2025/01/GHSA-jh93-vvqf-mfqc/GHSA-jh93-vvqf-mfqc.json index 04149a5d173..7f895c7fbb5 100644 --- a/advisories/unreviewed/2025/01/GHSA-jh93-vvqf-mfqc/GHSA-jh93-vvqf-mfqc.json +++ b/advisories/unreviewed/2025/01/GHSA-jh93-vvqf-mfqc/GHSA-jh93-vvqf-mfqc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-mjmq-wqpg-89pr/GHSA-mjmq-wqpg-89pr.json b/advisories/unreviewed/2025/01/GHSA-mjmq-wqpg-89pr/GHSA-mjmq-wqpg-89pr.json index b86987f531e..9fd08daf45f 100644 --- a/advisories/unreviewed/2025/01/GHSA-mjmq-wqpg-89pr/GHSA-mjmq-wqpg-89pr.json +++ b/advisories/unreviewed/2025/01/GHSA-mjmq-wqpg-89pr/GHSA-mjmq-wqpg-89pr.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-p6rw-52m8-833j/GHSA-p6rw-52m8-833j.json b/advisories/unreviewed/2025/01/GHSA-p6rw-52m8-833j/GHSA-p6rw-52m8-833j.json index 868ffa29495..554262ab9b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-p6rw-52m8-833j/GHSA-p6rw-52m8-833j.json +++ b/advisories/unreviewed/2025/01/GHSA-p6rw-52m8-833j/GHSA-p6rw-52m8-833j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-281" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-ppw6-g989-268j/GHSA-ppw6-g989-268j.json b/advisories/unreviewed/2025/01/GHSA-ppw6-g989-268j/GHSA-ppw6-g989-268j.json index 9cf4bfa231f..7bda08c9852 100644 --- a/advisories/unreviewed/2025/01/GHSA-ppw6-g989-268j/GHSA-ppw6-g989-268j.json +++ b/advisories/unreviewed/2025/01/GHSA-ppw6-g989-268j/GHSA-ppw6-g989-268j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json b/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json new file mode 100644 index 00000000000..da460e57cde --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8x5-7v94-rwpv", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2024-10929" + ], + "details": "In certain circumstances, an issue in Arm Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10929" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Spectre-BSE" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q9cm-88jx-3vfw/GHSA-q9cm-88jx-3vfw.json b/advisories/unreviewed/2025/01/GHSA-q9cm-88jx-3vfw/GHSA-q9cm-88jx-3vfw.json new file mode 100644 index 00000000000..bca59dd313a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q9cm-88jx-3vfw/GHSA-q9cm-88jx-3vfw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9cm-88jx-3vfw", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-24399" + ], + "details": "Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24399" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3461" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qjw6-xvrm-5f2h/GHSA-qjw6-xvrm-5f2h.json b/advisories/unreviewed/2025/01/GHSA-qjw6-xvrm-5f2h/GHSA-qjw6-xvrm-5f2h.json new file mode 100644 index 00000000000..98aaac6789c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qjw6-xvrm-5f2h/GHSA-qjw6-xvrm-5f2h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjw6-xvrm-5f2h", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-24398" + ], + "details": "Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24398" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3434" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rx38-xc89-vgrj/GHSA-rx38-xc89-vgrj.json b/advisories/unreviewed/2025/01/GHSA-rx38-xc89-vgrj/GHSA-rx38-xc89-vgrj.json new file mode 100644 index 00000000000..954161654eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rx38-xc89-vgrj/GHSA-rx38-xc89-vgrj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx38-xc89-vgrj", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-23809" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Blue Wrench Video Widget allows Reflected XSS. This issue affects Blue Wrench Video Widget: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23809" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blue-wrench-videos-widget/vulnerability/wordpress-blue-wrench-video-widget-plugin-2-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json b/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json index e4df5f407b2..0e8eb1bdad7 100644 --- a/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json +++ b/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v4mm-j7r5-wxq4", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-43771" ], "details": "In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json b/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json index 841bab3d18f..4a874ce0b14 100644 --- a/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json +++ b/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-vc42-8hvr-72r6/GHSA-vc42-8hvr-72r6.json b/advisories/unreviewed/2025/01/GHSA-vc42-8hvr-72r6/GHSA-vc42-8hvr-72r6.json index 4d6f5fef818..a3aec336267 100644 --- a/advisories/unreviewed/2025/01/GHSA-vc42-8hvr-72r6/GHSA-vc42-8hvr-72r6.json +++ b/advisories/unreviewed/2025/01/GHSA-vc42-8hvr-72r6/GHSA-vc42-8hvr-72r6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vc42-8hvr-72r6", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-22T18:31:53Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57160" ], "details": "07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T16:15:32Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vcg8-v453-837w/GHSA-vcg8-v453-837w.json b/advisories/unreviewed/2025/01/GHSA-vcg8-v453-837w/GHSA-vcg8-v453-837w.json index 99f5675e3d4..6f8909c1bc0 100644 --- a/advisories/unreviewed/2025/01/GHSA-vcg8-v453-837w/GHSA-vcg8-v453-837w.json +++ b/advisories/unreviewed/2025/01/GHSA-vcg8-v453-837w/GHSA-vcg8-v453-837w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vcg8-v453-837w", - "modified": "2025-01-16T21:31:02Z", + "modified": "2025-01-22T18:31:54Z", "published": "2025-01-16T21:31:02Z", "aliases": [ "CVE-2024-57575" ], "details": "Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T21:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wcg3-v8j6-c8gg/GHSA-wcg3-v8j6-c8gg.json b/advisories/unreviewed/2025/01/GHSA-wcg3-v8j6-c8gg/GHSA-wcg3-v8j6-c8gg.json index 6dd08660198..cc2134e09e1 100644 --- a/advisories/unreviewed/2025/01/GHSA-wcg3-v8j6-c8gg/GHSA-wcg3-v8j6-c8gg.json +++ b/advisories/unreviewed/2025/01/GHSA-wcg3-v8j6-c8gg/GHSA-wcg3-v8j6-c8gg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-wf83-p2hm-5f3v/GHSA-wf83-p2hm-5f3v.json b/advisories/unreviewed/2025/01/GHSA-wf83-p2hm-5f3v/GHSA-wf83-p2hm-5f3v.json index a11f3fbdc55..05bfdc9c69e 100644 --- a/advisories/unreviewed/2025/01/GHSA-wf83-p2hm-5f3v/GHSA-wf83-p2hm-5f3v.json +++ b/advisories/unreviewed/2025/01/GHSA-wf83-p2hm-5f3v/GHSA-wf83-p2hm-5f3v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wf83-p2hm-5f3v", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T18:31:55Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2024-49724" ], "details": "In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wh3h-j8wp-6p42/GHSA-wh3h-j8wp-6p42.json b/advisories/unreviewed/2025/01/GHSA-wh3h-j8wp-6p42/GHSA-wh3h-j8wp-6p42.json new file mode 100644 index 00000000000..a799a096b61 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wh3h-j8wp-6p42/GHSA-wh3h-j8wp-6p42.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh3h-j8wp-6p42", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:56Z", + "aliases": [ + "CVE-2025-24402" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24402" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3094" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x2gh-m7mc-2xf3/GHSA-x2gh-m7mc-2xf3.json b/advisories/unreviewed/2025/01/GHSA-x2gh-m7mc-2xf3/GHSA-x2gh-m7mc-2xf3.json new file mode 100644 index 00000000000..eb75b3cee28 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x2gh-m7mc-2xf3/GHSA-x2gh-m7mc-2xf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2gh-m7mc-2xf3", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-23914" + ], + "details": "Deserialization of Untrusted Data vulnerability in NotFound Muzaara Google Ads Report allows Object Injection. This issue affects Muzaara Google Ads Report: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23914" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/muzaara-adwords-optimize-dashboard/vulnerability/wordpress-muzaara-google-ads-report-plugin-3-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xhgq-h98j-859v/GHSA-xhgq-h98j-859v.json b/advisories/unreviewed/2025/01/GHSA-xhgq-h98j-859v/GHSA-xhgq-h98j-859v.json new file mode 100644 index 00000000000..532d38244d0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xhgq-h98j-859v/GHSA-xhgq-h98j-859v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhgq-h98j-859v", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-24397" + ], + "details": "An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24397" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-01-22/#SECURITY-3260" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xr87-g5hr-3m8h/GHSA-xr87-g5hr-3m8h.json b/advisories/unreviewed/2025/01/GHSA-xr87-g5hr-3m8h/GHSA-xr87-g5hr-3m8h.json new file mode 100644 index 00000000000..b6d5eb72491 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xr87-g5hr-3m8h/GHSA-xr87-g5hr-3m8h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr87-g5hr-3m8h", + "modified": "2025-01-22T18:31:56Z", + "published": "2025-01-22T18:31:56Z", + "aliases": [ + "CVE-2024-55957" + ], + "details": "In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55957" + }, + { + "type": "WEB", + "url": "https://assets.thermofisher.com/TFS-Assets/CORP/Product-Guides/Thermo_Scientific_Xcalibur_and_Foundation.pdf" + }, + { + "type": "WEB", + "url": "https://thermofisher.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xrv6-3vg3-5pm7/GHSA-xrv6-3vg3-5pm7.json b/advisories/unreviewed/2025/01/GHSA-xrv6-3vg3-5pm7/GHSA-xrv6-3vg3-5pm7.json new file mode 100644 index 00000000000..d3a4c76b827 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xrv6-3vg3-5pm7/GHSA-xrv6-3vg3-5pm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrv6-3vg3-5pm7", + "modified": "2025-01-22T18:31:55Z", + "published": "2025-01-22T18:31:55Z", + "aliases": [ + "CVE-2025-23992" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leetoo Toocheke Companion allows Stored XSS. This issue affects Toocheke Companion: from n/a through 1.166.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23992" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/toocheke-companion/vulnerability/wordpress-toocheke-companion-plugin-1-166-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T16:15:32Z" + } +} \ No newline at end of file