diff --git a/advisories/unreviewed/2022/11/GHSA-m7qp-53cf-v2wx/GHSA-m7qp-53cf-v2wx.json b/advisories/unreviewed/2022/11/GHSA-m7qp-53cf-v2wx/GHSA-m7qp-53cf-v2wx.json index 2df82e3aa0d..cf932271298 100644 --- a/advisories/unreviewed/2022/11/GHSA-m7qp-53cf-v2wx/GHSA-m7qp-53cf-v2wx.json +++ b/advisories/unreviewed/2022/11/GHSA-m7qp-53cf-v2wx/GHSA-m7qp-53cf-v2wx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-qwqp-jrw4-2x86/GHSA-qwqp-jrw4-2x86.json b/advisories/unreviewed/2022/11/GHSA-qwqp-jrw4-2x86/GHSA-qwqp-jrw4-2x86.json index f3bc99fbf12..a31421bf43a 100644 --- a/advisories/unreviewed/2022/11/GHSA-qwqp-jrw4-2x86/GHSA-qwqp-jrw4-2x86.json +++ b/advisories/unreviewed/2022/11/GHSA-qwqp-jrw4-2x86/GHSA-qwqp-jrw4-2x86.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-755" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-76vv-65xc-fv9q/GHSA-76vv-65xc-fv9q.json b/advisories/unreviewed/2023/04/GHSA-76vv-65xc-fv9q/GHSA-76vv-65xc-fv9q.json index bc1b67fada7..46c2e430d0b 100644 --- a/advisories/unreviewed/2023/04/GHSA-76vv-65xc-fv9q/GHSA-76vv-65xc-fv9q.json +++ b/advisories/unreviewed/2023/04/GHSA-76vv-65xc-fv9q/GHSA-76vv-65xc-fv9q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json b/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json index b854548269a..dbb50bbe369 100644 --- a/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json +++ b/advisories/unreviewed/2023/04/GHSA-89h6-2239-3vw2/GHSA-89h6-2239-3vw2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-8vh6-crr8-5pf8/GHSA-8vh6-crr8-5pf8.json b/advisories/unreviewed/2023/04/GHSA-8vh6-crr8-5pf8/GHSA-8vh6-crr8-5pf8.json index 66bf2d4f008..73236b753c3 100644 --- a/advisories/unreviewed/2023/04/GHSA-8vh6-crr8-5pf8/GHSA-8vh6-crr8-5pf8.json +++ b/advisories/unreviewed/2023/04/GHSA-8vh6-crr8-5pf8/GHSA-8vh6-crr8-5pf8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-j5wq-fj8p-rh45/GHSA-j5wq-fj8p-rh45.json b/advisories/unreviewed/2023/04/GHSA-j5wq-fj8p-rh45/GHSA-j5wq-fj8p-rh45.json index dbb28eb532c..6b398e8e2c3 100644 --- a/advisories/unreviewed/2023/04/GHSA-j5wq-fj8p-rh45/GHSA-j5wq-fj8p-rh45.json +++ b/advisories/unreviewed/2023/04/GHSA-j5wq-fj8p-rh45/GHSA-j5wq-fj8p-rh45.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j5wq-fj8p-rh45", - "modified": "2024-04-04T03:35:00Z", + "modified": "2025-02-05T18:34:34Z", "published": "2023-04-19T09:30:17Z", "aliases": [ "CVE-2023-25619" ], - "details": "\nA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that\ncould cause denial of service of the controller when communicating over the Modbus TCP\nprotocol. \n\n", + "details": "A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that\ncould cause denial of service of the controller when communicating over the Modbus TCP\nprotocol.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json b/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json index eea8f02bdea..dc321895f7f 100644 --- a/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json +++ b/advisories/unreviewed/2023/04/GHSA-jwhj-r8gf-xm67/GHSA-jwhj-r8gf-xm67.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-wr24-46rx-jr44/GHSA-wr24-46rx-jr44.json b/advisories/unreviewed/2023/04/GHSA-wr24-46rx-jr44/GHSA-wr24-46rx-jr44.json index 894c0ad752b..208530b6e06 100644 --- a/advisories/unreviewed/2023/04/GHSA-wr24-46rx-jr44/GHSA-wr24-46rx-jr44.json +++ b/advisories/unreviewed/2023/04/GHSA-wr24-46rx-jr44/GHSA-wr24-46rx-jr44.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-288" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json b/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json index 49736ddd00b..1631dc3ba78 100644 --- a/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json +++ b/advisories/unreviewed/2023/04/GHSA-xcx3-wvhg-c3h3/GHSA-xcx3-wvhg-c3h3.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json b/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json index 915b25ded5f..27b40a2c97a 100644 --- a/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json +++ b/advisories/unreviewed/2023/07/GHSA-pf4c-5rqp-wmc9/GHSA-pf4c-5rqp-wmc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf4c-5rqp-wmc9", - "modified": "2024-04-04T05:37:11Z", + "modified": "2025-02-05T18:34:35Z", "published": "2023-07-06T19:24:16Z", "aliases": [ "CVE-2021-33974" diff --git a/advisories/unreviewed/2024/02/GHSA-5x9h-vvfq-mc7m/GHSA-5x9h-vvfq-mc7m.json b/advisories/unreviewed/2024/02/GHSA-5x9h-vvfq-mc7m/GHSA-5x9h-vvfq-mc7m.json index 71687b7eb1a..9915ddda22a 100644 --- a/advisories/unreviewed/2024/02/GHSA-5x9h-vvfq-mc7m/GHSA-5x9h-vvfq-mc7m.json +++ b/advisories/unreviewed/2024/02/GHSA-5x9h-vvfq-mc7m/GHSA-5x9h-vvfq-mc7m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6rj2-w8v9-xrxq/GHSA-6rj2-w8v9-xrxq.json b/advisories/unreviewed/2024/02/GHSA-6rj2-w8v9-xrxq/GHSA-6rj2-w8v9-xrxq.json index 43c58b5ffe3..5092ffd304c 100644 --- a/advisories/unreviewed/2024/02/GHSA-6rj2-w8v9-xrxq/GHSA-6rj2-w8v9-xrxq.json +++ b/advisories/unreviewed/2024/02/GHSA-6rj2-w8v9-xrxq/GHSA-6rj2-w8v9-xrxq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json b/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json index 1559abd21f4..7adad506528 100644 --- a/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json +++ b/advisories/unreviewed/2024/02/GHSA-hwwp-7fmp-9cp2/GHSA-hwwp-7fmp-9cp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwwp-7fmp-9cp2", - "modified": "2024-02-22T06:30:34Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-02-22T06:30:34Z", "aliases": [ "CVE-2024-0903" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-m39f-3w96-jj8p/GHSA-m39f-3w96-jj8p.json b/advisories/unreviewed/2024/02/GHSA-m39f-3w96-jj8p/GHSA-m39f-3w96-jj8p.json index dfe94e0986e..36a8da61635 100644 --- a/advisories/unreviewed/2024/02/GHSA-m39f-3w96-jj8p/GHSA-m39f-3w96-jj8p.json +++ b/advisories/unreviewed/2024/02/GHSA-m39f-3w96-jj8p/GHSA-m39f-3w96-jj8p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-pqw3-hp3j-9x5q/GHSA-pqw3-hp3j-9x5q.json b/advisories/unreviewed/2024/02/GHSA-pqw3-hp3j-9x5q/GHSA-pqw3-hp3j-9x5q.json index e807166d34c..50452f370f2 100644 --- a/advisories/unreviewed/2024/02/GHSA-pqw3-hp3j-9x5q/GHSA-pqw3-hp3j-9x5q.json +++ b/advisories/unreviewed/2024/02/GHSA-pqw3-hp3j-9x5q/GHSA-pqw3-hp3j-9x5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqw3-hp3j-9x5q", - "modified": "2024-02-29T03:33:15Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-02-29T03:33:15Z", "aliases": [ "CVE-2024-0379" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json b/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json index bfc8d78dda3..3b928544803 100644 --- a/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json +++ b/advisories/unreviewed/2024/03/GHSA-597f-xh85-qc2h/GHSA-597f-xh85-qc2h.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json b/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json index 8489e8e89a9..6d797cac297 100644 --- a/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json +++ b/advisories/unreviewed/2024/03/GHSA-6h4j-9hpq-prqw/GHSA-6h4j-9hpq-prqw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6h4j-9hpq-prqw", - "modified": "2024-03-28T09:31:14Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-03-28T09:31:14Z", "aliases": [ "CVE-2024-30422" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.13.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.13.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-7789-4mf3-c7p3/GHSA-7789-4mf3-c7p3.json b/advisories/unreviewed/2024/03/GHSA-7789-4mf3-c7p3/GHSA-7789-4mf3-c7p3.json index 5dcaf423a44..ff114b17bce 100644 --- a/advisories/unreviewed/2024/03/GHSA-7789-4mf3-c7p3/GHSA-7789-4mf3-c7p3.json +++ b/advisories/unreviewed/2024/03/GHSA-7789-4mf3-c7p3/GHSA-7789-4mf3-c7p3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7789-4mf3-c7p3", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29792" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.93.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.93.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-fg4p-3qhr-755g/GHSA-fg4p-3qhr-755g.json b/advisories/unreviewed/2024/03/GHSA-fg4p-3qhr-755g/GHSA-fg4p-3qhr-755g.json index 459102ddbe1..88455aa3add 100644 --- a/advisories/unreviewed/2024/03/GHSA-fg4p-3qhr-755g/GHSA-fg4p-3qhr-755g.json +++ b/advisories/unreviewed/2024/03/GHSA-fg4p-3qhr-755g/GHSA-fg4p-3qhr-755g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fg4p-3qhr-755g", - "modified": "2024-03-26T21:30:47Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-03-26T21:30:47Z", "aliases": [ "CVE-2023-39307" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-pv4x-5wmj-f287/GHSA-pv4x-5wmj-f287.json b/advisories/unreviewed/2024/03/GHSA-pv4x-5wmj-f287/GHSA-pv4x-5wmj-f287.json index cbb6ef166d7..30e063237a5 100644 --- a/advisories/unreviewed/2024/03/GHSA-pv4x-5wmj-f287/GHSA-pv4x-5wmj-f287.json +++ b/advisories/unreviewed/2024/03/GHSA-pv4x-5wmj-f287/GHSA-pv4x-5wmj-f287.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-qj8h-3x8j-cqw9/GHSA-qj8h-3x8j-cqw9.json b/advisories/unreviewed/2024/03/GHSA-qj8h-3x8j-cqw9/GHSA-qj8h-3x8j-cqw9.json index ccd57ba3045..253cebf6295 100644 --- a/advisories/unreviewed/2024/03/GHSA-qj8h-3x8j-cqw9/GHSA-qj8h-3x8j-cqw9.json +++ b/advisories/unreviewed/2024/03/GHSA-qj8h-3x8j-cqw9/GHSA-qj8h-3x8j-cqw9.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rrxj-gwvr-gfp8/GHSA-rrxj-gwvr-gfp8.json b/advisories/unreviewed/2024/03/GHSA-rrxj-gwvr-gfp8/GHSA-rrxj-gwvr-gfp8.json index d7e06b0b16e..c86929f2f75 100644 --- a/advisories/unreviewed/2024/03/GHSA-rrxj-gwvr-gfp8/GHSA-rrxj-gwvr-gfp8.json +++ b/advisories/unreviewed/2024/03/GHSA-rrxj-gwvr-gfp8/GHSA-rrxj-gwvr-gfp8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rrxj-gwvr-gfp8", - "modified": "2024-03-27T15:30:38Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-03-27T15:30:38Z", "aliases": [ "CVE-2024-29760" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster for WooCommerce allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through 7.1.7.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster for WooCommerce allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through 7.1.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json b/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json index da6243fb12a..493d8d160a3 100644 --- a/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json +++ b/advisories/unreviewed/2024/03/GHSA-rw96-wm4j-gg9f/GHSA-rw96-wm4j-gg9f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rw96-wm4j-gg9f", - "modified": "2024-03-19T18:32:02Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-03-19T18:32:02Z", "aliases": [ "CVE-2024-29092" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json b/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json index ff72cb78a19..d93951ed7bb 100644 --- a/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json +++ b/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vjjj-7w4f-j46m", - "modified": "2024-03-27T12:30:41Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-03-27T12:30:41Z", "aliases": [ "CVE-2024-29935" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.0.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-w24g-v4mv-c58r/GHSA-w24g-v4mv-c58r.json b/advisories/unreviewed/2024/03/GHSA-w24g-v4mv-c58r/GHSA-w24g-v4mv-c58r.json index 4bd879577d7..6b700646fd0 100644 --- a/advisories/unreviewed/2024/03/GHSA-w24g-v4mv-c58r/GHSA-w24g-v4mv-c58r.json +++ b/advisories/unreviewed/2024/03/GHSA-w24g-v4mv-c58r/GHSA-w24g-v4mv-c58r.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wv6g-f8q7-v8cx/GHSA-wv6g-f8q7-v8cx.json b/advisories/unreviewed/2024/03/GHSA-wv6g-f8q7-v8cx/GHSA-wv6g-f8q7-v8cx.json index 7e0811b0fcb..4abfcadaf01 100644 --- a/advisories/unreviewed/2024/03/GHSA-wv6g-f8q7-v8cx/GHSA-wv6g-f8q7-v8cx.json +++ b/advisories/unreviewed/2024/03/GHSA-wv6g-f8q7-v8cx/GHSA-wv6g-f8q7-v8cx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-wv6g-f8q7-v8cx", - "modified": "2024-03-19T15:30:35Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-03-19T15:30:35Z", "aliases": [ "CVE-2024-29123" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-x59f-348f-p86c/GHSA-x59f-348f-p86c.json b/advisories/unreviewed/2024/03/GHSA-x59f-348f-p86c/GHSA-x59f-348f-p86c.json index d9886b705b1..96b75628cca 100644 --- a/advisories/unreviewed/2024/03/GHSA-x59f-348f-p86c/GHSA-x59f-348f-p86c.json +++ b/advisories/unreviewed/2024/03/GHSA-x59f-348f-p86c/GHSA-x59f-348f-p86c.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x59f-348f-p86c", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-02-05T18:34:37Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29777" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Reflected XSS.This issue affects Forminator: from n/a through 1.29.0.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Reflected XSS.This issue affects Forminator: from n/a through 1.29.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json b/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json index bac06bde452..cbce941ac58 100644 --- a/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json +++ b/advisories/unreviewed/2024/04/GHSA-2p66-2g75-qw5g/GHSA-2p66-2g75-qw5g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4992-rgh9-v55g/GHSA-4992-rgh9-v55g.json b/advisories/unreviewed/2024/04/GHSA-4992-rgh9-v55g/GHSA-4992-rgh9-v55g.json index bde93e2a9f0..23243e299a2 100644 --- a/advisories/unreviewed/2024/04/GHSA-4992-rgh9-v55g/GHSA-4992-rgh9-v55g.json +++ b/advisories/unreviewed/2024/04/GHSA-4992-rgh9-v55g/GHSA-4992-rgh9-v55g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4992-rgh9-v55g", - "modified": "2024-04-24T18:30:33Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-24T18:30:33Z", "aliases": [ "CVE-2023-31090" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-4vqm-wcg3-r4cm/GHSA-4vqm-wcg3-r4cm.json b/advisories/unreviewed/2024/04/GHSA-4vqm-wcg3-r4cm/GHSA-4vqm-wcg3-r4cm.json index b6981ae22e1..53445e447ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-4vqm-wcg3-r4cm/GHSA-4vqm-wcg3-r4cm.json +++ b/advisories/unreviewed/2024/04/GHSA-4vqm-wcg3-r4cm/GHSA-4vqm-wcg3-r4cm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4vqm-wcg3-r4cm", - "modified": "2024-04-24T18:30:33Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-24T18:30:33Z", "aliases": [ "CVE-2023-47504" ], - "details": "Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.\n\n", + "details": "Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json b/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json index 83bc0fee043..3889d03af45 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json +++ b/advisories/unreviewed/2024/04/GHSA-5qvc-39c2-6m74/GHSA-5qvc-39c2-6m74.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6x77-72j8-vq6j/GHSA-6x77-72j8-vq6j.json b/advisories/unreviewed/2024/04/GHSA-6x77-72j8-vq6j/GHSA-6x77-72j8-vq6j.json index 9a66531004b..44373b67d23 100644 --- a/advisories/unreviewed/2024/04/GHSA-6x77-72j8-vq6j/GHSA-6x77-72j8-vq6j.json +++ b/advisories/unreviewed/2024/04/GHSA-6x77-72j8-vq6j/GHSA-6x77-72j8-vq6j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6x77-72j8-vq6j", - "modified": "2024-04-25T09:32:09Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-25T09:32:09Z", "aliases": [ "CVE-2023-51478" ], - "details": "Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.\n\n", + "details": "Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-78g6-g9hf-844c/GHSA-78g6-g9hf-844c.json b/advisories/unreviewed/2024/04/GHSA-78g6-g9hf-844c/GHSA-78g6-g9hf-844c.json index 3a63f7f7103..9ece058cc7b 100644 --- a/advisories/unreviewed/2024/04/GHSA-78g6-g9hf-844c/GHSA-78g6-g9hf-844c.json +++ b/advisories/unreviewed/2024/04/GHSA-78g6-g9hf-844c/GHSA-78g6-g9hf-844c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78g6-g9hf-844c", - "modified": "2024-04-20T06:30:30Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-20T06:30:30Z", "aliases": [ "CVE-2024-1730" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-84cx-vvjm-fjvj/GHSA-84cx-vvjm-fjvj.json b/advisories/unreviewed/2024/04/GHSA-84cx-vvjm-fjvj/GHSA-84cx-vvjm-fjvj.json index 76c8477e19d..f4b4ce6b164 100644 --- a/advisories/unreviewed/2024/04/GHSA-84cx-vvjm-fjvj/GHSA-84cx-vvjm-fjvj.json +++ b/advisories/unreviewed/2024/04/GHSA-84cx-vvjm-fjvj/GHSA-84cx-vvjm-fjvj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-84cx-vvjm-fjvj", - "modified": "2024-04-18T12:30:30Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-18T12:30:30Z", "aliases": [ "CVE-2024-32575" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.1.9.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.1.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json b/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json index 1691433d0e1..23c3c3e0a9e 100644 --- a/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json +++ b/advisories/unreviewed/2024/04/GHSA-88wh-w28v-xrhh/GHSA-88wh-w28v-xrhh.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json b/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json index d76d1005b6e..59bb6c6408b 100644 --- a/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json +++ b/advisories/unreviewed/2024/04/GHSA-92jm-8w24-5mvr/GHSA-92jm-8w24-5mvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92jm-8w24-5mvr", - "modified": "2024-04-10T15:30:39Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-10T15:30:39Z", "aliases": [ "CVE-2024-1041" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json b/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json index 6a19e84f257..6006968730f 100644 --- a/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json +++ b/advisories/unreviewed/2024/04/GHSA-fgjr-q739-ggx5/GHSA-fgjr-q739-ggx5.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jx2v-8mfv-qw8p/GHSA-jx2v-8mfv-qw8p.json b/advisories/unreviewed/2024/04/GHSA-jx2v-8mfv-qw8p/GHSA-jx2v-8mfv-qw8p.json index 3723428b3d1..1a39408f1e4 100644 --- a/advisories/unreviewed/2024/04/GHSA-jx2v-8mfv-qw8p/GHSA-jx2v-8mfv-qw8p.json +++ b/advisories/unreviewed/2024/04/GHSA-jx2v-8mfv-qw8p/GHSA-jx2v-8mfv-qw8p.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jx2v-8mfv-qw8p", - "modified": "2024-04-17T12:32:03Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-17T12:32:03Z", "aliases": [ "CVE-2024-32456" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra allows Stored XSS.This issue affects Envo Extra: from n/a through 1.8.11.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra allows Stored XSS.This issue affects Envo Extra: from n/a through 1.8.11.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json b/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json index 023eb232181..fb6a227d93e 100644 --- a/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json +++ b/advisories/unreviewed/2024/04/GHSA-q7jc-6mj7-vqp9/GHSA-q7jc-6mj7-vqp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7jc-6mj7-vqp9", - "modified": "2024-04-09T21:31:58Z", + "modified": "2025-02-05T18:34:38Z", "published": "2024-04-09T21:31:58Z", "aliases": [ "CVE-2024-1893" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wm34-m2ww-gx7j/GHSA-wm34-m2ww-gx7j.json b/advisories/unreviewed/2024/04/GHSA-wm34-m2ww-gx7j/GHSA-wm34-m2ww-gx7j.json index 4ddab06d1f3..383081f9ab3 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm34-m2ww-gx7j/GHSA-wm34-m2ww-gx7j.json +++ b/advisories/unreviewed/2024/04/GHSA-wm34-m2ww-gx7j/GHSA-wm34-m2ww-gx7j.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-c7vh-4v2j-w7vm/GHSA-c7vh-4v2j-w7vm.json b/advisories/unreviewed/2024/05/GHSA-c7vh-4v2j-w7vm/GHSA-c7vh-4v2j-w7vm.json index dddb198d1bd..07678d8a5ef 100644 --- a/advisories/unreviewed/2024/05/GHSA-c7vh-4v2j-w7vm/GHSA-c7vh-4v2j-w7vm.json +++ b/advisories/unreviewed/2024/05/GHSA-c7vh-4v2j-w7vm/GHSA-c7vh-4v2j-w7vm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json b/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json index 1fdda3ad07c..0a76bf6adaf 100644 --- a/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json +++ b/advisories/unreviewed/2024/05/GHSA-xpqv-f82r-327v/GHSA-xpqv-f82r-327v.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-qw63-r4h7-wcxh/GHSA-qw63-r4h7-wcxh.json b/advisories/unreviewed/2024/06/GHSA-qw63-r4h7-wcxh/GHSA-qw63-r4h7-wcxh.json index fb4fe905abe..ec00d0d5220 100644 --- a/advisories/unreviewed/2024/06/GHSA-qw63-r4h7-wcxh/GHSA-qw63-r4h7-wcxh.json +++ b/advisories/unreviewed/2024/06/GHSA-qw63-r4h7-wcxh/GHSA-qw63-r4h7-wcxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw63-r4h7-wcxh", - "modified": "2024-06-15T15:30:26Z", + "modified": "2025-02-05T18:34:39Z", "published": "2024-06-15T15:30:26Z", "aliases": [ "CVE-2024-6007" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json b/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json index a995d0a766d..39ce1ac1df4 100644 --- a/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json +++ b/advisories/unreviewed/2025/01/GHSA-2f87-7wqp-6j6j/GHSA-2f87-7wqp-6j6j.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2ffg-9hw7-35q4/GHSA-2ffg-9hw7-35q4.json b/advisories/unreviewed/2025/01/GHSA-2ffg-9hw7-35q4/GHSA-2ffg-9hw7-35q4.json index f82e9a5cc01..b2c01c12b63 100644 --- a/advisories/unreviewed/2025/01/GHSA-2ffg-9hw7-35q4/GHSA-2ffg-9hw7-35q4.json +++ b/advisories/unreviewed/2025/01/GHSA-2ffg-9hw7-35q4/GHSA-2ffg-9hw7-35q4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2ffg-9hw7-35q4", - "modified": "2025-01-30T06:30:49Z", + "modified": "2025-02-05T18:34:40Z", "published": "2025-01-30T06:30:49Z", "aliases": [ "CVE-2025-0374" ], "details": "When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd.\n\nAn unprivileged local user may be able to read encrypted root and user passwords from the temporary master.passwd file created in /var/db/etcupdate/conflicts. This is possible only when conflicts within the password file arise during an update, and the unprotected file is deleted when conflicts are resolved.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-732" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T05:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json b/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json index 418c3e4437b..9388827513a 100644 --- a/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json +++ b/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-4j4g-v3h3-8mqg/GHSA-4j4g-v3h3-8mqg.json b/advisories/unreviewed/2025/01/GHSA-4j4g-v3h3-8mqg/GHSA-4j4g-v3h3-8mqg.json index 7d7f7b5624b..c10a9433d4b 100644 --- a/advisories/unreviewed/2025/01/GHSA-4j4g-v3h3-8mqg/GHSA-4j4g-v3h3-8mqg.json +++ b/advisories/unreviewed/2025/01/GHSA-4j4g-v3h3-8mqg/GHSA-4j4g-v3h3-8mqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4j4g-v3h3-8mqg", - "modified": "2025-01-30T06:30:49Z", + "modified": "2025-02-05T18:34:40Z", "published": "2025-01-30T06:30:49Z", "aliases": [ "CVE-2025-0373" ], "details": "On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer overflow.\n\nA NFS server that exports a cd9660, tarfs, or ext2fs file system can be made to panic by mounting and accessing the export with an NFS client. Further exploitation (e.g., bypassing file permission checking or remote kernel code execution) is potentially possible, though this has not been demonstrated. In particular, release kernels are compiled with stack protection enabled, and some instances of the overflow are caught by this mechanism, causing a panic.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T05:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json b/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json index 2b50ba24048..f76873e575b 100644 --- a/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json +++ b/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json b/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json index 822d9c4cbea..7203ffdc1b9 100644 --- a/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json +++ b/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-72hc-p753-5jcm", - "modified": "2025-01-24T21:31:28Z", + "modified": "2025-02-05T18:34:40Z", "published": "2025-01-24T21:31:28Z", "aliases": [ "CVE-2024-57277" ], "details": "InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-24T20:15:33Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json b/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json index 04098b28411..b7ccdc063cd 100644 --- a/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json +++ b/advisories/unreviewed/2025/01/GHSA-8hpx-q4cx-gfxw/GHSA-8hpx-q4cx-gfxw.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-617", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-c5hf-mm9g-jc66/GHSA-c5hf-mm9g-jc66.json b/advisories/unreviewed/2025/01/GHSA-c5hf-mm9g-jc66/GHSA-c5hf-mm9g-jc66.json index d0f9bc2d0f9..1ef6074bd2a 100644 --- a/advisories/unreviewed/2025/01/GHSA-c5hf-mm9g-jc66/GHSA-c5hf-mm9g-jc66.json +++ b/advisories/unreviewed/2025/01/GHSA-c5hf-mm9g-jc66/GHSA-c5hf-mm9g-jc66.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c5hf-mm9g-jc66", - "modified": "2025-01-29T00:31:53Z", + "modified": "2025-02-05T18:34:39Z", "published": "2025-01-17T00:30:48Z", "aliases": [ "CVE-2024-55511" ], "details": "A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows an attacker to elevate their privileges via executing a specially crafted executable.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T22:15:40Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json b/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json index 2040fed66ab..f33ca13685e 100644 --- a/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json +++ b/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json b/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json index 35903e15bcb..07b1a26ac35 100644 --- a/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json +++ b/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jp33-53rj-cx8p", - "modified": "2025-01-24T21:31:27Z", + "modified": "2025-02-05T18:34:39Z", "published": "2025-01-24T21:31:27Z", "aliases": [ "CVE-2024-57095" ], "details": "SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-24T20:15:33Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json b/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json index 979aa4e03e0..cf1f712181c 100644 --- a/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json +++ b/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json b/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json index 92c25c33295..b9e2f918311 100644 --- a/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json +++ b/advisories/unreviewed/2025/01/GHSA-v4x5-wpx5-pqc5/GHSA-v4x5-wpx5-pqc5.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-xf79-8g8m-ch82/GHSA-xf79-8g8m-ch82.json b/advisories/unreviewed/2025/01/GHSA-xf79-8g8m-ch82/GHSA-xf79-8g8m-ch82.json index 12dabe0f0ff..0b00ddacd84 100644 --- a/advisories/unreviewed/2025/01/GHSA-xf79-8g8m-ch82/GHSA-xf79-8g8m-ch82.json +++ b/advisories/unreviewed/2025/01/GHSA-xf79-8g8m-ch82/GHSA-xf79-8g8m-ch82.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xf79-8g8m-ch82", - "modified": "2025-01-29T15:31:35Z", + "modified": "2025-02-05T18:34:40Z", "published": "2025-01-29T15:31:35Z", "aliases": [ "CVE-2024-57437" ], "details": "RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-29T15:15:17Z" diff --git a/advisories/unreviewed/2025/02/GHSA-28jh-5pxq-q92w/GHSA-28jh-5pxq-q92w.json b/advisories/unreviewed/2025/02/GHSA-28jh-5pxq-q92w/GHSA-28jh-5pxq-q92w.json index c4193552349..5db2c13c8ae 100644 --- a/advisories/unreviewed/2025/02/GHSA-28jh-5pxq-q92w/GHSA-28jh-5pxq-q92w.json +++ b/advisories/unreviewed/2025/02/GHSA-28jh-5pxq-q92w/GHSA-28jh-5pxq-q92w.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-823" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-2fcc-jc2g-q7h3/GHSA-2fcc-jc2g-q7h3.json b/advisories/unreviewed/2025/02/GHSA-2fcc-jc2g-q7h3/GHSA-2fcc-jc2g-q7h3.json new file mode 100644 index 00000000000..a27749c4eff --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2fcc-jc2g-q7h3/GHSA-2fcc-jc2g-q7h3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fcc-jc2g-q7h3", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20175" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20175" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-805" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2mpq-2v9j-3j3j/GHSA-2mpq-2v9j-3j3j.json b/advisories/unreviewed/2025/02/GHSA-2mpq-2v9j-3j3j/GHSA-2mpq-2v9j-3j3j.json new file mode 100644 index 00000000000..73b8d2ded39 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2mpq-2v9j-3j3j/GHSA-2mpq-2v9j-3j3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mpq-2v9j-3j3j", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-21087" + ], + "details": "When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21087" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000134888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-47pf-mc42-q29m/GHSA-47pf-mc42-q29m.json b/advisories/unreviewed/2025/02/GHSA-47pf-mc42-q29m/GHSA-47pf-mc42-q29m.json new file mode 100644 index 00000000000..a1f257c7b9c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-47pf-mc42-q29m/GHSA-47pf-mc42-q29m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47pf-mc42-q29m", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-23239" + ], + "details": "When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23239" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138757" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-49rx-vpxq-535f/GHSA-49rx-vpxq-535f.json b/advisories/unreviewed/2025/02/GHSA-49rx-vpxq-535f/GHSA-49rx-vpxq-535f.json new file mode 100644 index 00000000000..e7b64c18bc6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-49rx-vpxq-535f/GHSA-49rx-vpxq-535f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49rx-vpxq-535f", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20204" + ], + "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. \n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20204" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4ch8-9r52-j78v/GHSA-4ch8-9r52-j78v.json b/advisories/unreviewed/2025/02/GHSA-4ch8-9r52-j78v/GHSA-4ch8-9r52-j78v.json new file mode 100644 index 00000000000..b5e723b72c3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4ch8-9r52-j78v/GHSA-4ch8-9r52-j78v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ch8-9r52-j78v", + "modified": "2025-02-05T18:34:44Z", + "published": "2025-02-05T18:34:44Z", + "aliases": [ + "CVE-2025-20124" + ], + "details": "A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device.\n\nThis vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected API. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges.\nNote: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20124" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4gh5-5c2x-4jc5/GHSA-4gh5-5c2x-4jc5.json b/advisories/unreviewed/2025/02/GHSA-4gh5-5c2x-4jc5/GHSA-4gh5-5c2x-4jc5.json new file mode 100644 index 00000000000..42ab98bad79 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4gh5-5c2x-4jc5/GHSA-4gh5-5c2x-4jc5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gh5-5c2x-4jc5", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2024-56134" + ], + "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.\n\nThis issue affects:\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.1 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.12 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\nMulti-Tenant Hypervisor \n\n\n\n\n\n7.1.35.12 and all prior versions \n\n\n\n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.1 (inclusive)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56134" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/LoadMaster-Security-Vulnerability-CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json b/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json index aed5d5d5ad4..86a6eaf667f 100644 --- a/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json +++ b/advisories/unreviewed/2025/02/GHSA-52c6-vx83-rc69/GHSA-52c6-vx83-rc69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-52c6-vx83-rc69", - "modified": "2025-02-04T09:31:08Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-04T09:31:08Z", "aliases": [ "CVE-2025-22205" ], "details": "Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-35" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T08:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json b/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json new file mode 100644 index 00000000000..979250f171e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52hm-37gj-qx5h", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2024-7595" + ], + "details": "GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.\n\nThis can be considered similar to CVE-2020-10136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7595" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc2784" + }, + { + "type": "WEB", + "url": "https://www.rfc-editor.org/rfc/rfc6169.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-654w-x4w9-5262/GHSA-654w-x4w9-5262.json b/advisories/unreviewed/2025/02/GHSA-654w-x4w9-5262/GHSA-654w-x4w9-5262.json new file mode 100644 index 00000000000..e8738570778 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-654w-x4w9-5262/GHSA-654w-x4w9-5262.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-654w-x4w9-5262", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20171" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20171" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-69xw-wf36-c369/GHSA-69xw-wf36-c369.json b/advisories/unreviewed/2025/02/GHSA-69xw-wf36-c369/GHSA-69xw-wf36-c369.json index 4b2bf162982..b0f151e5794 100644 --- a/advisories/unreviewed/2025/02/GHSA-69xw-wf36-c369/GHSA-69xw-wf36-c369.json +++ b/advisories/unreviewed/2025/02/GHSA-69xw-wf36-c369/GHSA-69xw-wf36-c369.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69xw-wf36-c369", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2023-52164" ], "details": "access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6chq-9qg2-rx7f/GHSA-6chq-9qg2-rx7f.json b/advisories/unreviewed/2025/02/GHSA-6chq-9qg2-rx7f/GHSA-6chq-9qg2-rx7f.json new file mode 100644 index 00000000000..ab12a308ecd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6chq-9qg2-rx7f/GHSA-6chq-9qg2-rx7f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6chq-9qg2-rx7f", + "modified": "2025-02-05T18:34:44Z", + "published": "2025-02-05T18:34:44Z", + "aliases": [ + "CVE-2024-39564" + ], + "details": "This is a similar, but different vulnerability than the issue reported as CVE-2024-39549.\n\nA double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute. This double free of memory is causing an rpd crash, leading to a Denial of Service (DoS).\n\n\nThis issue affects:\n\nJunos OS:  * from 22.4 before 22.4R3-S4.\n\n\nJunos OS Evolved: * from 22.4 before 22.4R3-S4-EVO.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39564" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA83011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6fqv-9m7r-mcwr/GHSA-6fqv-9m7r-mcwr.json b/advisories/unreviewed/2025/02/GHSA-6fqv-9m7r-mcwr/GHSA-6fqv-9m7r-mcwr.json new file mode 100644 index 00000000000..5b7ece5edcf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6fqv-9m7r-mcwr/GHSA-6fqv-9m7r-mcwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fqv-9m7r-mcwr", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20183" + ], + "details": "A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint. \n\nThe vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20183" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-swa-range-bypass-2BsEHYSu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6p7p-wm27-fv53/GHSA-6p7p-wm27-fv53.json b/advisories/unreviewed/2025/02/GHSA-6p7p-wm27-fv53/GHSA-6p7p-wm27-fv53.json new file mode 100644 index 00000000000..36c7dd941b2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6p7p-wm27-fv53/GHSA-6p7p-wm27-fv53.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p7p-wm27-fv53", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-24320" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 . \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24320" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000140578" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6wm7-ghvr-4m2g/GHSA-6wm7-ghvr-4m2g.json b/advisories/unreviewed/2025/02/GHSA-6wm7-ghvr-4m2g/GHSA-6wm7-ghvr-4m2g.json new file mode 100644 index 00000000000..ddbb7e6ee31 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6wm7-ghvr-4m2g/GHSA-6wm7-ghvr-4m2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wm7-ghvr-4m2g", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20185" + ], + "details": "A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.\n\nThis vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system.\nNote: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20185" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-785m-5v8g-vf98/GHSA-785m-5v8g-vf98.json b/advisories/unreviewed/2025/02/GHSA-785m-5v8g-vf98/GHSA-785m-5v8g-vf98.json new file mode 100644 index 00000000000..f5db07850be --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-785m-5v8g-vf98/GHSA-785m-5v8g-vf98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-785m-5v8g-vf98", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20174" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20174" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-805" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7qw3-c2vm-fjhq/GHSA-7qw3-c2vm-fjhq.json b/advisories/unreviewed/2025/02/GHSA-7qw3-c2vm-fjhq/GHSA-7qw3-c2vm-fjhq.json new file mode 100644 index 00000000000..70380845f26 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7qw3-c2vm-fjhq/GHSA-7qw3-c2vm-fjhq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qw3-c2vm-fjhq", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-24312" + ], + "details": "When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24312" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000141380" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7vr5-hcj8-96h7/GHSA-7vr5-hcj8-96h7.json b/advisories/unreviewed/2025/02/GHSA-7vr5-hcj8-96h7/GHSA-7vr5-hcj8-96h7.json new file mode 100644 index 00000000000..d7dd833b62d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7vr5-hcj8-96h7/GHSA-7vr5-hcj8-96h7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vr5-hcj8-96h7", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-24326" + ], + "details": "When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24326" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000140950" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8253-7fvw-x3gr/GHSA-8253-7fvw-x3gr.json b/advisories/unreviewed/2025/02/GHSA-8253-7fvw-x3gr/GHSA-8253-7fvw-x3gr.json new file mode 100644 index 00000000000..30c77fe03b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8253-7fvw-x3gr/GHSA-8253-7fvw-x3gr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8253-7fvw-x3gr", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-24497" + ], + "details": "When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24497" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000140920" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-848g-9jpp-6w84/GHSA-848g-9jpp-6w84.json b/advisories/unreviewed/2025/02/GHSA-848g-9jpp-6w84/GHSA-848g-9jpp-6w84.json new file mode 100644 index 00000000000..5064de9393f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-848g-9jpp-6w84/GHSA-848g-9jpp-6w84.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-848g-9jpp-6w84", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-20058" + ], + "details": "When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20058" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000140947" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json b/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json new file mode 100644 index 00000000000..7a4aeaa5634 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-84xh-pwc6-7g4g/GHSA-84xh-pwc6-7g4g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84xh-pwc6-7g4g", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-23419" + ], + "details": "When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23419" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000149173" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-86qr-6525-5m7v/GHSA-86qr-6525-5m7v.json b/advisories/unreviewed/2025/02/GHSA-86qr-6525-5m7v/GHSA-86qr-6525-5m7v.json new file mode 100644 index 00000000000..0c6def5244b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-86qr-6525-5m7v/GHSA-86qr-6525-5m7v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86qr-6525-5m7v", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-21091" + ], + "details": "When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21091" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000140933" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-892q-vr75-r4j3/GHSA-892q-vr75-r4j3.json b/advisories/unreviewed/2025/02/GHSA-892q-vr75-r4j3/GHSA-892q-vr75-r4j3.json new file mode 100644 index 00000000000..34882aadfb9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-892q-vr75-r4j3/GHSA-892q-vr75-r4j3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-892q-vr75-r4j3", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-22891" + ], + "details": "When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22891" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000139778" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-772" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json b/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json index 3e4ea1a1617..ebacc3cddc4 100644 --- a/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json +++ b/advisories/unreviewed/2025/02/GHSA-9m2c-r2hc-7gcr/GHSA-9m2c-r2hc-7gcr.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-9vgr-8wff-x9vq/GHSA-9vgr-8wff-x9vq.json b/advisories/unreviewed/2025/02/GHSA-9vgr-8wff-x9vq/GHSA-9vgr-8wff-x9vq.json new file mode 100644 index 00000000000..192ba08c3b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9vgr-8wff-x9vq/GHSA-9vgr-8wff-x9vq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vgr-8wff-x9vq", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20173" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20173" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c7xm-3c9x-23p2/GHSA-c7xm-3c9x-23p2.json b/advisories/unreviewed/2025/02/GHSA-c7xm-3c9x-23p2/GHSA-c7xm-3c9x-23p2.json new file mode 100644 index 00000000000..a68fa1f8c32 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c7xm-3c9x-23p2/GHSA-c7xm-3c9x-23p2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7xm-3c9x-23p2", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-23412" + ], + "details": "When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.\n\n\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23412" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000141003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cj2j-jvqc-2vrv/GHSA-cj2j-jvqc-2vrv.json b/advisories/unreviewed/2025/02/GHSA-cj2j-jvqc-2vrv/GHSA-cj2j-jvqc-2vrv.json index 709f2b95fe5..9fa0c04c11f 100644 --- a/advisories/unreviewed/2025/02/GHSA-cj2j-jvqc-2vrv/GHSA-cj2j-jvqc-2vrv.json +++ b/advisories/unreviewed/2025/02/GHSA-cj2j-jvqc-2vrv/GHSA-cj2j-jvqc-2vrv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj2j-jvqc-2vrv", - "modified": "2025-02-04T15:31:37Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-04T15:31:37Z", "aliases": [ "CVE-2025-1018" ], "details": "The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1021" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-fg9r-rh56-7jcv/GHSA-fg9r-rh56-7jcv.json b/advisories/unreviewed/2025/02/GHSA-fg9r-rh56-7jcv/GHSA-fg9r-rh56-7jcv.json new file mode 100644 index 00000000000..cf7a31e817c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fg9r-rh56-7jcv/GHSA-fg9r-rh56-7jcv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg9r-rh56-7jcv", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20172" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. For Cisco IOS and IOS XE Software, a successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. For Cisco IOS XR Software, a successful exploit could allow the attacker to cause the SNMP process to restart, resulting in an interrupted SNMP response from an affected device. Devices that are running Cisco IOS XR Software will not reload. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20172" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fr7h-wpf9-67rw/GHSA-fr7h-wpf9-67rw.json b/advisories/unreviewed/2025/02/GHSA-fr7h-wpf9-67rw/GHSA-fr7h-wpf9-67rw.json new file mode 100644 index 00000000000..ea44d027ae9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fr7h-wpf9-67rw/GHSA-fr7h-wpf9-67rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr7h-wpf9-67rw", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20205" + ], + "details": "A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. \n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20205" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g3x4-qg6f-w8x2/GHSA-g3x4-qg6f-w8x2.json b/advisories/unreviewed/2025/02/GHSA-g3x4-qg6f-w8x2/GHSA-g3x4-qg6f-w8x2.json index 9c5763b4001..ff2ec54bc54 100644 --- a/advisories/unreviewed/2025/02/GHSA-g3x4-qg6f-w8x2/GHSA-g3x4-qg6f-w8x2.json +++ b/advisories/unreviewed/2025/02/GHSA-g3x4-qg6f-w8x2/GHSA-g3x4-qg6f-w8x2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-g7gf-f662-24xm/GHSA-g7gf-f662-24xm.json b/advisories/unreviewed/2025/02/GHSA-g7gf-f662-24xm/GHSA-g7gf-f662-24xm.json new file mode 100644 index 00000000000..b1f1271a14d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g7gf-f662-24xm/GHSA-g7gf-f662-24xm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7gf-f662-24xm", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-20045" + ], + "details": "When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20045" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000138932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g9mx-x5c2-8c9j/GHSA-g9mx-x5c2-8c9j.json b/advisories/unreviewed/2025/02/GHSA-g9mx-x5c2-8c9j/GHSA-g9mx-x5c2-8c9j.json new file mode 100644 index 00000000000..288e919fd06 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g9mx-x5c2-8c9j/GHSA-g9mx-x5c2-8c9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9mx-x5c2-8c9j", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20184" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.\n\nThis vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20184" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hjjx-mmjm-vp9r/GHSA-hjjx-mmjm-vp9r.json b/advisories/unreviewed/2025/02/GHSA-hjjx-mmjm-vp9r/GHSA-hjjx-mmjm-vp9r.json index 0f9970b68db..9ab436f582e 100644 --- a/advisories/unreviewed/2025/02/GHSA-hjjx-mmjm-vp9r/GHSA-hjjx-mmjm-vp9r.json +++ b/advisories/unreviewed/2025/02/GHSA-hjjx-mmjm-vp9r/GHSA-hjjx-mmjm-vp9r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjjx-mmjm-vp9r", - "modified": "2025-02-04T15:31:37Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-04T15:31:37Z", "aliases": [ "CVE-2025-1012" ], "details": "A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T14:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json b/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json new file mode 100644 index 00000000000..462964b4d87 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrpp-92f9-h887", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:44Z", + "aliases": [ + "CVE-2025-20125" + ], + "details": "A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node.\n\nThis vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device.\nNote: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20125" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json b/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json new file mode 100644 index 00000000000..7406cb66402 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6xc-hhqx-8w7p", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20176" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20176" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json b/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json new file mode 100644 index 00000000000..48d5d08c3c0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jff7-8p33-28j3", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2024-7596" + ], + "details": "Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.\n\nThis can be considered similar to CVE-2020-10136.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7596" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/draft-ietf-intarea-gue" + }, + { + "type": "WEB", + "url": "https://www.rfc-editor.org/rfc/rfc6169.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mhcp-fqhx-3jmp/GHSA-mhcp-fqhx-3jmp.json b/advisories/unreviewed/2025/02/GHSA-mhcp-fqhx-3jmp/GHSA-mhcp-fqhx-3jmp.json new file mode 100644 index 00000000000..cb6dd0a3f15 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mhcp-fqhx-3jmp/GHSA-mhcp-fqhx-3jmp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhcp-fqhx-3jmp", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-20029" + ], + "details": "Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20029" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000148587" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mrvx-3qrr-qqxw/GHSA-mrvx-3qrr-qqxw.json b/advisories/unreviewed/2025/02/GHSA-mrvx-3qrr-qqxw/GHSA-mrvx-3qrr-qqxw.json index d9d77954491..89339f35749 100644 --- a/advisories/unreviewed/2025/02/GHSA-mrvx-3qrr-qqxw/GHSA-mrvx-3qrr-qqxw.json +++ b/advisories/unreviewed/2025/02/GHSA-mrvx-3qrr-qqxw/GHSA-mrvx-3qrr-qqxw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrvx-3qrr-qqxw", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2023-52163" ], "details": "Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-p97f-5rgg-7g94/GHSA-p97f-5rgg-7g94.json b/advisories/unreviewed/2025/02/GHSA-p97f-5rgg-7g94/GHSA-p97f-5rgg-7g94.json new file mode 100644 index 00000000000..8a99789b3a6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p97f-5rgg-7g94/GHSA-p97f-5rgg-7g94.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p97f-5rgg-7g94", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-24319" + ], + "details": "When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate.\n\n\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24319" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000148412" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pjcf-x483-vp8v/GHSA-pjcf-x483-vp8v.json b/advisories/unreviewed/2025/02/GHSA-pjcf-x483-vp8v/GHSA-pjcf-x483-vp8v.json index 7817bc08be7..deb88675208 100644 --- a/advisories/unreviewed/2025/02/GHSA-pjcf-x483-vp8v/GHSA-pjcf-x483-vp8v.json +++ b/advisories/unreviewed/2025/02/GHSA-pjcf-x483-vp8v/GHSA-pjcf-x483-vp8v.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-822" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-q8p5-49qg-m9wx/GHSA-q8p5-49qg-m9wx.json b/advisories/unreviewed/2025/02/GHSA-q8p5-49qg-m9wx/GHSA-q8p5-49qg-m9wx.json index 82e534690e8..672e8f502a5 100644 --- a/advisories/unreviewed/2025/02/GHSA-q8p5-49qg-m9wx/GHSA-q8p5-49qg-m9wx.json +++ b/advisories/unreviewed/2025/02/GHSA-q8p5-49qg-m9wx/GHSA-q8p5-49qg-m9wx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q8p5-49qg-m9wx", - "modified": "2025-02-03T18:30:43Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-03T18:30:43Z", "aliases": [ "CVE-2024-36437" ], "details": "The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-926" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T18:15:33Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qgr7-xw3q-mxrv/GHSA-qgr7-xw3q-mxrv.json b/advisories/unreviewed/2025/02/GHSA-qgr7-xw3q-mxrv/GHSA-qgr7-xw3q-mxrv.json new file mode 100644 index 00000000000..24abf97e596 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qgr7-xw3q-mxrv/GHSA-qgr7-xw3q-mxrv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgr7-xw3q-mxrv", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-22846" + ], + "details": "When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.\n\n\n\n  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22846" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000139780" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qr6j-94j6-gq32/GHSA-qr6j-94j6-gq32.json b/advisories/unreviewed/2025/02/GHSA-qr6j-94j6-gq32/GHSA-qr6j-94j6-gq32.json index f88e0b63f27..f66f683a8ac 100644 --- a/advisories/unreviewed/2025/02/GHSA-qr6j-94j6-gq32/GHSA-qr6j-94j6-gq32.json +++ b/advisories/unreviewed/2025/02/GHSA-qr6j-94j6-gq32/GHSA-qr6j-94j6-gq32.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-qvmm-8p36-5w5c/GHSA-qvmm-8p36-5w5c.json b/advisories/unreviewed/2025/02/GHSA-qvmm-8p36-5w5c/GHSA-qvmm-8p36-5w5c.json new file mode 100644 index 00000000000..bf1b7b0fa76 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qvmm-8p36-5w5c/GHSA-qvmm-8p36-5w5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvmm-8p36-5w5c", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2024-56132" + ], + "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.\n\nThis issue affects:\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.1 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.12 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.1 (inclusive)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56132" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/LoadMaster-Security-Vulnerability-CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r89w-qx4v-xpfv/GHSA-r89w-qx4v-xpfv.json b/advisories/unreviewed/2025/02/GHSA-r89w-qx4v-xpfv/GHSA-r89w-qx4v-xpfv.json new file mode 100644 index 00000000000..ac027e7380c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r89w-qx4v-xpfv/GHSA-r89w-qx4v-xpfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r89w-qx4v-xpfv", + "modified": "2025-02-05T18:34:44Z", + "published": "2025-02-05T18:34:44Z", + "aliases": [ + "CVE-2024-42207" + ], + "details": "HCL iAutomate is affected by a session fixation vulnerability.  An attacker could hijack a victim's session ID from their authenticated session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42207" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118946" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rh2h-7w4m-mhhp/GHSA-rh2h-7w4m-mhhp.json b/advisories/unreviewed/2025/02/GHSA-rh2h-7w4m-mhhp/GHSA-rh2h-7w4m-mhhp.json new file mode 100644 index 00000000000..eb651663790 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rh2h-7w4m-mhhp/GHSA-rh2h-7w4m-mhhp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh2h-7w4m-mhhp", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-23415" + ], + "details": "An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux.\n\n \n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23415" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000139656" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rm76-63g8-g9g3/GHSA-rm76-63g8-g9g3.json b/advisories/unreviewed/2025/02/GHSA-rm76-63g8-g9g3/GHSA-rm76-63g8-g9g3.json new file mode 100644 index 00000000000..eb4e1bc5d01 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rm76-63g8-g9g3/GHSA-rm76-63g8-g9g3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm76-63g8-g9g3", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2024-56131" + ], + "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.\n\nThis issue affects:\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.1 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.12 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\nMulti-Tenant Hypervisor \n\n\n\n\n\n7.1.35.12 and all prior versions \n\n\n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.1 (inclusive)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56131" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/LoadMaster-Security-Vulnerability-CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vjw2-gg68-3j52/GHSA-vjw2-gg68-3j52.json b/advisories/unreviewed/2025/02/GHSA-vjw2-gg68-3j52/GHSA-vjw2-gg68-3j52.json new file mode 100644 index 00000000000..434a583a37d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vjw2-gg68-3j52/GHSA-vjw2-gg68-3j52.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjw2-gg68-3j52", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2025-23413" + ], + "details": "When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23413" + }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000149185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vp2c-rcm4-hf9q/GHSA-vp2c-rcm4-hf9q.json b/advisories/unreviewed/2025/02/GHSA-vp2c-rcm4-hf9q/GHSA-vp2c-rcm4-hf9q.json new file mode 100644 index 00000000000..4fb0a82fcee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vp2c-rcm4-hf9q/GHSA-vp2c-rcm4-hf9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp2c-rcm4-hf9q", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20179" + ], + "details": "A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.\nNote: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20179" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-xss-uexUZrEW" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w3cf-qcr3-6ppg/GHSA-w3cf-qcr3-6ppg.json b/advisories/unreviewed/2025/02/GHSA-w3cf-qcr3-6ppg/GHSA-w3cf-qcr3-6ppg.json new file mode 100644 index 00000000000..093d0a28120 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w3cf-qcr3-6ppg/GHSA-w3cf-qcr3-6ppg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3cf-qcr3-6ppg", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20207" + ], + "details": "A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system.\n\nThis vulnerability exists because the appliances do not protect confidential information at rest in response to SNMP poll requests. An attacker could exploit this vulnerability by sending a crafted SNMP poll request to the affected appliance. A successful exploit could allow the attacker to discover confidential information that should be restricted. To exploit this vulnerability, an attacker must have the configured SNMP credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20207" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wcp5-9f53-qpcq/GHSA-wcp5-9f53-qpcq.json b/advisories/unreviewed/2025/02/GHSA-wcp5-9f53-qpcq/GHSA-wcp5-9f53-qpcq.json index 90aaad25d32..b5fb7f1f95b 100644 --- a/advisories/unreviewed/2025/02/GHSA-wcp5-9f53-qpcq/GHSA-wcp5-9f53-qpcq.json +++ b/advisories/unreviewed/2025/02/GHSA-wcp5-9f53-qpcq/GHSA-wcp5-9f53-qpcq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-823" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-wg77-mr52-g6pm/GHSA-wg77-mr52-g6pm.json b/advisories/unreviewed/2025/02/GHSA-wg77-mr52-g6pm/GHSA-wg77-mr52-g6pm.json new file mode 100644 index 00000000000..074505b49bb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wg77-mr52-g6pm/GHSA-wg77-mr52-g6pm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg77-mr52-g6pm", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:46Z", + "aliases": [ + "CVE-2024-56135" + ], + "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.\n\nThis issue affects:\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.1 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.12 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.1 (inclusive)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56135" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/LoadMaster-Security-Vulnerability-CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wpp5-72vx-9m3v/GHSA-wpp5-72vx-9m3v.json b/advisories/unreviewed/2025/02/GHSA-wpp5-72vx-9m3v/GHSA-wpp5-72vx-9m3v.json new file mode 100644 index 00000000000..f920875af8f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wpp5-72vx-9m3v/GHSA-wpp5-72vx-9m3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpp5-72vx-9m3v", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20169" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20169" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-805" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x4gm-qv5j-r6rh/GHSA-x4gm-qv5j-r6rh.json b/advisories/unreviewed/2025/02/GHSA-x4gm-qv5j-r6rh/GHSA-x4gm-qv5j-r6rh.json index 9952e58b701..63cdfe1274e 100644 --- a/advisories/unreviewed/2025/02/GHSA-x4gm-qv5j-r6rh/GHSA-x4gm-qv5j-r6rh.json +++ b/advisories/unreviewed/2025/02/GHSA-x4gm-qv5j-r6rh/GHSA-x4gm-qv5j-r6rh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x4gm-qv5j-r6rh", - "modified": "2025-02-04T15:31:36Z", + "modified": "2025-02-05T18:34:44Z", "published": "2025-02-04T15:31:36Z", "aliases": [ "CVE-2024-13699" diff --git a/advisories/unreviewed/2025/02/GHSA-x65q-fr32-9838/GHSA-x65q-fr32-9838.json b/advisories/unreviewed/2025/02/GHSA-x65q-fr32-9838/GHSA-x65q-fr32-9838.json new file mode 100644 index 00000000000..12ed9ecd899 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x65q-fr32-9838/GHSA-x65q-fr32-9838.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x65q-fr32-9838", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20170" + ], + "details": "A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.\n\nThis vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. \nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20170" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-805" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xcj6-9mrr-2jw3/GHSA-xcj6-9mrr-2jw3.json b/advisories/unreviewed/2025/02/GHSA-xcj6-9mrr-2jw3/GHSA-xcj6-9mrr-2jw3.json new file mode 100644 index 00000000000..03747d58368 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xcj6-9mrr-2jw3/GHSA-xcj6-9mrr-2jw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcj6-9mrr-2jw3", + "modified": "2025-02-05T18:34:45Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2025-20180" + ], + "details": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20180" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-xss-WCk2WcuG" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T17:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xqw2-8hr2-gw5r/GHSA-xqw2-8hr2-gw5r.json b/advisories/unreviewed/2025/02/GHSA-xqw2-8hr2-gw5r/GHSA-xqw2-8hr2-gw5r.json new file mode 100644 index 00000000000..c34d0f41af5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xqw2-8hr2-gw5r/GHSA-xqw2-8hr2-gw5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqw2-8hr2-gw5r", + "modified": "2025-02-05T18:34:46Z", + "published": "2025-02-05T18:34:45Z", + "aliases": [ + "CVE-2024-56133" + ], + "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.\n\nThis issue affects:\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.1 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.12 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.1 (inclusive)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56133" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/LoadMaster-Security-Vulnerability-CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T18:15:28Z" + } +} \ No newline at end of file