diff --git a/advisories/unreviewed/2022/01/GHSA-7mw2-m38p-22r4/GHSA-7mw2-m38p-22r4.json b/advisories/unreviewed/2022/01/GHSA-7mw2-m38p-22r4/GHSA-7mw2-m38p-22r4.json index 06ba169148e..c798ee73902 100644 --- a/advisories/unreviewed/2022/01/GHSA-7mw2-m38p-22r4/GHSA-7mw2-m38p-22r4.json +++ b/advisories/unreviewed/2022/01/GHSA-7mw2-m38p-22r4/GHSA-7mw2-m38p-22r4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mw2-m38p-22r4", - "modified": "2022-01-27T00:02:55Z", + "modified": "2025-01-15T18:30:34Z", "published": "2022-01-21T00:00:40Z", "aliases": [ "CVE-2021-44092" ], "details": "An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-wcc5-3gcc-8xv6/GHSA-wcc5-3gcc-8xv6.json b/advisories/unreviewed/2022/05/GHSA-wcc5-3gcc-8xv6/GHSA-wcc5-3gcc-8xv6.json index 6ef8d1b7c32..cf9eaae65fe 100644 --- a/advisories/unreviewed/2022/05/GHSA-wcc5-3gcc-8xv6/GHSA-wcc5-3gcc-8xv6.json +++ b/advisories/unreviewed/2022/05/GHSA-wcc5-3gcc-8xv6/GHSA-wcc5-3gcc-8xv6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wcc5-3gcc-8xv6", - "modified": "2022-05-24T16:57:57Z", + "modified": "2025-01-15T18:30:34Z", "published": "2022-05-24T16:57:57Z", "aliases": [ "CVE-2015-9452" ], "details": "The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-hw4x-q63w-42vp/GHSA-hw4x-q63w-42vp.json b/advisories/unreviewed/2023/05/GHSA-hw4x-q63w-42vp/GHSA-hw4x-q63w-42vp.json index 54261748438..5e926a92341 100644 --- a/advisories/unreviewed/2023/05/GHSA-hw4x-q63w-42vp/GHSA-hw4x-q63w-42vp.json +++ b/advisories/unreviewed/2023/05/GHSA-hw4x-q63w-42vp/GHSA-hw4x-q63w-42vp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw4x-q63w-42vp", - "modified": "2023-11-04T03:30:18Z", + "modified": "2025-01-15T18:30:34Z", "published": "2023-05-26T15:30:21Z", "aliases": [ "CVE-2022-46945" diff --git a/advisories/unreviewed/2023/05/GHSA-pgq4-vq29-6v5r/GHSA-pgq4-vq29-6v5r.json b/advisories/unreviewed/2023/05/GHSA-pgq4-vq29-6v5r/GHSA-pgq4-vq29-6v5r.json index 0f421865b6c..4a92376bc6e 100644 --- a/advisories/unreviewed/2023/05/GHSA-pgq4-vq29-6v5r/GHSA-pgq4-vq29-6v5r.json +++ b/advisories/unreviewed/2023/05/GHSA-pgq4-vq29-6v5r/GHSA-pgq4-vq29-6v5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgq4-vq29-6v5r", - "modified": "2023-11-16T21:22:33Z", + "modified": "2025-01-15T18:30:35Z", "published": "2023-05-26T21:30:23Z", "aliases": [ "CVE-2023-28321" diff --git a/advisories/unreviewed/2024/02/GHSA-635w-7jgp-9rf7/GHSA-635w-7jgp-9rf7.json b/advisories/unreviewed/2024/02/GHSA-635w-7jgp-9rf7/GHSA-635w-7jgp-9rf7.json index eee9919b94b..6152dc6c6c0 100644 --- a/advisories/unreviewed/2024/02/GHSA-635w-7jgp-9rf7/GHSA-635w-7jgp-9rf7.json +++ b/advisories/unreviewed/2024/02/GHSA-635w-7jgp-9rf7/GHSA-635w-7jgp-9rf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-635w-7jgp-9rf7", - "modified": "2024-02-29T03:33:16Z", + "modified": "2025-01-15T18:30:36Z", "published": "2024-02-29T03:33:16Z", "aliases": [ "CVE-2024-1129" @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6gx4-j85m-6p68/GHSA-6gx4-j85m-6p68.json b/advisories/unreviewed/2024/02/GHSA-6gx4-j85m-6p68/GHSA-6gx4-j85m-6p68.json index b6a25bd8e08..7d38711879d 100644 --- a/advisories/unreviewed/2024/02/GHSA-6gx4-j85m-6p68/GHSA-6gx4-j85m-6p68.json +++ b/advisories/unreviewed/2024/02/GHSA-6gx4-j85m-6p68/GHSA-6gx4-j85m-6p68.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-76cr-x9wq-mm5r/GHSA-76cr-x9wq-mm5r.json b/advisories/unreviewed/2024/02/GHSA-76cr-x9wq-mm5r/GHSA-76cr-x9wq-mm5r.json index f1b1ad3aa4d..a07025ded4e 100644 --- a/advisories/unreviewed/2024/02/GHSA-76cr-x9wq-mm5r/GHSA-76cr-x9wq-mm5r.json +++ b/advisories/unreviewed/2024/02/GHSA-76cr-x9wq-mm5r/GHSA-76cr-x9wq-mm5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76cr-x9wq-mm5r", - "modified": "2024-02-29T03:33:15Z", + "modified": "2025-01-15T18:30:36Z", "published": "2024-02-29T03:33:15Z", "aliases": [ "CVE-2024-0907" @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-m6m8-pj95-q4rg/GHSA-m6m8-pj95-q4rg.json b/advisories/unreviewed/2024/02/GHSA-m6m8-pj95-q4rg/GHSA-m6m8-pj95-q4rg.json index 882172ba724..1ec7bbfdf52 100644 --- a/advisories/unreviewed/2024/02/GHSA-m6m8-pj95-q4rg/GHSA-m6m8-pj95-q4rg.json +++ b/advisories/unreviewed/2024/02/GHSA-m6m8-pj95-q4rg/GHSA-m6m8-pj95-q4rg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6m8-pj95-q4rg", - "modified": "2024-02-29T03:33:16Z", + "modified": "2025-01-15T18:30:37Z", "published": "2024-02-29T03:33:16Z", "aliases": [ "CVE-2024-1130" @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-pf4f-q385-9wcr/GHSA-pf4f-q385-9wcr.json b/advisories/unreviewed/2024/02/GHSA-pf4f-q385-9wcr/GHSA-pf4f-q385-9wcr.json index a5dc375e3b4..2744adc458d 100644 --- a/advisories/unreviewed/2024/02/GHSA-pf4f-q385-9wcr/GHSA-pf4f-q385-9wcr.json +++ b/advisories/unreviewed/2024/02/GHSA-pf4f-q385-9wcr/GHSA-pf4f-q385-9wcr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pf4f-q385-9wcr", - "modified": "2024-02-29T03:33:16Z", + "modified": "2025-01-15T18:30:37Z", "published": "2024-02-29T03:33:16Z", "aliases": [ "CVE-2024-1133" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-w4c6-9hpf-wrhm/GHSA-w4c6-9hpf-wrhm.json b/advisories/unreviewed/2024/02/GHSA-w4c6-9hpf-wrhm/GHSA-w4c6-9hpf-wrhm.json index de7cba28e3d..19b09f253a2 100644 --- a/advisories/unreviewed/2024/02/GHSA-w4c6-9hpf-wrhm/GHSA-w4c6-9hpf-wrhm.json +++ b/advisories/unreviewed/2024/02/GHSA-w4c6-9hpf-wrhm/GHSA-w4c6-9hpf-wrhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4c6-9hpf-wrhm", - "modified": "2024-02-29T03:33:16Z", + "modified": "2025-01-15T18:30:36Z", "published": "2024-02-29T03:33:16Z", "aliases": [ "CVE-2024-1128" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-2wr3-hxqg-qp94/GHSA-2wr3-hxqg-qp94.json b/advisories/unreviewed/2024/03/GHSA-2wr3-hxqg-qp94/GHSA-2wr3-hxqg-qp94.json index e229334bd51..fbd83e8aed4 100644 --- a/advisories/unreviewed/2024/03/GHSA-2wr3-hxqg-qp94/GHSA-2wr3-hxqg-qp94.json +++ b/advisories/unreviewed/2024/03/GHSA-2wr3-hxqg-qp94/GHSA-2wr3-hxqg-qp94.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-3gww-3727-4334/GHSA-3gww-3727-4334.json b/advisories/unreviewed/2024/03/GHSA-3gww-3727-4334/GHSA-3gww-3727-4334.json index 20b05b5fca4..13119e47f37 100644 --- a/advisories/unreviewed/2024/03/GHSA-3gww-3727-4334/GHSA-3gww-3727-4334.json +++ b/advisories/unreviewed/2024/03/GHSA-3gww-3727-4334/GHSA-3gww-3727-4334.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-3hrh-p3gr-mv3p/GHSA-3hrh-p3gr-mv3p.json b/advisories/unreviewed/2024/03/GHSA-3hrh-p3gr-mv3p/GHSA-3hrh-p3gr-mv3p.json index 31af1f46eb6..56461f70f07 100644 --- a/advisories/unreviewed/2024/03/GHSA-3hrh-p3gr-mv3p/GHSA-3hrh-p3gr-mv3p.json +++ b/advisories/unreviewed/2024/03/GHSA-3hrh-p3gr-mv3p/GHSA-3hrh-p3gr-mv3p.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-48pf-f8q2-3pw7/GHSA-48pf-f8q2-3pw7.json b/advisories/unreviewed/2024/03/GHSA-48pf-f8q2-3pw7/GHSA-48pf-f8q2-3pw7.json index ccb3cf1f903..dd0fc2d786c 100644 --- a/advisories/unreviewed/2024/03/GHSA-48pf-f8q2-3pw7/GHSA-48pf-f8q2-3pw7.json +++ b/advisories/unreviewed/2024/03/GHSA-48pf-f8q2-3pw7/GHSA-48pf-f8q2-3pw7.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-4p7p-xfch-wpqg/GHSA-4p7p-xfch-wpqg.json b/advisories/unreviewed/2024/03/GHSA-4p7p-xfch-wpqg/GHSA-4p7p-xfch-wpqg.json index db833719291..152304a98be 100644 --- a/advisories/unreviewed/2024/03/GHSA-4p7p-xfch-wpqg/GHSA-4p7p-xfch-wpqg.json +++ b/advisories/unreviewed/2024/03/GHSA-4p7p-xfch-wpqg/GHSA-4p7p-xfch-wpqg.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-57cq-mhwv-qcfq/GHSA-57cq-mhwv-qcfq.json b/advisories/unreviewed/2024/03/GHSA-57cq-mhwv-qcfq/GHSA-57cq-mhwv-qcfq.json index 3e8e16aeaaa..3edfff103a4 100644 --- a/advisories/unreviewed/2024/03/GHSA-57cq-mhwv-qcfq/GHSA-57cq-mhwv-qcfq.json +++ b/advisories/unreviewed/2024/03/GHSA-57cq-mhwv-qcfq/GHSA-57cq-mhwv-qcfq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57cq-mhwv-qcfq", - "modified": "2024-03-06T00:31:27Z", + "modified": "2025-01-15T18:30:37Z", "published": "2024-03-06T00:31:27Z", "aliases": [ "CVE-2024-27278" ], "details": "OpenPNE Plugin \"opTimelinePlugin\" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which uses the affected product, when a user configures the profile with some malicious contents, an arbitrary script may be executed on the web browsers of other users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T00:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5r8q-qv6x-h2vp/GHSA-5r8q-qv6x-h2vp.json b/advisories/unreviewed/2024/03/GHSA-5r8q-qv6x-h2vp/GHSA-5r8q-qv6x-h2vp.json index bf0734bcc1d..201a81bffe8 100644 --- a/advisories/unreviewed/2024/03/GHSA-5r8q-qv6x-h2vp/GHSA-5r8q-qv6x-h2vp.json +++ b/advisories/unreviewed/2024/03/GHSA-5r8q-qv6x-h2vp/GHSA-5r8q-qv6x-h2vp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json b/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json index ddb9c749ad6..e6a0561c142 100644 --- a/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json +++ b/advisories/unreviewed/2024/03/GHSA-5xf8-64vx-2fcm/GHSA-5xf8-64vx-2fcm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xf8-64vx-2fcm", - "modified": "2024-03-08T09:30:33Z", + "modified": "2025-01-15T18:30:37Z", "published": "2024-03-08T09:30:33Z", "aliases": [ "CVE-2024-2298" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-675v-vq7w-gjcf/GHSA-675v-vq7w-gjcf.json b/advisories/unreviewed/2024/03/GHSA-675v-vq7w-gjcf/GHSA-675v-vq7w-gjcf.json index f1f7f6538b3..17c2a14ebf2 100644 --- a/advisories/unreviewed/2024/03/GHSA-675v-vq7w-gjcf/GHSA-675v-vq7w-gjcf.json +++ b/advisories/unreviewed/2024/03/GHSA-675v-vq7w-gjcf/GHSA-675v-vq7w-gjcf.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-6c3m-w6f2-9wmq/GHSA-6c3m-w6f2-9wmq.json b/advisories/unreviewed/2024/03/GHSA-6c3m-w6f2-9wmq/GHSA-6c3m-w6f2-9wmq.json index 99299aab232..65a3f0f7082 100644 --- a/advisories/unreviewed/2024/03/GHSA-6c3m-w6f2-9wmq/GHSA-6c3m-w6f2-9wmq.json +++ b/advisories/unreviewed/2024/03/GHSA-6c3m-w6f2-9wmq/GHSA-6c3m-w6f2-9wmq.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-7hr9-v742-j7xh/GHSA-7hr9-v742-j7xh.json b/advisories/unreviewed/2024/03/GHSA-7hr9-v742-j7xh/GHSA-7hr9-v742-j7xh.json index e62fc24e8a6..ff0dc9bcb3f 100644 --- a/advisories/unreviewed/2024/03/GHSA-7hr9-v742-j7xh/GHSA-7hr9-v742-j7xh.json +++ b/advisories/unreviewed/2024/03/GHSA-7hr9-v742-j7xh/GHSA-7hr9-v742-j7xh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7jx8-3f9v-r586/GHSA-7jx8-3f9v-r586.json b/advisories/unreviewed/2024/03/GHSA-7jx8-3f9v-r586/GHSA-7jx8-3f9v-r586.json index 7b6bc5cd8b3..61c8db1ce84 100644 --- a/advisories/unreviewed/2024/03/GHSA-7jx8-3f9v-r586/GHSA-7jx8-3f9v-r586.json +++ b/advisories/unreviewed/2024/03/GHSA-7jx8-3f9v-r586/GHSA-7jx8-3f9v-r586.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-7qm4-r332-p54j/GHSA-7qm4-r332-p54j.json b/advisories/unreviewed/2024/03/GHSA-7qm4-r332-p54j/GHSA-7qm4-r332-p54j.json index add44d5d367..c6c031911d0 100644 --- a/advisories/unreviewed/2024/03/GHSA-7qm4-r332-p54j/GHSA-7qm4-r332-p54j.json +++ b/advisories/unreviewed/2024/03/GHSA-7qm4-r332-p54j/GHSA-7qm4-r332-p54j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qm4-r332-p54j", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-15T18:30:38Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1127" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9gh2-q9mq-954r/GHSA-9gh2-q9mq-954r.json b/advisories/unreviewed/2024/03/GHSA-9gh2-q9mq-954r/GHSA-9gh2-q9mq-954r.json index b9c53068361..57e08d037f9 100644 --- a/advisories/unreviewed/2024/03/GHSA-9gh2-q9mq-954r/GHSA-9gh2-q9mq-954r.json +++ b/advisories/unreviewed/2024/03/GHSA-9gh2-q9mq-954r/GHSA-9gh2-q9mq-954r.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-cmxr-2hxf-h3pv/GHSA-cmxr-2hxf-h3pv.json b/advisories/unreviewed/2024/03/GHSA-cmxr-2hxf-h3pv/GHSA-cmxr-2hxf-h3pv.json index 583142b069a..419de1fad58 100644 --- a/advisories/unreviewed/2024/03/GHSA-cmxr-2hxf-h3pv/GHSA-cmxr-2hxf-h3pv.json +++ b/advisories/unreviewed/2024/03/GHSA-cmxr-2hxf-h3pv/GHSA-cmxr-2hxf-h3pv.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-g293-ch5f-pcjx/GHSA-g293-ch5f-pcjx.json b/advisories/unreviewed/2024/03/GHSA-g293-ch5f-pcjx/GHSA-g293-ch5f-pcjx.json index ada6677c0cc..2f28c7674c7 100644 --- a/advisories/unreviewed/2024/03/GHSA-g293-ch5f-pcjx/GHSA-g293-ch5f-pcjx.json +++ b/advisories/unreviewed/2024/03/GHSA-g293-ch5f-pcjx/GHSA-g293-ch5f-pcjx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-g3w4-73xh-8jrw/GHSA-g3w4-73xh-8jrw.json b/advisories/unreviewed/2024/03/GHSA-g3w4-73xh-8jrw/GHSA-g3w4-73xh-8jrw.json index 074631c91da..4aca31cf81d 100644 --- a/advisories/unreviewed/2024/03/GHSA-g3w4-73xh-8jrw/GHSA-g3w4-73xh-8jrw.json +++ b/advisories/unreviewed/2024/03/GHSA-g3w4-73xh-8jrw/GHSA-g3w4-73xh-8jrw.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-g5jg-fx5f-vrwh/GHSA-g5jg-fx5f-vrwh.json b/advisories/unreviewed/2024/03/GHSA-g5jg-fx5f-vrwh/GHSA-g5jg-fx5f-vrwh.json index bb763ef9e28..3109bbfb1d6 100644 --- a/advisories/unreviewed/2024/03/GHSA-g5jg-fx5f-vrwh/GHSA-g5jg-fx5f-vrwh.json +++ b/advisories/unreviewed/2024/03/GHSA-g5jg-fx5f-vrwh/GHSA-g5jg-fx5f-vrwh.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-gf3f-c8q8-x35q/GHSA-gf3f-c8q8-x35q.json b/advisories/unreviewed/2024/03/GHSA-gf3f-c8q8-x35q/GHSA-gf3f-c8q8-x35q.json index fd43d84cbbf..e4feaefb56d 100644 --- a/advisories/unreviewed/2024/03/GHSA-gf3f-c8q8-x35q/GHSA-gf3f-c8q8-x35q.json +++ b/advisories/unreviewed/2024/03/GHSA-gf3f-c8q8-x35q/GHSA-gf3f-c8q8-x35q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf3f-c8q8-x35q", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-01-15T18:30:38Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-1751" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-h37q-gmpw-89cr/GHSA-h37q-gmpw-89cr.json b/advisories/unreviewed/2024/03/GHSA-h37q-gmpw-89cr/GHSA-h37q-gmpw-89cr.json index e1eba157237..2c614ec8a67 100644 --- a/advisories/unreviewed/2024/03/GHSA-h37q-gmpw-89cr/GHSA-h37q-gmpw-89cr.json +++ b/advisories/unreviewed/2024/03/GHSA-h37q-gmpw-89cr/GHSA-h37q-gmpw-89cr.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-h729-53rr-wqh7/GHSA-h729-53rr-wqh7.json b/advisories/unreviewed/2024/03/GHSA-h729-53rr-wqh7/GHSA-h729-53rr-wqh7.json index d49b40cae5b..87c872dd517 100644 --- a/advisories/unreviewed/2024/03/GHSA-h729-53rr-wqh7/GHSA-h729-53rr-wqh7.json +++ b/advisories/unreviewed/2024/03/GHSA-h729-53rr-wqh7/GHSA-h729-53rr-wqh7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hq5f-j5j2-j69g/GHSA-hq5f-j5j2-j69g.json b/advisories/unreviewed/2024/03/GHSA-hq5f-j5j2-j69g/GHSA-hq5f-j5j2-j69g.json index 93365dcde63..2be452ba7c0 100644 --- a/advisories/unreviewed/2024/03/GHSA-hq5f-j5j2-j69g/GHSA-hq5f-j5j2-j69g.json +++ b/advisories/unreviewed/2024/03/GHSA-hq5f-j5j2-j69g/GHSA-hq5f-j5j2-j69g.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-j5gx-g2hf-5rv5/GHSA-j5gx-g2hf-5rv5.json b/advisories/unreviewed/2024/03/GHSA-j5gx-g2hf-5rv5/GHSA-j5gx-g2hf-5rv5.json index 45291ac1992..9ff2dc1b8fc 100644 --- a/advisories/unreviewed/2024/03/GHSA-j5gx-g2hf-5rv5/GHSA-j5gx-g2hf-5rv5.json +++ b/advisories/unreviewed/2024/03/GHSA-j5gx-g2hf-5rv5/GHSA-j5gx-g2hf-5rv5.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-j8j4-2jh5-rm7f/GHSA-j8j4-2jh5-rm7f.json b/advisories/unreviewed/2024/03/GHSA-j8j4-2jh5-rm7f/GHSA-j8j4-2jh5-rm7f.json index 8614b1c4207..94c2022abd5 100644 --- a/advisories/unreviewed/2024/03/GHSA-j8j4-2jh5-rm7f/GHSA-j8j4-2jh5-rm7f.json +++ b/advisories/unreviewed/2024/03/GHSA-j8j4-2jh5-rm7f/GHSA-j8j4-2jh5-rm7f.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-j8xv-pr77-4g5m/GHSA-j8xv-pr77-4g5m.json b/advisories/unreviewed/2024/03/GHSA-j8xv-pr77-4g5m/GHSA-j8xv-pr77-4g5m.json index 5ae3cba4cd1..b11ead0acfd 100644 --- a/advisories/unreviewed/2024/03/GHSA-j8xv-pr77-4g5m/GHSA-j8xv-pr77-4g5m.json +++ b/advisories/unreviewed/2024/03/GHSA-j8xv-pr77-4g5m/GHSA-j8xv-pr77-4g5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8xv-pr77-4g5m", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-15T18:30:38Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1126" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json b/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json index 2e428e42d22..bf35542691d 100644 --- a/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json +++ b/advisories/unreviewed/2024/03/GHSA-m9rc-7xvh-66c4/GHSA-m9rc-7xvh-66c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9rc-7xvh-66c4", - "modified": "2024-03-08T09:30:33Z", + "modified": "2025-01-15T18:30:37Z", "published": "2024-03-08T09:30:33Z", "aliases": [ "CVE-2024-1851" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json b/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json index 9b65882a314..35d57357d34 100644 --- a/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json +++ b/advisories/unreviewed/2024/03/GHSA-mq62-5vgw-569m/GHSA-mq62-5vgw-569m.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-v9v2-wxc2-c8j5/GHSA-v9v2-wxc2-c8j5.json b/advisories/unreviewed/2024/03/GHSA-v9v2-wxc2-c8j5/GHSA-v9v2-wxc2-c8j5.json index 1d5a141dc8b..862c47864fb 100644 --- a/advisories/unreviewed/2024/03/GHSA-v9v2-wxc2-c8j5/GHSA-v9v2-wxc2-c8j5.json +++ b/advisories/unreviewed/2024/03/GHSA-v9v2-wxc2-c8j5/GHSA-v9v2-wxc2-c8j5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xvxf-m2rv-ff79/GHSA-xvxf-m2rv-ff79.json b/advisories/unreviewed/2024/03/GHSA-xvxf-m2rv-ff79/GHSA-xvxf-m2rv-ff79.json index 5a94147087d..b0242f6606c 100644 --- a/advisories/unreviewed/2024/03/GHSA-xvxf-m2rv-ff79/GHSA-xvxf-m2rv-ff79.json +++ b/advisories/unreviewed/2024/03/GHSA-xvxf-m2rv-ff79/GHSA-xvxf-m2rv-ff79.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-669x-xjh2-j5gc/GHSA-669x-xjh2-j5gc.json b/advisories/unreviewed/2024/04/GHSA-669x-xjh2-j5gc/GHSA-669x-xjh2-j5gc.json index 6751eed0598..d255c2b797d 100644 --- a/advisories/unreviewed/2024/04/GHSA-669x-xjh2-j5gc/GHSA-669x-xjh2-j5gc.json +++ b/advisories/unreviewed/2024/04/GHSA-669x-xjh2-j5gc/GHSA-669x-xjh2-j5gc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fwx9-j2j6-84w3/GHSA-fwx9-j2j6-84w3.json b/advisories/unreviewed/2024/04/GHSA-fwx9-j2j6-84w3/GHSA-fwx9-j2j6-84w3.json index ac89cfbf986..07a399a7453 100644 --- a/advisories/unreviewed/2024/04/GHSA-fwx9-j2j6-84w3/GHSA-fwx9-j2j6-84w3.json +++ b/advisories/unreviewed/2024/04/GHSA-fwx9-j2j6-84w3/GHSA-fwx9-j2j6-84w3.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-87" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-2754-5257-hv37/GHSA-2754-5257-hv37.json b/advisories/unreviewed/2024/05/GHSA-2754-5257-hv37/GHSA-2754-5257-hv37.json index 0868163c603..68babcfa0ab 100644 --- a/advisories/unreviewed/2024/05/GHSA-2754-5257-hv37/GHSA-2754-5257-hv37.json +++ b/advisories/unreviewed/2024/05/GHSA-2754-5257-hv37/GHSA-2754-5257-hv37.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-35qw-h594-mg3j/GHSA-35qw-h594-mg3j.json b/advisories/unreviewed/2024/05/GHSA-35qw-h594-mg3j/GHSA-35qw-h594-mg3j.json index 15acca3c5e7..ce54e78fc1d 100644 --- a/advisories/unreviewed/2024/05/GHSA-35qw-h594-mg3j/GHSA-35qw-h594-mg3j.json +++ b/advisories/unreviewed/2024/05/GHSA-35qw-h594-mg3j/GHSA-35qw-h594-mg3j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-36j3-2772-j983/GHSA-36j3-2772-j983.json b/advisories/unreviewed/2024/05/GHSA-36j3-2772-j983/GHSA-36j3-2772-j983.json index 51c0e08915e..c0054a5b517 100644 --- a/advisories/unreviewed/2024/05/GHSA-36j3-2772-j983/GHSA-36j3-2772-j983.json +++ b/advisories/unreviewed/2024/05/GHSA-36j3-2772-j983/GHSA-36j3-2772-j983.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36j3-2772-j983", - "modified": "2024-05-14T18:30:55Z", + "modified": "2025-01-15T18:30:53Z", "published": "2024-05-14T18:30:55Z", "aliases": [ "CVE-2024-4449" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3qw8-r23q-rc4p/GHSA-3qw8-r23q-rc4p.json b/advisories/unreviewed/2024/05/GHSA-3qw8-r23q-rc4p/GHSA-3qw8-r23q-rc4p.json index ec153dfd0e0..b63584169b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-3qw8-r23q-rc4p/GHSA-3qw8-r23q-rc4p.json +++ b/advisories/unreviewed/2024/05/GHSA-3qw8-r23q-rc4p/GHSA-3qw8-r23q-rc4p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4x9w-v858-7pmq/GHSA-4x9w-v858-7pmq.json b/advisories/unreviewed/2024/05/GHSA-4x9w-v858-7pmq/GHSA-4x9w-v858-7pmq.json index dfc412d88d4..38d0dd5c769 100644 --- a/advisories/unreviewed/2024/05/GHSA-4x9w-v858-7pmq/GHSA-4x9w-v858-7pmq.json +++ b/advisories/unreviewed/2024/05/GHSA-4x9w-v858-7pmq/GHSA-4x9w-v858-7pmq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-823" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-6w47-73p5-43gv/GHSA-6w47-73p5-43gv.json b/advisories/unreviewed/2024/05/GHSA-6w47-73p5-43gv/GHSA-6w47-73p5-43gv.json index f14b978bb73..a93b031baac 100644 --- a/advisories/unreviewed/2024/05/GHSA-6w47-73p5-43gv/GHSA-6w47-73p5-43gv.json +++ b/advisories/unreviewed/2024/05/GHSA-6w47-73p5-43gv/GHSA-6w47-73p5-43gv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6w47-73p5-43gv", - "modified": "2024-05-14T18:30:55Z", + "modified": "2025-01-15T18:30:52Z", "published": "2024-05-14T18:30:55Z", "aliases": [ "CVE-2024-4448" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-88cq-675j-rm8v/GHSA-88cq-675j-rm8v.json b/advisories/unreviewed/2024/05/GHSA-88cq-675j-rm8v/GHSA-88cq-675j-rm8v.json index 3b9d69a9703..23e1a95f249 100644 --- a/advisories/unreviewed/2024/05/GHSA-88cq-675j-rm8v/GHSA-88cq-675j-rm8v.json +++ b/advisories/unreviewed/2024/05/GHSA-88cq-675j-rm8v/GHSA-88cq-675j-rm8v.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-945r-qfv2-22cj/GHSA-945r-qfv2-22cj.json b/advisories/unreviewed/2024/05/GHSA-945r-qfv2-22cj/GHSA-945r-qfv2-22cj.json index 763a9dad0ff..bf9e6233904 100644 --- a/advisories/unreviewed/2024/05/GHSA-945r-qfv2-22cj/GHSA-945r-qfv2-22cj.json +++ b/advisories/unreviewed/2024/05/GHSA-945r-qfv2-22cj/GHSA-945r-qfv2-22cj.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json b/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json index 5bd7acc7621..3829a45d6aa 100644 --- a/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json +++ b/advisories/unreviewed/2024/05/GHSA-chwm-xp9x-8vv7/GHSA-chwm-xp9x-8vv7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chwm-xp9x-8vv7", - "modified": "2024-05-21T18:31:21Z", + "modified": "2025-01-15T18:30:53Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52789" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: vcc: Add check for kstrdup() in vcc_probe()\n\nAdd check for the return value of kstrdup() and return the error, if it\nfails in order to avoid NULL pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cjf8-hcqf-6652/GHSA-cjf8-hcqf-6652.json b/advisories/unreviewed/2024/05/GHSA-cjf8-hcqf-6652/GHSA-cjf8-hcqf-6652.json index 4a007f6b205..0e21f04289d 100644 --- a/advisories/unreviewed/2024/05/GHSA-cjf8-hcqf-6652/GHSA-cjf8-hcqf-6652.json +++ b/advisories/unreviewed/2024/05/GHSA-cjf8-hcqf-6652/GHSA-cjf8-hcqf-6652.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjf8-hcqf-6652", - "modified": "2024-05-14T18:31:02Z", + "modified": "2025-01-15T18:30:53Z", "published": "2024-05-14T18:31:02Z", "aliases": [ "CVE-2024-4624" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-crh6-677f-9wg9/GHSA-crh6-677f-9wg9.json b/advisories/unreviewed/2024/05/GHSA-crh6-677f-9wg9/GHSA-crh6-677f-9wg9.json index a37fab0b819..f65f069b1be 100644 --- a/advisories/unreviewed/2024/05/GHSA-crh6-677f-9wg9/GHSA-crh6-677f-9wg9.json +++ b/advisories/unreviewed/2024/05/GHSA-crh6-677f-9wg9/GHSA-crh6-677f-9wg9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fghj-68h8-69xc/GHSA-fghj-68h8-69xc.json b/advisories/unreviewed/2024/05/GHSA-fghj-68h8-69xc/GHSA-fghj-68h8-69xc.json index 6140637f8cf..d4d2939cdac 100644 --- a/advisories/unreviewed/2024/05/GHSA-fghj-68h8-69xc/GHSA-fghj-68h8-69xc.json +++ b/advisories/unreviewed/2024/05/GHSA-fghj-68h8-69xc/GHSA-fghj-68h8-69xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fghj-68h8-69xc", - "modified": "2024-05-14T18:30:54Z", + "modified": "2025-01-15T18:30:52Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4275" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gjhf-p7pf-23vv/GHSA-gjhf-p7pf-23vv.json b/advisories/unreviewed/2024/05/GHSA-gjhf-p7pf-23vv/GHSA-gjhf-p7pf-23vv.json index abf3b77d662..a46175bd5d1 100644 --- a/advisories/unreviewed/2024/05/GHSA-gjhf-p7pf-23vv/GHSA-gjhf-p7pf-23vv.json +++ b/advisories/unreviewed/2024/05/GHSA-gjhf-p7pf-23vv/GHSA-gjhf-p7pf-23vv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-gq42-gvvc-m5hv/GHSA-gq42-gvvc-m5hv.json b/advisories/unreviewed/2024/05/GHSA-gq42-gvvc-m5hv/GHSA-gq42-gvvc-m5hv.json index 99341f4f516..17250fa47a6 100644 --- a/advisories/unreviewed/2024/05/GHSA-gq42-gvvc-m5hv/GHSA-gq42-gvvc-m5hv.json +++ b/advisories/unreviewed/2024/05/GHSA-gq42-gvvc-m5hv/GHSA-gq42-gvvc-m5hv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-h2c8-p665-64mv/GHSA-h2c8-p665-64mv.json b/advisories/unreviewed/2024/05/GHSA-h2c8-p665-64mv/GHSA-h2c8-p665-64mv.json index 6d8ab71302d..1afdd8736c1 100644 --- a/advisories/unreviewed/2024/05/GHSA-h2c8-p665-64mv/GHSA-h2c8-p665-64mv.json +++ b/advisories/unreviewed/2024/05/GHSA-h2c8-p665-64mv/GHSA-h2c8-p665-64mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2c8-p665-64mv", - "modified": "2024-05-02T18:30:55Z", + "modified": "2025-01-15T18:30:40Z", "published": "2024-05-02T18:30:55Z", "aliases": [ "CVE-2024-4003" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h5pg-7xwx-9864/GHSA-h5pg-7xwx-9864.json b/advisories/unreviewed/2024/05/GHSA-h5pg-7xwx-9864/GHSA-h5pg-7xwx-9864.json index 3f28b0b8804..d93986ec5a5 100644 --- a/advisories/unreviewed/2024/05/GHSA-h5pg-7xwx-9864/GHSA-h5pg-7xwx-9864.json +++ b/advisories/unreviewed/2024/05/GHSA-h5pg-7xwx-9864/GHSA-h5pg-7xwx-9864.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h5pg-7xwx-9864", - "modified": "2024-05-02T18:30:55Z", + "modified": "2025-01-15T18:30:40Z", "published": "2024-05-02T18:30:55Z", "aliases": [ "CVE-2024-4156" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json b/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json index 56f2d73bd7a..e162c4296bc 100644 --- a/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json +++ b/advisories/unreviewed/2024/05/GHSA-hgcx-34qp-j38m/GHSA-hgcx-34qp-j38m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hgcx-34qp-j38m", - "modified": "2024-05-21T18:31:22Z", + "modified": "2025-01-15T18:30:54Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52837" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: fix uaf in nbd_open\n\nCommit 4af5f2e03013 (\"nbd: use blk_mq_alloc_disk and\nblk_cleanup_disk\") cleans up disk by blk_cleanup_disk() and it won't set\ndisk->private_data as NULL as before. UAF may be triggered in nbd_open()\nif someone tries to open nbd device right after nbd_put() since nbd has\nbeen free in nbd_dev_remove().\n\nFix this by implementing ->free_disk and free private data in it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j258-9f79-77r3/GHSA-j258-9f79-77r3.json b/advisories/unreviewed/2024/05/GHSA-j258-9f79-77r3/GHSA-j258-9f79-77r3.json index c2192224d20..a4fe27c0ea0 100644 --- a/advisories/unreviewed/2024/05/GHSA-j258-9f79-77r3/GHSA-j258-9f79-77r3.json +++ b/advisories/unreviewed/2024/05/GHSA-j258-9f79-77r3/GHSA-j258-9f79-77r3.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q2jj-q5cf-hwvv/GHSA-q2jj-q5cf-hwvv.json b/advisories/unreviewed/2024/05/GHSA-q2jj-q5cf-hwvv/GHSA-q2jj-q5cf-hwvv.json index 0c339d92712..4e414828122 100644 --- a/advisories/unreviewed/2024/05/GHSA-q2jj-q5cf-hwvv/GHSA-q2jj-q5cf-hwvv.json +++ b/advisories/unreviewed/2024/05/GHSA-q2jj-q5cf-hwvv/GHSA-q2jj-q5cf-hwvv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-q7hg-j3j5-h37m/GHSA-q7hg-j3j5-h37m.json b/advisories/unreviewed/2024/05/GHSA-q7hg-j3j5-h37m/GHSA-q7hg-j3j5-h37m.json index 34ae0702a7f..af4362b7279 100644 --- a/advisories/unreviewed/2024/05/GHSA-q7hg-j3j5-h37m/GHSA-q7hg-j3j5-h37m.json +++ b/advisories/unreviewed/2024/05/GHSA-q7hg-j3j5-h37m/GHSA-q7hg-j3j5-h37m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wpfm-jh3c-j3r6/GHSA-wpfm-jh3c-j3r6.json b/advisories/unreviewed/2024/05/GHSA-wpfm-jh3c-j3r6/GHSA-wpfm-jh3c-j3r6.json index b560229aefd..6a95bc368b1 100644 --- a/advisories/unreviewed/2024/05/GHSA-wpfm-jh3c-j3r6/GHSA-wpfm-jh3c-j3r6.json +++ b/advisories/unreviewed/2024/05/GHSA-wpfm-jh3c-j3r6/GHSA-wpfm-jh3c-j3r6.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x228-mrpj-x9pr/GHSA-x228-mrpj-x9pr.json b/advisories/unreviewed/2024/05/GHSA-x228-mrpj-x9pr/GHSA-x228-mrpj-x9pr.json index 9a2cb3366a4..308092fb0a0 100644 --- a/advisories/unreviewed/2024/05/GHSA-x228-mrpj-x9pr/GHSA-x228-mrpj-x9pr.json +++ b/advisories/unreviewed/2024/05/GHSA-x228-mrpj-x9pr/GHSA-x228-mrpj-x9pr.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xhmv-mw7v-7gv2/GHSA-xhmv-mw7v-7gv2.json b/advisories/unreviewed/2024/05/GHSA-xhmv-mw7v-7gv2/GHSA-xhmv-mw7v-7gv2.json index 1bca57643a7..20653e19fda 100644 --- a/advisories/unreviewed/2024/05/GHSA-xhmv-mw7v-7gv2/GHSA-xhmv-mw7v-7gv2.json +++ b/advisories/unreviewed/2024/05/GHSA-xhmv-mw7v-7gv2/GHSA-xhmv-mw7v-7gv2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-597m-8j3v-mvc5/GHSA-597m-8j3v-mvc5.json b/advisories/unreviewed/2024/06/GHSA-597m-8j3v-mvc5/GHSA-597m-8j3v-mvc5.json index dcc051ff147..09878ccfabd 100644 --- a/advisories/unreviewed/2024/06/GHSA-597m-8j3v-mvc5/GHSA-597m-8j3v-mvc5.json +++ b/advisories/unreviewed/2024/06/GHSA-597m-8j3v-mvc5/GHSA-597m-8j3v-mvc5.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json b/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json index 3b722ef7887..67a7303b7ac 100644 --- a/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json +++ b/advisories/unreviewed/2024/06/GHSA-9267-324r-qccw/GHSA-9267-324r-qccw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9267-324r-qccw", - "modified": "2024-06-12T12:30:41Z", + "modified": "2025-01-15T18:30:55Z", "published": "2024-06-12T12:30:41Z", "aliases": [ "CVE-2024-3492" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json b/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json index ed039fa408b..73e49a0596a 100644 --- a/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json +++ b/advisories/unreviewed/2024/06/GHSA-qgm3-fv3v-22gp/GHSA-qgm3-fv3v-22gp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgm3-fv3v-22gp", - "modified": "2024-06-11T15:31:14Z", + "modified": "2025-01-15T18:30:55Z", "published": "2024-06-11T15:31:14Z", "aliases": [ "CVE-2024-5189" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-hrxm-8w25-wxc6/GHSA-hrxm-8w25-wxc6.json b/advisories/unreviewed/2024/07/GHSA-hrxm-8w25-wxc6/GHSA-hrxm-8w25-wxc6.json index 21494393795..d445d50038a 100644 --- a/advisories/unreviewed/2024/07/GHSA-hrxm-8w25-wxc6/GHSA-hrxm-8w25-wxc6.json +++ b/advisories/unreviewed/2024/07/GHSA-hrxm-8w25-wxc6/GHSA-hrxm-8w25-wxc6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-27wq-9xfm-724g/GHSA-27wq-9xfm-724g.json b/advisories/unreviewed/2025/01/GHSA-27wq-9xfm-724g/GHSA-27wq-9xfm-724g.json index 58ea469a5d5..e0911452a44 100644 --- a/advisories/unreviewed/2025/01/GHSA-27wq-9xfm-724g/GHSA-27wq-9xfm-724g.json +++ b/advisories/unreviewed/2025/01/GHSA-27wq-9xfm-724g/GHSA-27wq-9xfm-724g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-27wq-9xfm-724g", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57641" ], "details": "An issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json b/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json new file mode 100644 index 00000000000..da7435550ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2hwf-vrcf-2q7m/GHSA-2hwf-vrcf-2q7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hwf-vrcf-2q7m", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22759" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22759" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-and-page-builder/vulnerability/wordpress-post-and-page-builder-by-boldgrid-visual-drag-and-drop-editor-plugin-1-27-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2p97-mrrh-vgxm/GHSA-2p97-mrrh-vgxm.json b/advisories/unreviewed/2025/01/GHSA-2p97-mrrh-vgxm/GHSA-2p97-mrrh-vgxm.json new file mode 100644 index 00000000000..c63f8b9bdb4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2p97-mrrh-vgxm/GHSA-2p97-mrrh-vgxm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p97-mrrh-vgxm", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2024-56295" + ], + "details": "Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 5.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56295" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-plugin-5-5-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2pm8-xgpx-w63v/GHSA-2pm8-xgpx-w63v.json b/advisories/unreviewed/2025/01/GHSA-2pm8-xgpx-w63v/GHSA-2pm8-xgpx-w63v.json new file mode 100644 index 00000000000..bb60c268d8f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2pm8-xgpx-w63v/GHSA-2pm8-xgpx-w63v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pm8-xgpx-w63v", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22746" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HireHive HireHive Job Plugin allows Stored XSS.This issue affects HireHive Job Plugin: from n/a through 2.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22746" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zartis-job-plugin/vulnerability/wordpress-hirehive-job-plugin-plugin-2-9-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3238-v6wp-xx67/GHSA-3238-v6wp-xx67.json b/advisories/unreviewed/2025/01/GHSA-3238-v6wp-xx67/GHSA-3238-v6wp-xx67.json index 808dd020305..d7f57a6cb9b 100644 --- a/advisories/unreviewed/2025/01/GHSA-3238-v6wp-xx67/GHSA-3238-v6wp-xx67.json +++ b/advisories/unreviewed/2025/01/GHSA-3238-v6wp-xx67/GHSA-3238-v6wp-xx67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3238-v6wp-xx67", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57619" ], "details": "An issue in the atom_get_int component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-34ff-cx48-8mr5/GHSA-34ff-cx48-8mr5.json b/advisories/unreviewed/2025/01/GHSA-34ff-cx48-8mr5/GHSA-34ff-cx48-8mr5.json new file mode 100644 index 00000000000..6a9fd63b582 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-34ff-cx48-8mr5/GHSA-34ff-cx48-8mr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34ff-cx48-8mr5", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22752" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GSheetConnector GSheetConnector for Forminator Forms allows Reflected XSS.This issue affects GSheetConnector for Forminator Forms: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22752" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gsheetconnector-forminator/vulnerability/wordpress-gsheetconnector-for-forminator-forms-plugin-1-0-11-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-396f-r23h-8cqv/GHSA-396f-r23h-8cqv.json b/advisories/unreviewed/2025/01/GHSA-396f-r23h-8cqv/GHSA-396f-r23h-8cqv.json new file mode 100644 index 00000000000..887bf13502f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-396f-r23h-8cqv/GHSA-396f-r23h-8cqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-396f-r23h-8cqv", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22784" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Johan Ström Background Control allows Path Traversal.This issue affects Background Control: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22784" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/background-control/vulnerability/wordpress-background-control-plugin-1-0-5-csrf-to-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3q2w-qp4g-p28f/GHSA-3q2w-qp4g-p28f.json b/advisories/unreviewed/2025/01/GHSA-3q2w-qp4g-p28f/GHSA-3q2w-qp4g-p28f.json new file mode 100644 index 00000000000..5430deea6d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3q2w-qp4g-p28f/GHSA-3q2w-qp4g-p28f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q2w-qp4g-p28f", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22758" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aiwp Elementor AI Addons allows DOM-Based XSS.This issue affects Elementor AI Addons: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-addons-for-elementor/vulnerability/wordpress-elementor-ai-addons-plugin-2-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3xf8-5pv9-6q88/GHSA-3xf8-5pv9-6q88.json b/advisories/unreviewed/2025/01/GHSA-3xf8-5pv9-6q88/GHSA-3xf8-5pv9-6q88.json new file mode 100644 index 00000000000..7fb1de28353 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3xf8-5pv9-6q88/GHSA-3xf8-5pv9-6q88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xf8-5pv9-6q88", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22745" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Björn Weinbrenner Navigation Du Lapin Blanc allows DOM-Based XSS.This issue affects Navigation Du Lapin Blanc: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22745" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/navigation-du-lapin-blanc/vulnerability/wordpress-navigation-du-lapin-blanc-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-45v9-w9fh-33j6/GHSA-45v9-w9fh-33j6.json b/advisories/unreviewed/2025/01/GHSA-45v9-w9fh-33j6/GHSA-45v9-w9fh-33j6.json new file mode 100644 index 00000000000..75fee455d99 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-45v9-w9fh-33j6/GHSA-45v9-w9fh-33j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45v9-w9fh-33j6", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2025-20088" + ], + "details": "Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20088" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4rhc-q92g-rm98/GHSA-4rhc-q92g-rm98.json b/advisories/unreviewed/2025/01/GHSA-4rhc-q92g-rm98/GHSA-4rhc-q92g-rm98.json new file mode 100644 index 00000000000..52be6bfc3ef --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4rhc-q92g-rm98/GHSA-4rhc-q92g-rm98.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rhc-q92g-rm98", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2025-0480" + ], + "details": "A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0480" + }, + { + "type": "WEB", + "url": "https://github.com/wuzhicms/wuzhicms/issues/212" + }, + { + "type": "WEB", + "url": "https://github.com/wuzhicms/wuzhicms/issues/212#issue-2769226216" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.291915" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.291915" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474965" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4rm3-87xm-9h89/GHSA-4rm3-87xm-9h89.json b/advisories/unreviewed/2025/01/GHSA-4rm3-87xm-9h89/GHSA-4rm3-87xm-9h89.json index 178d9d07d75..20a690792d7 100644 --- a/advisories/unreviewed/2025/01/GHSA-4rm3-87xm-9h89/GHSA-4rm3-87xm-9h89.json +++ b/advisories/unreviewed/2025/01/GHSA-4rm3-87xm-9h89/GHSA-4rm3-87xm-9h89.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rm3-87xm-9h89", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57650" ], "details": "An issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4vwx-53cp-qmh4/GHSA-4vwx-53cp-qmh4.json b/advisories/unreviewed/2025/01/GHSA-4vwx-53cp-qmh4/GHSA-4vwx-53cp-qmh4.json new file mode 100644 index 00000000000..3b35b272633 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4vwx-53cp-qmh4/GHSA-4vwx-53cp-qmh4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vwx-53cp-qmh4", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2024-50953" + ], + "details": "An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50953" + }, + { + "type": "WEB", + "url": "https://github.com/Curator-Kim/Vulnerability-mining/blob/master/XINJE%20XL5E-16T%20Modbus/XINJE%20XL5E-16T%20Modbus%20DoS.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-544m-mj79-r4vj/GHSA-544m-mj79-r4vj.json b/advisories/unreviewed/2025/01/GHSA-544m-mj79-r4vj/GHSA-544m-mj79-r4vj.json new file mode 100644 index 00000000000..a235f8e0fbf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-544m-mj79-r4vj/GHSA-544m-mj79-r4vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-544m-mj79-r4vj", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22779" + ], + "details": "Missing Authorization vulnerability in Ugur CELIK WP News Sliders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP News Sliders: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22779" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-news-sliders/vulnerability/wordpress-wp-news-sliders-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-55ph-h7f5-3xh7/GHSA-55ph-h7f5-3xh7.json b/advisories/unreviewed/2025/01/GHSA-55ph-h7f5-3xh7/GHSA-55ph-h7f5-3xh7.json new file mode 100644 index 00000000000..6ab7b065278 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-55ph-h7f5-3xh7/GHSA-55ph-h7f5-3xh7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55ph-h7f5-3xh7", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22329" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AGILELOGIX Free Google Maps allows Stored XSS.This issue affects Free Google Maps: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22329" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-map/vulnerability/wordpress-free-google-maps-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5m7j-6gc4-ff5g/GHSA-5m7j-6gc4-ff5g.json b/advisories/unreviewed/2025/01/GHSA-5m7j-6gc4-ff5g/GHSA-5m7j-6gc4-ff5g.json new file mode 100644 index 00000000000..55d0c720b0e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5m7j-6gc4-ff5g/GHSA-5m7j-6gc4-ff5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m7j-6gc4-ff5g", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2025-20086" + ], + "details": "Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20086" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5xr2-p64c-3hvh/GHSA-5xr2-p64c-3hvh.json b/advisories/unreviewed/2025/01/GHSA-5xr2-p64c-3hvh/GHSA-5xr2-p64c-3hvh.json new file mode 100644 index 00000000000..574dddba135 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5xr2-p64c-3hvh/GHSA-5xr2-p64c-3hvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr2-p64c-3hvh", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22761" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer Ajax Contact Form allows Stored XSS.This issue affects Ajax Contact Form: from n/a through 1.2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fws-ajax-contact-form/vulnerability/wordpress-ajax-contact-form-plugin-ajax-contact-form-1-2-5-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-659m-5jrw-v7c5/GHSA-659m-5jrw-v7c5.json b/advisories/unreviewed/2025/01/GHSA-659m-5jrw-v7c5/GHSA-659m-5jrw-v7c5.json index c799311e488..3b8b4cd44fc 100644 --- a/advisories/unreviewed/2025/01/GHSA-659m-5jrw-v7c5/GHSA-659m-5jrw-v7c5.json +++ b/advisories/unreviewed/2025/01/GHSA-659m-5jrw-v7c5/GHSA-659m-5jrw-v7c5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-659m-5jrw-v7c5", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57627" ], "details": "An issue in the gc_col component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6927-5wrv-gqx4/GHSA-6927-5wrv-gqx4.json b/advisories/unreviewed/2025/01/GHSA-6927-5wrv-gqx4/GHSA-6927-5wrv-gqx4.json new file mode 100644 index 00000000000..8d56be29226 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6927-5wrv-gqx4/GHSA-6927-5wrv-gqx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6927-5wrv-gqx4", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22346" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Course Migration for LearnDash allows Server Side Request Forgery.This issue affects Course Migration for LearnDash: from 1.0.2 through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22346" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/course-migration-for-learndash/vulnerability/wordpress-course-migration-for-learndash-plugin-1-0-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6jp8-vgw3-8h23/GHSA-6jp8-vgw3-8h23.json b/advisories/unreviewed/2025/01/GHSA-6jp8-vgw3-8h23/GHSA-6jp8-vgw3-8h23.json new file mode 100644 index 00000000000..ea7116c5253 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6jp8-vgw3-8h23/GHSA-6jp8-vgw3-8h23.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jp8-vgw3-8h23", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22788" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codexpert, Inc CoDesigner WooCommerce Builder for Elementor allows Stored XSS.This issue affects CoDesigner WooCommerce Builder for Elementor: from n/a through 4.7.17.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22788" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woolementor/vulnerability/wordpress-codesigner-plugin-4-7-17-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6r3v-jvh3-993p/GHSA-6r3v-jvh3-993p.json b/advisories/unreviewed/2025/01/GHSA-6r3v-jvh3-993p/GHSA-6r3v-jvh3-993p.json index 63d890a0b54..94299652d01 100644 --- a/advisories/unreviewed/2025/01/GHSA-6r3v-jvh3-993p/GHSA-6r3v-jvh3-993p.json +++ b/advisories/unreviewed/2025/01/GHSA-6r3v-jvh3-993p/GHSA-6r3v-jvh3-993p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6r3v-jvh3-993p", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57645" ], "details": "An issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json b/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json new file mode 100644 index 00000000000..4bcdffcc9d0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jvg-x7c5-xw29", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2024-50954" + ], + "details": "The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a vulnerability in handling Modbus messages. When a TCP connection is established with the above series of controllers within a local area network (LAN), sending a specific Modbus message to the controller can cause the PLC to crash, interrupting the normal operation of the programs running in the PLC. This results in the ERR indicator light turning on and the RUN indicator light turning off.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50954" + }, + { + "type": "WEB", + "url": "https://github.com/Curator-Kim/Vulnerability-mining/blob/master/XINJE%20XL5E-16T%20XD5E-24R%20Modbus/XINJE%20XL5E-16T%20XD5E-24R%20Modbus.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7w4f-5rcv-q8pc/GHSA-7w4f-5rcv-q8pc.json b/advisories/unreviewed/2025/01/GHSA-7w4f-5rcv-q8pc/GHSA-7w4f-5rcv-q8pc.json new file mode 100644 index 00000000000..744938df5e0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7w4f-5rcv-q8pc/GHSA-7w4f-5rcv-q8pc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w4f-5rcv-q8pc", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2025-20036" + ], + "details": "Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20036" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-85mx-pqv6-r46j/GHSA-85mx-pqv6-r46j.json b/advisories/unreviewed/2025/01/GHSA-85mx-pqv6-r46j/GHSA-85mx-pqv6-r46j.json new file mode 100644 index 00000000000..33db4724258 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-85mx-pqv6-r46j/GHSA-85mx-pqv6-r46j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85mx-pqv6-r46j", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57017" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"pass\" parameter in setVpnAccountCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57017" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setVpnAccountCfg/setVpnAccountCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-86hg-8qx9-pcjm/GHSA-86hg-8qx9-pcjm.json b/advisories/unreviewed/2025/01/GHSA-86hg-8qx9-pcjm/GHSA-86hg-8qx9-pcjm.json new file mode 100644 index 00000000000..5f58e33be10 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-86hg-8qx9-pcjm/GHSA-86hg-8qx9-pcjm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86hg-8qx9-pcjm", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57019" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"limit\" parameter in setVpnAccountCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57019" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setVpnAccountCfg/setVpnAccountCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-87fh-8gjj-2h6f/GHSA-87fh-8gjj-2h6f.json b/advisories/unreviewed/2025/01/GHSA-87fh-8gjj-2h6f/GHSA-87fh-8gjj-2h6f.json new file mode 100644 index 00000000000..a08aecb7093 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-87fh-8gjj-2h6f/GHSA-87fh-8gjj-2h6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87fh-8gjj-2h6f", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22762" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Octrace Studio WordPress HelpDesk & Support Ticket System Plugin – Octrace Support allows Stored XSS.This issue affects WordPress HelpDesk & Support Ticket System Plugin – Octrace Support: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/octrace-support/vulnerability/wordpress-octrace-support-pro-plugin-1-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89gw-cghg-xxj8/GHSA-89gw-cghg-xxj8.json b/advisories/unreviewed/2025/01/GHSA-89gw-cghg-xxj8/GHSA-89gw-cghg-xxj8.json new file mode 100644 index 00000000000..67b604b45e4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-89gw-cghg-xxj8/GHSA-89gw-cghg-xxj8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89gw-cghg-xxj8", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57022" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"sHour\" parameter in setWiFiScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57022" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setWiFiScheduleCfg/setWiFiScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89xc-2h7r-qc62/GHSA-89xc-2h7r-qc62.json b/advisories/unreviewed/2025/01/GHSA-89xc-2h7r-qc62/GHSA-89xc-2h7r-qc62.json new file mode 100644 index 00000000000..1c9d6db2086 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-89xc-2h7r-qc62/GHSA-89xc-2h7r-qc62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89xc-2h7r-qc62", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2025-0502" + ], + "details": "Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0502" + }, + { + "type": "WEB", + "url": "https://craftercms.com/docs/current/security/advisory.html#cv-2025011501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-402" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8cxq-j8f9-28r7/GHSA-8cxq-j8f9-28r7.json b/advisories/unreviewed/2025/01/GHSA-8cxq-j8f9-28r7/GHSA-8cxq-j8f9-28r7.json index 1bffeaab693..ddf0d01886f 100644 --- a/advisories/unreviewed/2025/01/GHSA-8cxq-j8f9-28r7/GHSA-8cxq-j8f9-28r7.json +++ b/advisories/unreviewed/2025/01/GHSA-8cxq-j8f9-28r7/GHSA-8cxq-j8f9-28r7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8cxq-j8f9-28r7", - "modified": "2025-01-15T00:30:42Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T00:30:42Z", "aliases": [ "CVE-2025-22997" ], "details": "A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T00:15:45Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8j3q-gc9x-7972/GHSA-8j3q-gc9x-7972.json b/advisories/unreviewed/2025/01/GHSA-8j3q-gc9x-7972/GHSA-8j3q-gc9x-7972.json new file mode 100644 index 00000000000..4997685c97f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8j3q-gc9x-7972/GHSA-8j3q-gc9x-7972.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j3q-gc9x-7972", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-21088" + ], + "details": "Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21088" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8wr2-f5jf-r84r/GHSA-8wr2-f5jf-r84r.json b/advisories/unreviewed/2025/01/GHSA-8wr2-f5jf-r84r/GHSA-8wr2-f5jf-r84r.json new file mode 100644 index 00000000000..a183cc9de59 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8wr2-f5jf-r84r/GHSA-8wr2-f5jf-r84r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wr2-f5jf-r84r", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22795" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thorsten Krug Multilang Contact Form allows Reflected XSS.This issue affects Multilang Contact Form: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22795" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multilang-contact-form/vulnerability/wordpress-multilang-contact-form-plugin-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8x4q-xm64-x44j/GHSA-8x4q-xm64-x44j.json b/advisories/unreviewed/2025/01/GHSA-8x4q-xm64-x44j/GHSA-8x4q-xm64-x44j.json index 732083556f0..c5e92cd8d4f 100644 --- a/advisories/unreviewed/2025/01/GHSA-8x4q-xm64-x44j/GHSA-8x4q-xm64-x44j.json +++ b/advisories/unreviewed/2025/01/GHSA-8x4q-xm64-x44j/GHSA-8x4q-xm64-x44j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8x4q-xm64-x44j", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57621" ], "details": "An issue in the GDKanalytical_correlation component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-946c-g6p7-pvc8/GHSA-946c-g6p7-pvc8.json b/advisories/unreviewed/2025/01/GHSA-946c-g6p7-pvc8/GHSA-946c-g6p7-pvc8.json new file mode 100644 index 00000000000..390b4ce57a1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-946c-g6p7-pvc8/GHSA-946c-g6p7-pvc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-946c-g6p7-pvc8", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22764" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebs Team - VA Jariwala WP Post Corrector allows Reflected XSS.This issue affects WP Post Corrector: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22764" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-post-corrector/vulnerability/wordpress-wp-post-corrector-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96mp-54h2-gwwh/GHSA-96mp-54h2-gwwh.json b/advisories/unreviewed/2025/01/GHSA-96mp-54h2-gwwh/GHSA-96mp-54h2-gwwh.json new file mode 100644 index 00000000000..594a2420e30 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-96mp-54h2-gwwh/GHSA-96mp-54h2-gwwh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96mp-54h2-gwwh", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22769" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Brahma Multifox allows Stored XSS.This issue affects Multifox: from n/a through 1.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22769" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/multifox/vulnerability/wordpress-multifox-theme-1-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96r6-4wx6-2mhh/GHSA-96r6-4wx6-2mhh.json b/advisories/unreviewed/2025/01/GHSA-96r6-4wx6-2mhh/GHSA-96r6-4wx6-2mhh.json index ac44fdaaeda..fd3fbaaaef4 100644 --- a/advisories/unreviewed/2025/01/GHSA-96r6-4wx6-2mhh/GHSA-96r6-4wx6-2mhh.json +++ b/advisories/unreviewed/2025/01/GHSA-96r6-4wx6-2mhh/GHSA-96r6-4wx6-2mhh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96r6-4wx6-2mhh", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57620" ], "details": "An issue in the trimchars component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-996g-cjm8-8q33/GHSA-996g-cjm8-8q33.json b/advisories/unreviewed/2025/01/GHSA-996g-cjm8-8q33/GHSA-996g-cjm8-8q33.json index 92728d205e2..db47fec893f 100644 --- a/advisories/unreviewed/2025/01/GHSA-996g-cjm8-8q33/GHSA-996g-cjm8-8q33.json +++ b/advisories/unreviewed/2025/01/GHSA-996g-cjm8-8q33/GHSA-996g-cjm8-8q33.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-996g-cjm8-8q33", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57624" ], "details": "An issue in the exp_atom component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9c8h-46w3-gr5h/GHSA-9c8h-46w3-gr5h.json b/advisories/unreviewed/2025/01/GHSA-9c8h-46w3-gr5h/GHSA-9c8h-46w3-gr5h.json index cf2f809a573..7303adb62d0 100644 --- a/advisories/unreviewed/2025/01/GHSA-9c8h-46w3-gr5h/GHSA-9c8h-46w3-gr5h.json +++ b/advisories/unreviewed/2025/01/GHSA-9c8h-46w3-gr5h/GHSA-9c8h-46w3-gr5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9c8h-46w3-gr5h", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57622" ], "details": "An issue in the exp_bin component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9f75-w796-8rf8/GHSA-9f75-w796-8rf8.json b/advisories/unreviewed/2025/01/GHSA-9f75-w796-8rf8/GHSA-9f75-w796-8rf8.json new file mode 100644 index 00000000000..8bf2336187a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9f75-w796-8rf8/GHSA-9f75-w796-8rf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f75-w796-8rf8", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22731" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Build Private Store For Woocommerce allows Cross Site Request Forgery.This issue affects Build Private Store For Woocommerce: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/build-private-store-for-woocommerce/vulnerability/wordpress-build-private-store-for-woocommerce-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9gvr-6qfc-5gqv/GHSA-9gvr-6qfc-5gqv.json b/advisories/unreviewed/2025/01/GHSA-9gvr-6qfc-5gqv/GHSA-9gvr-6qfc-5gqv.json new file mode 100644 index 00000000000..a7dd919bb3d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9gvr-6qfc-5gqv/GHSA-9gvr-6qfc-5gqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gvr-6qfc-5gqv", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22754" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berkman Center for Internet & Society Amber allows Reflected XSS.This issue affects Amber: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22754" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/amberlink/vulnerability/wordpress-amber-plugin-1-4-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9jc3-5fp3-4j23/GHSA-9jc3-5fp3-4j23.json b/advisories/unreviewed/2025/01/GHSA-9jc3-5fp3-4j23/GHSA-9jc3-5fp3-4j23.json new file mode 100644 index 00000000000..0eafc917ff1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9jc3-5fp3-4j23/GHSA-9jc3-5fp3-4j23.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jc3-5fp3-4j23", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22747" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tor Morten Jensen Foundation Columns allows Stored XSS.This issue affects Foundation Columns: from n/a through 0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/foundation-columns/vulnerability/wordpress-foundation-columns-plugin-0-8-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mgw-3v2h-j5xq/GHSA-9mgw-3v2h-j5xq.json b/advisories/unreviewed/2025/01/GHSA-9mgw-3v2h-j5xq/GHSA-9mgw-3v2h-j5xq.json new file mode 100644 index 00000000000..ccc3755efe0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mgw-3v2h-j5xq/GHSA-9mgw-3v2h-j5xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mgw-3v2h-j5xq", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22785" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course Booking System allows SQL Injection.This issue affects Course Booking System: from n/a through 6.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22785" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/course-booking-system/vulnerability/wordpress-course-booking-system-plugin-6-0-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mjh-4fxm-m933/GHSA-9mjh-4fxm-m933.json b/advisories/unreviewed/2025/01/GHSA-9mjh-4fxm-m933/GHSA-9mjh-4fxm-m933.json new file mode 100644 index 00000000000..185b7a2854a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mjh-4fxm-m933/GHSA-9mjh-4fxm-m933.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mjh-4fxm-m933", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22799" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vertim Coders Neon Product Designer allows SQL Injection.This issue affects Neon Product Designer: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/neon-product-designer-for-woocommerce/vulnerability/wordpress-neon-product-designer-plugin-2-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json b/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json new file mode 100644 index 00000000000..245f2f51335 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9ppf-383x-3hmv/GHSA-9ppf-383x-3hmv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ppf-383x-3hmv", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22786" + ], + "details": "Path Traversal vulnerability in ElementInvader ElementInvader Addons for Elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for Elementor: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22786" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elementinvader-addons-for-elementor/vulnerability/wordpress-elementinvader-addons-for-elementor-plugin-1-2-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json b/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json new file mode 100644 index 00000000000..0e97156aae2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9pv3-7hg6-7xj7/GHSA-9pv3-7hg6-7xj7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pv3-7hg6-7xj7", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57014" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"recHour\" parameter in setScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57014" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setScheduleCfg/setScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9qpx-3xf9-26m7/GHSA-9qpx-3xf9-26m7.json b/advisories/unreviewed/2025/01/GHSA-9qpx-3xf9-26m7/GHSA-9qpx-3xf9-26m7.json new file mode 100644 index 00000000000..67a15e1b4e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9qpx-3xf9-26m7/GHSA-9qpx-3xf9-26m7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qpx-3xf9-26m7", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22742" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falldeaf WP ViewSTL allows DOM-Based XSS.This issue affects WP ViewSTL: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22742" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-viewstl/vulnerability/wordpress-wp-viewstl-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c4r3-mg87-6q9h/GHSA-c4r3-mg87-6q9h.json b/advisories/unreviewed/2025/01/GHSA-c4r3-mg87-6q9h/GHSA-c4r3-mg87-6q9h.json new file mode 100644 index 00000000000..cbe3d037344 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c4r3-mg87-6q9h/GHSA-c4r3-mg87-6q9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4r3-mg87-6q9h", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22778" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lijit Networks Inc. and Crowd Favorite Lijit Search allows Reflected XSS.This issue affects Lijit Search: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-lijit-wijit/vulnerability/wordpress-lijit-search-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json b/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json new file mode 100644 index 00000000000..2405e9728cc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5gc-hxmh-64hw", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57025" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"desc\" parameter in setWiFiScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57025" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setWiFiScheduleCfg/setWiFiScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c65j-hphr-96qj/GHSA-c65j-hphr-96qj.json b/advisories/unreviewed/2025/01/GHSA-c65j-hphr-96qj/GHSA-c65j-hphr-96qj.json new file mode 100644 index 00000000000..a956823451f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c65j-hphr-96qj/GHSA-c65j-hphr-96qj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c65j-hphr-96qj", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22766" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masoud Amini Zarinpal Paid Download allows Reflected XSS.This issue affects Zarinpal Paid Download: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zarinpal-paid-downloads/vulnerability/wordpress-zarinpal-paid-download-plugin-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json b/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json new file mode 100644 index 00000000000..885fe9ffb2d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c96m-hgv3-chpf", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57023" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"week\" parameter in setWiFiScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57023" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setWiFiScheduleCfg/setWiFiScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cjxx-684m-35wp/GHSA-cjxx-684m-35wp.json b/advisories/unreviewed/2025/01/GHSA-cjxx-684m-35wp/GHSA-cjxx-684m-35wp.json new file mode 100644 index 00000000000..36c79549670 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cjxx-684m-35wp/GHSA-cjxx-684m-35wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjxx-684m-35wp", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22317" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in galleryape Photo Gallery – Image Gallery by Ape allows Reflected XSS.This issue affects Photo Gallery – Image Gallery by Ape: from n/a through 2.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22317" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-images-ape/vulnerability/wordpress-gallery-images-ape-plugin-2-2-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f2q7-hmv9-hgpp/GHSA-f2q7-hmv9-hgpp.json b/advisories/unreviewed/2025/01/GHSA-f2q7-hmv9-hgpp/GHSA-f2q7-hmv9-hgpp.json index 954b99b3453..20347adab00 100644 --- a/advisories/unreviewed/2025/01/GHSA-f2q7-hmv9-hgpp/GHSA-f2q7-hmv9-hgpp.json +++ b/advisories/unreviewed/2025/01/GHSA-f2q7-hmv9-hgpp/GHSA-f2q7-hmv9-hgpp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f2q7-hmv9-hgpp", - "modified": "2025-01-15T00:30:42Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T00:30:42Z", "aliases": [ "CVE-2025-22996" ], "details": "A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T00:15:45Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f48g-2h6g-pj97/GHSA-f48g-2h6g-pj97.json b/advisories/unreviewed/2025/01/GHSA-f48g-2h6g-pj97/GHSA-f48g-2h6g-pj97.json index 33412121943..91ba3dc7ea7 100644 --- a/advisories/unreviewed/2025/01/GHSA-f48g-2h6g-pj97/GHSA-f48g-2h6g-pj97.json +++ b/advisories/unreviewed/2025/01/GHSA-f48g-2h6g-pj97/GHSA-f48g-2h6g-pj97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f48g-2h6g-pj97", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57647" ], "details": "An issue in the row_insert_cast component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f74f-p8g5-9548/GHSA-f74f-p8g5-9548.json b/advisories/unreviewed/2025/01/GHSA-f74f-p8g5-9548/GHSA-f74f-p8g5-9548.json new file mode 100644 index 00000000000..fc928270925 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f74f-p8g5-9548/GHSA-f74f-p8g5-9548.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f74f-p8g5-9548", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2024-52783" + ], + "details": "Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modification of the configuration file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52783" + }, + { + "type": "WEB", + "url": "https://github.com/Curator-Kim/Vulnerability-mining/blob/master/XDP%20Pro.exe%20incorrect%20permission%20for%20configuration%20file/Incorrect%20permission%20for%20configuration%20file%20in%20XDP%20Pro.exe.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fj2p-q9xp-46j5/GHSA-fj2p-q9xp-46j5.json b/advisories/unreviewed/2025/01/GHSA-fj2p-q9xp-46j5/GHSA-fj2p-q9xp-46j5.json new file mode 100644 index 00000000000..312b0e145ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fj2p-q9xp-46j5/GHSA-fj2p-q9xp-46j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj2p-q9xp-46j5", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22755" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in James Bavington WP Headmaster allows Reflected XSS.This issue affects WP Headmaster: from n/a through 0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22755" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-headmaster/vulnerability/wordpress-wp-headmaster-plugin-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fwj7-ghmr-xxhv/GHSA-fwj7-ghmr-xxhv.json b/advisories/unreviewed/2025/01/GHSA-fwj7-ghmr-xxhv/GHSA-fwj7-ghmr-xxhv.json new file mode 100644 index 00000000000..8bd4e3c4345 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fwj7-ghmr-xxhv/GHSA-fwj7-ghmr-xxhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwj7-ghmr-xxhv", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22736" + ], + "details": "Incorrect Privilege Assignment vulnerability in WPExperts User Management allows Privilege Escalation.This issue affects User Management: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22736" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-management/vulnerability/wordpress-user-management-plugin-1-2-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fx6f-54fh-4xc7/GHSA-fx6f-54fh-4xc7.json b/advisories/unreviewed/2025/01/GHSA-fx6f-54fh-4xc7/GHSA-fx6f-54fh-4xc7.json new file mode 100644 index 00000000000..f18320bb766 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fx6f-54fh-4xc7/GHSA-fx6f-54fh-4xc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx6f-54fh-4xc7", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22737" + ], + "details": "Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22737" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tour-booking-manager/vulnerability/wordpress-wptravelly-plugin-1-8-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json b/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json new file mode 100644 index 00000000000..b146613713e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g3x2-jq2q-7r55/GHSA-g3x2-jq2q-7r55.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3x2-jq2q-7r55", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2024-57013" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"switch\" parameter in setScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57013" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setScheduleCfg/setScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g4gw-8f84-4p28/GHSA-g4gw-8f84-4p28.json b/advisories/unreviewed/2025/01/GHSA-g4gw-8f84-4p28/GHSA-g4gw-8f84-4p28.json new file mode 100644 index 00000000000..f135adf75c2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g4gw-8f84-4p28/GHSA-g4gw-8f84-4p28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4gw-8f84-4p28", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22744" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob von Bothmer / SeoDev S-DEV SEO allows Stored XSS.This issue affects S-DEV SEO: from n/a through 1.88.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22744" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/s-dev-seo/vulnerability/wordpress-s-dev-seo-plugin-1-88-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5px-4886-7gh9/GHSA-g5px-4886-7gh9.json b/advisories/unreviewed/2025/01/GHSA-g5px-4886-7gh9/GHSA-g5px-4886-7gh9.json new file mode 100644 index 00000000000..678d32b77fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5px-4886-7gh9/GHSA-g5px-4886-7gh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5px-4886-7gh9", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22750" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tarak Patel Post Carousel & Slider allows Reflected XSS.This issue affects Post Carousel & Slider: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22750" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-types-carousel-slider/vulnerability/wordpress-post-carousel-slider-plugin-1-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gq5j-324q-qpp8/GHSA-gq5j-324q-qpp8.json b/advisories/unreviewed/2025/01/GHSA-gq5j-324q-qpp8/GHSA-gq5j-324q-qpp8.json new file mode 100644 index 00000000000..db53df96de9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gq5j-324q-qpp8/GHSA-gq5j-324q-qpp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq5j-324q-qpp8", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22729" + ], + "details": "Missing Authorization vulnerability in Infomaniak Staff VOD Infomaniak allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VOD Infomaniak: from n/a through 1.5.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22729" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vod-infomaniak/vulnerability/wordpress-vod-infomaniak-plugin-1-5-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gv3j-p87m-mr7g/GHSA-gv3j-p87m-mr7g.json b/advisories/unreviewed/2025/01/GHSA-gv3j-p87m-mr7g/GHSA-gv3j-p87m-mr7g.json index 9efc30f2e8c..c57402ef8f5 100644 --- a/advisories/unreviewed/2025/01/GHSA-gv3j-p87m-mr7g/GHSA-gv3j-p87m-mr7g.json +++ b/advisories/unreviewed/2025/01/GHSA-gv3j-p87m-mr7g/GHSA-gv3j-p87m-mr7g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gv3j-p87m-mr7g", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57639" ], "details": "An issue in the dc_elt_size component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h394-xchv-jh49/GHSA-h394-xchv-jh49.json b/advisories/unreviewed/2025/01/GHSA-h394-xchv-jh49/GHSA-h394-xchv-jh49.json new file mode 100644 index 00000000000..4d684dd12ee --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h394-xchv-jh49/GHSA-h394-xchv-jh49.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h394-xchv-jh49", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22968" + ], + "details": "An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22968" + }, + { + "type": "WEB", + "url": "https://github.com/CRUNZEX/CVE-2025-22968" + }, + { + "type": "WEB", + "url": "https://github.com/CRUNZEX/CVE-DLINK-LTE" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h654-746f-jr88/GHSA-h654-746f-jr88.json b/advisories/unreviewed/2025/01/GHSA-h654-746f-jr88/GHSA-h654-746f-jr88.json new file mode 100644 index 00000000000..86b91cb1eec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h654-746f-jr88/GHSA-h654-746f-jr88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h654-746f-jr88", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22776" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jay Carter WP Bulletin Board allows Reflected XSS.This issue affects WP Bulletin Board: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-bulletin-board/vulnerability/wordpress-wp-bulletin-board-plugin-1-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h88q-c9px-q22p/GHSA-h88q-c9px-q22p.json b/advisories/unreviewed/2025/01/GHSA-h88q-c9px-q22p/GHSA-h88q-c9px-q22p.json new file mode 100644 index 00000000000..034cb32c20c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h88q-c9px-q22p/GHSA-h88q-c9px-q22p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h88q-c9px-q22p", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-7085" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Solutions Business Manager (SBM) allows Stored XSS. \n\nThe vulnerability could result in the exposure of private information to an unauthorized actor. \n\nThis issue affects Solutions Business Manager (SBM): through 12.2.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:M/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7085" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000036201?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h8hh-7xxw-q4pg/GHSA-h8hh-7xxw-q4pg.json b/advisories/unreviewed/2025/01/GHSA-h8hh-7xxw-q4pg/GHSA-h8hh-7xxw-q4pg.json new file mode 100644 index 00000000000..d7c7b8e49ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h8hh-7xxw-q4pg/GHSA-h8hh-7xxw-q4pg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8hh-7xxw-q4pg", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2025-21083" + ], + "details": "Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21083" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json b/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json new file mode 100644 index 00000000000..a3a179a2f7b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8r3-h3c2-pp25", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57024" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"eMinute\" parameter in setWiFiScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57024" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setWiFiScheduleCfg/setWiFiScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h9hp-h3px-wfqx/GHSA-h9hp-h3px-wfqx.json b/advisories/unreviewed/2025/01/GHSA-h9hp-h3px-wfqx/GHSA-h9hp-h3px-wfqx.json index 42130425c2a..7bb76a3be4f 100644 --- a/advisories/unreviewed/2025/01/GHSA-h9hp-h3px-wfqx/GHSA-h9hp-h3px-wfqx.json +++ b/advisories/unreviewed/2025/01/GHSA-h9hp-h3px-wfqx/GHSA-h9hp-h3px-wfqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9hp-h3px-wfqx", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57640" ], "details": "An issue in the dc_add_int component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json b/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json new file mode 100644 index 00000000000..2297a57e79c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hg7g-25jg-2gmw/GHSA-hg7g-25jg-2gmw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg7g-25jg-2gmw", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2024-57012" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"week\" parameter in setScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57012" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setScheduleCfg/setScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hgg8-mjhj-4642/GHSA-hgg8-mjhj-4642.json b/advisories/unreviewed/2025/01/GHSA-hgg8-mjhj-4642/GHSA-hgg8-mjhj-4642.json index 7094912f3d2..5e2def0fe46 100644 --- a/advisories/unreviewed/2025/01/GHSA-hgg8-mjhj-4642/GHSA-hgg8-mjhj-4642.json +++ b/advisories/unreviewed/2025/01/GHSA-hgg8-mjhj-4642/GHSA-hgg8-mjhj-4642.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hgg8-mjhj-4642", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57648" ], "details": "An issue in the itc_set_param_row component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jggc-fm42-vpxm/GHSA-jggc-fm42-vpxm.json b/advisories/unreviewed/2025/01/GHSA-jggc-fm42-vpxm/GHSA-jggc-fm42-vpxm.json new file mode 100644 index 00000000000..42fb11b5fad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jggc-fm42-vpxm/GHSA-jggc-fm42-vpxm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jggc-fm42-vpxm", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22749" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwoThemes Social Media Engine allows Stored XSS.This issue affects Social Media Engine: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22749" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-media-engine/vulnerability/wordpress-social-media-engine-plugin-1-0-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m7m4-xr7w-gpv4/GHSA-m7m4-xr7w-gpv4.json b/advisories/unreviewed/2025/01/GHSA-m7m4-xr7w-gpv4/GHSA-m7m4-xr7w-gpv4.json index 619364326d5..9ca4c9172b9 100644 --- a/advisories/unreviewed/2025/01/GHSA-m7m4-xr7w-gpv4/GHSA-m7m4-xr7w-gpv4.json +++ b/advisories/unreviewed/2025/01/GHSA-m7m4-xr7w-gpv4/GHSA-m7m4-xr7w-gpv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7m4-xr7w-gpv4", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T15:31:25Z", "aliases": [ "CVE-2024-47002" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2091" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2091" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-m8p9-gp3p-vq9q/GHSA-m8p9-gp3p-vq9q.json b/advisories/unreviewed/2025/01/GHSA-m8p9-gp3p-vq9q/GHSA-m8p9-gp3p-vq9q.json new file mode 100644 index 00000000000..75fbffbdb26 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m8p9-gp3p-vq9q/GHSA-m8p9-gp3p-vq9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8p9-gp3p-vq9q", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22781" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nativery Developer Nativery allows DOM-Based XSS.This issue affects Nativery: from n/a through 0.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nativery/vulnerability/wordpress-nativery-plugin-plugin-0-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mc26-mpwh-wrhc/GHSA-mc26-mpwh-wrhc.json b/advisories/unreviewed/2025/01/GHSA-mc26-mpwh-wrhc/GHSA-mc26-mpwh-wrhc.json new file mode 100644 index 00000000000..fc2bdefca5e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mc26-mpwh-wrhc/GHSA-mc26-mpwh-wrhc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc26-mpwh-wrhc", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22780" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexey Yuzhakov wp-pano allows Stored XSS.This issue affects wp-pano: from n/a through 1.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-pano/vulnerability/wordpress-wp-pano-plugin-1-17-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mm37-x8r8-mr54/GHSA-mm37-x8r8-mr54.json b/advisories/unreviewed/2025/01/GHSA-mm37-x8r8-mr54/GHSA-mm37-x8r8-mr54.json new file mode 100644 index 00000000000..60cace1a01d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mm37-x8r8-mr54/GHSA-mm37-x8r8-mr54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm37-x8r8-mr54", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22793" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bold Bold pagos en linea allows DOM-Based XSS.This issue affects Bold pagos en linea: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22793" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bold-pagos-en-linea/vulnerability/wordpress-bold-pagos-en-linea-plugin-3-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mm92-9vfh-5m9g/GHSA-mm92-9vfh-5m9g.json b/advisories/unreviewed/2025/01/GHSA-mm92-9vfh-5m9g/GHSA-mm92-9vfh-5m9g.json index b1134c028c1..4c92a9deab5 100644 --- a/advisories/unreviewed/2025/01/GHSA-mm92-9vfh-5m9g/GHSA-mm92-9vfh-5m9g.json +++ b/advisories/unreviewed/2025/01/GHSA-mm92-9vfh-5m9g/GHSA-mm92-9vfh-5m9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mm92-9vfh-5m9g", - "modified": "2025-01-15T00:30:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T00:30:41Z", "aliases": [ "CVE-2024-50858" ], "details": "Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T22:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mqpq-866q-4xr5/GHSA-mqpq-866q-4xr5.json b/advisories/unreviewed/2025/01/GHSA-mqpq-866q-4xr5/GHSA-mqpq-866q-4xr5.json new file mode 100644 index 00000000000..75717d8edeb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mqpq-866q-4xr5/GHSA-mqpq-866q-4xr5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqpq-866q-4xr5", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57020" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"sMinute\" parameter in setWiFiScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57020" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setWiFiScheduleCfg/setWiFiScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json b/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json new file mode 100644 index 00000000000..65417f73936 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mx37-rcg6-jwqh/GHSA-mx37-rcg6-jwqh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx37-rcg6-jwqh", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57016" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"user\" parameter in setVpnAccountCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57016" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setVpnAccountCfg/setVpnAccountCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mx7x-mmcr-wf43/GHSA-mx7x-mmcr-wf43.json b/advisories/unreviewed/2025/01/GHSA-mx7x-mmcr-wf43/GHSA-mx7x-mmcr-wf43.json index aba1a07f7de..1439c8e71db 100644 --- a/advisories/unreviewed/2025/01/GHSA-mx7x-mmcr-wf43/GHSA-mx7x-mmcr-wf43.json +++ b/advisories/unreviewed/2025/01/GHSA-mx7x-mmcr-wf43/GHSA-mx7x-mmcr-wf43.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mx7x-mmcr-wf43", - "modified": "2025-01-15T00:30:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T00:30:41Z", "aliases": [ "CVE-2024-50861" ], "details": "The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the \"TSIG Key\" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T22:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p7g7-h5cm-36p7/GHSA-p7g7-h5cm-36p7.json b/advisories/unreviewed/2025/01/GHSA-p7g7-h5cm-36p7/GHSA-p7g7-h5cm-36p7.json index 884502705fa..db1c4748f85 100644 --- a/advisories/unreviewed/2025/01/GHSA-p7g7-h5cm-36p7/GHSA-p7g7-h5cm-36p7.json +++ b/advisories/unreviewed/2025/01/GHSA-p7g7-h5cm-36p7/GHSA-p7g7-h5cm-36p7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p7g7-h5cm-36p7", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57644" ], "details": "An issue in the itc_hash_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-pc9x-x955-fmg3/GHSA-pc9x-x955-fmg3.json b/advisories/unreviewed/2025/01/GHSA-pc9x-x955-fmg3/GHSA-pc9x-x955-fmg3.json new file mode 100644 index 00000000000..314d2d38ef8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pc9x-x955-fmg3/GHSA-pc9x-x955-fmg3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc9x-x955-fmg3", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2024-8603" + ], + "details": "A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8603" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA25P001-c478fad6.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pcqf-5mmm-j2v3/GHSA-pcqf-5mmm-j2v3.json b/advisories/unreviewed/2025/01/GHSA-pcqf-5mmm-j2v3/GHSA-pcqf-5mmm-j2v3.json new file mode 100644 index 00000000000..7223c61eea7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pcqf-5mmm-j2v3/GHSA-pcqf-5mmm-j2v3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcqf-5mmm-j2v3", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22760" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk allows Reflected XSS.This issue affects CodeBard Help Desk: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/codebard-help-desk/vulnerability/wordpress-codebard-help-desk-plugin-1-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pxcr-rm73-9whv/GHSA-pxcr-rm73-9whv.json b/advisories/unreviewed/2025/01/GHSA-pxcr-rm73-9whv/GHSA-pxcr-rm73-9whv.json new file mode 100644 index 00000000000..c09b19cd34f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pxcr-rm73-9whv/GHSA-pxcr-rm73-9whv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxcr-rm73-9whv", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22748" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SetMore Appointments SetMore Theme – Custom Post Types allows Stored XSS.This issue affects SetMore Theme – Custom Post Types: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22748" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/service-provider-profile-cpt/vulnerability/wordpress-setmore-theme-custom-post-types-plugin-1-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q473-3jgq-vvhm/GHSA-q473-3jgq-vvhm.json b/advisories/unreviewed/2025/01/GHSA-q473-3jgq-vvhm/GHSA-q473-3jgq-vvhm.json index d2dbbb7d9db..963b4457cbb 100644 --- a/advisories/unreviewed/2025/01/GHSA-q473-3jgq-vvhm/GHSA-q473-3jgq-vvhm.json +++ b/advisories/unreviewed/2025/01/GHSA-q473-3jgq-vvhm/GHSA-q473-3jgq-vvhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q473-3jgq-vvhm", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T15:31:25Z", "aliases": [ "CVE-2024-47140" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2090" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2090" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-q85h-37g3-grjx/GHSA-q85h-37g3-grjx.json b/advisories/unreviewed/2025/01/GHSA-q85h-37g3-grjx/GHSA-q85h-37g3-grjx.json new file mode 100644 index 00000000000..c6e108b9f95 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q85h-37g3-grjx/GHSA-q85h-37g3-grjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q85h-37g3-grjx", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22751" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mighty Digital Partners allows Reflected XSS.This issue affects Partners: from n/a through 0.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22751" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/partners/vulnerability/wordpress-partners-plugin-0-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qqwq-vvqh-jq2g/GHSA-qqwq-vvqh-jq2g.json b/advisories/unreviewed/2025/01/GHSA-qqwq-vvqh-jq2g/GHSA-qqwq-vvqh-jq2g.json new file mode 100644 index 00000000000..853e02a6314 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qqwq-vvqh-jq2g/GHSA-qqwq-vvqh-jq2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqwq-vvqh-jq2g", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22798" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer Responsive jQuery Slider allows Stored XSS.This issue affects Responsive jQuery Slider: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsive-jquery-slider/vulnerability/wordpress-responsive-jquery-slider-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json b/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json new file mode 100644 index 00000000000..103614fe33a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qrj7-mr7g-fh9r/GHSA-qrj7-mr7g-fh9r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrj7-mr7g-fh9r", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2024-57011" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"minute\" parameters in setScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57011" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setScheduleCfg/setScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qvj3-w34g-r27m/GHSA-qvj3-w34g-r27m.json b/advisories/unreviewed/2025/01/GHSA-qvj3-w34g-r27m/GHSA-qvj3-w34g-r27m.json index 8bbfb4b2c00..11478c2a969 100644 --- a/advisories/unreviewed/2025/01/GHSA-qvj3-w34g-r27m/GHSA-qvj3-w34g-r27m.json +++ b/advisories/unreviewed/2025/01/GHSA-qvj3-w34g-r27m/GHSA-qvj3-w34g-r27m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvj3-w34g-r27m", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-15T15:31:25Z", "aliases": [ "CVE-2024-45061" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2092" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2092" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-qvvq-vvxw-x67x/GHSA-qvvq-vvxw-x67x.json b/advisories/unreviewed/2025/01/GHSA-qvvq-vvxw-x67x/GHSA-qvvq-vvxw-x67x.json new file mode 100644 index 00000000000..f7988b7a23e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qvvq-vvxw-x67x/GHSA-qvvq-vvxw-x67x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvvq-vvxw-x67x", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22734" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Posts Footer Manager allows Stored XSS.This issue affects Posts Footer Manager: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22734" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/intelly-posts-footer-manager/vulnerability/wordpress-posts-footer-manager-plugin-2-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r6hj-h6qx-m84f/GHSA-r6hj-h6qx-m84f.json b/advisories/unreviewed/2025/01/GHSA-r6hj-h6qx-m84f/GHSA-r6hj-h6qx-m84f.json new file mode 100644 index 00000000000..716cacbb1e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r6hj-h6qx-m84f/GHSA-r6hj-h6qx-m84f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6hj-h6qx-m84f", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22587" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NCiphers SEO Bulk Editor allows Stored XSS.This issue affects SEO Bulk Editor: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seo-bulk-editor/vulnerability/wordpress-seo-bulk-editor-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json b/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json index 8f67936a1c8..2d30572ad68 100644 --- a/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json +++ b/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rg8w-4hqw-2p27", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2025-22621" diff --git a/advisories/unreviewed/2025/01/GHSA-rjfq-v4vx-5cwh/GHSA-rjfq-v4vx-5cwh.json b/advisories/unreviewed/2025/01/GHSA-rjfq-v4vx-5cwh/GHSA-rjfq-v4vx-5cwh.json index 2f73b020d0d..5433d5b36e2 100644 --- a/advisories/unreviewed/2025/01/GHSA-rjfq-v4vx-5cwh/GHSA-rjfq-v4vx-5cwh.json +++ b/advisories/unreviewed/2025/01/GHSA-rjfq-v4vx-5cwh/GHSA-rjfq-v4vx-5cwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rjfq-v4vx-5cwh", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57626" ], "details": "An issue in the mat_join2 component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v685-j9j5-5qhv/GHSA-v685-j9j5-5qhv.json b/advisories/unreviewed/2025/01/GHSA-v685-j9j5-5qhv/GHSA-v685-j9j5-5qhv.json index bbefdcfc117..bc09e6efb51 100644 --- a/advisories/unreviewed/2025/01/GHSA-v685-j9j5-5qhv/GHSA-v685-j9j5-5qhv.json +++ b/advisories/unreviewed/2025/01/GHSA-v685-j9j5-5qhv/GHSA-v685-j9j5-5qhv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v685-j9j5-5qhv", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57646" ], "details": "An issue in the psiginfo component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vgfj-pw4m-mj2x/GHSA-vgfj-pw4m-mj2x.json b/advisories/unreviewed/2025/01/GHSA-vgfj-pw4m-mj2x/GHSA-vgfj-pw4m-mj2x.json index e14eb39d6d7..63515a8f3f0 100644 --- a/advisories/unreviewed/2025/01/GHSA-vgfj-pw4m-mj2x/GHSA-vgfj-pw4m-mj2x.json +++ b/advisories/unreviewed/2025/01/GHSA-vgfj-pw4m-mj2x/GHSA-vgfj-pw4m-mj2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vgfj-pw4m-mj2x", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:56Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57649" ], "details": "An issue in the qst_vec_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vw55-rrj3-45hg/GHSA-vw55-rrj3-45hg.json b/advisories/unreviewed/2025/01/GHSA-vw55-rrj3-45hg/GHSA-vw55-rrj3-45hg.json new file mode 100644 index 00000000000..3eaa064b227 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vw55-rrj3-45hg/GHSA-vw55-rrj3-45hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw55-rrj3-45hg", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22724" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP Product Carousel For WooCommerce – WoorouSell allows Stored XSS.This issue affects Product Carousel For WooCommerce – WoorouSell: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22724" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woorousell/vulnerability/wordpress-product-carousel-for-woocommerce-woorousell-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w3cv-ccgf-hx85/GHSA-w3cv-ccgf-hx85.json b/advisories/unreviewed/2025/01/GHSA-w3cv-ccgf-hx85/GHSA-w3cv-ccgf-hx85.json new file mode 100644 index 00000000000..c2bbe2f45fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w3cv-ccgf-hx85/GHSA-w3cv-ccgf-hx85.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3cv-ccgf-hx85", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22743" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin Rasool Twitter Bootstrap Collapse aka Accordian Shortcode allows DOM-Based XSS.This issue affects Twitter Bootstrap Collapse aka Accordian Shortcode: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22743" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/twitter-bootstrap-collapse-aka-accordian-shortcode/vulnerability/wordpress-twitter-bootstrap-collapse-aka-accordian-shortcode-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w6f7-5v79-v5cg/GHSA-w6f7-5v79-v5cg.json b/advisories/unreviewed/2025/01/GHSA-w6f7-5v79-v5cg/GHSA-w6f7-5v79-v5cg.json new file mode 100644 index 00000000000..ddbd7b68e12 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w6f7-5v79-v5cg/GHSA-w6f7-5v79-v5cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6f7-5v79-v5cg", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2020-8094" + ], + "details": "An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8094" + }, + { + "type": "WEB", + "url": "https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-bitdefender-antivirus-free-2020-va-8422" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w853-63rg-474p/GHSA-w853-63rg-474p.json b/advisories/unreviewed/2025/01/GHSA-w853-63rg-474p/GHSA-w853-63rg-474p.json index 67728d2ec79..066ff892ce2 100644 --- a/advisories/unreviewed/2025/01/GHSA-w853-63rg-474p/GHSA-w853-63rg-474p.json +++ b/advisories/unreviewed/2025/01/GHSA-w853-63rg-474p/GHSA-w853-63rg-474p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w853-63rg-474p", - "modified": "2025-01-14T03:31:40Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:40Z", "aliases": [ "CVE-2024-57625" ], "details": "An issue in the merge_table_prune_and_unionize component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w8rp-wpwh-4229/GHSA-w8rp-wpwh-4229.json b/advisories/unreviewed/2025/01/GHSA-w8rp-wpwh-4229/GHSA-w8rp-wpwh-4229.json new file mode 100644 index 00000000000..bacefe25124 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w8rp-wpwh-4229/GHSA-w8rp-wpwh-4229.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8rp-wpwh-4229", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22753" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dueclic turboSMTP allows Reflected XSS.This issue affects turboSMTP: from n/a through 4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/turbosmtp/vulnerability/wordpress-turbosmtp-plugin-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-whh3-h44p-cpv9/GHSA-whh3-h44p-cpv9.json b/advisories/unreviewed/2025/01/GHSA-whh3-h44p-cpv9/GHSA-whh3-h44p-cpv9.json new file mode 100644 index 00000000000..3dbcba2bfa5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-whh3-h44p-cpv9/GHSA-whh3-h44p-cpv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whh3-h44p-cpv9", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22773" + ], + "details": "Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WPChill Htaccess File Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Htaccess File Editor: from n/a through 1.0.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22773" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/htaccess-file-editor/vulnerability/wordpress-htaccess-file-editor-1-0-19-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wp9g-p59f-6fmw/GHSA-wp9g-p59f-6fmw.json b/advisories/unreviewed/2025/01/GHSA-wp9g-p59f-6fmw/GHSA-wp9g-p59f-6fmw.json new file mode 100644 index 00000000000..0f2f7175fcf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wp9g-p59f-6fmw/GHSA-wp9g-p59f-6fmw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp9g-p59f-6fmw", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57021" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"eHour\" parameter in setWiFiScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57021" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setWiFiScheduleCfg/setWiFiScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wqjm-248p-mph4/GHSA-wqjm-248p-mph4.json b/advisories/unreviewed/2025/01/GHSA-wqjm-248p-mph4/GHSA-wqjm-248p-mph4.json new file mode 100644 index 00000000000..94976a312e2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wqjm-248p-mph4/GHSA-wqjm-248p-mph4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqjm-248p-mph4", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57018" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"desc\" parameter in setVpnAccountCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57018" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setVpnAccountCfg/setVpnAccountCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x3q9-c5xr-rhh8/GHSA-x3q9-c5xr-rhh8.json b/advisories/unreviewed/2025/01/GHSA-x3q9-c5xr-rhh8/GHSA-x3q9-c5xr-rhh8.json new file mode 100644 index 00000000000..8cfdd131cc1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x3q9-c5xr-rhh8/GHSA-x3q9-c5xr-rhh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3q9-c5xr-rhh8", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22782" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce allows Upload a Web Shell to a Web Server.This issue affects WR Price List Manager For Woocommerce: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wr-price-list-for-woocommerce/vulnerability/wordpress-wr-price-list-manager-for-woocommerce-plugin-1-0-8-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x6h6-8cff-h9rm/GHSA-x6h6-8cff-h9rm.json b/advisories/unreviewed/2025/01/GHSA-x6h6-8cff-h9rm/GHSA-x6h6-8cff-h9rm.json new file mode 100644 index 00000000000..ed0fb52a254 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x6h6-8cff-h9rm/GHSA-x6h6-8cff-h9rm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6h6-8cff-h9rm", + "modified": "2025-01-15T18:30:56Z", + "published": "2025-01-15T18:30:56Z", + "aliases": [ + "CVE-2025-22738" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TechnoWich WP ULike allows Stored XSS.This issue affects WP ULike: from n/a through 4.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ulike/vulnerability/wordpress-wp-ulike-plugin-4-7-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xgr3-26hm-39gg/GHSA-xgr3-26hm-39gg.json b/advisories/unreviewed/2025/01/GHSA-xgr3-26hm-39gg/GHSA-xgr3-26hm-39gg.json new file mode 100644 index 00000000000..33e4293d6c9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xgr3-26hm-39gg/GHSA-xgr3-26hm-39gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgr3-26hm-39gg", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22787" + ], + "details": "Missing Authorization vulnerability in bPlugins LLC Button Block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Button Block: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/button-block/vulnerability/wordpress-button-block-plugin-1-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xjgg-7884-8gh2/GHSA-xjgg-7884-8gh2.json b/advisories/unreviewed/2025/01/GHSA-xjgg-7884-8gh2/GHSA-xjgg-7884-8gh2.json new file mode 100644 index 00000000000..6c770949f4c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xjgg-7884-8gh2/GHSA-xjgg-7884-8gh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjgg-7884-8gh2", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22797" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oğulcan Özügenç Gallery and Lightbox allows Stored XSS.This issue affects Gallery and Lightbox: from n/a through 1.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22797" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-and-lightbox/vulnerability/wordpress-gallery-and-lightbox-plugin-1-0-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json b/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json new file mode 100644 index 00000000000..2982a67bc48 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xq2j-2jwj-gfcq/GHSA-xq2j-2jwj-gfcq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq2j-2jwj-gfcq", + "modified": "2025-01-15T18:30:58Z", + "published": "2025-01-15T18:30:58Z", + "aliases": [ + "CVE-2024-57015" + ], + "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"hour\" parameter in setScheduleCfg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57015" + }, + { + "type": "WEB", + "url": "https://github.com/tiger5671/Vulnerabilities/blob/main/TOTOLINK%20X5000R/setScheduleCfg/setScheduleCfg.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xq7f-m22p-4r3m/GHSA-xq7f-m22p-4r3m.json b/advisories/unreviewed/2025/01/GHSA-xq7f-m22p-4r3m/GHSA-xq7f-m22p-4r3m.json index 143eb37a5cb..3b58f102330 100644 --- a/advisories/unreviewed/2025/01/GHSA-xq7f-m22p-4r3m/GHSA-xq7f-m22p-4r3m.json +++ b/advisories/unreviewed/2025/01/GHSA-xq7f-m22p-4r3m/GHSA-xq7f-m22p-4r3m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xq7f-m22p-4r3m", - "modified": "2025-01-14T03:31:41Z", + "modified": "2025-01-15T18:30:55Z", "published": "2025-01-14T03:31:41Z", "aliases": [ "CVE-2024-57638" ], "details": "An issue in the dfe_body_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-14T01:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xrxq-r6x5-h4vf/GHSA-xrxq-r6x5-h4vf.json b/advisories/unreviewed/2025/01/GHSA-xrxq-r6x5-h4vf/GHSA-xrxq-r6x5-h4vf.json new file mode 100644 index 00000000000..d9afefd0689 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xrxq-r6x5-h4vf/GHSA-xrxq-r6x5-h4vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrxq-r6x5-h4vf", + "modified": "2025-01-15T18:30:57Z", + "published": "2025-01-15T18:30:57Z", + "aliases": [ + "CVE-2025-22765" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Weil WP Order By allows Reflected XSS.This issue affects WP Order By: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-order-by/vulnerability/wordpress-wp-order-by-plugin-1-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-15T16:15:39Z" + } +} \ No newline at end of file