From 4d173f68789f694386e05b8149e1b3fcce656b98 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Mar 2025 15:32:29 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2hv7-f89v-j5wh.json | 4 +- .../GHSA-53j7-jmxr-99h7.json | 4 +- .../GHSA-5xp3-fjrr-vv46.json | 4 +- .../GHSA-grxj-g635-2wcv.json | 4 +- .../GHSA-jc3f-vxgp-6jw9.json | 14 ++++- .../GHSA-pvfc-f4g9-hh2w.json | 4 +- .../GHSA-rpq9-9pj8-fx9v.json | 4 +- .../GHSA-495v-qvf2-25mh.json | 4 +- .../GHSA-722j-2mgg-rgc3.json | 6 ++- .../GHSA-77cp-583r-8x6c.json | 6 ++- .../GHSA-7xf5-p4g6-46v7.json | 4 +- .../GHSA-962f-jpc6-g76g.json | 6 ++- .../GHSA-gjhq-mx45-hxqm.json | 4 +- .../GHSA-rcmg-f2pm-c8pr.json | 4 +- .../GHSA-xvv7-wqpf-2qrv.json | 6 ++- .../GHSA-7m8c-9m95-h39f.json | 3 +- .../GHSA-c348-367f-c282.json | 1 + .../GHSA-c5cj-hmh6-45pv.json | 3 +- .../GHSA-qj8v-rq4h-7fwh.json | 2 +- .../GHSA-2qxm-j67j-mv87.json | 52 +++++++++++++++++++ .../GHSA-38gj-h5v9-v9pm.json | 36 +++++++++++++ .../GHSA-397j-v2wc-mwf3.json | 15 ++++-- .../GHSA-3g3r-jxgh-3hv4.json | 11 ++-- .../GHSA-3gj6-xgvp-x3gj.json | 52 +++++++++++++++++++ .../GHSA-45j7-2qxv-qg3v.json | 44 ++++++++++++++++ .../GHSA-48fw-wg5j-xwvv.json | 11 ++-- .../GHSA-4j4j-rc2f-g9m5.json | 15 ++++-- .../GHSA-4mv8-627w-3j67.json | 36 +++++++++++++ .../GHSA-4prc-vpwg-w736.json | 36 +++++++++++++ .../GHSA-57fw-f86h-vwgm.json | 36 +++++++++++++ .../GHSA-5mcw-cr6x-67pp.json | 11 ++-- .../GHSA-5wr9-jp8m-f367.json | 36 +++++++++++++ .../GHSA-62qj-786m-q427.json | 29 +++++++++++ .../GHSA-67j5-jp3p-gcg4.json | 44 ++++++++++++++++ .../GHSA-743h-33qg-wchq.json | 36 +++++++++++++ .../GHSA-7xpc-3wwm-65fg.json | 15 ++++-- .../GHSA-84cc-6q9c-25wg.json | 36 +++++++++++++ .../GHSA-8p42-9842-5whf.json | 11 ++-- .../GHSA-8v2j-3jg9-6qr6.json | 44 ++++++++++++++++ .../GHSA-9282-m2c9-q28w.json | 52 +++++++++++++++++++ .../GHSA-ch57-3pgj-79wf.json | 29 +++++++++++ .../GHSA-f8q4-8929-5859.json | 52 +++++++++++++++++++ .../GHSA-fcjw-j93v-hxxq.json | 36 +++++++++++++ .../GHSA-g4hp-jhhg-h69g.json | 44 ++++++++++++++++ .../GHSA-g4r3-8vqc-mhwc.json | 36 +++++++++++++ .../GHSA-g57w-j5gj-29qx.json | 29 +++++++++++ .../GHSA-g8qj-jv5h-78cp.json | 36 +++++++++++++ .../GHSA-gffv-9cg4-8hh4.json | 36 +++++++++++++ .../GHSA-gh94-277f-f7j3.json | 36 +++++++++++++ .../GHSA-h7wp-62hc-fvm5.json | 36 +++++++++++++ .../GHSA-j2cq-g9qm-4pcv.json | 36 +++++++++++++ .../GHSA-j6hj-9xq3-x536.json | 36 +++++++++++++ .../GHSA-j9mc-f96q-8ch7.json | 36 +++++++++++++ .../GHSA-mvc2-5crr-f7g7.json | 36 +++++++++++++ .../GHSA-mxmx-r6p4-736h.json | 44 ++++++++++++++++ .../GHSA-q6qg-c79q-f6q2.json | 11 ++-- .../GHSA-qxjq-4v6j-7ff6.json | 11 ++-- .../GHSA-r63r-pwwp-jvj8.json | 29 +++++++++++ .../GHSA-rmxr-xm7j-cmg8.json | 52 +++++++++++++++++++ .../GHSA-rw47-3hmf-cmhq.json | 15 ++++-- .../GHSA-v987-49gq-jh66.json | 11 ++-- .../GHSA-vcgc-h73q-2m2p.json | 36 +++++++++++++ .../GHSA-vx56-xwhw-6m46.json | 36 +++++++++++++ .../GHSA-w4pp-rhhp-qj56.json | 36 +++++++++++++ .../GHSA-wgm3-f6x3-rj6j.json | 11 ++-- .../GHSA-wpm6-95m5-fpxf.json | 15 ++++-- .../GHSA-xg2h-39gr-h327.json | 36 +++++++++++++ .../GHSA-xp2h-p87p-622p.json | 11 ++-- .../GHSA-xxrr-x8j4-g44v.json | 11 ++-- 69 files changed, 1551 insertions(+), 73 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2qxm-j67j-mv87/GHSA-2qxm-j67j-mv87.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38gj-h5v9-v9pm/GHSA-38gj-h5v9-v9pm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3gj6-xgvp-x3gj/GHSA-3gj6-xgvp-x3gj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-45j7-2qxv-qg3v/GHSA-45j7-2qxv-qg3v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4mv8-627w-3j67/GHSA-4mv8-627w-3j67.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4prc-vpwg-w736/GHSA-4prc-vpwg-w736.json create mode 100644 advisories/unreviewed/2025/03/GHSA-57fw-f86h-vwgm/GHSA-57fw-f86h-vwgm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5wr9-jp8m-f367/GHSA-5wr9-jp8m-f367.json create mode 100644 advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json create mode 100644 advisories/unreviewed/2025/03/GHSA-67j5-jp3p-gcg4/GHSA-67j5-jp3p-gcg4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-743h-33qg-wchq/GHSA-743h-33qg-wchq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-84cc-6q9c-25wg/GHSA-84cc-6q9c-25wg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8v2j-3jg9-6qr6/GHSA-8v2j-3jg9-6qr6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9282-m2c9-q28w/GHSA-9282-m2c9-q28w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f8q4-8929-5859/GHSA-f8q4-8929-5859.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fcjw-j93v-hxxq/GHSA-fcjw-j93v-hxxq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g4hp-jhhg-h69g/GHSA-g4hp-jhhg-h69g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g4r3-8vqc-mhwc/GHSA-g4r3-8vqc-mhwc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gffv-9cg4-8hh4/GHSA-gffv-9cg4-8hh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh94-277f-f7j3/GHSA-gh94-277f-f7j3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h7wp-62hc-fvm5/GHSA-h7wp-62hc-fvm5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j2cq-g9qm-4pcv/GHSA-j2cq-g9qm-4pcv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j6hj-9xq3-x536/GHSA-j6hj-9xq3-x536.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j9mc-f96q-8ch7/GHSA-j9mc-f96q-8ch7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mvc2-5crr-f7g7/GHSA-mvc2-5crr-f7g7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mxmx-r6p4-736h/GHSA-mxmx-r6p4-736h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rmxr-xm7j-cmg8/GHSA-rmxr-xm7j-cmg8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vx56-xwhw-6m46/GHSA-vx56-xwhw-6m46.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w4pp-rhhp-qj56/GHSA-w4pp-rhhp-qj56.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xg2h-39gr-h327/GHSA-xg2h-39gr-h327.json diff --git a/advisories/unreviewed/2023/02/GHSA-2hv7-f89v-j5wh/GHSA-2hv7-f89v-j5wh.json b/advisories/unreviewed/2023/02/GHSA-2hv7-f89v-j5wh/GHSA-2hv7-f89v-j5wh.json index e4e01993f69..d8bfc507522 100644 --- a/advisories/unreviewed/2023/02/GHSA-2hv7-f89v-j5wh/GHSA-2hv7-f89v-j5wh.json +++ b/advisories/unreviewed/2023/02/GHSA-2hv7-f89v-j5wh/GHSA-2hv7-f89v-j5wh.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-53j7-jmxr-99h7/GHSA-53j7-jmxr-99h7.json b/advisories/unreviewed/2023/02/GHSA-53j7-jmxr-99h7/GHSA-53j7-jmxr-99h7.json index 22b149ffe31..a5eb26e39c5 100644 --- a/advisories/unreviewed/2023/02/GHSA-53j7-jmxr-99h7/GHSA-53j7-jmxr-99h7.json +++ b/advisories/unreviewed/2023/02/GHSA-53j7-jmxr-99h7/GHSA-53j7-jmxr-99h7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-5xp3-fjrr-vv46/GHSA-5xp3-fjrr-vv46.json b/advisories/unreviewed/2023/02/GHSA-5xp3-fjrr-vv46/GHSA-5xp3-fjrr-vv46.json index 176a1e20c8d..09fedcfccd2 100644 --- a/advisories/unreviewed/2023/02/GHSA-5xp3-fjrr-vv46/GHSA-5xp3-fjrr-vv46.json +++ b/advisories/unreviewed/2023/02/GHSA-5xp3-fjrr-vv46/GHSA-5xp3-fjrr-vv46.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-grxj-g635-2wcv/GHSA-grxj-g635-2wcv.json b/advisories/unreviewed/2023/02/GHSA-grxj-g635-2wcv/GHSA-grxj-g635-2wcv.json index 4d173b17f70..a4c55f32dd1 100644 --- a/advisories/unreviewed/2023/02/GHSA-grxj-g635-2wcv/GHSA-grxj-g635-2wcv.json +++ b/advisories/unreviewed/2023/02/GHSA-grxj-g635-2wcv/GHSA-grxj-g635-2wcv.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-jc3f-vxgp-6jw9/GHSA-jc3f-vxgp-6jw9.json b/advisories/unreviewed/2023/02/GHSA-jc3f-vxgp-6jw9/GHSA-jc3f-vxgp-6jw9.json index f0e1fa5d681..3f3122a4ae6 100644 --- a/advisories/unreviewed/2023/02/GHSA-jc3f-vxgp-6jw9/GHSA-jc3f-vxgp-6jw9.json +++ b/advisories/unreviewed/2023/02/GHSA-jc3f-vxgp-6jw9/GHSA-jc3f-vxgp-6jw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jc3f-vxgp-6jw9", - "modified": "2023-03-06T18:30:22Z", + "modified": "2025-03-11T15:30:53Z", "published": "2023-02-28T21:30:16Z", "aliases": [ "CVE-2023-27372" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://git.spip.net/spip/spip/commit/96fbeb38711c6706e62457f2b732a652a04a409d" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/171921" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/173044" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5367" @@ -45,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-pvfc-f4g9-hh2w/GHSA-pvfc-f4g9-hh2w.json b/advisories/unreviewed/2023/02/GHSA-pvfc-f4g9-hh2w/GHSA-pvfc-f4g9-hh2w.json index 9f74e9400c1..ba45347ffd5 100644 --- a/advisories/unreviewed/2023/02/GHSA-pvfc-f4g9-hh2w/GHSA-pvfc-f4g9-hh2w.json +++ b/advisories/unreviewed/2023/02/GHSA-pvfc-f4g9-hh2w/GHSA-pvfc-f4g9-hh2w.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-rpq9-9pj8-fx9v/GHSA-rpq9-9pj8-fx9v.json b/advisories/unreviewed/2023/02/GHSA-rpq9-9pj8-fx9v/GHSA-rpq9-9pj8-fx9v.json index ebac4bf4465..080bcd3e0de 100644 --- a/advisories/unreviewed/2023/02/GHSA-rpq9-9pj8-fx9v/GHSA-rpq9-9pj8-fx9v.json +++ b/advisories/unreviewed/2023/02/GHSA-rpq9-9pj8-fx9v/GHSA-rpq9-9pj8-fx9v.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-495v-qvf2-25mh/GHSA-495v-qvf2-25mh.json b/advisories/unreviewed/2024/03/GHSA-495v-qvf2-25mh/GHSA-495v-qvf2-25mh.json index 48ac14c52c2..2a8be5d589a 100644 --- a/advisories/unreviewed/2024/03/GHSA-495v-qvf2-25mh/GHSA-495v-qvf2-25mh.json +++ b/advisories/unreviewed/2024/03/GHSA-495v-qvf2-25mh/GHSA-495v-qvf2-25mh.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-722j-2mgg-rgc3/GHSA-722j-2mgg-rgc3.json b/advisories/unreviewed/2024/03/GHSA-722j-2mgg-rgc3/GHSA-722j-2mgg-rgc3.json index 598ff0fc9a5..23156712f5e 100644 --- a/advisories/unreviewed/2024/03/GHSA-722j-2mgg-rgc3/GHSA-722j-2mgg-rgc3.json +++ b/advisories/unreviewed/2024/03/GHSA-722j-2mgg-rgc3/GHSA-722j-2mgg-rgc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-722j-2mgg-rgc3", - "modified": "2024-03-13T18:31:32Z", + "modified": "2025-03-11T15:30:57Z", "published": "2024-03-13T18:31:32Z", "aliases": [ "CVE-2024-0828" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-77cp-583r-8x6c/GHSA-77cp-583r-8x6c.json b/advisories/unreviewed/2024/03/GHSA-77cp-583r-8x6c/GHSA-77cp-583r-8x6c.json index fb8f887f7ba..ac2caf67c26 100644 --- a/advisories/unreviewed/2024/03/GHSA-77cp-583r-8x6c/GHSA-77cp-583r-8x6c.json +++ b/advisories/unreviewed/2024/03/GHSA-77cp-583r-8x6c/GHSA-77cp-583r-8x6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77cp-583r-8x6c", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-03-11T15:30:57Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1158" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7xf5-p4g6-46v7/GHSA-7xf5-p4g6-46v7.json b/advisories/unreviewed/2024/03/GHSA-7xf5-p4g6-46v7/GHSA-7xf5-p4g6-46v7.json index 067bbc4b33b..e237d47c081 100644 --- a/advisories/unreviewed/2024/03/GHSA-7xf5-p4g6-46v7/GHSA-7xf5-p4g6-46v7.json +++ b/advisories/unreviewed/2024/03/GHSA-7xf5-p4g6-46v7/GHSA-7xf5-p4g6-46v7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-962f-jpc6-g76g/GHSA-962f-jpc6-g76g.json b/advisories/unreviewed/2024/03/GHSA-962f-jpc6-g76g/GHSA-962f-jpc6-g76g.json index f2d2282c16f..78ee14102b5 100644 --- a/advisories/unreviewed/2024/03/GHSA-962f-jpc6-g76g/GHSA-962f-jpc6-g76g.json +++ b/advisories/unreviewed/2024/03/GHSA-962f-jpc6-g76g/GHSA-962f-jpc6-g76g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-962f-jpc6-g76g", - "modified": "2024-03-13T18:31:32Z", + "modified": "2025-03-11T15:30:57Z", "published": "2024-03-13T18:31:32Z", "aliases": [ "CVE-2024-0898" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gjhq-mx45-hxqm/GHSA-gjhq-mx45-hxqm.json b/advisories/unreviewed/2024/03/GHSA-gjhq-mx45-hxqm/GHSA-gjhq-mx45-hxqm.json index 12260ae52db..e51ac3202ed 100644 --- a/advisories/unreviewed/2024/03/GHSA-gjhq-mx45-hxqm/GHSA-gjhq-mx45-hxqm.json +++ b/advisories/unreviewed/2024/03/GHSA-gjhq-mx45-hxqm/GHSA-gjhq-mx45-hxqm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rcmg-f2pm-c8pr/GHSA-rcmg-f2pm-c8pr.json b/advisories/unreviewed/2024/03/GHSA-rcmg-f2pm-c8pr/GHSA-rcmg-f2pm-c8pr.json index 184ee638a2b..3f095ebd3fe 100644 --- a/advisories/unreviewed/2024/03/GHSA-rcmg-f2pm-c8pr/GHSA-rcmg-f2pm-c8pr.json +++ b/advisories/unreviewed/2024/03/GHSA-rcmg-f2pm-c8pr/GHSA-rcmg-f2pm-c8pr.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xvv7-wqpf-2qrv/GHSA-xvv7-wqpf-2qrv.json b/advisories/unreviewed/2024/03/GHSA-xvv7-wqpf-2qrv/GHSA-xvv7-wqpf-2qrv.json index d6b8f5a7dee..649210fb251 100644 --- a/advisories/unreviewed/2024/03/GHSA-xvv7-wqpf-2qrv/GHSA-xvv7-wqpf-2qrv.json +++ b/advisories/unreviewed/2024/03/GHSA-xvv7-wqpf-2qrv/GHSA-xvv7-wqpf-2qrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvv7-wqpf-2qrv", - "modified": "2024-03-13T18:31:32Z", + "modified": "2025-03-11T15:30:57Z", "published": "2024-03-13T18:31:32Z", "aliases": [ "CVE-2024-0827" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-7m8c-9m95-h39f/GHSA-7m8c-9m95-h39f.json b/advisories/unreviewed/2025/02/GHSA-7m8c-9m95-h39f/GHSA-7m8c-9m95-h39f.json index 2e9ff99b057..ca16343702e 100644 --- a/advisories/unreviewed/2025/02/GHSA-7m8c-9m95-h39f/GHSA-7m8c-9m95-h39f.json +++ b/advisories/unreviewed/2025/02/GHSA-7m8c-9m95-h39f/GHSA-7m8c-9m95-h39f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7m8c-9m95-h39f", - "modified": "2025-02-20T06:31:03Z", + "modified": "2025-03-11T15:30:57Z", "published": "2025-02-20T06:31:03Z", "aliases": [ "CVE-2024-49355" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-c348-367f-c282/GHSA-c348-367f-c282.json b/advisories/unreviewed/2025/02/GHSA-c348-367f-c282/GHSA-c348-367f-c282.json index b0dcb9a8539..74088c5cbea 100644 --- a/advisories/unreviewed/2025/02/GHSA-c348-367f-c282/GHSA-c348-367f-c282.json +++ b/advisories/unreviewed/2025/02/GHSA-c348-367f-c282/GHSA-c348-367f-c282.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-c5cj-hmh6-45pv/GHSA-c5cj-hmh6-45pv.json b/advisories/unreviewed/2025/02/GHSA-c5cj-hmh6-45pv/GHSA-c5cj-hmh6-45pv.json index f049b88f3cc..9368c1cb9bd 100644 --- a/advisories/unreviewed/2025/02/GHSA-c5cj-hmh6-45pv/GHSA-c5cj-hmh6-45pv.json +++ b/advisories/unreviewed/2025/02/GHSA-c5cj-hmh6-45pv/GHSA-c5cj-hmh6-45pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5cj-hmh6-45pv", - "modified": "2025-02-20T06:31:03Z", + "modified": "2025-03-11T15:30:57Z", "published": "2025-02-20T06:31:03Z", "aliases": [ "CVE-2024-49782" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-295", "CWE-297" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-qj8v-rq4h-7fwh/GHSA-qj8v-rq4h-7fwh.json b/advisories/unreviewed/2025/02/GHSA-qj8v-rq4h-7fwh/GHSA-qj8v-rq4h-7fwh.json index 0f0bf481290..783a9537c1a 100644 --- a/advisories/unreviewed/2025/02/GHSA-qj8v-rq4h-7fwh/GHSA-qj8v-rq4h-7fwh.json +++ b/advisories/unreviewed/2025/02/GHSA-qj8v-rq4h-7fwh/GHSA-qj8v-rq4h-7fwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qj8v-rq4h-7fwh", - "modified": "2025-02-20T12:31:13Z", + "modified": "2025-03-11T15:30:57Z", "published": "2025-02-20T06:31:03Z", "aliases": [ "CVE-2024-49780" diff --git a/advisories/unreviewed/2025/03/GHSA-2qxm-j67j-mv87/GHSA-2qxm-j67j-mv87.json b/advisories/unreviewed/2025/03/GHSA-2qxm-j67j-mv87/GHSA-2qxm-j67j-mv87.json new file mode 100644 index 00000000000..630c72e38e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2qxm-j67j-mv87/GHSA-2qxm-j67j-mv87.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qxm-j67j-mv87", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-2195" + ], + "details": "A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument name/path leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2195" + }, + { + "type": "WEB", + "url": "https://github.com/IceFoxH/VULN/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299220" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299220" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38gj-h5v9-v9pm/GHSA-38gj-h5v9-v9pm.json b/advisories/unreviewed/2025/03/GHSA-38gj-h5v9-v9pm/GHSA-38gj-h5v9-v9pm.json new file mode 100644 index 00000000000..7114b9d0cab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38gj-h5v9-v9pm/GHSA-38gj-h5v9-v9pm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38gj-h5v9-v9pm", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2025-22454" + ], + "details": "Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22454" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/March-Security-Advisory-Ivanti-Secure-Access-Client-ISAC-CVE-2025-22454" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-397j-v2wc-mwf3/GHSA-397j-v2wc-mwf3.json b/advisories/unreviewed/2025/03/GHSA-397j-v2wc-mwf3/GHSA-397j-v2wc-mwf3.json index 9379f07cc15..b86f57c79f1 100644 --- a/advisories/unreviewed/2025/03/GHSA-397j-v2wc-mwf3/GHSA-397j-v2wc-mwf3.json +++ b/advisories/unreviewed/2025/03/GHSA-397j-v2wc-mwf3/GHSA-397j-v2wc-mwf3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-397j-v2wc-mwf3", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-54469" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sequoia 15, macOS Sonoma 14.7, visionOS 2, iOS 18 and iPadOS 18. A local user may be able to leak sensitive user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json b/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json index da394e8c497..b581dae1f20 100644 --- a/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json +++ b/advisories/unreviewed/2025/03/GHSA-3g3r-jxgh-3hv4/GHSA-3g3r-jxgh-3hv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3g3r-jxgh-3hv4", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13862" ], "details": "The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3gj6-xgvp-x3gj/GHSA-3gj6-xgvp-x3gj.json b/advisories/unreviewed/2025/03/GHSA-3gj6-xgvp-x3gj/GHSA-3gj6-xgvp-x3gj.json new file mode 100644 index 00000000000..abc6b3ecad8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3gj6-xgvp-x3gj/GHSA-3gj6-xgvp-x3gj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gj6-xgvp-x3gj", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-2196" + ], + "details": "A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /admin/file/upload.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2196" + }, + { + "type": "WEB", + "url": "https://github.com/IceFoxH/VULN/issues/5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299221" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299221" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511735" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-45j7-2qxv-qg3v/GHSA-45j7-2qxv-qg3v.json b/advisories/unreviewed/2025/03/GHSA-45j7-2qxv-qg3v/GHSA-45j7-2qxv-qg3v.json new file mode 100644 index 00000000000..0599bccffd9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-45j7-2qxv-qg3v/GHSA-45j7-2qxv-qg3v.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45j7-2qxv-qg3v", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-22369" + ], + "details": "The ReadFile endpoint of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to read arbitrary files from the underlying OS.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22369" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22369" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00003" + }, + { + "type": "WEB", + "url": "https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-48fw-wg5j-xwvv/GHSA-48fw-wg5j-xwvv.json b/advisories/unreviewed/2025/03/GHSA-48fw-wg5j-xwvv/GHSA-48fw-wg5j-xwvv.json index bb0d5921091..13c76dade99 100644 --- a/advisories/unreviewed/2025/03/GHSA-48fw-wg5j-xwvv/GHSA-48fw-wg5j-xwvv.json +++ b/advisories/unreviewed/2025/03/GHSA-48fw-wg5j-xwvv/GHSA-48fw-wg5j-xwvv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48fw-wg5j-xwvv", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13574" ], "details": "The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4j4j-rc2f-g9m5/GHSA-4j4j-rc2f-g9m5.json b/advisories/unreviewed/2025/03/GHSA-4j4j-rc2f-g9m5/GHSA-4j4j-rc2f-g9m5.json index 617aa0a4d7e..926e0366242 100644 --- a/advisories/unreviewed/2025/03/GHSA-4j4j-rc2f-g9m5/GHSA-4j4j-rc2f-g9m5.json +++ b/advisories/unreviewed/2025/03/GHSA-4j4j-rc2f-g9m5/GHSA-4j4j-rc2f-g9m5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4j4j-rc2f-g9m5", - "modified": "2025-03-10T21:31:11Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-10T21:31:11Z", "aliases": [ "CVE-2024-44192" ], "details": "The issue was addressed with improved checks. This issue is fixed in watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4mv8-627w-3j67/GHSA-4mv8-627w-3j67.json b/advisories/unreviewed/2025/03/GHSA-4mv8-627w-3j67/GHSA-4mv8-627w-3j67.json new file mode 100644 index 00000000000..8538f679562 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4mv8-627w-3j67/GHSA-4mv8-627w-3j67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mv8-627w-3j67", + "modified": "2025-03-11T15:30:59Z", + "published": "2025-03-11T15:30:59Z", + "aliases": [ + "CVE-2024-12546" + ], + "details": "EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12546" + }, + { + "type": "WEB", + "url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2025/AMI-SA-2025003.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4prc-vpwg-w736/GHSA-4prc-vpwg-w736.json b/advisories/unreviewed/2025/03/GHSA-4prc-vpwg-w736/GHSA-4prc-vpwg-w736.json new file mode 100644 index 00000000000..ffd1eae03a8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4prc-vpwg-w736/GHSA-4prc-vpwg-w736.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4prc-vpwg-w736", + "modified": "2025-03-11T15:30:59Z", + "published": "2025-03-11T15:30:59Z", + "aliases": [ + "CVE-2024-54084" + ], + "details": "APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition by local means. Successful exploitation of this vulnerability may lead to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54084" + }, + { + "type": "WEB", + "url": "https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57fw-f86h-vwgm/GHSA-57fw-f86h-vwgm.json b/advisories/unreviewed/2025/03/GHSA-57fw-f86h-vwgm/GHSA-57fw-f86h-vwgm.json new file mode 100644 index 00000000000..8293ca08a74 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-57fw-f86h-vwgm/GHSA-57fw-f86h-vwgm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57fw-f86h-vwgm", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-46663" + ], + "details": "A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46663" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-331" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5mcw-cr6x-67pp/GHSA-5mcw-cr6x-67pp.json b/advisories/unreviewed/2025/03/GHSA-5mcw-cr6x-67pp/GHSA-5mcw-cr6x-67pp.json index 385e40abac0..82b4a5a9ee7 100644 --- a/advisories/unreviewed/2025/03/GHSA-5mcw-cr6x-67pp/GHSA-5mcw-cr6x-67pp.json +++ b/advisories/unreviewed/2025/03/GHSA-5mcw-cr6x-67pp/GHSA-5mcw-cr6x-67pp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5mcw-cr6x-67pp", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13864" ], "details": "The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5wr9-jp8m-f367/GHSA-5wr9-jp8m-f367.json b/advisories/unreviewed/2025/03/GHSA-5wr9-jp8m-f367/GHSA-5wr9-jp8m-f367.json new file mode 100644 index 00000000000..6effb9601f6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5wr9-jp8m-f367/GHSA-5wr9-jp8m-f367.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wr9-jp8m-f367", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2023-42784" + ], + "details": "An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42784" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-228" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json b/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json new file mode 100644 index 00000000000..767a173c8f4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62qj-786m-q427", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-51320" + ], + "details": "Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51320" + }, + { + "type": "WEB", + "url": "https://members.backbox.org/zucchetti-ad-hoc-infinity-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-67j5-jp3p-gcg4/GHSA-67j5-jp3p-gcg4.json b/advisories/unreviewed/2025/03/GHSA-67j5-jp3p-gcg4/GHSA-67j5-jp3p-gcg4.json new file mode 100644 index 00000000000..d06337a8951 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-67j5-jp3p-gcg4/GHSA-67j5-jp3p-gcg4.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67j5-jp3p-gcg4", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-22366" + ], + "details": "The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22366" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22366" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00003" + }, + { + "type": "WEB", + "url": "https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-743h-33qg-wchq/GHSA-743h-33qg-wchq.json b/advisories/unreviewed/2025/03/GHSA-743h-33qg-wchq/GHSA-743h-33qg-wchq.json new file mode 100644 index 00000000000..04470b0e6c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-743h-33qg-wchq/GHSA-743h-33qg-wchq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-743h-33qg-wchq", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-52960" + ], + "details": "A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52960" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7xpc-3wwm-65fg/GHSA-7xpc-3wwm-65fg.json b/advisories/unreviewed/2025/03/GHSA-7xpc-3wwm-65fg/GHSA-7xpc-3wwm-65fg.json index 7851a0996ca..23c19e83983 100644 --- a/advisories/unreviewed/2025/03/GHSA-7xpc-3wwm-65fg/GHSA-7xpc-3wwm-65fg.json +++ b/advisories/unreviewed/2025/03/GHSA-7xpc-3wwm-65fg/GHSA-7xpc-3wwm-65fg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xpc-3wwm-65fg", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-54473" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-84cc-6q9c-25wg/GHSA-84cc-6q9c-25wg.json b/advisories/unreviewed/2025/03/GHSA-84cc-6q9c-25wg/GHSA-84cc-6q9c-25wg.json new file mode 100644 index 00000000000..c7458ef6f26 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-84cc-6q9c-25wg/GHSA-84cc-6q9c-25wg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84cc-6q9c-25wg", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2023-37933" + ], + "details": "An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1\tand before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37933" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8p42-9842-5whf/GHSA-8p42-9842-5whf.json b/advisories/unreviewed/2025/03/GHSA-8p42-9842-5whf/GHSA-8p42-9842-5whf.json index 2d588432827..7170a86951d 100644 --- a/advisories/unreviewed/2025/03/GHSA-8p42-9842-5whf/GHSA-8p42-9842-5whf.json +++ b/advisories/unreviewed/2025/03/GHSA-8p42-9842-5whf/GHSA-8p42-9842-5whf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8p42-9842-5whf", - "modified": "2025-03-10T21:31:13Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-10T21:31:13Z", "aliases": [ "CVE-2025-2137" ], "details": "Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T21:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8v2j-3jg9-6qr6/GHSA-8v2j-3jg9-6qr6.json b/advisories/unreviewed/2025/03/GHSA-8v2j-3jg9-6qr6/GHSA-8v2j-3jg9-6qr6.json new file mode 100644 index 00000000000..7681319bfb3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8v2j-3jg9-6qr6/GHSA-8v2j-3jg9-6qr6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v2j-3jg9-6qr6", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-22368" + ], + "details": "The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS commands are improperly neutralized when certain fields are passed to the underlying OS.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22368" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22368" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00003" + }, + { + "type": "WEB", + "url": "https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9282-m2c9-q28w/GHSA-9282-m2c9-q28w.json b/advisories/unreviewed/2025/03/GHSA-9282-m2c9-q28w/GHSA-9282-m2c9-q28w.json new file mode 100644 index 00000000000..f7df9dd3fe0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9282-m2c9-q28w/GHSA-9282-m2c9-q28w.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9282-m2c9-q28w", + "modified": "2025-03-11T15:30:59Z", + "published": "2025-03-11T15:30:59Z", + "aliases": [ + "CVE-2025-2192" + ], + "details": "A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component Login Page. The manipulation of the argument inpRedirectURL leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2192" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/17QAEbzVIjTUj8FDOVMwfl9-7j8LRcK4V/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299217" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299217" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511708" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json b/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json new file mode 100644 index 00000000000..4844e5c3200 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch57-3pgj-79wf", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-51322" + ], + "details": "Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51322" + }, + { + "type": "WEB", + "url": "https://members.backbox.org/zucchetti-ad-hoc-infinity-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f8q4-8929-5859/GHSA-f8q4-8929-5859.json b/advisories/unreviewed/2025/03/GHSA-f8q4-8929-5859/GHSA-f8q4-8929-5859.json new file mode 100644 index 00000000000..767a245ca7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f8q4-8929-5859/GHSA-f8q4-8929-5859.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8q4-8929-5859", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-2194" + ], + "details": "A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2194" + }, + { + "type": "WEB", + "url": "https://github.com/IceFoxH/VULN/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511732" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fcjw-j93v-hxxq/GHSA-fcjw-j93v-hxxq.json b/advisories/unreviewed/2025/03/GHSA-fcjw-j93v-hxxq/GHSA-fcjw-j93v-hxxq.json new file mode 100644 index 00000000000..044aabed919 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fcjw-j93v-hxxq/GHSA-fcjw-j93v-hxxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcjw-j93v-hxxq", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2023-48790" + ], + "details": "A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48790" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g4hp-jhhg-h69g/GHSA-g4hp-jhhg-h69g.json b/advisories/unreviewed/2025/03/GHSA-g4hp-jhhg-h69g/GHSA-g4hp-jhhg-h69g.json new file mode 100644 index 00000000000..e55aadf50e1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g4hp-jhhg-h69g/GHSA-g4hp-jhhg-h69g.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4hp-jhhg-h69g", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-22370" + ], + "details": "Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22370" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22370" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00003" + }, + { + "type": "WEB", + "url": "https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g4r3-8vqc-mhwc/GHSA-g4r3-8vqc-mhwc.json b/advisories/unreviewed/2025/03/GHSA-g4r3-8vqc-mhwc/GHSA-g4r3-8vqc-mhwc.json new file mode 100644 index 00000000000..d54455715f6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g4r3-8vqc-mhwc/GHSA-g4r3-8vqc-mhwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4r3-8vqc-mhwc", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2023-40723" + ], + "details": "An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through 6.1.2 and 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 allows attacker to execute unauthorized code or commands via api request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40723" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json b/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json new file mode 100644 index 00000000000..2679d328e2b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g57w-j5gj-29qx", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-51319" + ], + "details": "A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51319" + }, + { + "type": "WEB", + "url": "https://members.backbox.org/zucchetti-ad-hoc-infinity-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json b/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json new file mode 100644 index 00000000000..a3277355a1e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g8qj-jv5h-78cp/GHSA-g8qj-jv5h-78cp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8qj-jv5h-78cp", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-27363" + ], + "details": "An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27363" + }, + { + "type": "WEB", + "url": "https://www.facebook.com/security/advisories/cve-2025-27363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gffv-9cg4-8hh4/GHSA-gffv-9cg4-8hh4.json b/advisories/unreviewed/2025/03/GHSA-gffv-9cg4-8hh4/GHSA-gffv-9cg4-8hh4.json new file mode 100644 index 00000000000..f70631fcbd6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gffv-9cg4-8hh4/GHSA-gffv-9cg4-8hh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gffv-9cg4-8hh4", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-45324" + ], + "details": "A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 through 1.4.2 and before 1.3.1 and FortiWeb version 7.4.0 through 7.4.5, version 7.2.0 through 7.2.10 and before 7.0.10 allows a privileged attacker to execute unauthorized code or commands via specially crafted HTTP or HTTPS commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45324" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-325" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-134" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gh94-277f-f7j3/GHSA-gh94-277f-f7j3.json b/advisories/unreviewed/2025/03/GHSA-gh94-277f-f7j3/GHSA-gh94-277f-f7j3.json new file mode 100644 index 00000000000..c9065a17491 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gh94-277f-f7j3/GHSA-gh94-277f-f7j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh94-277f-f7j3", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-55597" + ], + "details": "A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55597" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-439" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h7wp-62hc-fvm5/GHSA-h7wp-62hc-fvm5.json b/advisories/unreviewed/2025/03/GHSA-h7wp-62hc-fvm5/GHSA-h7wp-62hc-fvm5.json new file mode 100644 index 00000000000..75a351f0061 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h7wp-62hc-fvm5/GHSA-h7wp-62hc-fvm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7wp-62hc-fvm5", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-33501" + ], + "details": "Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via specifically crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33501" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j2cq-g9qm-4pcv/GHSA-j2cq-g9qm-4pcv.json b/advisories/unreviewed/2025/03/GHSA-j2cq-g9qm-4pcv/GHSA-j2cq-g9qm-4pcv.json new file mode 100644 index 00000000000..283ba953d5b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j2cq-g9qm-4pcv/GHSA-j2cq-g9qm-4pcv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2cq-g9qm-4pcv", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-54018" + ], + "details": "Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54018" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j6hj-9xq3-x536/GHSA-j6hj-9xq3-x536.json b/advisories/unreviewed/2025/03/GHSA-j6hj-9xq3-x536/GHSA-j6hj-9xq3-x536.json new file mode 100644 index 00000000000..7a68870b2e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j6hj-9xq3-x536/GHSA-j6hj-9xq3-x536.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6hj-9xq3-x536", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-54026" + ], + "details": "An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23.4, FortiSandbox at least 4.4.0 through 4.4.6 and 4.2.0 through 4.2.7 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 allows attacker to execute unauthorized code or commands via specifically crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54026" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j9mc-f96q-8ch7/GHSA-j9mc-f96q-8ch7.json b/advisories/unreviewed/2025/03/GHSA-j9mc-f96q-8ch7/GHSA-j9mc-f96q-8ch7.json new file mode 100644 index 00000000000..c51436288b9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j9mc-f96q-8ch7/GHSA-j9mc-f96q-8ch7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9mc-f96q-8ch7", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-32123" + ], + "details": "Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2\n7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and 5.4.0 through 5.4.7 and 5.2.0 through 5.2.10 and 5.0.0 through 5.0.12 and 4.3.4 through 4.3.8 allows attacker to execute unauthorized code or commands via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32123" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-24-124" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mvc2-5crr-f7g7/GHSA-mvc2-5crr-f7g7.json b/advisories/unreviewed/2025/03/GHSA-mvc2-5crr-f7g7/GHSA-mvc2-5crr-f7g7.json new file mode 100644 index 00000000000..a73c411c354 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mvc2-5crr-f7g7/GHSA-mvc2-5crr-f7g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvc2-5crr-f7g7", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-52961" + ], + "details": "An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.7, 4.2.0 through 4.2.7 and before 4.0.5 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52961" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-306" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mxmx-r6p4-736h/GHSA-mxmx-r6p4-736h.json b/advisories/unreviewed/2025/03/GHSA-mxmx-r6p4-736h/GHSA-mxmx-r6p4-736h.json new file mode 100644 index 00000000000..0d2ca30f916 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mxmx-r6p4-736h/GHSA-mxmx-r6p4-736h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxmx-r6p4-736h", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2025-22367" + ], + "details": "The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for command execution because OS command are improperly neutralized when certain fields are passed to the underlying OS.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22367" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22367" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2025-00003" + }, + { + "type": "WEB", + "url": "https://www.mennekes.nl/fileadmin/MEN-Deutschland/emobility/04_software/06_smart_premium/Release_Notes_for_2.15_06.03.2025.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json b/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json index dfef40b531f..aabdcd04b03 100644 --- a/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json +++ b/advisories/unreviewed/2025/03/GHSA-q6qg-c79q-f6q2/GHSA-q6qg-c79q-f6q2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q6qg-c79q-f6q2", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2025-0629" ], "details": "The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qxjq-4v6j-7ff6/GHSA-qxjq-4v6j-7ff6.json b/advisories/unreviewed/2025/03/GHSA-qxjq-4v6j-7ff6/GHSA-qxjq-4v6j-7ff6.json index dc8ecac38b7..dd18c4c1c03 100644 --- a/advisories/unreviewed/2025/03/GHSA-qxjq-4v6j-7ff6/GHSA-qxjq-4v6j-7ff6.json +++ b/advisories/unreviewed/2025/03/GHSA-qxjq-4v6j-7ff6/GHSA-qxjq-4v6j-7ff6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qxjq-4v6j-7ff6", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13615" ], "details": "The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap WordPress plugin through 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json b/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json new file mode 100644 index 00000000000..f6919f124b8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r63r-pwwp-jvj8", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-51321" + ], + "details": "In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51321" + }, + { + "type": "WEB", + "url": "https://members.backbox.org/zucchetti-ad-hoc-infinity-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmxr-xm7j-cmg8/GHSA-rmxr-xm7j-cmg8.json b/advisories/unreviewed/2025/03/GHSA-rmxr-xm7j-cmg8/GHSA-rmxr-xm7j-cmg8.json new file mode 100644 index 00000000000..99e7834a2b2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmxr-xm7j-cmg8/GHSA-rmxr-xm7j-cmg8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmxr-xm7j-cmg8", + "modified": "2025-03-11T15:30:59Z", + "published": "2025-03-11T15:30:59Z", + "aliases": [ + "CVE-2025-2193" + ], + "details": "A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path/name leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2193" + }, + { + "type": "WEB", + "url": "https://github.com/IceFoxH/VULN/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rw47-3hmf-cmhq/GHSA-rw47-3hmf-cmhq.json b/advisories/unreviewed/2025/03/GHSA-rw47-3hmf-cmhq/GHSA-rw47-3hmf-cmhq.json index 1ceb26a1a89..791327acbca 100644 --- a/advisories/unreviewed/2025/03/GHSA-rw47-3hmf-cmhq/GHSA-rw47-3hmf-cmhq.json +++ b/advisories/unreviewed/2025/03/GHSA-rw47-3hmf-cmhq/GHSA-rw47-3hmf-cmhq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rw47-3hmf-cmhq", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13853" ], "details": "The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v987-49gq-jh66/GHSA-v987-49gq-jh66.json b/advisories/unreviewed/2025/03/GHSA-v987-49gq-jh66/GHSA-v987-49gq-jh66.json index d2974fcb7a9..dae169ea0b4 100644 --- a/advisories/unreviewed/2025/03/GHSA-v987-49gq-jh66/GHSA-v987-49gq-jh66.json +++ b/advisories/unreviewed/2025/03/GHSA-v987-49gq-jh66/GHSA-v987-49gq-jh66.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v987-49gq-jh66", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13836" ], "details": "The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json b/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json new file mode 100644 index 00000000000..2280ebb0a27 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcgc-h73q-2m2p", + "modified": "2025-03-11T15:31:00Z", + "published": "2025-03-11T15:31:00Z", + "aliases": [ + "CVE-2024-54085" + ], + "details": "AMI’s SPx contains\na vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation\nof this vulnerability may lead to a loss of confidentiality, integrity, and/or\navailability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54085" + }, + { + "type": "WEB", + "url": "https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vx56-xwhw-6m46/GHSA-vx56-xwhw-6m46.json b/advisories/unreviewed/2025/03/GHSA-vx56-xwhw-6m46/GHSA-vx56-xwhw-6m46.json new file mode 100644 index 00000000000..b97b0ae66fd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vx56-xwhw-6m46/GHSA-vx56-xwhw-6m46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx56-xwhw-6m46", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-55590" + ], + "details": "Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically crafted CLI commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55590" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-178" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w4pp-rhhp-qj56/GHSA-w4pp-rhhp-qj56.json b/advisories/unreviewed/2025/03/GHSA-w4pp-rhhp-qj56/GHSA-w4pp-rhhp-qj56.json new file mode 100644 index 00000000000..fdaebb672a2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w4pp-rhhp-qj56/GHSA-w4pp-rhhp-qj56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4pp-rhhp-qj56", + "modified": "2025-03-11T15:31:02Z", + "published": "2025-03-11T15:31:02Z", + "aliases": [ + "CVE-2024-55592" + ], + "details": "An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to perform unauthorized operations on incidents via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55592" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wgm3-f6x3-rj6j/GHSA-wgm3-f6x3-rj6j.json b/advisories/unreviewed/2025/03/GHSA-wgm3-f6x3-rj6j/GHSA-wgm3-f6x3-rj6j.json index e9c2a4678a7..be5c48a54ea 100644 --- a/advisories/unreviewed/2025/03/GHSA-wgm3-f6x3-rj6j/GHSA-wgm3-f6x3-rj6j.json +++ b/advisories/unreviewed/2025/03/GHSA-wgm3-f6x3-rj6j/GHSA-wgm3-f6x3-rj6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgm3-f6x3-rj6j", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2025-2136" ], "details": "Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T21:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wpm6-95m5-fpxf/GHSA-wpm6-95m5-fpxf.json b/advisories/unreviewed/2025/03/GHSA-wpm6-95m5-fpxf/GHSA-wpm6-95m5-fpxf.json index 5e696f6a27e..8c5bc56299b 100644 --- a/advisories/unreviewed/2025/03/GHSA-wpm6-95m5-fpxf/GHSA-wpm6-95m5-fpxf.json +++ b/advisories/unreviewed/2025/03/GHSA-wpm6-95m5-fpxf/GHSA-wpm6-95m5-fpxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wpm6-95m5-fpxf", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-54560" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, watchOS 11, tvOS 18, macOS Sequoia 15. A malicious app may be able to modify other apps without having App Management permission.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xg2h-39gr-h327/GHSA-xg2h-39gr-h327.json b/advisories/unreviewed/2025/03/GHSA-xg2h-39gr-h327/GHSA-xg2h-39gr-h327.json new file mode 100644 index 00000000000..73d4ab37a60 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xg2h-39gr-h327/GHSA-xg2h-39gr-h327.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg2h-39gr-h327", + "modified": "2025-03-11T15:31:01Z", + "published": "2025-03-11T15:31:01Z", + "aliases": [ + "CVE-2024-45328" + ], + "details": "An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45328" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-261" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xp2h-p87p-622p/GHSA-xp2h-p87p-622p.json b/advisories/unreviewed/2025/03/GHSA-xp2h-p87p-622p/GHSA-xp2h-p87p-622p.json index 86bb9ad9822..2a9c3265bb7 100644 --- a/advisories/unreviewed/2025/03/GHSA-xp2h-p87p-622p/GHSA-xp2h-p87p-622p.json +++ b/advisories/unreviewed/2025/03/GHSA-xp2h-p87p-622p/GHSA-xp2h-p87p-622p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xp2h-p87p-622p", - "modified": "2025-03-11T09:30:30Z", + "modified": "2025-03-11T15:30:59Z", "published": "2025-03-11T09:30:30Z", "aliases": [ "CVE-2025-2190" ], "details": "The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-300" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T07:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xxrr-x8j4-g44v/GHSA-xxrr-x8j4-g44v.json b/advisories/unreviewed/2025/03/GHSA-xxrr-x8j4-g44v/GHSA-xxrr-x8j4-g44v.json index 64a909d6145..583a2ced7ec 100644 --- a/advisories/unreviewed/2025/03/GHSA-xxrr-x8j4-g44v/GHSA-xxrr-x8j4-g44v.json +++ b/advisories/unreviewed/2025/03/GHSA-xxrr-x8j4-g44v/GHSA-xxrr-x8j4-g44v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xxrr-x8j4-g44v", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-03-11T15:30:58Z", "published": "2025-03-11T06:30:38Z", "aliases": [ "CVE-2024-13580" ], "details": "The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T06:15:25Z"