diff --git a/advisories/unreviewed/2022/05/GHSA-5r7w-xvrp-rg22/GHSA-5r7w-xvrp-rg22.json b/advisories/unreviewed/2022/05/GHSA-5r7w-xvrp-rg22/GHSA-5r7w-xvrp-rg22.json index 7780cbf7b74..46e51425994 100644 --- a/advisories/unreviewed/2022/05/GHSA-5r7w-xvrp-rg22/GHSA-5r7w-xvrp-rg22.json +++ b/advisories/unreviewed/2022/05/GHSA-5r7w-xvrp-rg22/GHSA-5r7w-xvrp-rg22.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5r7w-xvrp-rg22", - "modified": "2022-10-07T18:15:58Z", + "modified": "2025-04-01T21:30:28Z", "published": "2022-05-24T16:47:12Z", "aliases": [ "CVE-2019-10149" diff --git a/advisories/unreviewed/2023/01/GHSA-h9jm-ppr9-845g/GHSA-h9jm-ppr9-845g.json b/advisories/unreviewed/2023/01/GHSA-h9jm-ppr9-845g/GHSA-h9jm-ppr9-845g.json index b8f4ea831fb..624269ef6a2 100644 --- a/advisories/unreviewed/2023/01/GHSA-h9jm-ppr9-845g/GHSA-h9jm-ppr9-845g.json +++ b/advisories/unreviewed/2023/01/GHSA-h9jm-ppr9-845g/GHSA-h9jm-ppr9-845g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-59" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-mhww-mq8c-j9q5/GHSA-mhww-mq8c-j9q5.json b/advisories/unreviewed/2023/01/GHSA-mhww-mq8c-j9q5/GHSA-mhww-mq8c-j9q5.json index ca218ac3255..2ae51ba17ba 100644 --- a/advisories/unreviewed/2023/01/GHSA-mhww-mq8c-j9q5/GHSA-mhww-mq8c-j9q5.json +++ b/advisories/unreviewed/2023/01/GHSA-mhww-mq8c-j9q5/GHSA-mhww-mq8c-j9q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhww-mq8c-j9q5", - "modified": "2023-02-03T21:30:29Z", + "modified": "2025-04-01T21:30:28Z", "published": "2023-01-26T21:30:29Z", "aliases": [ "CVE-2020-18330" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/cybertoxin/CVEs/blob/main/CVE_2020_18330.md" }, + { + "type": "WEB", + "url": "https://medium.com/%40SergiuSechel/insecure-permissions-and-multiple-vulnerabilities-in-chinamobile-plc-wireless-routers-leaves-more-d3eb9ff70d24" + }, { "type": "WEB", "url": "https://medium.com/@SergiuSechel/insecure-permissions-and-multiple-vulnerabilities-in-chinamobile-plc-wireless-routers-leaves-more-d3eb9ff70d24" diff --git a/advisories/unreviewed/2023/01/GHSA-w48q-2q3f-h2f8/GHSA-w48q-2q3f-h2f8.json b/advisories/unreviewed/2023/01/GHSA-w48q-2q3f-h2f8/GHSA-w48q-2q3f-h2f8.json index b00f5343c09..677612485cb 100644 --- a/advisories/unreviewed/2023/01/GHSA-w48q-2q3f-h2f8/GHSA-w48q-2q3f-h2f8.json +++ b/advisories/unreviewed/2023/01/GHSA-w48q-2q3f-h2f8/GHSA-w48q-2q3f-h2f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w48q-2q3f-h2f8", - "modified": "2023-02-03T21:30:29Z", + "modified": "2025-04-01T21:30:28Z", "published": "2023-01-26T21:30:29Z", "aliases": [ "CVE-2020-18331" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/cybertoxin/CVEs/blob/main/CVE_2020_18331.md" }, + { + "type": "WEB", + "url": "https://medium.com/%40SergiuSechel/insecure-permissions-and-multiple-vulnerabilities-in-chinamobile-plc-wireless-routers-leaves-more-d3eb9ff70d24" + }, { "type": "WEB", "url": "https://medium.com/@SergiuSechel/insecure-permissions-and-multiple-vulnerabilities-in-chinamobile-plc-wireless-routers-leaves-more-d3eb9ff70d24" diff --git a/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json b/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json index b8606a4dd5e..23b701b01dc 100644 --- a/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json +++ b/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8mp7-25cp-m483/GHSA-8mp7-25cp-m483.json b/advisories/unreviewed/2024/03/GHSA-8mp7-25cp-m483/GHSA-8mp7-25cp-m483.json index 17b0c83af8d..1a8db799bb8 100644 --- a/advisories/unreviewed/2024/03/GHSA-8mp7-25cp-m483/GHSA-8mp7-25cp-m483.json +++ b/advisories/unreviewed/2024/03/GHSA-8mp7-25cp-m483/GHSA-8mp7-25cp-m483.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8mp7-25cp-m483", - "modified": "2024-03-27T15:30:37Z", + "modified": "2025-04-01T21:30:28Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-29790" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Squirrly SEO Plugin by Squirrly SEO allows Reflected XSS.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.3.16.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Squirrly SEO Plugin by Squirrly SEO allows Reflected XSS.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.3.16.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-vhpq-5rff-2gh4/GHSA-vhpq-5rff-2gh4.json b/advisories/unreviewed/2024/03/GHSA-vhpq-5rff-2gh4/GHSA-vhpq-5rff-2gh4.json index 4fbc402f570..256ac942fd0 100644 --- a/advisories/unreviewed/2024/03/GHSA-vhpq-5rff-2gh4/GHSA-vhpq-5rff-2gh4.json +++ b/advisories/unreviewed/2024/03/GHSA-vhpq-5rff-2gh4/GHSA-vhpq-5rff-2gh4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vhpq-5rff-2gh4", - "modified": "2024-03-27T15:30:38Z", + "modified": "2025-04-01T21:30:28Z", "published": "2024-03-27T15:30:38Z", "aliases": [ "CVE-2024-30238" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.2.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json b/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json index fa583924e1e..b6f01c33b2d 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json +++ b/advisories/unreviewed/2024/04/GHSA-4jvv-2c5h-wr97/GHSA-4jvv-2c5h-wr97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4jvv-2c5h-wr97", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-04-01T21:30:29Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26788" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: fsl-qdma: init irq after reg initialization\n\nInitialize the qDMA irqs after the registers are configured so that\ninterrupts that may have been pending from a primary kernel don't get\nprocessed by the irq handler before it is ready to and cause panic with\nthe following trace:\n\n Call trace:\n fsl_qdma_queue_handler+0xf8/0x3e8\n __handle_irq_event_percpu+0x78/0x2b0\n handle_irq_event_percpu+0x1c/0x68\n handle_irq_event+0x44/0x78\n handle_fasteoi_irq+0xc8/0x178\n generic_handle_irq+0x24/0x38\n __handle_domain_irq+0x90/0x100\n gic_handle_irq+0x5c/0xb8\n el1_irq+0xb8/0x180\n _raw_spin_unlock_irqrestore+0x14/0x40\n __setup_irq+0x4bc/0x798\n request_threaded_irq+0xd8/0x190\n devm_request_threaded_irq+0x74/0xe8\n fsl_qdma_probe+0x4d4/0xca8\n platform_drv_probe+0x50/0xa0\n really_probe+0xe0/0x3f8\n driver_probe_device+0x64/0x130\n device_driver_attach+0x6c/0x78\n __driver_attach+0xbc/0x158\n bus_for_each_dev+0x5c/0x98\n driver_attach+0x20/0x28\n bus_add_driver+0x158/0x220\n driver_register+0x60/0x110\n __platform_driver_register+0x44/0x50\n fsl_qdma_driver_init+0x18/0x20\n do_one_initcall+0x48/0x258\n kernel_init_freeable+0x1a4/0x23c\n kernel_init+0x10/0xf8\n ret_from_fork+0x10/0x18", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json b/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json index d987bf3734a..cfc3da0800a 100644 --- a/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json +++ b/advisories/unreviewed/2024/04/GHSA-866j-mv4h-26jh/GHSA-866j-mv4h-26jh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-866j-mv4h-26jh", - "modified": "2024-04-04T09:30:36Z", + "modified": "2025-04-01T21:30:29Z", "published": "2024-04-04T09:30:36Z", "aliases": [ "CVE-2024-26803" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: veth: clear GRO when clearing XDP even when down\n\nveth sets NETIF_F_GRO automatically when XDP is enabled,\nbecause both features use the same NAPI machinery.\n\nThe logic to clear NETIF_F_GRO sits in veth_disable_xdp() which\nis called both on ndo_stop and when XDP is turned off.\nTo avoid the flag from being cleared when the device is brought\ndown, the clearing is skipped when IFF_UP is not set.\nBringing the device down should indeed not modify its features.\n\nUnfortunately, this means that clearing is also skipped when\nXDP is disabled _while_ the device is down. And there's nothing\non the open path to bring the device features back into sync.\nIOW if user enables XDP, disables it and then brings the device\nup we'll end up with a stray GRO flag set but no NAPI instances.\n\nWe don't depend on the GRO flag on the datapath, so the datapath\nwon't crash. We will crash (or hang), however, next time features\nare sync'ed (either by user via ethtool or peer changing its config).\nThe GRO flag will go away, and veth will try to disable the NAPIs.\nBut the open path never created them since XDP was off, the GRO flag\nwas a stray. If NAPI was initialized before we'll hang in napi_disable().\nIf it never was we'll crash trying to stop uninitialized hrtimer.\n\nMove the GRO flag updates to the XDP enable / disable paths,\ninstead of mixing them with the ndo_open / ndo_close paths.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json b/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json index 873a3061b3e..5f4e49c9e7b 100644 --- a/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json +++ b/advisories/unreviewed/2024/04/GHSA-wm99-2g28-jp5m/GHSA-wm99-2g28-jp5m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wm99-2g28-jp5m", - "modified": "2024-04-04T09:30:36Z", + "modified": "2025-04-01T21:30:29Z", "published": "2024-04-04T09:30:36Z", "aliases": [ "CVE-2024-26798" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbcon: always restore the old font data in fbcon_do_set_font()\n\nCommit a5a923038d70 (fbdev: fbcon: Properly revert changes when\nvc_resize() failed) started restoring old font data upon failure (of\nvc_resize()). But it performs so only for user fonts. It means that the\n\"system\"/internal fonts are not restored at all. So in result, the very\nfirst call to fbcon_do_set_font() performs no restore at all upon\nfailing vc_resize().\n\nThis can be reproduced by Syzkaller to crash the system on the next\ninvocation of font_get(). It's rather hard to hit the allocation failure\nin vc_resize() on the first font_set(), but not impossible. Esp. if\nfault injection is used to aid the execution/failure. It was\ndemonstrated by Sirius:\n BUG: unable to handle page fault for address: fffffffffffffff8\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD cb7b067 P4D cb7b067 PUD cb7d067 PMD 0\n Oops: 0000 [#1] PREEMPT SMP KASAN\n CPU: 1 PID: 8007 Comm: poc Not tainted 6.7.0-g9d1694dc91ce #20\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:fbcon_get_font+0x229/0x800 drivers/video/fbdev/core/fbcon.c:2286\n Call Trace:\n \n con_font_get drivers/tty/vt/vt.c:4558 [inline]\n con_font_op+0x1fc/0xf20 drivers/tty/vt/vt.c:4673\n vt_k_ioctl drivers/tty/vt/vt_ioctl.c:474 [inline]\n vt_ioctl+0x632/0x2ec0 drivers/tty/vt/vt_ioctl.c:752\n tty_ioctl+0x6f8/0x1570 drivers/tty/tty_io.c:2803\n vfs_ioctl fs/ioctl.c:51 [inline]\n ...\n\nSo restore the font data in any case, not only for user fonts. Note the\nlater 'if' is now protected by 'old_userfont' and not 'old_data' as the\nlatter is always set now. (And it is supposed to be non-NULL. Otherwise\nwe would see the bug above again.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json b/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json index 17a5286858f..875c51eccc9 100644 --- a/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json +++ b/advisories/unreviewed/2024/06/GHSA-5w4f-cwfr-f344/GHSA-5w4f-cwfr-f344.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5w4f-cwfr-f344", - "modified": "2024-06-27T15:30:39Z", + "modified": "2025-04-01T21:30:33Z", "published": "2024-06-03T09:30:47Z", "aliases": [ "CVE-2024-36960" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix invalid reads in fence signaled events\n\nCorrectly set the length of the drm_event to the size of the structure\nthat's actually used.\n\nThe length of the drm_event was set to the parent structure instead of\nto the drm_vmw_event_fence which is supposed to be read. drm_read\nuses the length parameter to copy the event to the user space thus\nresuling in oob reads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -59,7 +64,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T08:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json b/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json index b21e08172fd..bdbd4ba039d 100644 --- a/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json +++ b/advisories/unreviewed/2024/06/GHSA-7g8p-3g9q-44r8/GHSA-7g8p-3g9q-44r8.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-129" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json b/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json index 3e6f9942853..e8f88908835 100644 --- a/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json +++ b/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2fqc-9m76-ppwc", - "modified": "2025-03-28T21:30:47Z", + "modified": "2025-04-01T21:30:46Z", "published": "2025-03-28T21:30:47Z", "aliases": [ "CVE-2024-56975" ], "details": "InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T21:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2vwh-mc47-47fv/GHSA-2vwh-mc47-47fv.json b/advisories/unreviewed/2025/03/GHSA-2vwh-mc47-47fv/GHSA-2vwh-mc47-47fv.json index e4b09ab6d18..46196c67ccf 100644 --- a/advisories/unreviewed/2025/03/GHSA-2vwh-mc47-47fv/GHSA-2vwh-mc47-47fv.json +++ b/advisories/unreviewed/2025/03/GHSA-2vwh-mc47-47fv/GHSA-2vwh-mc47-47fv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-4q2r-xgxr-vvqm/GHSA-4q2r-xgxr-vvqm.json b/advisories/unreviewed/2025/03/GHSA-4q2r-xgxr-vvqm/GHSA-4q2r-xgxr-vvqm.json index 7c87b587780..e84f9b1fece 100644 --- a/advisories/unreviewed/2025/03/GHSA-4q2r-xgxr-vvqm/GHSA-4q2r-xgxr-vvqm.json +++ b/advisories/unreviewed/2025/03/GHSA-4q2r-xgxr-vvqm/GHSA-4q2r-xgxr-vvqm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json b/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json index 08e2a07d011..82614417f88 100644 --- a/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json +++ b/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json b/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json index f8bb4dcaed6..2d0d3f31ccb 100644 --- a/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json +++ b/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-918" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json b/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json index dbe2bc6fc3c..0991d50c72d 100644 --- a/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json +++ b/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-798j-m949-2j7c", - "modified": "2025-03-28T21:30:46Z", + "modified": "2025-04-01T21:30:46Z", "published": "2025-03-28T21:30:46Z", "aliases": [ "CVE-2024-24292" ], "details": "A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T21:15:15Z" diff --git a/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json b/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json index 70435ca09e2..a759abeb10b 100644 --- a/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json +++ b/advisories/unreviewed/2025/03/GHSA-g533-46g7-g2f9/GHSA-g533-46g7-g2f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g533-46g7-g2f9", - "modified": "2025-03-28T18:33:08Z", + "modified": "2025-04-01T21:30:46Z", "published": "2025-03-26T18:30:50Z", "aliases": [ "CVE-2025-2825" @@ -19,10 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2825" }, + { + "type": "WEB", + "url": "https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825/rapid7-analysis" + }, { "type": "WEB", "url": "https://projectdiscovery.io/blog/crushftp-authentication-bypass" }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/cves/2025/CVE-2025-2825.yaml" + }, { "type": "WEB", "url": "https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update" diff --git a/advisories/unreviewed/2025/03/GHSA-g97r-96hh-j5vv/GHSA-g97r-96hh-j5vv.json b/advisories/unreviewed/2025/03/GHSA-g97r-96hh-j5vv/GHSA-g97r-96hh-j5vv.json index 454c0406043..9f4508114a7 100644 --- a/advisories/unreviewed/2025/03/GHSA-g97r-96hh-j5vv/GHSA-g97r-96hh-j5vv.json +++ b/advisories/unreviewed/2025/03/GHSA-g97r-96hh-j5vv/GHSA-g97r-96hh-j5vv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json b/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json index 320685f468f..9998ad146c4 100644 --- a/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json +++ b/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json b/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json index 9c9ad8ba7d2..78ba1b6b3e2 100644 --- a/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json +++ b/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-q7m6-hfxq-rj34/GHSA-q7m6-hfxq-rj34.json b/advisories/unreviewed/2025/03/GHSA-q7m6-hfxq-rj34/GHSA-q7m6-hfxq-rj34.json index e0543ba27e1..596c44c68d6 100644 --- a/advisories/unreviewed/2025/03/GHSA-q7m6-hfxq-rj34/GHSA-q7m6-hfxq-rj34.json +++ b/advisories/unreviewed/2025/03/GHSA-q7m6-hfxq-rj34/GHSA-q7m6-hfxq-rj34.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json b/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json index ce20113a75f..0b22b5c8f70 100644 --- a/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json +++ b/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q87j-52xg-48j5", - "modified": "2025-03-28T21:30:47Z", + "modified": "2025-04-01T21:30:46Z", "published": "2025-03-28T21:30:47Z", "aliases": [ "CVE-2025-22953" ], "details": "A SQL injection vulnerability exists in the Epicor HCM 2021 1.9, specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T21:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v93x-jrj3-9rwc/GHSA-v93x-jrj3-9rwc.json b/advisories/unreviewed/2025/03/GHSA-v93x-jrj3-9rwc/GHSA-v93x-jrj3-9rwc.json index e9b178a716c..5d093f21b22 100644 --- a/advisories/unreviewed/2025/03/GHSA-v93x-jrj3-9rwc/GHSA-v93x-jrj3-9rwc.json +++ b/advisories/unreviewed/2025/03/GHSA-v93x-jrj3-9rwc/GHSA-v93x-jrj3-9rwc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v93x-jrj3-9rwc", - "modified": "2025-03-21T12:30:32Z", + "modified": "2025-04-01T21:30:41Z", "published": "2025-03-21T12:30:32Z", "aliases": [ "CVE-2025-2597" ], "details": "Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability could allow an attacker to execute malicious Javascript code via GET and POST requests to the ‘/index.php’ endpoint and injecting code into the ‘id_session.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json b/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json index a9ad8451506..261fbf8a5f7 100644 --- a/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json +++ b/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json b/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json index 4d98e5c3a87..534bf85c585 100644 --- a/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json +++ b/advisories/unreviewed/2025/03/GHSA-x45p-6x9h-wr36/GHSA-x45p-6x9h-wr36.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json b/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json index cb0588f77e1..f2928166c97 100644 --- a/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json +++ b/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-296v-93wv-2fxf/GHSA-296v-93wv-2fxf.json b/advisories/unreviewed/2025/04/GHSA-296v-93wv-2fxf/GHSA-296v-93wv-2fxf.json new file mode 100644 index 00000000000..a1b9a2b5188 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-296v-93wv-2fxf/GHSA-296v-93wv-2fxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-296v-93wv-2fxf", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31461" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NanoSupport allows Reflected XSS. This issue affects NanoSupport: from n/a through 0.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nanosupport/vulnerability/wordpress-nanosupport-plugin-0-6-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-29j2-32mq-q4jm/GHSA-29j2-32mq-q4jm.json b/advisories/unreviewed/2025/04/GHSA-29j2-32mq-q4jm/GHSA-29j2-32mq-q4jm.json new file mode 100644 index 00000000000..444db39cff9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-29j2-32mq-q4jm/GHSA-29j2-32mq-q4jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29j2-32mq-q4jm", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:34Z", + "aliases": [ + "CVE-2025-31571" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy The Logo Slider allows Reflected XSS. This issue affects The Logo Slider: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31571" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-logo-slider/vulnerability/wordpress-the-logo-slider-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json b/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json index 196dfceba0e..a7cc7130a4a 100644 --- a/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json +++ b/advisories/unreviewed/2025/04/GHSA-2c76-7cf4-w44v/GHSA-2c76-7cf4-w44v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2c76-7cf4-w44v", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T21:31:05Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24250" ], "details": "This issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2f73-87g5-539c/GHSA-2f73-87g5-539c.json b/advisories/unreviewed/2025/04/GHSA-2f73-87g5-539c/GHSA-2f73-87g5-539c.json new file mode 100644 index 00000000000..db162b1bf79 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2f73-87g5-539c/GHSA-2f73-87g5-539c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f73-87g5-539c", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31578" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wisdomlogix Solutions Pvt. Ltd. Fonts Manager | Custom Fonts allows Reflected XSS. This issue affects Fonts Manager | Custom Fonts: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fonts-manager-custom-fonts/vulnerability/wordpress-fonts-manager-custom-fonts-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-37g8-5wch-2c6c/GHSA-37g8-5wch-2c6c.json b/advisories/unreviewed/2025/04/GHSA-37g8-5wch-2c6c/GHSA-37g8-5wch-2c6c.json new file mode 100644 index 00000000000..dfc336f93e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37g8-5wch-2c6c/GHSA-37g8-5wch-2c6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37g8-5wch-2c6c", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31078" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Reflected XSS. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31078" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/small-package-quotes-wwe-edition/vulnerability/wordpress-small-package-quotes-worldwide-express-edition-plugin-5-2-18-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json b/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json index fcbcb0b678f..6a869ed2d37 100644 --- a/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json +++ b/advisories/unreviewed/2025/04/GHSA-38rr-jcx6-prmh/GHSA-38rr-jcx6-prmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-38rr-jcx6-prmh", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T21:31:02Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24198" ], "details": "This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3p7r-h3vx-2qj9/GHSA-3p7r-h3vx-2qj9.json b/advisories/unreviewed/2025/04/GHSA-3p7r-h3vx-2qj9/GHSA-3p7r-h3vx-2qj9.json new file mode 100644 index 00000000000..10f3dd18802 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3p7r-h3vx-2qj9/GHSA-3p7r-h3vx-2qj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p7r-h3vx-2qj9", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31551" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows SQL Injection. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gf-salesmate-add-on/vulnerability/wordpress-salesmate-add-on-for-gravity-forms-plugin-2-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3q3v-vh74-59jw/GHSA-3q3v-vh74-59jw.json b/advisories/unreviewed/2025/04/GHSA-3q3v-vh74-59jw/GHSA-3q3v-vh74-59jw.json new file mode 100644 index 00000000000..0ce0a210c69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3q3v-vh74-59jw/GHSA-3q3v-vh74-59jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q3v-vh74-59jw", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31612" + ], + "details": "Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll allows Object Injection. This issue affects CBX Poll: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31612" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cbxpoll/vulnerability/wordpress-cbx-poll-plugin-1-2-7-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-43x9-pvmm-pvx5/GHSA-43x9-pvmm-pvx5.json b/advisories/unreviewed/2025/04/GHSA-43x9-pvmm-pvx5/GHSA-43x9-pvmm-pvx5.json new file mode 100644 index 00000000000..a9d59638542 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43x9-pvmm-pvx5/GHSA-43x9-pvmm-pvx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43x9-pvmm-pvx5", + "modified": "2025-04-01T21:31:31Z", + "published": "2025-04-01T21:31:31Z", + "aliases": [ + "CVE-2025-30580" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/digiwidgets-image-editor/vulnerability/wordpress-digiwidgets-image-editor-1-10-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-47jh-4rfj-2mwq/GHSA-47jh-4rfj-2mwq.json b/advisories/unreviewed/2025/04/GHSA-47jh-4rfj-2mwq/GHSA-47jh-4rfj-2mwq.json new file mode 100644 index 00000000000..d540f7f40c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-47jh-4rfj-2mwq/GHSA-47jh-4rfj-2mwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47jh-4rfj-2mwq", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:34Z", + "aliases": [ + "CVE-2025-31628" + ], + "details": "Missing Authorization vulnerability in SlicedInvoices Sliced Invoices. This issue affects Sliced Invoices: from n/a through 3.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sliced-invoices/vulnerability/wordpress-sliced-invoices-plugin-3-9-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json b/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json index 98ce94beb18..77d6533fe0b 100644 --- a/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json +++ b/advisories/unreviewed/2025/04/GHSA-4rpr-22rq-29fr/GHSA-4rpr-22rq-29fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rpr-22rq-29fr", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T21:31:07Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30437" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4wwq-85c4-8p8r/GHSA-4wwq-85c4-8p8r.json b/advisories/unreviewed/2025/04/GHSA-4wwq-85c4-8p8r/GHSA-4wwq-85c4-8p8r.json new file mode 100644 index 00000000000..87951a97a06 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4wwq-85c4-8p8r/GHSA-4wwq-85c4-8p8r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wwq-85c4-8p8r", + "modified": "2025-04-01T21:31:27Z", + "published": "2025-04-01T21:31:27Z", + "aliases": [ + "CVE-2025-26054" + ], + "details": "Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the \"Description\" field during LAN configuration.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26054" + }, + { + "type": "WEB", + "url": "https://github.com/rohan-pt/CVE-2025-26054" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T19:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json b/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json index 75240892f65..f44fb3eb541 100644 --- a/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json +++ b/advisories/unreviewed/2025/04/GHSA-4x4g-h2vr-367c/GHSA-4x4g-h2vr-367c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4x4g-h2vr-367c", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T21:31:02Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24196" ], "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4x5f-7wrq-wc68/GHSA-4x5f-7wrq-wc68.json b/advisories/unreviewed/2025/04/GHSA-4x5f-7wrq-wc68/GHSA-4x5f-7wrq-wc68.json new file mode 100644 index 00000000000..d496c0c3285 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4x5f-7wrq-wc68/GHSA-4x5f-7wrq-wc68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x5f-7wrq-wc68", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31594" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPglob Auto scroll for reading allows Reflected XSS. This issue affects Auto scroll for reading: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/auto-scroll-for-reading/vulnerability/wordpress-auto-scroll-for-reading-plugin-1-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json b/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json index e2f7ddcb441..87caa15ffeb 100644 --- a/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json +++ b/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57xv-4vp5-7v49", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T21:31:17Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3033" ], "details": "After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. \n*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5955-rp5c-5293/GHSA-5955-rp5c-5293.json b/advisories/unreviewed/2025/04/GHSA-5955-rp5c-5293/GHSA-5955-rp5c-5293.json new file mode 100644 index 00000000000..c6efa0dceca --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5955-rp5c-5293/GHSA-5955-rp5c-5293.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5955-rp5c-5293", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31455" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Limit Max IPs Per User allows DOM-Based XSS. This issue affects Limit Max IPs Per User: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/limit-max-ips-per-user/vulnerability/wordpress-limit-max-ips-per-user-plugin-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json b/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json index d7dcc1cc5fc..3826cd95170 100644 --- a/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json +++ b/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5v8r-67h5-p4jj", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T21:31:17Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3031" ], "details": "An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json b/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json new file mode 100644 index 00000000000..3203f601f26 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xfw-qg2p-394c/GHSA-5xfw-qg2p-394c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xfw-qg2p-394c", + "modified": "2025-04-01T21:31:28Z", + "published": "2025-04-01T21:31:28Z", + "aliases": [ + "CVE-2025-26055" + ], + "details": "An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26055" + }, + { + "type": "WEB", + "url": "https://github.com/rohan-pt/CVE-2025-26055" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T19:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-66j2-p2w8-5252/GHSA-66j2-p2w8-5252.json b/advisories/unreviewed/2025/04/GHSA-66j2-p2w8-5252/GHSA-66j2-p2w8-5252.json new file mode 100644 index 00000000000..744d65534b8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-66j2-p2w8-5252/GHSA-66j2-p2w8-5252.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66j2-p2w8-5252", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:34Z", + "aliases": [ + "CVE-2025-31819" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks by Pixelgrade. This issue affects Nova Blocks by Pixelgrade: from n/a through 2.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nova-blocks/vulnerability/wordpress-nova-blocks-by-pixelgrade-plugin-2-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6xfj-hhwh-r3c2/GHSA-6xfj-hhwh-r3c2.json b/advisories/unreviewed/2025/04/GHSA-6xfj-hhwh-r3c2/GHSA-6xfj-hhwh-r3c2.json new file mode 100644 index 00000000000..d8e807c086a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xfj-hhwh-r3c2/GHSA-6xfj-hhwh-r3c2.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xfj-hhwh-r3c2", + "modified": "2025-04-01T21:31:30Z", + "published": "2025-04-01T21:31:30Z", + "aliases": [ + "CVE-2024-13941" + ], + "details": "A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. The manipulation of the argument month leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.4.0 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13941" + }, + { + "type": "WEB", + "url": "https://github.com/ouch-org/ouch/issues/707" + }, + { + "type": "WEB", + "url": "https://github.com/rustsec/advisory-db/pull/2084/files" + }, + { + "type": "WEB", + "url": "https://github.com/ouch-org/ouch/releases/tag/0.4.0" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/16767988/ouch.crash.report.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.302055" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.302055" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524511" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-75ch-4hq7-jvqv/GHSA-75ch-4hq7-jvqv.json b/advisories/unreviewed/2025/04/GHSA-75ch-4hq7-jvqv/GHSA-75ch-4hq7-jvqv.json new file mode 100644 index 00000000000..7a8f0ef266b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-75ch-4hq7-jvqv/GHSA-75ch-4hq7-jvqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75ch-4hq7-jvqv", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30852" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite allows Reflected XSS. This issue affects Oracle Cards Lite: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30852" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/oracle-cards/vulnerability/wordpress-oracle-cards-lite-plugin-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json b/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json index ccb1f83ca81..4d0b5fabb44 100644 --- a/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json +++ b/advisories/unreviewed/2025/04/GHSA-75q7-hpjm-4cf5/GHSA-75q7-hpjm-4cf5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-75q7-hpjm-4cf5", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T21:31:03Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24207" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json b/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json index a7195fbc1ac..671c07cc983 100644 --- a/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json +++ b/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-799g-3g44-3g9m", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T21:31:16Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3029" ], "details": "A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7fwg-h4wf-x2r5/GHSA-7fwg-h4wf-x2r5.json b/advisories/unreviewed/2025/04/GHSA-7fwg-h4wf-x2r5/GHSA-7fwg-h4wf-x2r5.json new file mode 100644 index 00000000000..4051d1db7cf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7fwg-h4wf-x2r5/GHSA-7fwg-h4wf-x2r5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fwg-h4wf-x2r5", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31560" + ], + "details": "Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system allows Privilege Escalation. This issue affects Salon booking system: from n/a through 10.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31560" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/salon-booking-system/vulnerability/wordpress-salon-booking-system-plugin-10-11-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json b/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json new file mode 100644 index 00000000000..edc4f6cfb04 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7jfm-6phc-jjwh/GHSA-7jfm-6phc-jjwh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jfm-6phc-jjwh", + "modified": "2025-04-01T21:31:30Z", + "published": "2025-04-01T21:31:30Z", + "aliases": [ + "CVE-2025-29033" + ], + "details": "An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=\" HTTP GET parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29033" + }, + { + "type": "WEB", + "url": "https://github.com/nikolas-ch/CVEs/tree/main/Bamboohr_25.0210.170831-83b08dd/OpenRedirect" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7w5j-39rx-j497/GHSA-7w5j-39rx-j497.json b/advisories/unreviewed/2025/04/GHSA-7w5j-39rx-j497/GHSA-7w5j-39rx-j497.json new file mode 100644 index 00000000000..39823b79e16 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7w5j-39rx-j497/GHSA-7w5j-39rx-j497.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w5j-39rx-j497", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31580" + ], + "details": "Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Product Enquiry allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ni WooCommerce Product Enquiry: from n/a through 4.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-product-enquiry/vulnerability/wordpress-ni-woocommerce-product-enquiry-plugin-4-1-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7x57-hhw5-3367/GHSA-7x57-hhw5-3367.json b/advisories/unreviewed/2025/04/GHSA-7x57-hhw5-3367/GHSA-7x57-hhw5-3367.json new file mode 100644 index 00000000000..9703a20f2b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7x57-hhw5-3367/GHSA-7x57-hhw5-3367.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x57-hhw5-3367", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31086" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick McReynolds Product Table by WBW allows Reflected XSS. This issue affects Product Table by WBW: from n/a through 2.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31086" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-product-tables/vulnerability/wordpress-product-table-by-wbw-plugin-2-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-829c-jp2v-3j35/GHSA-829c-jp2v-3j35.json b/advisories/unreviewed/2025/04/GHSA-829c-jp2v-3j35/GHSA-829c-jp2v-3j35.json new file mode 100644 index 00000000000..45539de2603 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-829c-jp2v-3j35/GHSA-829c-jp2v-3j35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-829c-jp2v-3j35", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30892" + ], + "details": "Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly allows Object Injection. This issue affects WpTravelly: from n/a through 1.8.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30892" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tour-booking-manager/vulnerability/wordpress-wptravelly-plugin-1-8-7-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-85q7-rf45-8qfm/GHSA-85q7-rf45-8qfm.json b/advisories/unreviewed/2025/04/GHSA-85q7-rf45-8qfm/GHSA-85q7-rf45-8qfm.json new file mode 100644 index 00000000000..b2f747fd312 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-85q7-rf45-8qfm/GHSA-85q7-rf45-8qfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85q7-rf45-8qfm", + "modified": "2025-04-01T21:31:31Z", + "published": "2025-04-01T21:31:31Z", + "aliases": [ + "CVE-2025-30778" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/v-form/vulnerability/wordpress-vform-plugin-3-1-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-869p-365f-xwr8/GHSA-869p-365f-xwr8.json b/advisories/unreviewed/2025/04/GHSA-869p-365f-xwr8/GHSA-869p-365f-xwr8.json new file mode 100644 index 00000000000..861fa81c092 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-869p-365f-xwr8/GHSA-869p-365f-xwr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-869p-365f-xwr8", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31619" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync allows SQL Injection. This issue affects Actionwear products sync: from n/a through 2.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/actionwear-products-sync/vulnerability/wordpress-actionwear-products-sync-plugin-2-3-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json b/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json index b7848623bf7..4bf14bc02a5 100644 --- a/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json +++ b/advisories/unreviewed/2025/04/GHSA-8852-5rrc-3m6q/GHSA-8852-5rrc-3m6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8852-5rrc-3m6q", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T21:31:05Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24249" ], "details": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to check the existence of an arbitrary path on the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8pm2-3pq8-6mh7/GHSA-8pm2-3pq8-6mh7.json b/advisories/unreviewed/2025/04/GHSA-8pm2-3pq8-6mh7/GHSA-8pm2-3pq8-6mh7.json new file mode 100644 index 00000000000..959e7664849 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8pm2-3pq8-6mh7/GHSA-8pm2-3pq8-6mh7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pm2-3pq8-6mh7", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31082" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack allows PHP Local File Inclusion. This issue affects News & Blog Designer Pack: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31082" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blog-designer-pack/vulnerability/wordpress-news-blog-designer-pack-plugin-4-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json b/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json index 71268b903af..b588de4688b 100644 --- a/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json +++ b/advisories/unreviewed/2025/04/GHSA-8q4c-gc84-4w63/GHSA-8q4c-gc84-4w63.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8q4c-gc84-4w63", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-01T21:31:02Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2025-24157" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8rhq-v947-5f3j/GHSA-8rhq-v947-5f3j.json b/advisories/unreviewed/2025/04/GHSA-8rhq-v947-5f3j/GHSA-8rhq-v947-5f3j.json new file mode 100644 index 00000000000..5c581f5552c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rhq-v947-5f3j/GHSA-8rhq-v947-5f3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rhq-v947-5f3j", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31085" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language allows Reflected XSS. This issue affects xili-language: from n/a through 2.21.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31085" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xili-language/vulnerability/wordpress-xili-language-plugin-2-21-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-929m-phjg-qwcc/GHSA-929m-phjg-qwcc.json b/advisories/unreviewed/2025/04/GHSA-929m-phjg-qwcc/GHSA-929m-phjg-qwcc.json new file mode 100644 index 00000000000..e8c26afaa3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-929m-phjg-qwcc/GHSA-929m-phjg-qwcc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-929m-phjg-qwcc", + "modified": "2025-04-01T21:31:30Z", + "published": "2025-04-01T21:31:30Z", + "aliases": [ + "CVE-2025-29049" + ], + "details": "Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29049" + }, + { + "type": "WEB", + "url": "https://github.com/arnog/mathlive/commit/abc26056fd5e29a99edfa96a0bbe855ea2a8b678" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-qwj6-q94f-8425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-96x5-3667-hf45/GHSA-96x5-3667-hf45.json b/advisories/unreviewed/2025/04/GHSA-96x5-3667-hf45/GHSA-96x5-3667-hf45.json new file mode 100644 index 00000000000..a62e7142634 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-96x5-3667-hf45/GHSA-96x5-3667-hf45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96x5-3667-hf45", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31525" + ], + "details": "Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Mobile Bottom Menu: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31525" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobile-bottom-menu-for-wp/vulnerability/wordpress-wp-mobile-bottom-menu-plugin-1-2-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-98mm-2r5v-4cvp/GHSA-98mm-2r5v-4cvp.json b/advisories/unreviewed/2025/04/GHSA-98mm-2r5v-4cvp/GHSA-98mm-2r5v-4cvp.json new file mode 100644 index 00000000000..78749ddc6ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-98mm-2r5v-4cvp/GHSA-98mm-2r5v-4cvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98mm-2r5v-4cvp", + "modified": "2025-04-01T21:31:31Z", + "published": "2025-04-01T21:31:31Z", + "aliases": [ + "CVE-2025-30807" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next-Cart Store to WooCommerce Migration allows SQL Injection. This issue affects Next-Cart Store to WooCommerce Migration: from n/a through 3.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30807" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nextcart-woocommerce-migration/vulnerability/wordpress-next-cart-store-to-woocommerce-migration-plugin-3-9-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9mc7-2j58-jq7g/GHSA-9mc7-2j58-jq7g.json b/advisories/unreviewed/2025/04/GHSA-9mc7-2j58-jq7g/GHSA-9mc7-2j58-jq7g.json new file mode 100644 index 00000000000..15b923aa5b4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9mc7-2j58-jq7g/GHSA-9mc7-2j58-jq7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mc7-2j58-jq7g", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31553" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting allows SQL Injection. This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webd-woocommerce-advanced-reporting-statistics/vulnerability/wordpress-advanced-woocommerce-product-sales-reporting-plugin-3-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9xvh-9rh2-x377/GHSA-9xvh-9rh2-x377.json b/advisories/unreviewed/2025/04/GHSA-9xvh-9rh2-x377/GHSA-9xvh-9rh2-x377.json new file mode 100644 index 00000000000..708a982d57a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9xvh-9rh2-x377/GHSA-9xvh-9rh2-x377.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xvh-9rh2-x377", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31561" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M. Tuhin Ultimate Push Notifications allows SQL Injection. This issue affects Ultimate Push Notifications: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31561" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-push-notifications/vulnerability/wordpress-ultimate-push-notifications-plugin-1-1-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c645-v9hc-x2j3/GHSA-c645-v9hc-x2j3.json b/advisories/unreviewed/2025/04/GHSA-c645-v9hc-x2j3/GHSA-c645-v9hc-x2j3.json new file mode 100644 index 00000000000..d057406f11a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c645-v9hc-x2j3/GHSA-c645-v9hc-x2j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c645-v9hc-x2j3", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31446" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jiangmiao WP Cleaner allows Reflected XSS. This issue affects WP Cleaner: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcleaner/vulnerability/wordpress-wp-cleaner-plugin-1-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfw2-8644-vppr/GHSA-cfw2-8644-vppr.json b/advisories/unreviewed/2025/04/GHSA-cfw2-8644-vppr/GHSA-cfw2-8644-vppr.json new file mode 100644 index 00000000000..9a9402ca838 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cfw2-8644-vppr/GHSA-cfw2-8644-vppr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfw2-8644-vppr", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31579" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EXEIdeas International WP AutoKeyword allows SQL Injection. This issue affects WP AutoKeyword: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-autokeyword/vulnerability/wordpress-wp-autokeyword-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxq6-h5g6-m6cr/GHSA-cxq6-h5g6-m6cr.json b/advisories/unreviewed/2025/04/GHSA-cxq6-h5g6-m6cr/GHSA-cxq6-h5g6-m6cr.json new file mode 100644 index 00000000000..cb621c56038 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxq6-h5g6-m6cr/GHSA-cxq6-h5g6-m6cr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxq6-h5g6-m6cr", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:31Z", + "aliases": [ + "CVE-2025-30825" + ], + "details": "Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce allows Privilege Escalation. This issue affects WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30825" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpc-smart-linked-products/vulnerability/wordpress-wpc-smart-linked-products-plugin-1-3-5-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f2xh-wfr6-g4gh/GHSA-f2xh-wfr6-g4gh.json b/advisories/unreviewed/2025/04/GHSA-f2xh-wfr6-g4gh/GHSA-f2xh-wfr6-g4gh.json new file mode 100644 index 00000000000..0eaddd6cec3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f2xh-wfr6-g4gh/GHSA-f2xh-wfr6-g4gh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2xh-wfr6-g4gh", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30905" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30905" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/secure-copy-content-protection/vulnerability/wordpress-secure-copy-content-protection-and-content-locking-plugin-4-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json b/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json new file mode 100644 index 00000000000..39762c5ae66 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fg5p-ff4v-v3c7/GHSA-fg5p-ff4v-v3c7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg5p-ff4v-v3c7", + "modified": "2025-04-01T21:31:28Z", + "published": "2025-04-01T21:31:28Z", + "aliases": [ + "CVE-2025-26056" + ], + "details": "A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module \"MTR\" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26056" + }, + { + "type": "WEB", + "url": "https://github.com/rohan-pt/CVE-2025-26056" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T19:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fwjj-9qq6-w324/GHSA-fwjj-9qq6-w324.json b/advisories/unreviewed/2025/04/GHSA-fwjj-9qq6-w324/GHSA-fwjj-9qq6-w324.json new file mode 100644 index 00000000000..05cdf8f2c1e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fwjj-9qq6-w324/GHSA-fwjj-9qq6-w324.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwjj-9qq6-w324", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30844" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz allows Reflected XSS. This issue affects Watu Quiz: from n/a through 3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30844" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/watu/vulnerability/wordpress-watu-quiz-plugin-3-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fxj6-7gh4-px89/GHSA-fxj6-7gh4-px89.json b/advisories/unreviewed/2025/04/GHSA-fxj6-7gh4-px89/GHSA-fxj6-7gh4-px89.json new file mode 100644 index 00000000000..04d5522a6a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fxj6-7gh4-px89/GHSA-fxj6-7gh4-px89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxj6-7gh4-px89", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30853" + ], + "details": "Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShortPixel Adaptive Images: from n/a through 3.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30853" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shortpixel-adaptive-images/vulnerability/wordpress-shortpixel-adaptive-images-plugin-3-10-0-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json b/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json index d77ddd96d4c..9bb585a5f56 100644 --- a/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json +++ b/advisories/unreviewed/2025/04/GHSA-g3v9-6xm2-qr9w/GHSA-g3v9-6xm2-qr9w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g3v9-6xm2-qr9w", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T21:31:04Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24229" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A sandboxed app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json b/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json index 21f0c9a2db4..5b5b6c7e57f 100644 --- a/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json +++ b/advisories/unreviewed/2025/04/GHSA-g7xp-7fwj-m5hv/GHSA-g7xp-7fwj-m5hv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7xp-7fwj-m5hv", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T21:31:04Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24246" ], "details": "An injection issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json b/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json index 03f21d30885..ab5693530aa 100644 --- a/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json +++ b/advisories/unreviewed/2025/04/GHSA-ghrr-554g-qqv5/GHSA-ghrr-554g-qqv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ghrr-554g-qqv5", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T21:31:08Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30461" ], "details": "An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gwq2-m8h6-8gvq/GHSA-gwq2-m8h6-8gvq.json b/advisories/unreviewed/2025/04/GHSA-gwq2-m8h6-8gvq/GHSA-gwq2-m8h6-8gvq.json new file mode 100644 index 00000000000..7d3cae8a4f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwq2-m8h6-8gvq/GHSA-gwq2-m8h6-8gvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwq2-m8h6-8gvq", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31568" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wiredmindshelp LeadLab by wiredminds allows Reflected XSS. This issue affects LeadLab by wiredminds: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31568" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wiredminds-leadlab/vulnerability/wordpress-leadlab-by-wiredminds-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json b/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json index e5a5cfdf437..c9398288fc8 100644 --- a/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json +++ b/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3xj-xc3c-cvpm", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T21:31:17Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3032" ], "details": "Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-403" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hgpg-8wmj-hgr4/GHSA-hgpg-8wmj-hgr4.json b/advisories/unreviewed/2025/04/GHSA-hgpg-8wmj-hgr4/GHSA-hgpg-8wmj-hgr4.json new file mode 100644 index 00000000000..b1e266572e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hgpg-8wmj-hgr4/GHSA-hgpg-8wmj-hgr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgpg-8wmj-hgr4", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31445" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pages Order allows Reflected XSS. This issue affects Pages Order: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31445" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pages-order/vulnerability/wordpress-pages-order-plugin-1-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hhc7-9jf4-whgx/GHSA-hhc7-9jf4-whgx.json b/advisories/unreviewed/2025/04/GHSA-hhc7-9jf4-whgx/GHSA-hhc7-9jf4-whgx.json index 015c0067d03..94bf617a8bc 100644 --- a/advisories/unreviewed/2025/04/GHSA-hhc7-9jf4-whgx/GHSA-hhc7-9jf4-whgx.json +++ b/advisories/unreviewed/2025/04/GHSA-hhc7-9jf4-whgx/GHSA-hhc7-9jf4-whgx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hhc7-9jf4-whgx", - "modified": "2025-04-01T03:31:32Z", + "modified": "2025-04-01T21:31:10Z", "published": "2025-04-01T03:31:32Z", "aliases": [ "CVE-2025-30673" ], "details": "Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238.\n\nIf an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution.\n\nSub::HandlesVia uses Mite to produce the affected code section due to CVE-2025-30672", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T03:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hjj5-539p-596j/GHSA-hjj5-539p-596j.json b/advisories/unreviewed/2025/04/GHSA-hjj5-539p-596j/GHSA-hjj5-539p-596j.json new file mode 100644 index 00000000000..df4ae103be5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hjj5-539p-596j/GHSA-hjj5-539p-596j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjj5-539p-596j", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31081" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n/a through 4.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31081" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enable-media-replace/vulnerability/wordpress-enable-media-replace-plugin-4-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hqqj-jcw8-c3rx/GHSA-hqqj-jcw8-c3rx.json b/advisories/unreviewed/2025/04/GHSA-hqqj-jcw8-c3rx/GHSA-hqqj-jcw8-c3rx.json new file mode 100644 index 00000000000..a49ab9f5793 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hqqj-jcw8-c3rx/GHSA-hqqj-jcw8-c3rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqqj-jcw8-c3rx", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31563" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vimal Kava AI Search Bar allows Stored XSS. This issue affects AI Search Bar: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/open-ai-search-bar/vulnerability/wordpress-ai-search-bar-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json b/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json index b51977e6d37..c2286caf617 100644 --- a/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json +++ b/advisories/unreviewed/2025/04/GHSA-j8gc-8grp-vffr/GHSA-j8gc-8grp-vffr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j8gc-8grp-vffr", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T21:31:03Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24209" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jj64-9xrj-3w59/GHSA-jj64-9xrj-3w59.json b/advisories/unreviewed/2025/04/GHSA-jj64-9xrj-3w59/GHSA-jj64-9xrj-3w59.json new file mode 100644 index 00000000000..49d44ad43b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jj64-9xrj-3w59/GHSA-jj64-9xrj-3w59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj64-9xrj-3w59", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30913" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podpirate Access Areas allows Reflected XSS. This issue affects Access Areas: from n/a through 1.5.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-access-areas/vulnerability/wordpress-access-areas-plugin-1-5-19-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json b/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json index e9e5fc9c0df..dc4bdd7507d 100644 --- a/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json +++ b/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jrg4-7p24-jjmf", - "modified": "2025-04-01T18:30:55Z", + "modified": "2025-04-01T21:31:27Z", "published": "2025-04-01T18:30:55Z", "aliases": [ "CVE-2025-28131" ], "details": "A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with \"Read-Only\" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T17:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jx2w-pp8j-qrcj/GHSA-jx2w-pp8j-qrcj.json b/advisories/unreviewed/2025/04/GHSA-jx2w-pp8j-qrcj/GHSA-jx2w-pp8j-qrcj.json index 8f5257ccb2d..f2e191cf6c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-jx2w-pp8j-qrcj/GHSA-jx2w-pp8j-qrcj.json +++ b/advisories/unreviewed/2025/04/GHSA-jx2w-pp8j-qrcj/GHSA-jx2w-pp8j-qrcj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jx2w-pp8j-qrcj", - "modified": "2025-04-01T03:31:32Z", + "modified": "2025-04-01T21:31:09Z", "published": "2025-04-01T03:31:32Z", "aliases": [ "CVE-2025-30672" ], "details": "Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238.\n\nIf an attacker can place a malicious file in current working directory, it may be \nloaded instead of the intended file, potentially leading to arbitrary \ncode execution.\n\nThis affects the Mite distribution itself, and other distributions that contain code generated by Mite.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T02:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m25x-mccm-6phm/GHSA-m25x-mccm-6phm.json b/advisories/unreviewed/2025/04/GHSA-m25x-mccm-6phm/GHSA-m25x-mccm-6phm.json new file mode 100644 index 00000000000..579d8e8f566 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m25x-mccm-6phm/GHSA-m25x-mccm-6phm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m25x-mccm-6phm", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31441" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S WordPress Galleria allows Reflected XSS. This issue affects WordPress Galleria: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-galleria/vulnerability/wordpress-wordpress-galleria-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json b/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json index 629b8b655d5..62028babdab 100644 --- a/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json +++ b/advisories/unreviewed/2025/04/GHSA-m8pg-77c8-3wj6/GHSA-m8pg-77c8-3wj6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8pg-77c8-3wj6", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-01T21:31:02Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2024-54533" ], "details": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m9fg-4mrx-27hp/GHSA-m9fg-4mrx-27hp.json b/advisories/unreviewed/2025/04/GHSA-m9fg-4mrx-27hp/GHSA-m9fg-4mrx-27hp.json new file mode 100644 index 00000000000..91a6b71c100 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m9fg-4mrx-27hp/GHSA-m9fg-4mrx-27hp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9fg-4mrx-27hp", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31431" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Bookmarks allows Reflected XSS. This issue affects WP Bookmarks: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-bookmarks/vulnerability/wordpress-wp-bookmarks-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mq67-mxx2-598j/GHSA-mq67-mxx2-598j.json b/advisories/unreviewed/2025/04/GHSA-mq67-mxx2-598j/GHSA-mq67-mxx2-598j.json new file mode 100644 index 00000000000..f1af74332f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mq67-mxx2-598j/GHSA-mq67-mxx2-598j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq67-mxx2-598j", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31537" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS. This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31537" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-noindex-nofollow-toolkit-by-mad-fish/vulnerability/wordpress-bulk-noindex-nofollow-toolkit-plugin-2-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mxj6-rm7w-82p5/GHSA-mxj6-rm7w-82p5.json b/advisories/unreviewed/2025/04/GHSA-mxj6-rm7w-82p5/GHSA-mxj6-rm7w-82p5.json new file mode 100644 index 00000000000..0b32a869f36 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mxj6-rm7w-82p5/GHSA-mxj6-rm7w-82p5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxj6-rm7w-82p5", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:34Z", + "aliases": [ + "CVE-2025-31889" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor. This issue affects Extensions for Elementor: from n/a through 2.0.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31889" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/extensions-for-elementor/vulnerability/wordpress-extensions-for-elementor-plugin-2-0-40-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json b/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json index 6929d539458..b0a19243bd8 100644 --- a/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json +++ b/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5r8-47qx-x497", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T21:31:16Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3028" ], "details": "JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pmm6-x9mw-vxqc/GHSA-pmm6-x9mw-vxqc.json b/advisories/unreviewed/2025/04/GHSA-pmm6-x9mw-vxqc/GHSA-pmm6-x9mw-vxqc.json new file mode 100644 index 00000000000..7febcb2bb80 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pmm6-x9mw-vxqc/GHSA-pmm6-x9mw-vxqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmm6-x9mw-vxqc", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31080" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS. This issue affects HTML Forms: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31080" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/html-forms/vulnerability/wordpress-html-forms-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json b/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json index a6ccc924f3a..641f22421c1 100644 --- a/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json +++ b/advisories/unreviewed/2025/04/GHSA-pph7-4r52-2m8q/GHSA-pph7-4r52-2m8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pph7-4r52-2m8q", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T21:31:04Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24218" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. An app may be able to access information about a user's contacts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pq7c-rw4g-fc5q/GHSA-pq7c-rw4g-fc5q.json b/advisories/unreviewed/2025/04/GHSA-pq7c-rw4g-fc5q/GHSA-pq7c-rw4g-fc5q.json new file mode 100644 index 00000000000..d5cb4c7469e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pq7c-rw4g-fc5q/GHSA-pq7c-rw4g-fc5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq7c-rw4g-fc5q", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31454" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Delete Post Revision allows Reflected XSS. This issue affects Delete Post Revision: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/delete-post-revision/vulnerability/wordpress-delete-post-revision-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q2hm-mp4x-64qg/GHSA-q2hm-mp4x-64qg.json b/advisories/unreviewed/2025/04/GHSA-q2hm-mp4x-64qg/GHSA-q2hm-mp4x-64qg.json index 5c2a7c3ebf8..1b9b5b6cef5 100644 --- a/advisories/unreviewed/2025/04/GHSA-q2hm-mp4x-64qg/GHSA-q2hm-mp4x-64qg.json +++ b/advisories/unreviewed/2025/04/GHSA-q2hm-mp4x-64qg/GHSA-q2hm-mp4x-64qg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q2hm-mp4x-64qg", - "modified": "2025-04-01T03:31:33Z", + "modified": "2025-04-01T21:31:11Z", "published": "2025-04-01T03:31:33Z", "aliases": [ "CVE-2025-3051" ], "details": "Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238.\n\nIf an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution.\n\nLinux::Statm::Tiny uses Mite to produce the affected code section due to CVE-2025-30672", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-427" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T03:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q3c3-9cvm-mvh9/GHSA-q3c3-9cvm-mvh9.json b/advisories/unreviewed/2025/04/GHSA-q3c3-9cvm-mvh9/GHSA-q3c3-9cvm-mvh9.json new file mode 100644 index 00000000000..9ea0d1e4501 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q3c3-9cvm-mvh9/GHSA-q3c3-9cvm-mvh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3c3-9cvm-mvh9", + "modified": "2025-04-01T21:31:31Z", + "published": "2025-04-01T21:31:31Z", + "aliases": [ + "CVE-2025-30841" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30841" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/countdown-builder/vulnerability/wordpress-countdown-clock-plugin-2-8-8-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json b/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json index 67202a6d3c6..316c43aebba 100644 --- a/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json +++ b/advisories/unreviewed/2025/04/GHSA-q3w8-9x53-fgrm/GHSA-q3w8-9x53-fgrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q3w8-9x53-fgrm", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T21:31:03Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24211" ], "details": "This issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json b/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json index de62447f05e..faa82716313 100644 --- a/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json +++ b/advisories/unreviewed/2025/04/GHSA-q556-7cxr-pm34/GHSA-q556-7cxr-pm34.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q556-7cxr-pm34", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T21:31:02Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24182" ], "details": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. Processing a maliciously crafted font may result in the disclosure of process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json b/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json new file mode 100644 index 00000000000..e93e5872227 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qgv4-vprj-x2fq/GHSA-qgv4-vprj-x2fq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgv4-vprj-x2fq", + "modified": "2025-04-01T21:31:30Z", + "published": "2025-04-01T21:31:30Z", + "aliases": [ + "CVE-2025-29070" + ], + "details": "A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29070" + }, + { + "type": "WEB", + "url": "https://github.com/mm2/Little-CMS/issues/475" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qm6j-763r-9qfq/GHSA-qm6j-763r-9qfq.json b/advisories/unreviewed/2025/04/GHSA-qm6j-763r-9qfq/GHSA-qm6j-763r-9qfq.json new file mode 100644 index 00000000000..cd4bc890c6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qm6j-763r-9qfq/GHSA-qm6j-763r-9qfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm6j-763r-9qfq", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31531" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in click5 History Log by click5 allows SQL Injection. This issue affects History Log by click5: from n/a through 1.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31531" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/history-log-by-click5/vulnerability/wordpress-history-log-by-click5-plugin-1-0-13-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json b/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json index 90555785123..e0e759e8e20 100644 --- a/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json +++ b/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrfj-w3wq-p623", - "modified": "2025-04-01T18:30:55Z", + "modified": "2025-04-01T21:31:27Z", "published": "2025-04-01T18:30:55Z", "aliases": [ "CVE-2025-28132" ], "details": "A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T17:15:46Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qw5v-92q5-cgx7/GHSA-qw5v-92q5-cgx7.json b/advisories/unreviewed/2025/04/GHSA-qw5v-92q5-cgx7/GHSA-qw5v-92q5-cgx7.json new file mode 100644 index 00000000000..7f47e570471 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qw5v-92q5-cgx7/GHSA-qw5v-92q5-cgx7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw5v-92q5-cgx7", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31089" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fahad Mahmood Order Splitter for WooCommerce allows SQL Injection. This issue affects Order Splitter for WooCommerce: from n/a through 5.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31089" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-order-splitter/vulnerability/wordpress-order-splitter-for-woocommerce-5-3-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r3xw-jfrq-jvvx/GHSA-r3xw-jfrq-jvvx.json b/advisories/unreviewed/2025/04/GHSA-r3xw-jfrq-jvvx/GHSA-r3xw-jfrq-jvvx.json new file mode 100644 index 00000000000..bdd95f7aca4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r3xw-jfrq-jvvx/GHSA-r3xw-jfrq-jvvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3xw-jfrq-jvvx", + "modified": "2025-04-01T21:31:31Z", + "published": "2025-04-01T21:31:31Z", + "aliases": [ + "CVE-2025-30554" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Frizzly allows Reflected XSS. This issue affects Frizzly: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30554" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/frizzly/vulnerability/wordpress-frizzly-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r8mw-qm8w-jjr3/GHSA-r8mw-qm8w-jjr3.json b/advisories/unreviewed/2025/04/GHSA-r8mw-qm8w-jjr3/GHSA-r8mw-qm8w-jjr3.json new file mode 100644 index 00000000000..485964106ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r8mw-qm8w-jjr3/GHSA-r8mw-qm8w-jjr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8mw-qm8w-jjr3", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-30906" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coffee Code Tech Plugin Oficial – Getnet para WooCommerce allows Reflected XSS. This issue affects Plugin Oficial – Getnet para WooCommerce: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30906" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-checkout-getnet/vulnerability/wordpress-plugin-oficial-getnet-para-woocommerce-plugin-1-7-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rpf4-742m-wgm9/GHSA-rpf4-742m-wgm9.json b/advisories/unreviewed/2025/04/GHSA-rpf4-742m-wgm9/GHSA-rpf4-742m-wgm9.json new file mode 100644 index 00000000000..1ff7b2c35d1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rpf4-742m-wgm9/GHSA-rpf4-742m-wgm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpf4-742m-wgm9", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:34Z", + "aliases": [ + "CVE-2025-31753" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser. This issue affects Advanced Speed Increaser: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-speed-increaser/vulnerability/wordpress-advanced-speed-increaser-plugin-2-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json b/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json index b06b780ac5f..5c3a703c6df 100644 --- a/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json +++ b/advisories/unreviewed/2025/04/GHSA-rx8v-vhcf-rfq6/GHSA-rx8v-vhcf-rfq6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rx8v-vhcf-rfq6", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T21:31:07Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30441" ], "details": "This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v7cj-mpqj-pgwf/GHSA-v7cj-mpqj-pgwf.json b/advisories/unreviewed/2025/04/GHSA-v7cj-mpqj-pgwf/GHSA-v7cj-mpqj-pgwf.json new file mode 100644 index 00000000000..61529845214 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v7cj-mpqj-pgwf/GHSA-v7cj-mpqj-pgwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7cj-mpqj-pgwf", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31552" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker allows SQL Injection. This issue affects RSVPMarker : from n/a through 11.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rsvpmaker/vulnerability/wordpress-rsvpmarker-plugin-11-4-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vgf8-f9xm-cx7m/GHSA-vgf8-f9xm-cx7m.json b/advisories/unreviewed/2025/04/GHSA-vgf8-f9xm-cx7m/GHSA-vgf8-f9xm-cx7m.json new file mode 100644 index 00000000000..aa2e33fd708 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vgf8-f9xm-cx7m/GHSA-vgf8-f9xm-cx7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgf8-f9xm-cx7m", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31534" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shopper allows SQL Injection. This issue affects Shopper: from n/a through 3.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31534" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shopper/vulnerability/wordpress-shopper-plugin-3-2-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json index 7b0ad264162..1c1892d44a4 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json +++ b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhg6-m6c8-39c2", - "modified": "2025-04-01T15:31:37Z", + "modified": "2025-04-01T21:31:17Z", "published": "2025-04-01T15:31:37Z", "aliases": [ "CVE-2025-30676" ], "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: before 18.12.19.\n\nUsers are recommended to upgrade to version 18.12.19, which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-80" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T15:16:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json b/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json index 3421b11936b..704a72676bc 100644 --- a/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json +++ b/advisories/unreviewed/2025/04/GHSA-vjfx-mp69-qfw4/GHSA-vjfx-mp69-qfw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vjfx-mp69-qfw4", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T21:31:05Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24248" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json b/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json index d75bacaa2fe..aae329f509d 100644 --- a/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json +++ b/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vq4p-pchp-6g6v", - "modified": "2025-04-01T12:30:34Z", + "modified": "2025-04-01T21:31:16Z", "published": "2025-04-01T12:30:34Z", "aliases": [ "CVE-2025-30177" ], "details": "Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions.\n\nThis issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6.\n\nUsers are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS.\n\nCamel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the \"out\" direction, while it doesn't filter the \"in\" direction.\n\n\nThis allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -31,7 +36,7 @@ "cwe_ids": [ "CWE-164" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T12:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json b/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json index 880ea7dbfd0..f4b25c7e688 100644 --- a/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json +++ b/advisories/unreviewed/2025/04/GHSA-vwcg-r7w2-v8qc/GHSA-vwcg-r7w2-v8qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vwcg-r7w2-v8qc", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T21:31:03Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24208" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vww2-wxfv-25rq/GHSA-vww2-wxfv-25rq.json b/advisories/unreviewed/2025/04/GHSA-vww2-wxfv-25rq/GHSA-vww2-wxfv-25rq.json new file mode 100644 index 00000000000..64526b1cd85 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vww2-wxfv-25rq/GHSA-vww2-wxfv-25rq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vww2-wxfv-25rq", + "modified": "2025-04-01T21:31:32Z", + "published": "2025-04-01T21:31:32Z", + "aliases": [ + "CVE-2025-31097" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31097" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/material-dashboard/vulnerability/wordpress-material-dashboard-1-4-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json b/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json new file mode 100644 index 00000000000..30ebc54be0e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w3mx-ghvj-8vc2/GHSA-w3mx-ghvj-8vc2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3mx-ghvj-8vc2", + "modified": "2025-04-01T21:31:29Z", + "published": "2025-04-01T21:31:29Z", + "aliases": [ + "CVE-2003-20001" + ], + "details": "An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2003-20001" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/31445" + }, + { + "type": "WEB", + "url": "https://rb.gy/1smt22" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/49176" + }, + { + "type": "WEB", + "url": "http://olografix.org/acme/mitel.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json b/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json new file mode 100644 index 00000000000..807bd2b8c67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w9qw-39gf-jp7r/GHSA-w9qw-39gf-jp7r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9qw-39gf-jp7r", + "modified": "2025-04-01T21:31:29Z", + "published": "2025-04-01T21:31:29Z", + "aliases": [ + "CVE-2025-29069" + ], + "details": "A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29069" + }, + { + "type": "WEB", + "url": "https://github.com/mm2/Little-CMS/issues/476" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wg43-7q89-q52r/GHSA-wg43-7q89-q52r.json b/advisories/unreviewed/2025/04/GHSA-wg43-7q89-q52r/GHSA-wg43-7q89-q52r.json new file mode 100644 index 00000000000..daf3ef96580 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wg43-7q89-q52r/GHSA-wg43-7q89-q52r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg43-7q89-q52r", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31550" + ], + "details": "Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in thom4 WP-LESS allows Retrieve Embedded Sensitive Data. This issue affects WP-LESS: from 1.9.3 through 3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31550" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-less/vulnerability/wordpress-wp-less-plugin-1-9-3-3-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json b/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json index 6561ce4f455..8e498b783d2 100644 --- a/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json +++ b/advisories/unreviewed/2025/04/GHSA-wp33-fh49-7crr/GHSA-wp33-fh49-7crr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wp33-fh49-7crr", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T21:31:09Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30467" ], "details": "The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json b/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json index f82e3c060e5..d1464bea84e 100644 --- a/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json +++ b/advisories/unreviewed/2025/04/GHSA-wrwh-5f9j-74c6/GHSA-wrwh-5f9j-74c6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wrwh-5f9j-74c6", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T21:31:08Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30460" ], "details": "A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x784-p7w9-pf32/GHSA-x784-p7w9-pf32.json b/advisories/unreviewed/2025/04/GHSA-x784-p7w9-pf32/GHSA-x784-p7w9-pf32.json new file mode 100644 index 00000000000..9fc35963a1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x784-p7w9-pf32/GHSA-x784-p7w9-pf32.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x784-p7w9-pf32", + "modified": "2025-04-01T21:31:29Z", + "published": "2025-04-01T21:31:29Z", + "aliases": [ + "CVE-2025-3096" + ], + "details": "Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3096" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2022-2297" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php-clinics-patient-management-system-source-code" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T19:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x8c8-54jh-wpc2/GHSA-x8c8-54jh-wpc2.json b/advisories/unreviewed/2025/04/GHSA-x8c8-54jh-wpc2/GHSA-x8c8-54jh-wpc2.json new file mode 100644 index 00000000000..08d4e37ac04 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x8c8-54jh-wpc2/GHSA-x8c8-54jh-wpc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8c8-54jh-wpc2", + "modified": "2025-04-01T21:31:34Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31564" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One allows Blind SQL Injection. This issue affects Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-auto-tool/vulnerability/chatgpt-ai-auto-tool-content-writing-assistant-gemini-writer-chatgpt-all-in-one-plugin-2-1-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json b/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json new file mode 100644 index 00000000000..81be21cf1f0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x8jj-j32x-rqj9/GHSA-x8jj-j32x-rqj9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8jj-j32x-rqj9", + "modified": "2025-04-01T21:31:30Z", + "published": "2025-04-01T21:31:30Z", + "aliases": [ + "CVE-2025-29036" + ], + "details": "An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29036" + }, + { + "type": "WEB", + "url": "https://github.com/sahat/hackathon-starter/issues/1326" + }, + { + "type": "WEB", + "url": "https://github.com/sahat/hackathon-starter/pull/1328" + }, + { + "type": "WEB", + "url": "https://github.com/HypeDuke/vulnerable-research/blob/main/CVE-2025-29036" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x9cf-qv7q-gcr9/GHSA-x9cf-qv7q-gcr9.json b/advisories/unreviewed/2025/04/GHSA-x9cf-qv7q-gcr9/GHSA-x9cf-qv7q-gcr9.json new file mode 100644 index 00000000000..95b01f2fd6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x9cf-qv7q-gcr9/GHSA-x9cf-qv7q-gcr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9cf-qv7q-gcr9", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31462" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rzfarrell CGM Event Calendar allows Reflected XSS. This issue affects CGM Event Calendar: from n/a through 0.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31462" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cgm-event-calendar/vulnerability/wordpress-cgm-event-calendar-0-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json b/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json index 313f3d5b9a3..3e18822c6d3 100644 --- a/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json +++ b/advisories/unreviewed/2025/04/GHSA-xg7p-78j8-hfrp/GHSA-xg7p-78j8-hfrp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xg7p-78j8-hfrp", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T21:31:07Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-30430" ], "details": "This issue was addressed through improved state management. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Password autofill may fill in passwords after failing authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xjcf-7v2j-xmr4/GHSA-xjcf-7v2j-xmr4.json b/advisories/unreviewed/2025/04/GHSA-xjcf-7v2j-xmr4/GHSA-xjcf-7v2j-xmr4.json new file mode 100644 index 00000000000..dd48850e06b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjcf-7v2j-xmr4/GHSA-xjcf-7v2j-xmr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjcf-7v2j-xmr4", + "modified": "2025-04-01T21:31:33Z", + "published": "2025-04-01T21:31:33Z", + "aliases": [ + "CVE-2025-31548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Tuhin Ultimate Push Notifications allows Reflected XSS. This issue affects Ultimate Push Notifications: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-push-notifications/vulnerability/wordpress-ultimate-push-notifications-plugin-1-1-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T21:15:49Z" + } +} \ No newline at end of file