diff --git a/advisories/unreviewed/2023/03/GHSA-cqq6-v7j5-vr3p/GHSA-cqq6-v7j5-vr3p.json b/advisories/unreviewed/2023/03/GHSA-cqq6-v7j5-vr3p/GHSA-cqq6-v7j5-vr3p.json index 6d248d3d0a7..55ff19b7460 100644 --- a/advisories/unreviewed/2023/03/GHSA-cqq6-v7j5-vr3p/GHSA-cqq6-v7j5-vr3p.json +++ b/advisories/unreviewed/2023/03/GHSA-cqq6-v7j5-vr3p/GHSA-cqq6-v7j5-vr3p.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-305" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4rwx-mrf5-wx33/GHSA-4rwx-mrf5-wx33.json b/advisories/unreviewed/2024/02/GHSA-4rwx-mrf5-wx33/GHSA-4rwx-mrf5-wx33.json index c3415f23a2d..cc159e0d03f 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rwx-mrf5-wx33/GHSA-4rwx-mrf5-wx33.json +++ b/advisories/unreviewed/2024/02/GHSA-4rwx-mrf5-wx33/GHSA-4rwx-mrf5-wx33.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f27j-4f6g-jp27/GHSA-f27j-4f6g-jp27.json b/advisories/unreviewed/2024/02/GHSA-f27j-4f6g-jp27/GHSA-f27j-4f6g-jp27.json index 44e9e55d0d5..abc0adc93df 100644 --- a/advisories/unreviewed/2024/02/GHSA-f27j-4f6g-jp27/GHSA-f27j-4f6g-jp27.json +++ b/advisories/unreviewed/2024/02/GHSA-f27j-4f6g-jp27/GHSA-f27j-4f6g-jp27.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r92g-h2wj-6rv5/GHSA-r92g-h2wj-6rv5.json b/advisories/unreviewed/2024/04/GHSA-r92g-h2wj-6rv5/GHSA-r92g-h2wj-6rv5.json index 56744cad29b..724320455d5 100644 --- a/advisories/unreviewed/2024/04/GHSA-r92g-h2wj-6rv5/GHSA-r92g-h2wj-6rv5.json +++ b/advisories/unreviewed/2024/04/GHSA-r92g-h2wj-6rv5/GHSA-r92g-h2wj-6rv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r92g-h2wj-6rv5", - "modified": "2024-04-29T00:30:42Z", + "modified": "2025-02-12T15:31:53Z", "published": "2024-04-29T00:30:42Z", "aliases": [ "CVE-2024-33891" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://docs.delinea.com/online-help/secret-server/release-notes/ss-rn-11-7-000001.htm" }, + { + "type": "WEB", + "url": "https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2024-33891.py" + }, { "type": "WEB", "url": "https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3" diff --git a/advisories/unreviewed/2025/02/GHSA-29vj-gvmm-9fp3/GHSA-29vj-gvmm-9fp3.json b/advisories/unreviewed/2025/02/GHSA-29vj-gvmm-9fp3/GHSA-29vj-gvmm-9fp3.json new file mode 100644 index 00000000000..f9093260ca2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-29vj-gvmm-9fp3/GHSA-29vj-gvmm-9fp3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29vj-gvmm-9fp3", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2024-23563" + ], + "details": "HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23563" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2ghh-xmvf-53hw/GHSA-2ghh-xmvf-53hw.json b/advisories/unreviewed/2025/02/GHSA-2ghh-xmvf-53hw/GHSA-2ghh-xmvf-53hw.json index c7b8b0dd356..b1a1439348e 100644 --- a/advisories/unreviewed/2025/02/GHSA-2ghh-xmvf-53hw/GHSA-2ghh-xmvf-53hw.json +++ b/advisories/unreviewed/2025/02/GHSA-2ghh-xmvf-53hw/GHSA-2ghh-xmvf-53hw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2rr6-jrx8-xrg7/GHSA-2rr6-jrx8-xrg7.json b/advisories/unreviewed/2025/02/GHSA-2rr6-jrx8-xrg7/GHSA-2rr6-jrx8-xrg7.json new file mode 100644 index 00000000000..7c2ac04c215 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2rr6-jrx8-xrg7/GHSA-2rr6-jrx8-xrg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rr6-jrx8-xrg7", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26358" + ], + "details": "A CWE-20 \"Improper Input Validation\" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26358" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26358" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2vrc-ghfq-ww6x/GHSA-2vrc-ghfq-ww6x.json b/advisories/unreviewed/2025/02/GHSA-2vrc-ghfq-ww6x/GHSA-2vrc-ghfq-ww6x.json index 4c56cce2acf..83243355332 100644 --- a/advisories/unreviewed/2025/02/GHSA-2vrc-ghfq-ww6x/GHSA-2vrc-ghfq-ww6x.json +++ b/advisories/unreviewed/2025/02/GHSA-2vrc-ghfq-ww6x/GHSA-2vrc-ghfq-ww6x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2x8g-3gf7-5cw3/GHSA-2x8g-3gf7-5cw3.json b/advisories/unreviewed/2025/02/GHSA-2x8g-3gf7-5cw3/GHSA-2x8g-3gf7-5cw3.json new file mode 100644 index 00000000000..1fc0a3439e5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2x8g-3gf7-5cw3/GHSA-2x8g-3gf7-5cw3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x8g-3gf7-5cw3", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26365" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable front panel authentication via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26365" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-34m4-9vvp-p7j9/GHSA-34m4-9vvp-p7j9.json b/advisories/unreviewed/2025/02/GHSA-34m4-9vvp-p7j9/GHSA-34m4-9vvp-p7j9.json index 4f3876b3fa5..b6067c7a1fc 100644 --- a/advisories/unreviewed/2025/02/GHSA-34m4-9vvp-p7j9/GHSA-34m4-9vvp-p7j9.json +++ b/advisories/unreviewed/2025/02/GHSA-34m4-9vvp-p7j9/GHSA-34m4-9vvp-p7j9.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-357m-wr6w-wcjg/GHSA-357m-wr6w-wcjg.json b/advisories/unreviewed/2025/02/GHSA-357m-wr6w-wcjg/GHSA-357m-wr6w-wcjg.json new file mode 100644 index 00000000000..1a01e361af9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-357m-wr6w-wcjg/GHSA-357m-wr6w-wcjg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-357m-wr6w-wcjg", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26357" + ], + "details": "A CWE-35 \"Path Traversal\" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26357" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26357" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-384q-wx27-r5cm/GHSA-384q-wx27-r5cm.json b/advisories/unreviewed/2025/02/GHSA-384q-wx27-r5cm/GHSA-384q-wx27-r5cm.json index 62d480380a2..8f3cbe24883 100644 --- a/advisories/unreviewed/2025/02/GHSA-384q-wx27-r5cm/GHSA-384q-wx27-r5cm.json +++ b/advisories/unreviewed/2025/02/GHSA-384q-wx27-r5cm/GHSA-384q-wx27-r5cm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-3vf5-967m-jfcw/GHSA-3vf5-967m-jfcw.json b/advisories/unreviewed/2025/02/GHSA-3vf5-967m-jfcw/GHSA-3vf5-967m-jfcw.json new file mode 100644 index 00000000000..75ee534ac8d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3vf5-967m-jfcw/GHSA-3vf5-967m-jfcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vf5-967m-jfcw", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26361" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26361" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26361" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4gwx-j98p-3g7q/GHSA-4gwx-j98p-3g7q.json b/advisories/unreviewed/2025/02/GHSA-4gwx-j98p-3g7q/GHSA-4gwx-j98p-3g7q.json new file mode 100644 index 00000000000..b0a8bb07998 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4gwx-j98p-3g7q/GHSA-4gwx-j98p-3g7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gwx-j98p-3g7q", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26370" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove privileges from user groups via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26370" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26370" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4xg2-vjm8-8r9m/GHSA-4xg2-vjm8-8r9m.json b/advisories/unreviewed/2025/02/GHSA-4xg2-vjm8-8r9m/GHSA-4xg2-vjm8-8r9m.json new file mode 100644 index 00000000000..91b16273a9d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4xg2-vjm8-8r9m/GHSA-4xg2-vjm8-8r9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xg2-vjm8-8r9m", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26343" + ], + "details": "A CWE-1390 \"Weak Authentication\" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26343" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26343" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5c3r-jc6c-jrpr/GHSA-5c3r-jc6c-jrpr.json b/advisories/unreviewed/2025/02/GHSA-5c3r-jc6c-jrpr/GHSA-5c3r-jc6c-jrpr.json new file mode 100644 index 00000000000..3824dc36534 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5c3r-jc6c-jrpr/GHSA-5c3r-jc6c-jrpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c3r-jc6c-jrpr", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26342" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to create arbitrary users, including administrators, via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26342" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5j5f-9wh9-hfj9/GHSA-5j5f-9wh9-hfj9.json b/advisories/unreviewed/2025/02/GHSA-5j5f-9wh9-hfj9/GHSA-5j5f-9wh9-hfj9.json new file mode 100644 index 00000000000..e9a71d0da3a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5j5f-9wh9-hfj9/GHSA-5j5f-9wh9-hfj9.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j5f-9wh9-hfj9", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2024-57951" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhrtimers: Handle CPU state correctly on hotplug\n\nConsider a scenario where a CPU transitions from CPUHP_ONLINE to halfway\nthrough a CPU hotunplug down to CPUHP_HRTIMERS_PREPARE, and then back to\nCPUHP_ONLINE:\n\nSince hrtimers_prepare_cpu() does not run, cpu_base.hres_active remains set\nto 1 throughout. However, during a CPU unplug operation, the tick and the\nclockevents are shut down at CPUHP_AP_TICK_DYING. On return to the online\nstate, for instance CFS incorrectly assumes that the hrtick is already\nactive, and the chance of the clockevent device to transition to oneshot\nmode is also lost forever for the CPU, unless it goes back to a lower state\nthan CPUHP_HRTIMERS_PREPARE once.\n\nThis round-trip reveals another issue; cpu_base.online is not set to 1\nafter the transition, which appears as a WARN_ON_ONCE in enqueue_hrtimer().\n\nAside of that, the bulk of the per CPU state is not reset either, which\nmeans there are dangling pointers in the worst case.\n\nAddress this by adding a corresponding startup() callback, which resets the\nstale per CPU state and sets the online flag.\n\n[ tglx: Make the new callback unconditionally available, remove the online\n \tmodification in the prepare() callback and clear the remaining\n \tstate in the starting callback instead of the prepare callback ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57951" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14984139f1f2768883332965db566ef26db609e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15b453db41d36184cf0ccc21e7df624014ab6a1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f8dea1692eef2b7ba6a256246ed82c365fdc686" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38492f6ee883c7b1d33338bf531a62cff69b4b28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d41dbf82e10c44e53ea602398ab002baec27e75" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95e4f62df23f4df1ce6ef897d44b8e23c260921a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5cbbea145b400e40540c34816d16d36e0374fbc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5wmc-7h58-9rmm/GHSA-5wmc-7h58-9rmm.json b/advisories/unreviewed/2025/02/GHSA-5wmc-7h58-9rmm/GHSA-5wmc-7h58-9rmm.json index 0847b25cc55..d6761278acd 100644 --- a/advisories/unreviewed/2025/02/GHSA-5wmc-7h58-9rmm/GHSA-5wmc-7h58-9rmm.json +++ b/advisories/unreviewed/2025/02/GHSA-5wmc-7h58-9rmm/GHSA-5wmc-7h58-9rmm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-5xh3-j434-h57h/GHSA-5xh3-j434-h57h.json b/advisories/unreviewed/2025/02/GHSA-5xh3-j434-h57h/GHSA-5xh3-j434-h57h.json new file mode 100644 index 00000000000..4a180a2b4d3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5xh3-j434-h57h/GHSA-5xh3-j434-h57h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xh3-j434-h57h", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26348" + ], + "details": "A CWE-89 \"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\" in maxprofile/menu/model.lua (editUserMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute arbitrary SQL commands via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26348" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-62j6-3mx6-32xv/GHSA-62j6-3mx6-32xv.json b/advisories/unreviewed/2025/02/GHSA-62j6-3mx6-32xv/GHSA-62j6-3mx6-32xv.json new file mode 100644 index 00000000000..2fbf591c6d4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-62j6-3mx6-32xv/GHSA-62j6-3mx6-32xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62j6-3mx6-32xv", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26355" + ], + "details": "A CWE-35 \"Path Traversal\" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26355" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-657f-qvvx-wqv4/GHSA-657f-qvvx-wqv4.json b/advisories/unreviewed/2025/02/GHSA-657f-qvvx-wqv4/GHSA-657f-qvvx-wqv4.json new file mode 100644 index 00000000000..9e9aae47e61 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-657f-qvvx-wqv4/GHSA-657f-qvvx-wqv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-657f-qvvx-wqv4", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-1102" + ], + "details": "A CWE-346 \"Origin Validation Error\" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URLs or HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1102" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-1102" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-68hg-5q58-g3cv/GHSA-68hg-5q58-g3cv.json b/advisories/unreviewed/2025/02/GHSA-68hg-5q58-g3cv/GHSA-68hg-5q58-g3cv.json new file mode 100644 index 00000000000..63a6c52caab --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-68hg-5q58-g3cv/GHSA-68hg-5q58-g3cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68hg-5q58-g3cv", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2025-1212" + ], + "details": "An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1212" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/502196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6g4p-cff3-27jf/GHSA-6g4p-cff3-27jf.json b/advisories/unreviewed/2025/02/GHSA-6g4p-cff3-27jf/GHSA-6g4p-cff3-27jf.json new file mode 100644 index 00000000000..f1a2d7ead0a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6g4p-cff3-27jf/GHSA-6g4p-cff3-27jf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g4p-cff3-27jf", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26371" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to groups via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26371" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26371" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6g66-g3cm-gp6c/GHSA-6g66-g3cm-gp6c.json b/advisories/unreviewed/2025/02/GHSA-6g66-g3cm-gp6c/GHSA-6g66-g3cm-gp6c.json new file mode 100644 index 00000000000..82e41a13c82 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6g66-g3cm-gp6c/GHSA-6g66-g3cm-gp6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g66-g3cm-gp6c", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-26339" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability in multiple unspecified ways via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26339" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26339" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6jr2-j7cv-fg3m/GHSA-6jr2-j7cv-fg3m.json b/advisories/unreviewed/2025/02/GHSA-6jr2-j7cv-fg3m/GHSA-6jr2-j7cv-fg3m.json new file mode 100644 index 00000000000..72d75295375 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6jr2-j7cv-fg3m/GHSA-6jr2-j7cv-fg3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jr2-j7cv-fg3m", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-1100" + ], + "details": "A CWE-259 \"Use of Hard-coded Password\" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1100" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-1100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6p46-cg8v-f84m/GHSA-6p46-cg8v-f84m.json b/advisories/unreviewed/2025/02/GHSA-6p46-cg8v-f84m/GHSA-6p46-cg8v-f84m.json new file mode 100644 index 00000000000..0d1801d1115 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6p46-cg8v-f84m/GHSA-6p46-cg8v-f84m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p46-cg8v-f84m", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26364" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an authentication profile server via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26364" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6q8c-8rxm-f6fh/GHSA-6q8c-8rxm-f6fh.json b/advisories/unreviewed/2025/02/GHSA-6q8c-8rxm-f6fh/GHSA-6q8c-8rxm-f6fh.json new file mode 100644 index 00000000000..0616773ad37 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6q8c-8rxm-f6fh/GHSA-6q8c-8rxm-f6fh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q8c-8rxm-f6fh", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-21696" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: clear uffd-wp PTE/PMD state on mremap()\n\nWhen mremap()ing a memory region previously registered with userfaultfd as\nwrite-protected but without UFFD_FEATURE_EVENT_REMAP, an inconsistency in\nflag clearing leads to a mismatch between the vma flags (which have\nuffd-wp cleared) and the pte/pmd flags (which do not have uffd-wp\ncleared). This mismatch causes a subsequent mprotect(PROT_WRITE) to\ntrigger a warning in page_table_check_pte_flags() due to setting the pte\nto writable while uffd-wp is still set.\n\nFix this by always explicitly clearing the uffd-wp pte/pmd flags on any\nsuch mremap() so that the values are consistent with the existing clearing\nof VM_UFFD_WP. Be careful to clear the logical flag regardless of its\nphysical form; a PTE bit, a swap PTE bit, or a PTE marker. Cover PTE,\nhuge PMD and hugetlb paths.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21696" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cef0bb836e3cfe00f08f9606c72abd72fe78ca3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/310ac886d68de661c3a334198d8604b722d7fdf8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7g2j-gh73-wrxr/GHSA-7g2j-gh73-wrxr.json b/advisories/unreviewed/2025/02/GHSA-7g2j-gh73-wrxr/GHSA-7g2j-gh73-wrxr.json index 07a291840e0..f60f828b358 100644 --- a/advisories/unreviewed/2025/02/GHSA-7g2j-gh73-wrxr/GHSA-7g2j-gh73-wrxr.json +++ b/advisories/unreviewed/2025/02/GHSA-7g2j-gh73-wrxr/GHSA-7g2j-gh73-wrxr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-7m89-vh3r-4j38/GHSA-7m89-vh3r-4j38.json b/advisories/unreviewed/2025/02/GHSA-7m89-vh3r-4j38/GHSA-7m89-vh3r-4j38.json new file mode 100644 index 00000000000..d0ebdd4a2e3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7m89-vh3r-4j38/GHSA-7m89-vh3r-4j38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m89-vh3r-4j38", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26366" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable front panel authentication via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26366" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26366" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7mr4-qghc-9cw2/GHSA-7mr4-qghc-9cw2.json b/advisories/unreviewed/2025/02/GHSA-7mr4-qghc-9cw2/GHSA-7mr4-qghc-9cw2.json new file mode 100644 index 00000000000..050d668a933 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7mr4-qghc-9cw2/GHSA-7mr4-qghc-9cw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mr4-qghc-9cw2", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26372" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from groups via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26372" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26372" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json b/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json index d62536fea08..c281362ad1f 100644 --- a/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json +++ b/advisories/unreviewed/2025/02/GHSA-7wpm-58fr-6p69/GHSA-7wpm-58fr-6p69.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1391", "CWE-327" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json b/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json index f68a46cf114..9e96190b1ed 100644 --- a/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json +++ b/advisories/unreviewed/2025/02/GHSA-7xf9-6rpx-2c4r/GHSA-7xf9-6rpx-2c4r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xf9-6rpx-2c4r", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-12T15:31:56Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2022-3180" ], "details": "The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-290" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T22:15:24Z" diff --git a/advisories/unreviewed/2025/02/GHSA-845r-wpwf-v7g7/GHSA-845r-wpwf-v7g7.json b/advisories/unreviewed/2025/02/GHSA-845r-wpwf-v7g7/GHSA-845r-wpwf-v7g7.json new file mode 100644 index 00000000000..19c3c42e8fb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-845r-wpwf-v7g7/GHSA-845r-wpwf-v7g7.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-845r-wpwf-v7g7", + "modified": "2025-02-12T15:31:58Z", + "published": "2025-02-12T15:31:58Z", + "aliases": [ + "CVE-2024-10322" + ], + "details": "The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10322" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3231744" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3231744/brizy/trunk/admin/svg/main.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/brizy/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3b2ef7c3-4610-4e8b-ab27-2d6cbdbed097?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-883q-m76c-j5wj/GHSA-883q-m76c-j5wj.json b/advisories/unreviewed/2025/02/GHSA-883q-m76c-j5wj/GHSA-883q-m76c-j5wj.json new file mode 100644 index 00000000000..b114ffea35e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-883q-m76c-j5wj/GHSA-883q-m76c-j5wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-883q-m76c-j5wj", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26362" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26362" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8c5g-jg5f-5fjc/GHSA-8c5g-jg5f-5fjc.json b/advisories/unreviewed/2025/02/GHSA-8c5g-jg5f-5fjc/GHSA-8c5g-jg5f-5fjc.json new file mode 100644 index 00000000000..620fc46c617 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8c5g-jg5f-5fjc/GHSA-8c5g-jg5f-5fjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c5g-jg5f-5fjc", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26359" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26359" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26359" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8ch6-wp35-jv3j/GHSA-8ch6-wp35-jv3j.json b/advisories/unreviewed/2025/02/GHSA-8ch6-wp35-jv3j/GHSA-8ch6-wp35-jv3j.json new file mode 100644 index 00000000000..e931f3892a0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8ch6-wp35-jv3j/GHSA-8ch6-wp35-jv3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ch6-wp35-jv3j", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26369" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to user groups via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26369" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8mjp-767h-9569/GHSA-8mjp-767h-9569.json b/advisories/unreviewed/2025/02/GHSA-8mjp-767h-9569/GHSA-8mjp-767h-9569.json new file mode 100644 index 00000000000..259b9b68efc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8mjp-767h-9569/GHSA-8mjp-767h-9569.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mjp-767h-9569", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-21694" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc: fix softlockup in __read_vmcore (part 2)\n\nSince commit 5cbcb62dddf5 (\"fs/proc: fix softlockup in __read_vmcore\") the\nnumber of softlockups in __read_vmcore at kdump time have gone down, but\nthey still happen sometimes.\n\nIn a memory constrained environment like the kdump image, a softlockup is\nnot just a harmless message, but it can interfere with things like RCU\nfreeing memory, causing the crashdump to get stuck.\n\nThe second loop in __read_vmcore has a lot more opportunities for natural\nsleep points, like scheduling out while waiting for a data write to\nhappen, but apparently that is not always enough.\n\nAdd a cond_resched() to the second loop in __read_vmcore to (hopefully)\nget rid of the softlockups.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21694" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/649b266606bc413407ce315f710c8ce8a88ee30a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65c367bd9d4f43513c7f837df5753bea9561b836" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80828540dad0757b6337c6561d49c81038f38d87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80da29deb88a3a907441fc35bb7bac309f31e713" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84c4ed15626574c9ac6c1039ba9c137a77bcc7f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5a2ee8144c3897d37403a69118c3e3dc5713958" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbc5dde0a461240046e8a41c43d7c3b76d5db952" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8rgx-fmm3-3qvv/GHSA-8rgx-fmm3-3qvv.json b/advisories/unreviewed/2025/02/GHSA-8rgx-fmm3-3qvv/GHSA-8rgx-fmm3-3qvv.json new file mode 100644 index 00000000000..51d4c42fb4c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8rgx-fmm3-3qvv/GHSA-8rgx-fmm3-3qvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rgx-fmm3-3qvv", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-26340" + ], + "details": "A CWE-321 \"Use of Hard-coded Cryptographic Key\" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to bypass the authentication via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26340" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26340" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8rmw-8cch-2w5c/GHSA-8rmw-8cch-2w5c.json b/advisories/unreviewed/2025/02/GHSA-8rmw-8cch-2w5c/GHSA-8rmw-8cch-2w5c.json new file mode 100644 index 00000000000..de0ed2a0ac3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8rmw-8cch-2w5c/GHSA-8rmw-8cch-2w5c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rmw-8cch-2w5c", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2025-0376" + ], + "details": "An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0376" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2930243" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/512603" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8xqh-vr8h-f939/GHSA-8xqh-vr8h-f939.json b/advisories/unreviewed/2025/02/GHSA-8xqh-vr8h-f939/GHSA-8xqh-vr8h-f939.json new file mode 100644 index 00000000000..d2171c11cd7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8xqh-vr8h-f939/GHSA-8xqh-vr8h-f939.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xqh-vr8h-f939", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26373" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26373" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-97qh-3m6m-6c3w/GHSA-97qh-3m6m-6c3w.json b/advisories/unreviewed/2025/02/GHSA-97qh-3m6m-6c3w/GHSA-97qh-3m6m-6c3w.json new file mode 100644 index 00000000000..dcedb1f8bb0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-97qh-3m6m-6c3w/GHSA-97qh-3m6m-6c3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97qh-3m6m-6c3w", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26351" + ], + "details": "A CWE-35 \"Path Traversal\" in the template download mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26351" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26351" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9qm8-38h3-v7p7/GHSA-9qm8-38h3-v7p7.json b/advisories/unreviewed/2025/02/GHSA-9qm8-38h3-v7p7/GHSA-9qm8-38h3-v7p7.json index 2f6bfdb7de2..d610c09c57c 100644 --- a/advisories/unreviewed/2025/02/GHSA-9qm8-38h3-v7p7/GHSA-9qm8-38h3-v7p7.json +++ b/advisories/unreviewed/2025/02/GHSA-9qm8-38h3-v7p7/GHSA-9qm8-38h3-v7p7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json b/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json index 64258b9a7f0..5263f92bc1c 100644 --- a/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json +++ b/advisories/unreviewed/2025/02/GHSA-9r56-r7r5-55vj/GHSA-9r56-r7r5-55vj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-9wp5-p6h6-rmw9/GHSA-9wp5-p6h6-rmw9.json b/advisories/unreviewed/2025/02/GHSA-9wp5-p6h6-rmw9/GHSA-9wp5-p6h6-rmw9.json new file mode 100644 index 00000000000..89583cb301c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9wp5-p6h6-rmw9/GHSA-9wp5-p6h6-rmw9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wp5-p6h6-rmw9", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-1200" + ], + "details": "A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/app/slider_crud.php. The manipulation of the argument del_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1200" + }, + { + "type": "WEB", + "url": "https://github.com/Yesec/Best-church-management-software/blob/main/slider_crud.php_SQLi.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496950" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9xrv-rxvq-776c/GHSA-9xrv-rxvq-776c.json b/advisories/unreviewed/2025/02/GHSA-9xrv-rxvq-776c/GHSA-9xrv-rxvq-776c.json new file mode 100644 index 00000000000..3c5077ded2b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9xrv-rxvq-776c/GHSA-9xrv-rxvq-776c.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xrv-rxvq-776c", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2024-54160" + ], + "details": "dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54160" + }, + { + "type": "WEB", + "url": "https://github.com/opensearch-project/dashboards-reporting/pull/476" + }, + { + "type": "WEB", + "url": "https://github.com/Jflye/CVE-2024-54160--Opensearch-HTML-Injection" + }, + { + "type": "WEB", + "url": "https://github.com/opensearch-project/dashboards-reporting/compare/2.18.0.0...2.19.0.0" + }, + { + "type": "WEB", + "url": "https://github.com/opensearch-project/opensearch-build/blob/main/release-notes/opensearch-release-notes-2.19.0.md" + }, + { + "type": "WEB", + "url": "https://opensearch.org/releases.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f529-5jxm-j388/GHSA-f529-5jxm-j388.json b/advisories/unreviewed/2025/02/GHSA-f529-5jxm-j388/GHSA-f529-5jxm-j388.json index fda3deb046e..96214266148 100644 --- a/advisories/unreviewed/2025/02/GHSA-f529-5jxm-j388/GHSA-f529-5jxm-j388.json +++ b/advisories/unreviewed/2025/02/GHSA-f529-5jxm-j388/GHSA-f529-5jxm-j388.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-f73r-7g7h-494m/GHSA-f73r-7g7h-494m.json b/advisories/unreviewed/2025/02/GHSA-f73r-7g7h-494m/GHSA-f73r-7g7h-494m.json new file mode 100644 index 00000000000..41fa029378e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f73r-7g7h-494m/GHSA-f73r-7g7h-494m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f73r-7g7h-494m", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2025-1042" + ], + "details": "An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1042" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2886976" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/50849943" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-frcf-g5px-vp53/GHSA-frcf-g5px-vp53.json b/advisories/unreviewed/2025/02/GHSA-frcf-g5px-vp53/GHSA-frcf-g5px-vp53.json index 1fd13fc8b0e..66ea4e960c8 100644 --- a/advisories/unreviewed/2025/02/GHSA-frcf-g5px-vp53/GHSA-frcf-g5px-vp53.json +++ b/advisories/unreviewed/2025/02/GHSA-frcf-g5px-vp53/GHSA-frcf-g5px-vp53.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-g838-jqfg-7xgx/GHSA-g838-jqfg-7xgx.json b/advisories/unreviewed/2025/02/GHSA-g838-jqfg-7xgx/GHSA-g838-jqfg-7xgx.json new file mode 100644 index 00000000000..442a3c2ca83 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g838-jqfg-7xgx/GHSA-g838-jqfg-7xgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g838-jqfg-7xgx", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-26341" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset arbitrary user passwords via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26341" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26341" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ggh5-8m9w-pgpg/GHSA-ggh5-8m9w-pgpg.json b/advisories/unreviewed/2025/02/GHSA-ggh5-8m9w-pgpg/GHSA-ggh5-8m9w-pgpg.json new file mode 100644 index 00000000000..c4e3d1255a8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ggh5-8m9w-pgpg/GHSA-ggh5-8m9w-pgpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggh5-8m9w-pgpg", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26356" + ], + "details": "A CWE-35 \"Path Traversal\" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26356" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json new file mode 100644 index 00000000000..99afb20d0c1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gghq-qp34-gqg8", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2025-1244" + ], + "details": "A flaw was found in the Emacs text editor. Improper handling of custom \"man\" URI schemes allows attackers to execute arbitrary shell commands by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1244" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-1244" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345150" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gm44-gx44-cwv9/GHSA-gm44-gx44-cwv9.json b/advisories/unreviewed/2025/02/GHSA-gm44-gx44-cwv9/GHSA-gm44-gx44-cwv9.json index 3952a90d76d..ab8f561dda7 100644 --- a/advisories/unreviewed/2025/02/GHSA-gm44-gx44-cwv9/GHSA-gm44-gx44-cwv9.json +++ b/advisories/unreviewed/2025/02/GHSA-gm44-gx44-cwv9/GHSA-gm44-gx44-cwv9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-gmm4-3ppf-2fxm/GHSA-gmm4-3ppf-2fxm.json b/advisories/unreviewed/2025/02/GHSA-gmm4-3ppf-2fxm/GHSA-gmm4-3ppf-2fxm.json new file mode 100644 index 00000000000..d23503d7892 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gmm4-3ppf-2fxm/GHSA-gmm4-3ppf-2fxm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmm4-3ppf-2fxm", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2025-1202" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Best Church Management Software 1.1. Affected is an unknown function of the file /admin/edit_slider.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1202" + }, + { + "type": "WEB", + "url": "https://github.com/Yesec/Best-church-management-software/blob/main/edit_slider.php.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496954" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gpqf-qcrr-qp6h/GHSA-gpqf-qcrr-qp6h.json b/advisories/unreviewed/2025/02/GHSA-gpqf-qcrr-qp6h/GHSA-gpqf-qcrr-qp6h.json new file mode 100644 index 00000000000..f0ecdfb81c2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gpqf-qcrr-qp6h/GHSA-gpqf-qcrr-qp6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpqf-qcrr-qp6h", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26354" + ], + "details": "A CWE-35 \"Path Traversal\" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26354" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26354" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h65m-c8p2-9448/GHSA-h65m-c8p2-9448.json b/advisories/unreviewed/2025/02/GHSA-h65m-c8p2-9448/GHSA-h65m-c8p2-9448.json new file mode 100644 index 00000000000..3f82799b6c7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h65m-c8p2-9448/GHSA-h65m-c8p2-9448.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h65m-c8p2-9448", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26363" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26363" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h82m-pvf6-9gjr/GHSA-h82m-pvf6-9gjr.json b/advisories/unreviewed/2025/02/GHSA-h82m-pvf6-9gjr/GHSA-h82m-pvf6-9gjr.json new file mode 100644 index 00000000000..bce98fdbca2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h82m-pvf6-9gjr/GHSA-h82m-pvf6-9gjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h82m-pvf6-9gjr", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26347" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user permissions via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26347" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26347" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hcg3-9g3p-xjxq/GHSA-hcg3-9g3p-xjxq.json b/advisories/unreviewed/2025/02/GHSA-hcg3-9g3p-xjxq/GHSA-hcg3-9g3p-xjxq.json index 6f1cec971ed..2528ca02ea2 100644 --- a/advisories/unreviewed/2025/02/GHSA-hcg3-9g3p-xjxq/GHSA-hcg3-9g3p-xjxq.json +++ b/advisories/unreviewed/2025/02/GHSA-hcg3-9g3p-xjxq/GHSA-hcg3-9g3p-xjxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hcg3-9g3p-xjxq", - "modified": "2025-02-12T09:31:44Z", + "modified": "2025-02-12T15:31:57Z", "published": "2025-02-12T09:31:44Z", "aliases": [ "CVE-2024-13794" diff --git a/advisories/unreviewed/2025/02/GHSA-hv64-fpvc-rw9x/GHSA-hv64-fpvc-rw9x.json b/advisories/unreviewed/2025/02/GHSA-hv64-fpvc-rw9x/GHSA-hv64-fpvc-rw9x.json new file mode 100644 index 00000000000..806ccd93c21 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hv64-fpvc-rw9x/GHSA-hv64-fpvc-rw9x.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv64-fpvc-rw9x", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-21697" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Ensure job pointer is set to NULL after job completion\n\nAfter a job completes, the corresponding pointer in the device must\nbe set to NULL. Failing to do so triggers a warning when unloading\nthe driver, as it appears the job is still active. To prevent this,\nassign the job pointer to NULL after completing the job, indicating\nthe job has finished.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21697" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14e0a874488e79086340ba8e2d238cb9596b68a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bd6303d08c85072ce40ac01a767ab67195105bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a1c88f7ca5c12dff6fa6787492ac910bb9e4407" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63195bae1cbf78f1d392b1bc9ae4b03c82d0ebf3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a34050f70e7955a359874dff1a912a748724a140" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b22467b1ae104073dcb11aa78562a331cd7fb0e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4b5ccd392b92300a2b341705cc4805681094e49" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json b/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json index bb8b0390935..c5597bb343f 100644 --- a/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json +++ b/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2v6-fxfh-8942", - "modified": "2025-02-12T12:30:47Z", + "modified": "2025-02-12T15:31:58Z", "published": "2025-02-12T12:30:47Z", "aliases": [ "CVE-2024-13473" diff --git a/advisories/unreviewed/2025/02/GHSA-jcg7-x4r6-2q3x/GHSA-jcg7-x4r6-2q3x.json b/advisories/unreviewed/2025/02/GHSA-jcg7-x4r6-2q3x/GHSA-jcg7-x4r6-2q3x.json new file mode 100644 index 00000000000..da402efe070 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jcg7-x4r6-2q3x/GHSA-jcg7-x4r6-2q3x.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcg7-x4r6-2q3x", + "modified": "2025-02-12T15:31:58Z", + "published": "2025-02-12T15:31:58Z", + "aliases": [ + "CVE-2025-1197" + ], + "details": "A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /_parse/load_user-profile.php. The manipulation of the argument userhash leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1197" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/YinshengLu/CVE/blob/main/cve3.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295105" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295105" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74", + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jmp9-2jgh-3327/GHSA-jmp9-2jgh-3327.json b/advisories/unreviewed/2025/02/GHSA-jmp9-2jgh-3327/GHSA-jmp9-2jgh-3327.json new file mode 100644 index 00000000000..c4310ca079c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jmp9-2jgh-3327/GHSA-jmp9-2jgh-3327.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmp9-2jgh-3327", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26368" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove user groups via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26368" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jrmv-pjxx-f4c4/GHSA-jrmv-pjxx-f4c4.json b/advisories/unreviewed/2025/02/GHSA-jrmv-pjxx-f4c4/GHSA-jrmv-pjxx-f4c4.json new file mode 100644 index 00000000000..ceed6869c4f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jrmv-pjxx-f4c4/GHSA-jrmv-pjxx-f4c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrmv-pjxx-f4c4", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-1101" + ], + "details": "A CWE-204 \"Observable Response Discrepancy\" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enumerate valid usernames via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1101" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-1101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m248-h4r7-gvcg/GHSA-m248-h4r7-gvcg.json b/advisories/unreviewed/2025/02/GHSA-m248-h4r7-gvcg/GHSA-m248-h4r7-gvcg.json new file mode 100644 index 00000000000..eb9e7b0167a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m248-h4r7-gvcg/GHSA-m248-h4r7-gvcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m248-h4r7-gvcg", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26349" + ], + "details": "A CWE-23 \"Relative Path Traversal\" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26349" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m2wq-mm6r-mjcc/GHSA-m2wq-mm6r-mjcc.json b/advisories/unreviewed/2025/02/GHSA-m2wq-mm6r-mjcc/GHSA-m2wq-mm6r-mjcc.json index 720c8a7a028..4aab76af849 100644 --- a/advisories/unreviewed/2025/02/GHSA-m2wq-mm6r-mjcc/GHSA-m2wq-mm6r-mjcc.json +++ b/advisories/unreviewed/2025/02/GHSA-m2wq-mm6r-mjcc/GHSA-m2wq-mm6r-mjcc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-mw64-9qfm-r8wr/GHSA-mw64-9qfm-r8wr.json b/advisories/unreviewed/2025/02/GHSA-mw64-9qfm-r8wr/GHSA-mw64-9qfm-r8wr.json new file mode 100644 index 00000000000..8c5bb94285f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mw64-9qfm-r8wr/GHSA-mw64-9qfm-r8wr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw64-9qfm-r8wr", + "modified": "2025-02-12T15:31:58Z", + "published": "2025-02-12T15:31:58Z", + "aliases": [ + "CVE-2025-1199" + ], + "details": "A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been classified as critical. This affects an unknown part of the file /admin/app/role_crud.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1199" + }, + { + "type": "WEB", + "url": "https://github.com/Yesec/Best-church-management-software/blob/main/role_crud.php_SQLi.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295107" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295107" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496946" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p5g5-f63j-r685/GHSA-p5g5-f63j-r685.json b/advisories/unreviewed/2025/02/GHSA-p5g5-f63j-r685/GHSA-p5g5-f63j-r685.json new file mode 100644 index 00000000000..139eef8a78e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p5g5-f63j-r685/GHSA-p5g5-f63j-r685.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5g5-f63j-r685", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26360" + ], + "details": "A CWE-306 \"Missing Authentication for Critical Function\" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delete dashboards via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26360" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pg74-cxmf-8p2w/GHSA-pg74-cxmf-8p2w.json b/advisories/unreviewed/2025/02/GHSA-pg74-cxmf-8p2w/GHSA-pg74-cxmf-8p2w.json new file mode 100644 index 00000000000..c7e842698e3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pg74-cxmf-8p2w/GHSA-pg74-cxmf-8p2w.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg74-cxmf-8p2w", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-21698" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null\"\n\nThis reverts commit 13014969cbf07f18d62ceea40bd8ca8ec9d36cec.\n\nIt is reported to cause crashes on Tegra systems, so revert it for now.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21698" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/086fd062bc3883ae1ce4166cff5355db315ad879" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20ce02f2f73af331dec76d3b8b78b18f4699db05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33233b06ad15730d0463e8f152db2eca15c7f498" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d8f4dc8c78ffd77a4106614977c1e51531690f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76e7577bb89b327abdf72d4c0d486074a17f712a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99c866bea85efdebfb6953a8a305f21ef5ca4991" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb50dc2aa49dcb5cc81205d814c08337b5da28ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8b8883ad76d36ee890b18311096af7af7d7a921" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pwq9-pfrr-gc7w/GHSA-pwq9-pfrr-gc7w.json b/advisories/unreviewed/2025/02/GHSA-pwq9-pfrr-gc7w/GHSA-pwq9-pfrr-gc7w.json index 8b82e3d1290..29e843595c7 100644 --- a/advisories/unreviewed/2025/02/GHSA-pwq9-pfrr-gc7w/GHSA-pwq9-pfrr-gc7w.json +++ b/advisories/unreviewed/2025/02/GHSA-pwq9-pfrr-gc7w/GHSA-pwq9-pfrr-gc7w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-pxm7-vg3w-72r8/GHSA-pxm7-vg3w-72r8.json b/advisories/unreviewed/2025/02/GHSA-pxm7-vg3w-72r8/GHSA-pxm7-vg3w-72r8.json index 18dbcc7c333..4abfe7b1eb8 100644 --- a/advisories/unreviewed/2025/02/GHSA-pxm7-vg3w-72r8/GHSA-pxm7-vg3w-72r8.json +++ b/advisories/unreviewed/2025/02/GHSA-pxm7-vg3w-72r8/GHSA-pxm7-vg3w-72r8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-q3mg-hh3m-f7pm/GHSA-q3mg-hh3m-f7pm.json b/advisories/unreviewed/2025/02/GHSA-q3mg-hh3m-f7pm/GHSA-q3mg-hh3m-f7pm.json new file mode 100644 index 00000000000..975c57aad4b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q3mg-hh3m-f7pm/GHSA-q3mg-hh3m-f7pm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3mg-hh3m-f7pm", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26374" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to enumerate users via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26374" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q5ph-hv6h-q9vh/GHSA-q5ph-hv6h-q9vh.json b/advisories/unreviewed/2025/02/GHSA-q5ph-hv6h-q9vh/GHSA-q5ph-hv6h-q9vh.json new file mode 100644 index 00000000000..6348553c916 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q5ph-hv6h-q9vh/GHSA-q5ph-hv6h-q9vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5ph-hv6h-q9vh", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26352" + ], + "details": "A CWE-35 \"Path Traversal\" in the template deletion mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26352" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26352" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qfmg-63qc-57cq/GHSA-qfmg-63qc-57cq.json b/advisories/unreviewed/2025/02/GHSA-qfmg-63qc-57cq/GHSA-qfmg-63qc-57cq.json new file mode 100644 index 00000000000..d221cf29c44 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qfmg-63qc-57cq/GHSA-qfmg-63qc-57cq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfmg-63qc-57cq", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26378" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords, including the ones of administrator accounts, via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26378" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26378" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qq2q-77mx-9g8p/GHSA-qq2q-77mx-9g8p.json b/advisories/unreviewed/2025/02/GHSA-qq2q-77mx-9g8p/GHSA-qq2q-77mx-9g8p.json index fdc8838b39c..c27dacfad69 100644 --- a/advisories/unreviewed/2025/02/GHSA-qq2q-77mx-9g8p/GHSA-qq2q-77mx-9g8p.json +++ b/advisories/unreviewed/2025/02/GHSA-qq2q-77mx-9g8p/GHSA-qq2q-77mx-9g8p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json b/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json index 9f78e985333..73906eec3e7 100644 --- a/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json +++ b/advisories/unreviewed/2025/02/GHSA-qr8x-m34w-97pj/GHSA-qr8x-m34w-97pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qr8x-m34w-97pj", - "modified": "2025-02-12T12:30:47Z", + "modified": "2025-02-12T15:31:58Z", "published": "2025-02-12T12:30:47Z", "aliases": [ "CVE-2025-0506" diff --git a/advisories/unreviewed/2025/02/GHSA-qvh8-2fqm-584p/GHSA-qvh8-2fqm-584p.json b/advisories/unreviewed/2025/02/GHSA-qvh8-2fqm-584p/GHSA-qvh8-2fqm-584p.json new file mode 100644 index 00000000000..521e70edfee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qvh8-2fqm-584p/GHSA-qvh8-2fqm-584p.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvh8-2fqm-584p", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-21699" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Truncate address space when flipping GFS2_DIF_JDATA flag\n\nTruncate an inode's address space when flipping the GFS2_DIF_JDATA flag:\ndepending on that flag, the pages in the address space will either use\nbuffer heads or iomap_folio_state structs, and we cannot mix the two.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21699" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a40a140e11fec699e128170ccaa98b6b82cb503" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b0bd5051ad1c1e9ef4879f18e15a7712c974f3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4516febe325342555bb09ca5b396fb816d655821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4dd57d1f0e9844311c635a7fb39abce4f2ac5a61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e3ded34f3f3c9d7ed2aac7be8cf51153646574a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5bb1fd0855bb0abc7d97e44758d6ffed7882d2d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c9d9223802fbed4dee1ae301661bf346964c9d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c41abc11aa8438c9ed2d973f97e66674c0355df" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qxjr-36pm-q2q2/GHSA-qxjr-36pm-q2q2.json b/advisories/unreviewed/2025/02/GHSA-qxjr-36pm-q2q2/GHSA-qxjr-36pm-q2q2.json new file mode 100644 index 00000000000..aa44c2c0f64 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qxjr-36pm-q2q2/GHSA-qxjr-36pm-q2q2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxjr-36pm-q2q2", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2024-57952" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"libfs: fix infinite directory reads for offset dir\"\n\nThe current directory offset allocator (based on mtree_alloc_cyclic)\nstores the next offset value to return in octx->next_offset. This\nmechanism typically returns values that increase monotonically over\ntime. Eventually, though, the newly allocated offset value wraps\nback to a low number (say, 2) which is smaller than other already-\nallocated offset values.\n\nYu Kuai reports that, after commit 64a7ce76fb90\n(\"libfs: fix infinite directory reads for offset dir\"), if a\ndirectory's offset allocator wraps, existing entries are no longer\nvisible via readdir/getdents because offset_readdir() stops listing\nentries once an entry's offset is larger than octx->next_offset.\nThese entries vanish persistently -- they can be looked up, but will\nnever again appear in readdir(3) output.\n\nThe reason for this is that the commit treats directory offsets as\nmonotonically increasing integer values rather than opaque cookies,\nand introduces this comparison:\n\n\tif (dentry2offset(dentry) >= last_index) {\n\nOn 64-bit platforms, the directory offset value upper bound is\n2^63 - 1. Directory offsets will monotonically increase for millions\nof years without wrapping.\n\nOn 32-bit platforms, however, LONG_MAX is 2^31 - 1. The allocator\ncan wrap after only a few weeks (at worst).\n\nRevert commit 64a7ce76fb90 (\"libfs: fix infinite directory reads for\noffset dir\") to prepare for a fix that can work properly on 32-bit\nsystems and might apply to recent LTS kernels where shmem employs\nthe simple_offset mechanism.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57952" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f250b82040a72b0059ae00855a74d8570ad2147" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e9e710f68bac49bd9b587823c077d06363440e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b662d858131da9a8a14e68661656989b14dbf113" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r2p5-4w5h-4hfc/GHSA-r2p5-4w5h-4hfc.json b/advisories/unreviewed/2025/02/GHSA-r2p5-4w5h-4hfc/GHSA-r2p5-4w5h-4hfc.json new file mode 100644 index 00000000000..682c0232f84 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r2p5-4w5h-4hfc/GHSA-r2p5-4w5h-4hfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2p5-4w5h-4hfc", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26350" + ], + "details": "A CWE-434 \"Unrestricted Upload of File with Dangerous Type\" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to upload malicious files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26350" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rvrh-x349-rcjm/GHSA-rvrh-x349-rcjm.json b/advisories/unreviewed/2025/02/GHSA-rvrh-x349-rcjm/GHSA-rvrh-x349-rcjm.json new file mode 100644 index 00000000000..0f5b5c44e33 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rvrh-x349-rcjm/GHSA-rvrh-x349-rcjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvrh-x349-rcjm", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26375" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrary privileges via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26375" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rw98-vjxr-5rgp/GHSA-rw98-vjxr-5rgp.json b/advisories/unreviewed/2025/02/GHSA-rw98-vjxr-5rgp/GHSA-rw98-vjxr-5rgp.json new file mode 100644 index 00000000000..1a9b8e81b66 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rw98-vjxr-5rgp/GHSA-rw98-vjxr-5rgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw98-vjxr-5rgp", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26353" + ], + "details": "A CWE-35 \"Path Traversal\" in maxtime/api/sql/sql.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26353" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v488-9cvj-5mx7/GHSA-v488-9cvj-5mx7.json b/advisories/unreviewed/2025/02/GHSA-v488-9cvj-5mx7/GHSA-v488-9cvj-5mx7.json new file mode 100644 index 00000000000..65b0cb46ae4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v488-9cvj-5mx7/GHSA-v488-9cvj-5mx7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v488-9cvj-5mx7", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2024-12379" + ], + "details": "A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12379" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2871791" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/508559" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vmvf-f857-43v5/GHSA-vmvf-f857-43v5.json b/advisories/unreviewed/2025/02/GHSA-vmvf-f857-43v5/GHSA-vmvf-f857-43v5.json new file mode 100644 index 00000000000..30a8a38f37f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vmvf-f857-43v5/GHSA-vmvf-f857-43v5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmvf-f857-43v5", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-21695" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: dell-uart-backlight: fix serdev race\n\nThe dell_uart_bl_serdev_probe() function calls devm_serdev_device_open()\nbefore setting the client ops via serdev_device_set_client_ops(). This\nordering can trigger a NULL pointer dereference in the serdev controller's\nreceive_buf handler, as it assumes serdev->ops is valid when\nSERPORT_ACTIVE is set.\n\nThis is similar to the issue fixed in commit 5e700b384ec1\n(\"platform/chrome: cros_ec_uart: properly fix race condition\") where\ndevm_serdev_device_open() was called before fully initializing the\ndevice.\n\nFix the race by ensuring client ops are set before enabling the port via\ndevm_serdev_device_open().\n\nNote, serdev_device_set_baudrate() and serdev_device_set_flow_control()\ncalls should be after the devm_serdev_device_open() call.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21695" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b2128aa2d45ab20b22548dcf4b48906298ca7fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3a24d923333f75aaece9acb051d676edc0afb75" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vrmp-6wjg-454m/GHSA-vrmp-6wjg-454m.json b/advisories/unreviewed/2025/02/GHSA-vrmp-6wjg-454m/GHSA-vrmp-6wjg-454m.json new file mode 100644 index 00000000000..c163f7fb3f6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vrmp-6wjg-454m/GHSA-vrmp-6wjg-454m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrmp-6wjg-454m", + "modified": "2025-02-12T15:32:00Z", + "published": "2025-02-12T15:32:00Z", + "aliases": [ + "CVE-2025-26346" + ], + "details": "A CWE-89 \"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')\" in maxprofile/menu/model.lua (editUserGroupMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute arbitrary SQL commands via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26346" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26346" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w67j-246x-g8f8/GHSA-w67j-246x-g8f8.json b/advisories/unreviewed/2025/02/GHSA-w67j-246x-g8f8/GHSA-w67j-246x-g8f8.json new file mode 100644 index 00000000000..97cc3fe3e53 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w67j-246x-g8f8/GHSA-w67j-246x-g8f8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w67j-246x-g8f8", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26367" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create arbitrary user groups via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26367" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26367" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w7pm-c3qq-4vc8/GHSA-w7pm-c3qq-4vc8.json b/advisories/unreviewed/2025/02/GHSA-w7pm-c3qq-4vc8/GHSA-w7pm-c3qq-4vc8.json new file mode 100644 index 00000000000..4acb67959e1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w7pm-c3qq-4vc8/GHSA-w7pm-c3qq-4vc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7pm-c3qq-4vc8", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26376" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26376" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w9gw-5cvf-6753/GHSA-w9gw-5cvf-6753.json b/advisories/unreviewed/2025/02/GHSA-w9gw-5cvf-6753/GHSA-w9gw-5cvf-6753.json new file mode 100644 index 00000000000..6a1080aa1b4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w9gw-5cvf-6753/GHSA-w9gw-5cvf-6753.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9gw-5cvf-6753", + "modified": "2025-02-12T15:32:01Z", + "published": "2025-02-12T15:32:01Z", + "aliases": [ + "CVE-2025-26377" + ], + "details": "A CWE-862 \"Missing Authorization\" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26377" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26377" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wm8h-j7xc-cc9x/GHSA-wm8h-j7xc-cc9x.json b/advisories/unreviewed/2025/02/GHSA-wm8h-j7xc-cc9x/GHSA-wm8h-j7xc-cc9x.json index 44dfc6851ab..31328b136b1 100644 --- a/advisories/unreviewed/2025/02/GHSA-wm8h-j7xc-cc9x/GHSA-wm8h-j7xc-cc9x.json +++ b/advisories/unreviewed/2025/02/GHSA-wm8h-j7xc-cc9x/GHSA-wm8h-j7xc-cc9x.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-x5h2-7246-rqqh/GHSA-x5h2-7246-rqqh.json b/advisories/unreviewed/2025/02/GHSA-x5h2-7246-rqqh/GHSA-x5h2-7246-rqqh.json new file mode 100644 index 00000000000..c03d5d8adc3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x5h2-7246-rqqh/GHSA-x5h2-7246-rqqh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5h2-7246-rqqh", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2025-1206" + ], + "details": "A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file /dashboard/admin/viewdetailroutine.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1206" + }, + { + "type": "WEB", + "url": "https://github.com/sekaino-sakura/CVE/blob/main/CVE_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295143" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295143" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496961" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x6xq-q38p-mchg/GHSA-x6xq-q38p-mchg.json b/advisories/unreviewed/2025/02/GHSA-x6xq-q38p-mchg/GHSA-x6xq-q38p-mchg.json new file mode 100644 index 00000000000..8d659be10e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x6xq-q38p-mchg/GHSA-x6xq-q38p-mchg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6xq-q38p-mchg", + "modified": "2025-02-12T15:31:59Z", + "published": "2025-02-12T15:31:59Z", + "aliases": [ + "CVE-2025-1201" + ], + "details": "A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/app/profile_crud.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1201" + }, + { + "type": "WEB", + "url": "https://github.com/Yesec/Best-church-management-software/blob/main/profile_crud.php_SQLi.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496951" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json b/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json new file mode 100644 index 00000000000..b997aadb254 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8vm-v82f-5f3c", + "modified": "2025-02-12T15:32:02Z", + "published": "2025-02-12T15:32:02Z", + "aliases": [ + "CVE-2024-12251" + ], + "details": "In Progress® Telerik® UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12251" + }, + { + "type": "WEB", + "url": "https://docs.telerik.com/devtools/winui/security/kb-security-command-injection-cve-2024-12251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T15:15:12Z" + } +} \ No newline at end of file