From 5b2e548dbd798501b13ddd8d69ff8c24947bde0c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 22 Jan 2025 15:34:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r467-q4j9-32j6.json | 4 +- .../GHSA-c8pj-3w86-3gqp.json | 3 +- .../GHSA-28jj-97w4-wxm3.json | 15 +++++-- .../GHSA-223j-8f9f-qhc5.json | 36 +++++++++++++++++ .../GHSA-24mg-jfm6-jfr2.json | 36 +++++++++++++++++ .../GHSA-2cvx-pp7q-xwgc.json | 36 +++++++++++++++++ .../GHSA-2f5q-2vvh-mm3g.json | 29 ++++++++++++++ .../GHSA-2g4r-3v66-3h7f.json | 29 ++++++++++++++ .../GHSA-2gfv-rcv2-m5rp.json | 36 +++++++++++++++++ .../GHSA-2gxh-5pgf-vmgr.json | 36 +++++++++++++++++ .../GHSA-35q6-7298-9c8j.json | 29 ++++++++++++++ .../GHSA-37rh-2c9j-68mm.json | 11 +++-- .../GHSA-3fj3-c843-g89w.json | 15 +++++-- .../GHSA-3fr5-hr7q-wjm9.json | 36 +++++++++++++++++ .../GHSA-3qjq-q9wp-57vc.json | 36 +++++++++++++++++ .../GHSA-44qw-73mc-gq59.json | 36 +++++++++++++++++ .../GHSA-46hp-7jph-mgxf.json | 29 ++++++++++++++ .../GHSA-4849-5wjh-4xff.json | 36 +++++++++++++++++ .../GHSA-49c4-cq95-33g9.json | 36 +++++++++++++++++ .../GHSA-4jfp-x3q6-2vqx.json | 36 +++++++++++++++++ .../GHSA-4mwx-vgq4-7vr5.json | 29 ++++++++++++++ .../GHSA-4pmv-5pj5-58xg.json | 36 +++++++++++++++++ .../GHSA-4xpw-6594-8f5m.json | 35 ++++++++++++++++ .../GHSA-54wg-v6xv-5r7h.json | 36 +++++++++++++++++ .../GHSA-5jwj-c4gj-x35c.json | 29 ++++++++++++++ .../GHSA-5pwm-738f-25mv.json | 15 +++++-- .../GHSA-5r3w-hh48-xhgg.json | 36 +++++++++++++++++ .../GHSA-5vq5-vqqj-wgjc.json | 36 +++++++++++++++++ .../GHSA-65vg-m8q8-fg5r.json | 36 +++++++++++++++++ .../GHSA-676f-vgw4-7c2q.json | 36 +++++++++++++++++ .../GHSA-697m-mg58-66vr.json | 29 ++++++++++++++ .../GHSA-6cvp-82cv-4v82.json | 15 +++++-- .../GHSA-6fv9-329c-mrq6.json | 36 +++++++++++++++++ .../GHSA-6q2v-hjxc-f9rp.json | 36 +++++++++++++++++ .../GHSA-6xjp-947h-mxr8.json | 29 ++++++++++++++ .../GHSA-73jw-x37m-r2h9.json | 36 +++++++++++++++++ .../GHSA-75x7-c33w-j8c8.json | 36 +++++++++++++++++ .../GHSA-7jx3-j4mg-5rvc.json | 36 +++++++++++++++++ .../GHSA-7m3j-45xq-3xj9.json | 36 +++++++++++++++++ .../GHSA-7www-5pg7-vg69.json | 36 +++++++++++++++++ .../GHSA-8254-xv48-7mrq.json | 29 ++++++++++++++ .../GHSA-83f2-g28h-f9cf.json | 36 +++++++++++++++++ .../GHSA-8cw5-2qqr-3xvc.json | 36 +++++++++++++++++ .../GHSA-8ppx-rwm8-h7rp.json | 29 ++++++++++++++ .../GHSA-8w89-r7hw-4xgj.json | 36 +++++++++++++++++ .../GHSA-976w-5vj5-frv8.json | 36 +++++++++++++++++ .../GHSA-9c2g-h7p9-73f9.json | 36 +++++++++++++++++ .../GHSA-9pm6-fvgj-xj4x.json | 36 +++++++++++++++++ .../GHSA-9qxf-frvg-wwgq.json | 29 ++++++++++++++ .../GHSA-c3xq-xww5-9347.json | 36 +++++++++++++++++ .../GHSA-c4mr-f695-j8p8.json | 15 +++++-- .../GHSA-c73h-5523-53rr.json | 36 +++++++++++++++++ .../GHSA-c874-8h7r-5764.json | 29 ++++++++++++++ .../GHSA-cffw-755r-8qx2.json | 11 +++-- .../GHSA-cggj-gprv-7895.json | 36 +++++++++++++++++ .../GHSA-cr43-57pq-9qgj.json | 36 +++++++++++++++++ .../GHSA-cwgj-88jc-p385.json | 29 ++++++++++++++ .../GHSA-f226-gv22-gg2h.json | 36 +++++++++++++++++ .../GHSA-f5m2-vc78-7pcq.json | 36 +++++++++++++++++ .../GHSA-f74v-w38w-9rp4.json | 36 +++++++++++++++++ .../GHSA-f76g-5494-q868.json | 36 +++++++++++++++++ .../GHSA-fgwg-x6m4-8h2r.json | 36 +++++++++++++++++ .../GHSA-fmmp-vh78-7jjx.json | 36 +++++++++++++++++ .../GHSA-fq84-vv4r-9gjq.json | 36 +++++++++++++++++ .../GHSA-g2fw-hxwc-j3px.json | 36 +++++++++++++++++ .../GHSA-g359-p277-83p3.json | 11 +++-- .../GHSA-gcmq-4hqx-cf48.json | 36 +++++++++++++++++ .../GHSA-gpqj-4j66-2gh4.json | 36 +++++++++++++++++ .../GHSA-gqgm-6hg6-vrvf.json | 36 +++++++++++++++++ .../GHSA-h483-px82-mchv.json | 29 ++++++++++++++ .../GHSA-h4w3-ffw8-rr28.json | 36 +++++++++++++++++ .../GHSA-h53w-84fj-6mjw.json | 15 +++++-- .../GHSA-h5p7-26p5-jx9h.json | 36 +++++++++++++++++ .../GHSA-h8qv-cwpv-997w.json | 36 +++++++++++++++++ .../GHSA-hjqg-mr87-p6m3.json | 36 +++++++++++++++++ .../GHSA-j648-x338-vqvm.json | 36 +++++++++++++++++ .../GHSA-j85f-xv44-mr6x.json | 36 +++++++++++++++++ .../GHSA-jhfj-4x6v-p4q6.json | 36 +++++++++++++++++ .../GHSA-jjxh-vpf5-jm42.json | 11 +++-- .../GHSA-jm92-jw9v-j6h2.json | 36 +++++++++++++++++ .../GHSA-m3hp-8546-5qmr.json | 40 +++++++++++++++++++ .../GHSA-m4jr-5394-x5vm.json | 36 +++++++++++++++++ .../GHSA-m8vc-jw77-wxj4.json | 15 +++++-- .../GHSA-m98h-h759-qxcc.json | 36 +++++++++++++++++ .../GHSA-m993-jwwj-jxc2.json | 36 +++++++++++++++++ .../GHSA-mf84-jxh2-rc4j.json | 29 ++++++++++++++ .../GHSA-mh53-5gcx-h6x9.json | 36 +++++++++++++++++ .../GHSA-mjj5-4qc2-r6g6.json | 36 +++++++++++++++++ .../GHSA-mp7w-vq3p-xp89.json | 36 +++++++++++++++++ .../GHSA-mr5r-7w8p-59p7.json | 36 +++++++++++++++++ .../GHSA-mvjr-xfhv-mwpw.json | 29 ++++++++++++++ .../GHSA-mw75-cjrf-477c.json | 36 +++++++++++++++++ .../GHSA-mwrc-pj94-779p.json | 36 +++++++++++++++++ .../GHSA-mx53-8x3c-jgqv.json | 29 ++++++++++++++ .../GHSA-p2xw-hr6c-g7h5.json | 15 +++++-- .../GHSA-p44p-wgq8-46qm.json | 29 ++++++++++++++ .../GHSA-p6q2-w3w9-4cjw.json | 33 +++++++++++++++ .../GHSA-p8gf-75qm-vcj2.json | 36 +++++++++++++++++ .../GHSA-ph64-rj79-fwm3.json | 36 +++++++++++++++++ .../GHSA-pqj9-qcr7-74fh.json | 29 ++++++++++++++ .../GHSA-px86-7w9g-5j6m.json | 15 +++++-- .../GHSA-q7jg-p665-r7wq.json | 36 +++++++++++++++++ .../GHSA-qcjc-qmxq-wf6x.json | 29 ++++++++++++++ .../GHSA-qjmq-8gw8-9273.json | 36 +++++++++++++++++ .../GHSA-qv2m-4wv2-f33h.json | 29 ++++++++++++++ .../GHSA-r492-f75w-fpq9.json | 29 ++++++++++++++ .../GHSA-r4h2-pqcr-8272.json | 36 +++++++++++++++++ .../GHSA-r8gm-64g7-7736.json | 36 +++++++++++++++++ .../GHSA-rgrx-5mj9-r82x.json | 36 +++++++++++++++++ .../GHSA-rq53-4cvw-2q74.json | 36 +++++++++++++++++ .../GHSA-v339-89pg-gj89.json | 36 +++++++++++++++++ .../GHSA-v4x5-x848-6pj8.json | 36 +++++++++++++++++ .../GHSA-vv53-gg69-w9q3.json | 36 +++++++++++++++++ .../GHSA-wfff-769x-fr8w.json | 36 +++++++++++++++++ .../GHSA-wfj2-2gqr-p45g.json | 36 +++++++++++++++++ .../GHSA-wg5v-689x-wgmp.json | 36 +++++++++++++++++ .../GHSA-whxf-qv83-4936.json | 29 ++++++++++++++ .../GHSA-wm2x-9fx6-qgf6.json | 36 +++++++++++++++++ .../GHSA-wm3f-xqqj-vggp.json | 36 +++++++++++++++++ .../GHSA-wp44-pvxx-4qfw.json | 36 +++++++++++++++++ .../GHSA-wq35-6cg9-m5mj.json | 36 +++++++++++++++++ .../GHSA-wrhm-vqgx-q8p6.json | 15 +++++-- .../GHSA-x22m-7748-229x.json | 15 +++++-- .../GHSA-x39p-jxrw-mp33.json | 36 +++++++++++++++++ .../GHSA-x6x7-wx46-gh2c.json | 36 +++++++++++++++++ .../GHSA-x76x-v36q-wqrf.json | 29 ++++++++++++++ .../GHSA-x7pq-2j3f-24rv.json | 29 ++++++++++++++ .../GHSA-xcp6-3jg8-q26g.json | 36 +++++++++++++++++ .../GHSA-xfgj-h6r5-fqg7.json | 36 +++++++++++++++++ .../GHSA-xh3r-5ccq-fg8p.json | 29 ++++++++++++++ 130 files changed, 4044 insertions(+), 58 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-223j-8f9f-qhc5/GHSA-223j-8f9f-qhc5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-24mg-jfm6-jfr2/GHSA-24mg-jfm6-jfr2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2cvx-pp7q-xwgc/GHSA-2cvx-pp7q-xwgc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2g4r-3v66-3h7f/GHSA-2g4r-3v66-3h7f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2gfv-rcv2-m5rp/GHSA-2gfv-rcv2-m5rp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2gxh-5pgf-vmgr/GHSA-2gxh-5pgf-vmgr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-35q6-7298-9c8j/GHSA-35q6-7298-9c8j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3qjq-q9wp-57vc/GHSA-3qjq-q9wp-57vc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-44qw-73mc-gq59/GHSA-44qw-73mc-gq59.json create mode 100644 advisories/unreviewed/2025/01/GHSA-46hp-7jph-mgxf/GHSA-46hp-7jph-mgxf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4849-5wjh-4xff/GHSA-4849-5wjh-4xff.json create mode 100644 advisories/unreviewed/2025/01/GHSA-49c4-cq95-33g9/GHSA-49c4-cq95-33g9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4jfp-x3q6-2vqx/GHSA-4jfp-x3q6-2vqx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4pmv-5pj5-58xg/GHSA-4pmv-5pj5-58xg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-54wg-v6xv-5r7h/GHSA-54wg-v6xv-5r7h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5jwj-c4gj-x35c/GHSA-5jwj-c4gj-x35c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5r3w-hh48-xhgg/GHSA-5r3w-hh48-xhgg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5vq5-vqqj-wgjc/GHSA-5vq5-vqqj-wgjc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-65vg-m8q8-fg5r/GHSA-65vg-m8q8-fg5r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-676f-vgw4-7c2q/GHSA-676f-vgw4-7c2q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-697m-mg58-66vr/GHSA-697m-mg58-66vr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6fv9-329c-mrq6/GHSA-6fv9-329c-mrq6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6q2v-hjxc-f9rp/GHSA-6q2v-hjxc-f9rp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6xjp-947h-mxr8/GHSA-6xjp-947h-mxr8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-73jw-x37m-r2h9/GHSA-73jw-x37m-r2h9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-75x7-c33w-j8c8/GHSA-75x7-c33w-j8c8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7jx3-j4mg-5rvc/GHSA-7jx3-j4mg-5rvc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7m3j-45xq-3xj9/GHSA-7m3j-45xq-3xj9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7www-5pg7-vg69/GHSA-7www-5pg7-vg69.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8254-xv48-7mrq/GHSA-8254-xv48-7mrq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-83f2-g28h-f9cf/GHSA-83f2-g28h-f9cf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8cw5-2qqr-3xvc/GHSA-8cw5-2qqr-3xvc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8w89-r7hw-4xgj/GHSA-8w89-r7hw-4xgj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-976w-5vj5-frv8/GHSA-976w-5vj5-frv8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9c2g-h7p9-73f9/GHSA-9c2g-h7p9-73f9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9pm6-fvgj-xj4x/GHSA-9pm6-fvgj-xj4x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9qxf-frvg-wwgq/GHSA-9qxf-frvg-wwgq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c3xq-xww5-9347/GHSA-c3xq-xww5-9347.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c73h-5523-53rr/GHSA-c73h-5523-53rr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c874-8h7r-5764/GHSA-c874-8h7r-5764.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cggj-gprv-7895/GHSA-cggj-gprv-7895.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cr43-57pq-9qgj/GHSA-cr43-57pq-9qgj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f226-gv22-gg2h/GHSA-f226-gv22-gg2h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f5m2-vc78-7pcq/GHSA-f5m2-vc78-7pcq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f74v-w38w-9rp4/GHSA-f74v-w38w-9rp4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f76g-5494-q868/GHSA-f76g-5494-q868.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fgwg-x6m4-8h2r/GHSA-fgwg-x6m4-8h2r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fmmp-vh78-7jjx/GHSA-fmmp-vh78-7jjx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fq84-vv4r-9gjq/GHSA-fq84-vv4r-9gjq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g2fw-hxwc-j3px/GHSA-g2fw-hxwc-j3px.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gcmq-4hqx-cf48/GHSA-gcmq-4hqx-cf48.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gpqj-4j66-2gh4/GHSA-gpqj-4j66-2gh4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gqgm-6hg6-vrvf/GHSA-gqgm-6hg6-vrvf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h483-px82-mchv/GHSA-h483-px82-mchv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h4w3-ffw8-rr28/GHSA-h4w3-ffw8-rr28.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h5p7-26p5-jx9h/GHSA-h5p7-26p5-jx9h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h8qv-cwpv-997w/GHSA-h8qv-cwpv-997w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hjqg-mr87-p6m3/GHSA-hjqg-mr87-p6m3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j648-x338-vqvm/GHSA-j648-x338-vqvm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j85f-xv44-mr6x/GHSA-j85f-xv44-mr6x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jhfj-4x6v-p4q6/GHSA-jhfj-4x6v-p4q6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jm92-jw9v-j6h2/GHSA-jm92-jw9v-j6h2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m3hp-8546-5qmr/GHSA-m3hp-8546-5qmr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m4jr-5394-x5vm/GHSA-m4jr-5394-x5vm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m98h-h759-qxcc/GHSA-m98h-h759-qxcc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m993-jwwj-jxc2/GHSA-m993-jwwj-jxc2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mf84-jxh2-rc4j/GHSA-mf84-jxh2-rc4j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mh53-5gcx-h6x9/GHSA-mh53-5gcx-h6x9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mjj5-4qc2-r6g6/GHSA-mjj5-4qc2-r6g6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mp7w-vq3p-xp89/GHSA-mp7w-vq3p-xp89.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mr5r-7w8p-59p7/GHSA-mr5r-7w8p-59p7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mvjr-xfhv-mwpw/GHSA-mvjr-xfhv-mwpw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mw75-cjrf-477c/GHSA-mw75-cjrf-477c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mwrc-pj94-779p/GHSA-mwrc-pj94-779p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mx53-8x3c-jgqv/GHSA-mx53-8x3c-jgqv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p6q2-w3w9-4cjw/GHSA-p6q2-w3w9-4cjw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p8gf-75qm-vcj2/GHSA-p8gf-75qm-vcj2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-ph64-rj79-fwm3/GHSA-ph64-rj79-fwm3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pqj9-qcr7-74fh/GHSA-pqj9-qcr7-74fh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q7jg-p665-r7wq/GHSA-q7jg-p665-r7wq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qcjc-qmxq-wf6x/GHSA-qcjc-qmxq-wf6x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qjmq-8gw8-9273/GHSA-qjmq-8gw8-9273.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r4h2-pqcr-8272/GHSA-r4h2-pqcr-8272.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r8gm-64g7-7736/GHSA-r8gm-64g7-7736.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rgrx-5mj9-r82x/GHSA-rgrx-5mj9-r82x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rq53-4cvw-2q74/GHSA-rq53-4cvw-2q74.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v339-89pg-gj89/GHSA-v339-89pg-gj89.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vv53-gg69-w9q3/GHSA-vv53-gg69-w9q3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wfff-769x-fr8w/GHSA-wfff-769x-fr8w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wfj2-2gqr-p45g/GHSA-wfj2-2gqr-p45g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wg5v-689x-wgmp/GHSA-wg5v-689x-wgmp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-whxf-qv83-4936/GHSA-whxf-qv83-4936.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wm2x-9fx6-qgf6/GHSA-wm2x-9fx6-qgf6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wm3f-xqqj-vggp/GHSA-wm3f-xqqj-vggp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wp44-pvxx-4qfw/GHSA-wp44-pvxx-4qfw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wq35-6cg9-m5mj/GHSA-wq35-6cg9-m5mj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x39p-jxrw-mp33/GHSA-x39p-jxrw-mp33.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x6x7-wx46-gh2c/GHSA-x6x7-wx46-gh2c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x7pq-2j3f-24rv/GHSA-x7pq-2j3f-24rv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xcp6-3jg8-q26g/GHSA-xcp6-3jg8-q26g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xfgj-h6r5-fqg7/GHSA-xfgj-h6r5-fqg7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xh3r-5ccq-fg8p/GHSA-xh3r-5ccq-fg8p.json diff --git a/advisories/unreviewed/2023/05/GHSA-r467-q4j9-32j6/GHSA-r467-q4j9-32j6.json b/advisories/unreviewed/2023/05/GHSA-r467-q4j9-32j6/GHSA-r467-q4j9-32j6.json index 57f2c21c29d..0b9c340511a 100644 --- a/advisories/unreviewed/2023/05/GHSA-r467-q4j9-32j6/GHSA-r467-q4j9-32j6.json +++ b/advisories/unreviewed/2023/05/GHSA-r467-q4j9-32j6/GHSA-r467-q4j9-32j6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-c8pj-3w86-3gqp/GHSA-c8pj-3w86-3gqp.json b/advisories/unreviewed/2024/02/GHSA-c8pj-3w86-3gqp/GHSA-c8pj-3w86-3gqp.json index 214e401bb68..c6e6ff774fb 100644 --- a/advisories/unreviewed/2024/02/GHSA-c8pj-3w86-3gqp/GHSA-c8pj-3w86-3gqp.json +++ b/advisories/unreviewed/2024/02/GHSA-c8pj-3w86-3gqp/GHSA-c8pj-3w86-3gqp.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-131" + "CWE-131", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-28jj-97w4-wxm3/GHSA-28jj-97w4-wxm3.json b/advisories/unreviewed/2024/03/GHSA-28jj-97w4-wxm3/GHSA-28jj-97w4-wxm3.json index b3f36730437..945c0eacb3d 100644 --- a/advisories/unreviewed/2024/03/GHSA-28jj-97w4-wxm3/GHSA-28jj-97w4-wxm3.json +++ b/advisories/unreviewed/2024/03/GHSA-28jj-97w4-wxm3/GHSA-28jj-97w4-wxm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-28jj-97w4-wxm3", - "modified": "2024-03-12T21:30:59Z", + "modified": "2025-01-22T15:32:33Z", "published": "2024-03-12T21:30:59Z", "aliases": [ "CVE-2023-42307" ], "details": "Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via \"Subject Name\" and \"Subject Code\" section.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-12T21:15:55Z" diff --git a/advisories/unreviewed/2025/01/GHSA-223j-8f9f-qhc5/GHSA-223j-8f9f-qhc5.json b/advisories/unreviewed/2025/01/GHSA-223j-8f9f-qhc5/GHSA-223j-8f9f-qhc5.json new file mode 100644 index 00000000000..3b68c9b3d4a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-223j-8f9f-qhc5/GHSA-223j-8f9f-qhc5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-223j-8f9f-qhc5", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23874" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23874" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-block-pack/vulnerability/wordpress-wp-block-pack-plugin-1-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-24mg-jfm6-jfr2/GHSA-24mg-jfm6-jfr2.json b/advisories/unreviewed/2025/01/GHSA-24mg-jfm6-jfr2/GHSA-24mg-jfm6-jfr2.json new file mode 100644 index 00000000000..1e0504b7e9e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-24mg-jfm6-jfr2/GHSA-24mg-jfm6-jfr2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24mg-jfm6-jfr2", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23706" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Jet Skinner for BuddyPress allows Reflected XSS. This issue affects Jet Skinner for BuddyPress: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23706" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-skinner-for-buddypress/vulnerability/wordpress-jet-skinner-for-buddypress-plugin-1-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2cvx-pp7q-xwgc/GHSA-2cvx-pp7q-xwgc.json b/advisories/unreviewed/2025/01/GHSA-2cvx-pp7q-xwgc/GHSA-2cvx-pp7q-xwgc.json new file mode 100644 index 00000000000..4b17de18cae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2cvx-pp7q-xwgc/GHSA-2cvx-pp7q-xwgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cvx-pp7q-xwgc", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23672" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Instant Appointment allows Reflected XSS. This issue affects Instant Appointment: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23672" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/instant-appointment/vulnerability/wordpress-instant-appointment-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json b/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json new file mode 100644 index 00000000000..6b2fd9289bf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2f5q-2vvh-mm3g/GHSA-2f5q-2vvh-mm3g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f5q-2vvh-mm3g", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37011" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37011" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2g4r-3v66-3h7f/GHSA-2g4r-3v66-3h7f.json b/advisories/unreviewed/2025/01/GHSA-2g4r-3v66-3h7f/GHSA-2g4r-3v66-3h7f.json new file mode 100644 index 00000000000..1031616ac34 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2g4r-3v66-3h7f/GHSA-2g4r-3v66-3h7f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g4r-3v66-3h7f", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37021" + ], + "details": "Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37021" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2gfv-rcv2-m5rp/GHSA-2gfv-rcv2-m5rp.json b/advisories/unreviewed/2025/01/GHSA-2gfv-rcv2-m5rp/GHSA-2gfv-rcv2-m5rp.json new file mode 100644 index 00000000000..8ec3c1442fa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2gfv-rcv2-m5rp/GHSA-2gfv-rcv2-m5rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gfv-rcv2-m5rp", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23758" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pootle button allows Reflected XSS. This issue affects Pootle button: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pootle-button/vulnerability/wordpress-pootle-button-plugin-1-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2gxh-5pgf-vmgr/GHSA-2gxh-5pgf-vmgr.json b/advisories/unreviewed/2025/01/GHSA-2gxh-5pgf-vmgr/GHSA-2gxh-5pgf-vmgr.json new file mode 100644 index 00000000000..0032fda972a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2gxh-5pgf-vmgr/GHSA-2gxh-5pgf-vmgr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gxh-5pgf-vmgr", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23812" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23812" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-round-robin-lead-distribution/vulnerability/wordpress-contact-form-7-round-robin-lead-distribution-plugin-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-35q6-7298-9c8j/GHSA-35q6-7298-9c8j.json b/advisories/unreviewed/2025/01/GHSA-35q6-7298-9c8j/GHSA-35q6-7298-9c8j.json new file mode 100644 index 00000000000..08629a57d3e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-35q6-7298-9c8j/GHSA-35q6-7298-9c8j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35q6-7298-9c8j", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2024-24432" + ], + "details": "A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24432" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-37rh-2c9j-68mm/GHSA-37rh-2c9j-68mm.json b/advisories/unreviewed/2025/01/GHSA-37rh-2c9j-68mm/GHSA-37rh-2c9j-68mm.json index e0477fd558d..4fed96bb992 100644 --- a/advisories/unreviewed/2025/01/GHSA-37rh-2c9j-68mm/GHSA-37rh-2c9j-68mm.json +++ b/advisories/unreviewed/2025/01/GHSA-37rh-2c9j-68mm/GHSA-37rh-2c9j-68mm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-37rh-2c9j-68mm", - "modified": "2025-01-22T00:33:36Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:36Z", "aliases": [ "CVE-2025-23196" ], "details": "A code injection vulnerability exists in the Ambari Alert Definition \nfeature, allowing authenticated users to inject and execute arbitrary \nshell commands. The vulnerability arises when defining alert scripts, \nwhere the script filename field is executed using `sh -c`. An attacker \nwith authenticated access can exploit this vulnerability to inject \nmalicious commands, leading to remote code execution on the server. The \nissue has been fixed in the latest versions of Ambari.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3fj3-c843-g89w/GHSA-3fj3-c843-g89w.json b/advisories/unreviewed/2025/01/GHSA-3fj3-c843-g89w/GHSA-3fj3-c843-g89w.json index e359fd5b652..24f3ec9e811 100644 --- a/advisories/unreviewed/2025/01/GHSA-3fj3-c843-g89w/GHSA-3fj3-c843-g89w.json +++ b/advisories/unreviewed/2025/01/GHSA-3fj3-c843-g89w/GHSA-3fj3-c843-g89w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3fj3-c843-g89w", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49748" ], "details": "In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json b/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json new file mode 100644 index 00000000000..df7bb4a085b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3fr5-hr7q-wjm9/GHSA-3fr5-hr7q-wjm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fr5-hr7q-wjm9", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23697" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebDeal s.r.o. Podčlánková inzerce allows Reflected XSS. This issue affects Podčlánková inzerce: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23697" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/podclankova-inzerce/vulnerability/wordpress-podclankova-inzerce-plugin-2-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3qjq-q9wp-57vc/GHSA-3qjq-q9wp-57vc.json b/advisories/unreviewed/2025/01/GHSA-3qjq-q9wp-57vc/GHSA-3qjq-q9wp-57vc.json new file mode 100644 index 00000000000..1970f02a810 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3qjq-q9wp-57vc/GHSA-3qjq-q9wp-57vc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qjq-q9wp-57vc", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23866" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EU DSGVO Helper allows Reflected XSS. This issue affects EU DSGVO Helper: from n/a through 1.0.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dsgvo/vulnerability/wordpress-eu-dsgvo-helper-plugin-1-0-6-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-44qw-73mc-gq59/GHSA-44qw-73mc-gq59.json b/advisories/unreviewed/2025/01/GHSA-44qw-73mc-gq59/GHSA-44qw-73mc-gq59.json new file mode 100644 index 00000000000..8241d5f070b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-44qw-73mc-gq59/GHSA-44qw-73mc-gq59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44qw-73mc-gq59", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23944" + ], + "details": "Deserialization of Untrusted Data vulnerability in WOOEXIM.COM WOOEXIM allows Object Injection. This issue affects WOOEXIM: from n/a through 5.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23944" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wooexim/vulnerability/wordpress-wooexim-plugin-5-0-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-46hp-7jph-mgxf/GHSA-46hp-7jph-mgxf.json b/advisories/unreviewed/2025/01/GHSA-46hp-7jph-mgxf/GHSA-46hp-7jph-mgxf.json new file mode 100644 index 00000000000..9026cf52936 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-46hp-7jph-mgxf/GHSA-46hp-7jph-mgxf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46hp-7jph-mgxf", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2024-34235" + ], + "details": "Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34235" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4849-5wjh-4xff/GHSA-4849-5wjh-4xff.json b/advisories/unreviewed/2025/01/GHSA-4849-5wjh-4xff/GHSA-4849-5wjh-4xff.json new file mode 100644 index 00000000000..bc9e5c19cc0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4849-5wjh-4xff/GHSA-4849-5wjh-4xff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4849-5wjh-4xff", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23959" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linus Lundahl Good Old Gallery allows Reflected XSS. This issue affects Good Old Gallery: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23959" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/good-old-gallery/vulnerability/wordpress-good-old-gallery-plugin-2-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-49c4-cq95-33g9/GHSA-49c4-cq95-33g9.json b/advisories/unreviewed/2025/01/GHSA-49c4-cq95-33g9/GHSA-49c4-cq95-33g9.json new file mode 100644 index 00000000000..bffafdf8fdc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-49c4-cq95-33g9/GHSA-49c4-cq95-33g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49c4-cq95-33g9", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23676" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound LH Email allows Reflected XSS. This issue affects LH Email: from n/a through 1.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23676" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lh-email/vulnerability/wordpress-lh-email-plugin-1-12-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4jfp-x3q6-2vqx/GHSA-4jfp-x3q6-2vqx.json b/advisories/unreviewed/2025/01/GHSA-4jfp-x3q6-2vqx/GHSA-4jfp-x3q6-2vqx.json new file mode 100644 index 00000000000..52821d363a2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4jfp-x3q6-2vqx/GHSA-4jfp-x3q6-2vqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jfp-x3q6-2vqx", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23562" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound XLSXviewer allows Path Traversal. This issue affects XLSXviewer: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xlsx-viewer/vulnerability/wordpress-xlsxviewer-plugin-2-1-1-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json b/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json new file mode 100644 index 00000000000..f4507472e23 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4mwx-vgq4-7vr5/GHSA-4mwx-vgq4-7vr5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mwx-vgq4-7vr5", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37003" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37003" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4pmv-5pj5-58xg/GHSA-4pmv-5pj5-58xg.json b/advisories/unreviewed/2025/01/GHSA-4pmv-5pj5-58xg/GHSA-4pmv-5pj5-58xg.json new file mode 100644 index 00000000000..869b22b4086 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4pmv-5pj5-58xg/GHSA-4pmv-5pj5-58xg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmv-5pj5-58xg", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23846" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kolja Nolte Flexible Blogtitle allows Reflected XSS. This issue affects Flexible Blogtitle: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23846" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexible-blogtitle/vulnerability/wordpress-flexible-blogtitle-plugin-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json new file mode 100644 index 00000000000..7774fda1a9c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xpw-6594-8f5m", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2025-0395" + ], + "details": "When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0395" + }, + { + "type": "WEB", + "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32582" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-54wg-v6xv-5r7h/GHSA-54wg-v6xv-5r7h.json b/advisories/unreviewed/2025/01/GHSA-54wg-v6xv-5r7h/GHSA-54wg-v6xv-5r7h.json new file mode 100644 index 00000000000..c64cc726ff6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-54wg-v6xv-5r7h/GHSA-54wg-v6xv-5r7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54wg-v6xv-5r7h", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-22772" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mapbox for WP Advanced allows Reflected XSS. This issue affects Mapbox for WP Advanced: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22772" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapbox-for-wp-advanced/vulnerability/wordpress-mapbox-for-wp-advanced-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5jwj-c4gj-x35c/GHSA-5jwj-c4gj-x35c.json b/advisories/unreviewed/2025/01/GHSA-5jwj-c4gj-x35c/GHSA-5jwj-c4gj-x35c.json new file mode 100644 index 00000000000..edc4bbfb9df --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5jwj-c4gj-x35c/GHSA-5jwj-c4gj-x35c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jwj-c4gj-x35c", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37013" + ], + "details": "Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading to denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37013" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json b/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json index 8216d5d2592..374a54ec90a 100644 --- a/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json +++ b/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5pwm-738f-25mv", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49742" ], "details": "In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5r3w-hh48-xhgg/GHSA-5r3w-hh48-xhgg.json b/advisories/unreviewed/2025/01/GHSA-5r3w-hh48-xhgg/GHSA-5r3w-hh48-xhgg.json new file mode 100644 index 00000000000..bf9556b0921 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5r3w-hh48-xhgg/GHSA-5r3w-hh48-xhgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r3w-hh48-xhgg", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23611" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WH Cache & Security allows Reflected XSS. This issue affects WH Cache & Security: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23611" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wh-cache-and-security/vulnerability/wordpress-wh-cache-security-plugin-1-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5vq5-vqqj-wgjc/GHSA-5vq5-vqqj-wgjc.json b/advisories/unreviewed/2025/01/GHSA-5vq5-vqqj-wgjc/GHSA-5vq5-vqqj-wgjc.json new file mode 100644 index 00000000000..3971f5a6eaf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5vq5-vqqj-wgjc/GHSA-5vq5-vqqj-wgjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vq5-vqqj-wgjc", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23784" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows SQL Injection. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23784" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-round-robin-lead-distribution/vulnerability/wordpress-contact-form-7-round-robin-lead-distribution-plugin-1-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-65vg-m8q8-fg5r/GHSA-65vg-m8q8-fg5r.json b/advisories/unreviewed/2025/01/GHSA-65vg-m8q8-fg5r/GHSA-65vg-m8q8-fg5r.json new file mode 100644 index 00000000000..1933f7b6594 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-65vg-m8q8-fg5r/GHSA-65vg-m8q8-fg5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65vg-m8q8-fg5r", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23462" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FWD Slider allows Reflected XSS. This issue affects FWD Slider: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23462" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fwd-slider/vulnerability/wordpress-fwd-slider-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-676f-vgw4-7c2q/GHSA-676f-vgw4-7c2q.json b/advisories/unreviewed/2025/01/GHSA-676f-vgw4-7c2q/GHSA-676f-vgw4-7c2q.json new file mode 100644 index 00000000000..d915d959967 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-676f-vgw4-7c2q/GHSA-676f-vgw4-7c2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-676f-vgw4-7c2q", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23932" + ], + "details": "Deserialization of Untrusted Data vulnerability in NotFound Quick Count allows Object Injection. This issue affects Quick Count: from n/a through 3.00.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-count/vulnerability/wordpress-quick-count-plugin-3-00-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-697m-mg58-66vr/GHSA-697m-mg58-66vr.json b/advisories/unreviewed/2025/01/GHSA-697m-mg58-66vr/GHSA-697m-mg58-66vr.json new file mode 100644 index 00000000000..714674fbfc6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-697m-mg58-66vr/GHSA-697m-mg58-66vr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-697m-mg58-66vr", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37020" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Complete` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37020" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6cvp-82cv-4v82/GHSA-6cvp-82cv-4v82.json b/advisories/unreviewed/2025/01/GHSA-6cvp-82cv-4v82/GHSA-6cvp-82cv-4v82.json index 80a06893146..9437cf1bb42 100644 --- a/advisories/unreviewed/2025/01/GHSA-6cvp-82cv-4v82/GHSA-6cvp-82cv-4v82.json +++ b/advisories/unreviewed/2025/01/GHSA-6cvp-82cv-4v82/GHSA-6cvp-82cv-4v82.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6cvp-82cv-4v82", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49749" ], "details": "In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6fv9-329c-mrq6/GHSA-6fv9-329c-mrq6.json b/advisories/unreviewed/2025/01/GHSA-6fv9-329c-mrq6/GHSA-6fv9-329c-mrq6.json new file mode 100644 index 00000000000..46c667d144b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6fv9-329c-mrq6/GHSA-6fv9-329c-mrq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fv9-329c-mrq6", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23498" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Translation.Pro allows Reflected XSS. This issue affects Translation.Pro: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/translation-pro/vulnerability/wordpress-translation-pro-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6q2v-hjxc-f9rp/GHSA-6q2v-hjxc-f9rp.json b/advisories/unreviewed/2025/01/GHSA-6q2v-hjxc-f9rp/GHSA-6q2v-hjxc-f9rp.json new file mode 100644 index 00000000000..acfea09de95 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6q2v-hjxc-f9rp/GHSA-6q2v-hjxc-f9rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q2v-hjxc-f9rp", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23512" + ], + "details": "Missing Authorization vulnerability in Team118GROUP Team 118GROUP Agent allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team 118GROUP Agent: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23512" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/team-118group-agent/vulnerability/wordpress-team-118group-agent-plugin-1-6-0-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xjp-947h-mxr8/GHSA-6xjp-947h-mxr8.json b/advisories/unreviewed/2025/01/GHSA-6xjp-947h-mxr8/GHSA-6xjp-947h-mxr8.json new file mode 100644 index 00000000000..674da103c40 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6xjp-947h-mxr8/GHSA-6xjp-947h-mxr8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xjp-947h-mxr8", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-22980" + ], + "details": "A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22980" + }, + { + "type": "WEB", + "url": "https://github.com/slims/slims9_bulian/issues/270" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-73jw-x37m-r2h9/GHSA-73jw-x37m-r2h9.json b/advisories/unreviewed/2025/01/GHSA-73jw-x37m-r2h9/GHSA-73jw-x37m-r2h9.json new file mode 100644 index 00000000000..f918e9be225 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-73jw-x37m-r2h9/GHSA-73jw-x37m-r2h9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73jw-x37m-r2h9", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23781" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WM Options Import Export allows Retrieve Embedded Sensitive Data. This issue affects WM Options Import Export: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wm-options-import-export/vulnerability/wordpress-wm-options-import-export-plugin-1-0-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-75x7-c33w-j8c8/GHSA-75x7-c33w-j8c8.json b/advisories/unreviewed/2025/01/GHSA-75x7-c33w-j8c8/GHSA-75x7-c33w-j8c8.json new file mode 100644 index 00000000000..cdc8b8299e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-75x7-c33w-j8c8/GHSA-75x7-c33w-j8c8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75x7-c33w-j8c8", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23630" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cyber Slider allows Reflected XSS. This issue affects Cyber Slider: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23630" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cyber-new-slider/vulnerability/wordpress-cyber-slider-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7jx3-j4mg-5rvc/GHSA-7jx3-j4mg-5rvc.json b/advisories/unreviewed/2025/01/GHSA-7jx3-j4mg-5rvc/GHSA-7jx3-j4mg-5rvc.json new file mode 100644 index 00000000000..36341ee79bd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7jx3-j4mg-5rvc/GHSA-7jx3-j4mg-5rvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jx3-j4mg-5rvc", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23678" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound LocalGrid allows Reflected XSS. This issue affects LocalGrid: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/localgrid/vulnerability/wordpress-localgrid-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7m3j-45xq-3xj9/GHSA-7m3j-45xq-3xj9.json b/advisories/unreviewed/2025/01/GHSA-7m3j-45xq-3xj9/GHSA-7m3j-45xq-3xj9.json new file mode 100644 index 00000000000..5bc55dcd983 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7m3j-45xq-3xj9/GHSA-7m3j-45xq-3xj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m3j-45xq-3xj9", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23631" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Content Planner allows Reflected XSS. This issue affects Content Planner: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/content-planner/vulnerability/wordpress-content-planner-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7www-5pg7-vg69/GHSA-7www-5pg7-vg69.json b/advisories/unreviewed/2025/01/GHSA-7www-5pg7-vg69/GHSA-7www-5pg7-vg69.json new file mode 100644 index 00000000000..59135c9474c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7www-5pg7-vg69/GHSA-7www-5pg7-vg69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7www-5pg7-vg69", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23583" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Membership allows Reflected XSS. This issue affects Explara Membership: from n/a through 0.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/explara-membership/vulnerability/wordpress-explara-membership-plugin-0-0-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8254-xv48-7mrq/GHSA-8254-xv48-7mrq.json b/advisories/unreviewed/2025/01/GHSA-8254-xv48-7mrq/GHSA-8254-xv48-7mrq.json new file mode 100644 index 00000000000..d7e2b51a0b7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8254-xv48-7mrq/GHSA-8254-xv48-7mrq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8254-xv48-7mrq", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37018" + ], + "details": "Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37018" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-83f2-g28h-f9cf/GHSA-83f2-g28h-f9cf.json b/advisories/unreviewed/2025/01/GHSA-83f2-g28h-f9cf/GHSA-83f2-g28h-f9cf.json new file mode 100644 index 00000000000..a9d7b9a7fac --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-83f2-g28h-f9cf/GHSA-83f2-g28h-f9cf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83f2-g28h-f9cf", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23509" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound HyperComments allows Reflected XSS. This issue affects HyperComments: from n/a through 0.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23509" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/comments-with-hypercommentscom/vulnerability/wordpress-hypercomments-plugin-0-9-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8cw5-2qqr-3xvc/GHSA-8cw5-2qqr-3xvc.json b/advisories/unreviewed/2025/01/GHSA-8cw5-2qqr-3xvc/GHSA-8cw5-2qqr-3xvc.json new file mode 100644 index 00000000000..f88b96050b7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8cw5-2qqr-3xvc/GHSA-8cw5-2qqr-3xvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cw5-2qqr-3xvc", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23684" + ], + "details": "Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Debug Tool: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23684" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/debug-tool/vulnerability/wordpress-debug-tool-plugin-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json b/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json new file mode 100644 index 00000000000..3a2ed8f58f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8ppx-rwm8-h7rp/GHSA-8ppx-rwm8-h7rp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ppx-rwm8-h7rp", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37010" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37010" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8w89-r7hw-4xgj/GHSA-8w89-r7hw-4xgj.json b/advisories/unreviewed/2025/01/GHSA-8w89-r7hw-4xgj/GHSA-8w89-r7hw-4xgj.json new file mode 100644 index 00000000000..0655bdd9c7d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8w89-r7hw-4xgj/GHSA-8w89-r7hw-4xgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w89-r7hw-4xgj", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23949" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free Version: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23949" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/improved-sale-badges-free-version/vulnerability/wordpress-improved-sale-badges-free-version-plugin-1-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-976w-5vj5-frv8/GHSA-976w-5vj5-frv8.json b/advisories/unreviewed/2025/01/GHSA-976w-5vj5-frv8/GHSA-976w-5vj5-frv8.json new file mode 100644 index 00000000000..defe8d2e157 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-976w-5vj5-frv8/GHSA-976w-5vj5-frv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-976w-5vj5-frv8", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23609" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Helmuth Lammer Tagesteller allows Reflected XSS. This issue affects Tagesteller: from n/a through v.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tagesteller/vulnerability/wordpress-tagesteller-plugin-v-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9c2g-h7p9-73f9/GHSA-9c2g-h7p9-73f9.json b/advisories/unreviewed/2025/01/GHSA-9c2g-h7p9-73f9/GHSA-9c2g-h7p9-73f9.json new file mode 100644 index 00000000000..f29b47a9506 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9c2g-h7p9-73f9/GHSA-9c2g-h7p9-73f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c2g-h7p9-73f9", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23683" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MACME allows Reflected XSS. This issue affects MACME: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/macme/vulnerability/wordpress-macme-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9pm6-fvgj-xj4x/GHSA-9pm6-fvgj-xj4x.json b/advisories/unreviewed/2025/01/GHSA-9pm6-fvgj-xj4x/GHSA-9pm6-fvgj-xj4x.json new file mode 100644 index 00000000000..a651ed73c1b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9pm6-fvgj-xj4x/GHSA-9pm6-fvgj-xj4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pm6-fvgj-xj4x", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23578" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom CSS Addons allows Reflected XSS. This issue affects Custom CSS Addons: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css-addons/vulnerability/wordpress-custom-css-addons-plugin-1-9-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9qxf-frvg-wwgq/GHSA-9qxf-frvg-wwgq.json b/advisories/unreviewed/2025/01/GHSA-9qxf-frvg-wwgq/GHSA-9qxf-frvg-wwgq.json new file mode 100644 index 00000000000..e3c79a346ad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9qxf-frvg-wwgq/GHSA-9qxf-frvg-wwgq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qxf-frvg-wwgq", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37012" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` message missing a required `PLMN Identity` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37012" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c3xq-xww5-9347/GHSA-c3xq-xww5-9347.json b/advisories/unreviewed/2025/01/GHSA-c3xq-xww5-9347/GHSA-c3xq-xww5-9347.json new file mode 100644 index 00000000000..44feefc27a4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c3xq-xww5-9347/GHSA-c3xq-xww5-9347.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3xq-xww5-9347", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23806" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeFarmer Ultimate Subscribe allows Reflected XSS. This issue affects Ultimate Subscribe: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-subscribe/vulnerability/wordpress-ultimate-subscribe-plugin-1-3-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c4mr-f695-j8p8/GHSA-c4mr-f695-j8p8.json b/advisories/unreviewed/2025/01/GHSA-c4mr-f695-j8p8/GHSA-c4mr-f695-j8p8.json index 3d5bc4be3dc..32517953adc 100644 --- a/advisories/unreviewed/2025/01/GHSA-c4mr-f695-j8p8/GHSA-c4mr-f695-j8p8.json +++ b/advisories/unreviewed/2025/01/GHSA-c4mr-f695-j8p8/GHSA-c4mr-f695-j8p8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c4mr-f695-j8p8", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49736" ], "details": "In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c73h-5523-53rr/GHSA-c73h-5523-53rr.json b/advisories/unreviewed/2025/01/GHSA-c73h-5523-53rr/GHSA-c73h-5523-53rr.json new file mode 100644 index 00000000000..fffa0e7cb7d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c73h-5523-53rr/GHSA-c73h-5523-53rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c73h-5523-53rr", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23589" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ContentOptin Lite allows Reflected XSS. This issue affects ContentOptin Lite: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23589" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contentoptin/vulnerability/wordpress-contentoptin-lite-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c874-8h7r-5764/GHSA-c874-8h7r-5764.json b/advisories/unreviewed/2025/01/GHSA-c874-8h7r-5764/GHSA-c874-8h7r-5764.json new file mode 100644 index 00000000000..9b692cadc59 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c874-8h7r-5764/GHSA-c874-8h7r-5764.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c874-8h7r-5764", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37016" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37016" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json b/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json index a16fd6eabee..1289c3ae213 100644 --- a/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json +++ b/advisories/unreviewed/2025/01/GHSA-cffw-755r-8qx2/GHSA-cffw-755r-8qx2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cffw-755r-8qx2", - "modified": "2025-01-18T06:30:24Z", + "modified": "2025-01-22T15:32:33Z", "published": "2025-01-18T06:30:24Z", "aliases": [ "CVE-2024-9020" ], "details": "The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T06:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cggj-gprv-7895/GHSA-cggj-gprv-7895.json b/advisories/unreviewed/2025/01/GHSA-cggj-gprv-7895/GHSA-cggj-gprv-7895.json new file mode 100644 index 00000000000..032537385f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cggj-gprv-7895/GHSA-cggj-gprv-7895.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cggj-gprv-7895", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23769" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Content Mirror allows Reflected XSS. This issue affects Content Mirror: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23769" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/content-mirror/vulnerability/wordpress-content-mirror-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cr43-57pq-9qgj/GHSA-cr43-57pq-9qgj.json b/advisories/unreviewed/2025/01/GHSA-cr43-57pq-9qgj/GHSA-cr43-57pq-9qgj.json new file mode 100644 index 00000000000..d99251f1a08 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cr43-57pq-9qgj/GHSA-cr43-57pq-9qgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr43-57pq-9qgj", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23942" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in NgocCode WP Load Gallery allows Upload a Web Shell to a Web Server. This issue affects WP Load Gallery: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23942" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-load-gallery/vulnerability/wordpress-wp-load-gallery-plugin-2-1-6-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json b/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json new file mode 100644 index 00000000000..5551193fd0f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cwgj-88jc-p385/GHSA-cwgj-88jc-p385.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwgj-88jc-p385", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37002" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Modification Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37002" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f226-gv22-gg2h/GHSA-f226-gv22-gg2h.json b/advisories/unreviewed/2025/01/GHSA-f226-gv22-gg2h/GHSA-f226-gv22-gg2h.json new file mode 100644 index 00000000000..d7936525cd5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f226-gv22-gg2h/GHSA-f226-gv22-gg2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f226-gv22-gg2h", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23681" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jannatqualitybacklinks.com REDIRECTION PLUS allows Reflected XSS. This issue affects REDIRECTION PLUS: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23681" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/redirection-plus/vulnerability/wordpress-redirection-plus-plugin-2-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f5m2-vc78-7pcq/GHSA-f5m2-vc78-7pcq.json b/advisories/unreviewed/2025/01/GHSA-f5m2-vc78-7pcq/GHSA-f5m2-vc78-7pcq.json new file mode 100644 index 00000000000..874bcde150b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f5m2-vc78-7pcq/GHSA-f5m2-vc78-7pcq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5m2-vc78-7pcq", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23601" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tab My Content allows Reflected XSS. This issue affects Tab My Content: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23601" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tab-my-content/vulnerability/wordpress-tab-my-content-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f74v-w38w-9rp4/GHSA-f74v-w38w-9rp4.json b/advisories/unreviewed/2025/01/GHSA-f74v-w38w-9rp4/GHSA-f74v-w38w-9rp4.json new file mode 100644 index 00000000000..9a5cb0e35e2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f74v-w38w-9rp4/GHSA-f74v-w38w-9rp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f74v-w38w-9rp4", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23931" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WordPress Local SEO allows Blind SQL Injection. This issue affects WordPress Local SEO: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dh-local-seo/vulnerability/wordpress-wordpress-local-seo-plugin-2-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f76g-5494-q868/GHSA-f76g-5494-q868.json b/advisories/unreviewed/2025/01/GHSA-f76g-5494-q868/GHSA-f76g-5494-q868.json new file mode 100644 index 00000000000..c48e7f2b22b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f76g-5494-q868/GHSA-f76g-5494-q868.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f76g-5494-q868", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23882" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Download Codes allows Reflected XSS. This issue affects WP Download Codes: from n/a through 2.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23882" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-download-codes/vulnerability/wordpress-wp-download-codes-plugin-2-5-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fgwg-x6m4-8h2r/GHSA-fgwg-x6m4-8h2r.json b/advisories/unreviewed/2025/01/GHSA-fgwg-x6m4-8h2r/GHSA-fgwg-x6m4-8h2r.json new file mode 100644 index 00000000000..c88911c575a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fgwg-x6m4-8h2r/GHSA-fgwg-x6m4-8h2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgwg-x6m4-8h2r", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23604" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Rezdy Reloaded allows Stored XSS. This issue affects Rezdy Reloaded: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23604" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/reloaded-rezdy/vulnerability/wordpress-rezdy-reloaded-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmmp-vh78-7jjx/GHSA-fmmp-vh78-7jjx.json b/advisories/unreviewed/2025/01/GHSA-fmmp-vh78-7jjx/GHSA-fmmp-vh78-7jjx.json new file mode 100644 index 00000000000..ca59fb9f13e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmmp-vh78-7jjx/GHSA-fmmp-vh78-7jjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmmp-vh78-7jjx", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23811" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP2APP allows Reflected XSS. This issue affects WP2APP: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23811" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp2appir/vulnerability/wordpress-wp2app-plugin-2-6-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fq84-vv4r-9gjq/GHSA-fq84-vv4r-9gjq.json b/advisories/unreviewed/2025/01/GHSA-fq84-vv4r-9gjq/GHSA-fq84-vv4r-9gjq.json new file mode 100644 index 00000000000..eb3cf943009 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fq84-vv4r-9gjq/GHSA-fq84-vv4r-9gjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq84-vv4r-9gjq", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23475" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound History timeline allows Reflected XSS. This issue affects History timeline: from n/a through 0.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23475" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/history-timeline/vulnerability/wordpress-history-timeline-plugin-0-7-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g2fw-hxwc-j3px/GHSA-g2fw-hxwc-j3px.json b/advisories/unreviewed/2025/01/GHSA-g2fw-hxwc-j3px/GHSA-g2fw-hxwc-j3px.json new file mode 100644 index 00000000000..c13b0e05fc0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g2fw-hxwc-j3px/GHSA-g2fw-hxwc-j3px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2fw-hxwc-j3px", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23607" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camoo Sarl CAMOO SMS allows Reflected XSS. This issue affects CAMOO SMS: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23607" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/camoo-sms/vulnerability/wordpress-camoo-sms-plugin-3-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json b/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json index 4efe68cbd83..42d45f24d16 100644 --- a/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json +++ b/advisories/unreviewed/2025/01/GHSA-g359-p277-83p3/GHSA-g359-p277-83p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g359-p277-83p3", - "modified": "2025-01-22T00:33:36Z", + "modified": "2025-01-22T15:32:33Z", "published": "2025-01-22T00:33:36Z", "aliases": [ "CVE-2024-51941" ], "details": "A remote code injection vulnerability exists in the Ambari Metrics and \nAMS Alerts feature, allowing authenticated users to inject and execute \narbitrary code. The vulnerability occurs when processing alert \ndefinitions, where malicious input can be injected into the alert script\n execution path. An attacker with authenticated access can exploit this \nvulnerability to execute arbitrary commands on the server. The issue has\n been fixed in the latest versions of Ambari.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-75" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gcmq-4hqx-cf48/GHSA-gcmq-4hqx-cf48.json b/advisories/unreviewed/2025/01/GHSA-gcmq-4hqx-cf48/GHSA-gcmq-4hqx-cf48.json new file mode 100644 index 00000000000..083ec856e62 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gcmq-4hqx-cf48/GHSA-gcmq-4hqx-cf48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcmq-4hqx-cf48", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23867" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress File Search allows Reflected XSS. This issue affects WordPress File Search: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23867" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpfilesearch/vulnerability/wordpress-wordpress-file-search-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gpqj-4j66-2gh4/GHSA-gpqj-4j66-2gh4.json b/advisories/unreviewed/2025/01/GHSA-gpqj-4j66-2gh4/GHSA-gpqj-4j66-2gh4.json new file mode 100644 index 00000000000..afccc95dc24 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gpqj-4j66-2gh4/GHSA-gpqj-4j66-2gh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpqj-4j66-2gh4", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23605" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LamPD Call To Action Popup allows Reflected XSS. This issue affects Call To Action Popup: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/call-to-action-popup/vulnerability/wordpress-call-to-action-popup-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gqgm-6hg6-vrvf/GHSA-gqgm-6hg6-vrvf.json b/advisories/unreviewed/2025/01/GHSA-gqgm-6hg6-vrvf/GHSA-gqgm-6hg6-vrvf.json new file mode 100644 index 00000000000..c9bc7a80720 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gqgm-6hg6-vrvf/GHSA-gqgm-6hg6-vrvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqgm-6hg6-vrvf", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23486" + ], + "details": "Missing Authorization vulnerability in NotFound Database Sync allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Database Sync: from n/a through 0.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23486" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/database-sync/vulnerability/wordpress-database-sync-plugin-0-5-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h483-px82-mchv/GHSA-h483-px82-mchv.json b/advisories/unreviewed/2025/01/GHSA-h483-px82-mchv/GHSA-h483-px82-mchv.json new file mode 100644 index 00000000000..da7dd5d9887 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h483-px82-mchv/GHSA-h483-px82-mchv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h483-px82-mchv", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37015" + ], + "details": "Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37015" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h4w3-ffw8-rr28/GHSA-h4w3-ffw8-rr28.json b/advisories/unreviewed/2025/01/GHSA-h4w3-ffw8-rr28/GHSA-h4w3-ffw8-rr28.json new file mode 100644 index 00000000000..067a646444b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h4w3-ffw8-rr28/GHSA-h4w3-ffw8-rr28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4w3-ffw8-rr28", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23602" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EELV Newsletter allows Reflected XSS. This issue affects EELV Newsletter: from n/a through 4.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23602" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eelv-newsletter/vulnerability/wordpress-eelv-newsletter-plugin-4-8-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h53w-84fj-6mjw/GHSA-h53w-84fj-6mjw.json b/advisories/unreviewed/2025/01/GHSA-h53w-84fj-6mjw/GHSA-h53w-84fj-6mjw.json index fd61372fe58..d5297199cd9 100644 --- a/advisories/unreviewed/2025/01/GHSA-h53w-84fj-6mjw/GHSA-h53w-84fj-6mjw.json +++ b/advisories/unreviewed/2025/01/GHSA-h53w-84fj-6mjw/GHSA-h53w-84fj-6mjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h53w-84fj-6mjw", - "modified": "2025-01-22T00:33:37Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:37Z", "aliases": [ "CVE-2023-37035" ], "details": "A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missing an expected `Global eNB ID` field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h5p7-26p5-jx9h/GHSA-h5p7-26p5-jx9h.json b/advisories/unreviewed/2025/01/GHSA-h5p7-26p5-jx9h/GHSA-h5p7-26p5-jx9h.json new file mode 100644 index 00000000000..de4b1d0cf8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h5p7-26p5-jx9h/GHSA-h5p7-26p5-jx9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5p7-26p5-jx9h", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23625" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AWcode, PDSonline Unique UX allows Reflected XSS. This issue affects Unique UX: from n/a through 0.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/unique-ux/vulnerability/wordpress-unique-ux-plugin-0-9-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h8qv-cwpv-997w/GHSA-h8qv-cwpv-997w.json b/advisories/unreviewed/2025/01/GHSA-h8qv-cwpv-997w/GHSA-h8qv-cwpv-997w.json new file mode 100644 index 00000000000..ab94f8d2ce5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h8qv-cwpv-997w/GHSA-h8qv-cwpv-997w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8qv-cwpv-997w", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23507" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blrt Blrt WP Embed allows Reflected XSS. This issue affects Blrt WP Embed: from n/a through 1.6.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blrt-wp-embed/vulnerability/wordpress-blrt-wp-embed-plugin-1-6-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hjqg-mr87-p6m3/GHSA-hjqg-mr87-p6m3.json b/advisories/unreviewed/2025/01/GHSA-hjqg-mr87-p6m3/GHSA-hjqg-mr87-p6m3.json new file mode 100644 index 00000000000..dbe9b19dc69 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hjqg-mr87-p6m3/GHSA-hjqg-mr87-p6m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjqg-mr87-p6m3", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23918" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Smallerik File Browser allows Upload a Web Shell to a Web Server. This issue affects Smallerik File Browser: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23918" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smallerik-file-browser/vulnerability/wordpress-smallerik-file-browser-plugin-1-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j648-x338-vqvm/GHSA-j648-x338-vqvm.json b/advisories/unreviewed/2025/01/GHSA-j648-x338-vqvm/GHSA-j648-x338-vqvm.json new file mode 100644 index 00000000000..491f12abe72 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j648-x338-vqvm/GHSA-j648-x338-vqvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j648-x338-vqvm", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23938" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Image Gallery Box by CRUDLab allows PHP Local File Inclusion. This issue affects Image Gallery Box by CRUDLab: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23938" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-gallery-box-by-crudlab/vulnerability/wordpress-image-gallery-box-by-crudlab-plugin-1-0-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j85f-xv44-mr6x/GHSA-j85f-xv44-mr6x.json b/advisories/unreviewed/2025/01/GHSA-j85f-xv44-mr6x/GHSA-j85f-xv44-mr6x.json new file mode 100644 index 00000000000..d15b2ddf2ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j85f-xv44-mr6x/GHSA-j85f-xv44-mr6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j85f-xv44-mr6x", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23606" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Calendi allows Reflected XSS. This issue affects Calendi: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23606" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/calendi/vulnerability/wordpress-calendi-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jhfj-4x6v-p4q6/GHSA-jhfj-4x6v-p4q6.json b/advisories/unreviewed/2025/01/GHSA-jhfj-4x6v-p4q6/GHSA-jhfj-4x6v-p4q6.json new file mode 100644 index 00000000000..b77d67d484f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jhfj-4x6v-p4q6/GHSA-jhfj-4x6v-p4q6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhfj-4x6v-p4q6", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23700" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yonatan Reinberg yCyclista allows Reflected XSS. This issue affects yCyclista: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23700" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ycyclista/vulnerability/wordpress-ycyclista-plugin-1-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jjxh-vpf5-jm42/GHSA-jjxh-vpf5-jm42.json b/advisories/unreviewed/2025/01/GHSA-jjxh-vpf5-jm42/GHSA-jjxh-vpf5-jm42.json index 84369eb6987..ebb9a1c3547 100644 --- a/advisories/unreviewed/2025/01/GHSA-jjxh-vpf5-jm42/GHSA-jjxh-vpf5-jm42.json +++ b/advisories/unreviewed/2025/01/GHSA-jjxh-vpf5-jm42/GHSA-jjxh-vpf5-jm42.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jjxh-vpf5-jm42", - "modified": "2025-01-22T00:33:36Z", + "modified": "2025-01-22T15:32:33Z", "published": "2025-01-22T00:33:36Z", "aliases": [ "CVE-2025-23195" ], "details": "An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie \nproject, allowing an attacker to inject malicious XML entities. This \nvulnerability occurs due to insecure parsing of XML input using the \n`DocumentBuilderFactory` class without disabling external entity \nresolution. An attacker can exploit this vulnerability to read arbitrary\n files on the server or perform server-side request forgery (SSRF) \nattacks. The issue has been fixed in both Ambari 2.7.9 and the trunk \nbranch.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-611" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jm92-jw9v-j6h2/GHSA-jm92-jw9v-j6h2.json b/advisories/unreviewed/2025/01/GHSA-jm92-jw9v-j6h2/GHSA-jm92-jw9v-j6h2.json new file mode 100644 index 00000000000..f0e4c6dd2db --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jm92-jw9v-j6h2/GHSA-jm92-jw9v-j6h2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm92-jw9v-j6h2", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23709" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiro G. Formatted post allows Reflected XSS. This issue affects Formatted post: from n/a through 1.01.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23709" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/formatted-post/vulnerability/wordpress-formatted-post-plugin-1-01-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m3hp-8546-5qmr/GHSA-m3hp-8546-5qmr.json b/advisories/unreviewed/2025/01/GHSA-m3hp-8546-5qmr/GHSA-m3hp-8546-5qmr.json new file mode 100644 index 00000000000..6a6accd1ba7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m3hp-8546-5qmr/GHSA-m3hp-8546-5qmr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3hp-8546-5qmr", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-0604" + ], + "details": "A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD restrictions. The issue enables authentication bypass and could allow unauthorized access under certain conditions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0604" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0604" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2338993" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m4jr-5394-x5vm/GHSA-m4jr-5394-x5vm.json b/advisories/unreviewed/2025/01/GHSA-m4jr-5394-x5vm/GHSA-m4jr-5394-x5vm.json new file mode 100644 index 00000000000..3ddf0be018d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m4jr-5394-x5vm/GHSA-m4jr-5394-x5vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4jr-5394-x5vm", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23770" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Fast Tube allows Reflected XSS. This issue affects Fast Tube: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fast-tube/vulnerability/wordpress-fast-tube-plugin-2-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m8vc-jw77-wxj4/GHSA-m8vc-jw77-wxj4.json b/advisories/unreviewed/2025/01/GHSA-m8vc-jw77-wxj4/GHSA-m8vc-jw77-wxj4.json index 9969125c86f..a5824683765 100644 --- a/advisories/unreviewed/2025/01/GHSA-m8vc-jw77-wxj4/GHSA-m8vc-jw77-wxj4.json +++ b/advisories/unreviewed/2025/01/GHSA-m8vc-jw77-wxj4/GHSA-m8vc-jw77-wxj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8vc-jw77-wxj4", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49737" ], "details": "In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m98h-h759-qxcc/GHSA-m98h-h759-qxcc.json b/advisories/unreviewed/2025/01/GHSA-m98h-h759-qxcc/GHSA-m98h-h759-qxcc.json new file mode 100644 index 00000000000..b27e86a19e0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m98h-h759-qxcc/GHSA-m98h-h759-qxcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m98h-h759-qxcc", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23803" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PQINA Snippy allows Reflected XSS. This issue affects Snippy: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/snippy/vulnerability/wordpress-snippy-plugin-1-4-1-csrf-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m993-jwwj-jxc2/GHSA-m993-jwwj-jxc2.json b/advisories/unreviewed/2025/01/GHSA-m993-jwwj-jxc2/GHSA-m993-jwwj-jxc2.json new file mode 100644 index 00000000000..a7601e16f39 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m993-jwwj-jxc2/GHSA-m993-jwwj-jxc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m993-jwwj-jxc2", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23592" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound dForms allows Reflected XSS. This issue affects dForms: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23592" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dforms/vulnerability/wordpress-dforms-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mf84-jxh2-rc4j/GHSA-mf84-jxh2-rc4j.json b/advisories/unreviewed/2025/01/GHSA-mf84-jxh2-rc4j/GHSA-mf84-jxh2-rc4j.json new file mode 100644 index 00000000000..720a9056938 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mf84-jxh2-rc4j/GHSA-mf84-jxh2-rc4j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf84-jxh2-rc4j", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2024-24430" + ], + "details": "A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24430" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mh53-5gcx-h6x9/GHSA-mh53-5gcx-h6x9.json b/advisories/unreviewed/2025/01/GHSA-mh53-5gcx-h6x9/GHSA-mh53-5gcx-h6x9.json new file mode 100644 index 00000000000..4d9988a2eb2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mh53-5gcx-h6x9/GHSA-mh53-5gcx-h6x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh53-5gcx-h6x9", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23500" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Ahmed, Technial Architect,faaiqsj@gmail.com Simple Custom post type custom field allows Reflected XSS. This issue affects Simple Custom post type custom field: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23500" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-content-construction-kit/vulnerability/wordpress-simple-custom-post-type-custom-field-plugin-1-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mjj5-4qc2-r6g6/GHSA-mjj5-4qc2-r6g6.json b/advisories/unreviewed/2025/01/GHSA-mjj5-4qc2-r6g6/GHSA-mjj5-4qc2-r6g6.json new file mode 100644 index 00000000000..8167456dc60 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mjj5-4qc2-r6g6/GHSA-mjj5-4qc2-r6g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjj5-4qc2-r6g6", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23953" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Innovative Solutions user files allows Upload a Web Shell to a Web Server. This issue affects user files: from n/a through 2.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23953" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-files/vulnerability/wordpress-user-files-plugin-2-4-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mp7w-vq3p-xp89/GHSA-mp7w-vq3p-xp89.json b/advisories/unreviewed/2025/01/GHSA-mp7w-vq3p-xp89/GHSA-mp7w-vq3p-xp89.json new file mode 100644 index 00000000000..b6f54592cb6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mp7w-vq3p-xp89/GHSA-mp7w-vq3p-xp89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp7w-vq3p-xp89", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23535" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in clickandsell REAL WordPress Sidebar allows Stored XSS. This issue affects REAL WordPress Sidebar: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/drag-and-drop-custom-sidebar/vulnerability/wordpress-real-wordpress-sidebar-plugin-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mr5r-7w8p-59p7/GHSA-mr5r-7w8p-59p7.json b/advisories/unreviewed/2025/01/GHSA-mr5r-7w8p-59p7/GHSA-mr5r-7w8p-59p7.json new file mode 100644 index 00000000000..5bf34e9455a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mr5r-7w8p-59p7/GHSA-mr5r-7w8p-59p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr5r-7w8p-59p7", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23503" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Customizable Captcha and Contact Us allows Reflected XSS. This issue affects Customizable Captcha and Contact Us: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/customizable-captcha-and-contact-us-form/vulnerability/wordpress-customizable-captcha-and-contact-us-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mvjr-xfhv-mwpw/GHSA-mvjr-xfhv-mwpw.json b/advisories/unreviewed/2025/01/GHSA-mvjr-xfhv-mwpw/GHSA-mvjr-xfhv-mwpw.json new file mode 100644 index 00000000000..a7672eb1d41 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mvjr-xfhv-mwpw/GHSA-mvjr-xfhv-mwpw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvjr-xfhv-mwpw", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37019" + ], + "details": "Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37019" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mw75-cjrf-477c/GHSA-mw75-cjrf-477c.json b/advisories/unreviewed/2025/01/GHSA-mw75-cjrf-477c/GHSA-mw75-cjrf-477c.json new file mode 100644 index 00000000000..519765eb07d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mw75-cjrf-477c/GHSA-mw75-cjrf-477c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw75-cjrf-477c", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23696" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Staging CDN allows Reflected XSS. This issue affects Staging CDN: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23696" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/staging-cdn/vulnerability/wordpress-staging-cdn-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mwrc-pj94-779p/GHSA-mwrc-pj94-779p.json b/advisories/unreviewed/2025/01/GHSA-mwrc-pj94-779p/GHSA-mwrc-pj94-779p.json new file mode 100644 index 00000000000..b0980eac4a0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mwrc-pj94-779p/GHSA-mwrc-pj94-779p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwrc-pj94-779p", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23449" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple shortcode buttons allows Reflected XSS. This issue affects Simple shortcode buttons: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-shortcode-buttons/vulnerability/wordpress-simple-shortcode-buttons-plugin-1-3-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mx53-8x3c-jgqv/GHSA-mx53-8x3c-jgqv.json b/advisories/unreviewed/2025/01/GHSA-mx53-8x3c-jgqv/GHSA-mx53-8x3c-jgqv.json new file mode 100644 index 00000000000..397ba120097 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mx53-8x3c-jgqv/GHSA-mx53-8x3c-jgqv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx53-8x3c-jgqv", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37022" + ], + "details": "Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37022" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json b/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json index d55749a500b..2553dedaa41 100644 --- a/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json +++ b/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2xw-hr6c-g7h5", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49747" ], "details": "In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json b/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json new file mode 100644 index 00000000000..58b9b382bd4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p44p-wgq8-46qm/GHSA-p44p-wgq8-46qm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p44p-wgq8-46qm", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37006" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Request Ack` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37006" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p6q2-w3w9-4cjw/GHSA-p6q2-w3w9-4cjw.json b/advisories/unreviewed/2025/01/GHSA-p6q2-w3w9-4cjw/GHSA-p6q2-w3w9-4cjw.json new file mode 100644 index 00000000000..fd9f7dcb010 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p6q2-w3w9-4cjw/GHSA-p6q2-w3w9-4cjw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6q2-w3w9-4cjw", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-36998" + ], + "details": "The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the stack with arbitrary bytes. An attacker with a cellphone connection to any base station managed by the MME may exploit this vulnerability without having to authenticate with the LTE core.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36998" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + }, + { + "type": "WEB", + "url": "http://nextepc.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p8gf-75qm-vcj2/GHSA-p8gf-75qm-vcj2.json b/advisories/unreviewed/2025/01/GHSA-p8gf-75qm-vcj2/GHSA-p8gf-75qm-vcj2.json new file mode 100644 index 00000000000..8e4b1b2dfb2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p8gf-75qm-vcj2/GHSA-p8gf-75qm-vcj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8gf-75qm-vcj2", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23603" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Group category creator allows Reflected XSS. This issue affects Group category creator: from n/a through 1.3.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23603" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/group-category-creator/vulnerability/wordpress-group-category-creator-plugin-1-3-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ph64-rj79-fwm3/GHSA-ph64-rj79-fwm3.json b/advisories/unreviewed/2025/01/GHSA-ph64-rj79-fwm3/GHSA-ph64-rj79-fwm3.json new file mode 100644 index 00000000000..7d18037e58d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ph64-rj79-fwm3/GHSA-ph64-rj79-fwm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph64-rj79-fwm3", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23774" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows Retrieve Embedded Sensitive Data. This issue affects WPDB to Sql: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23774" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpdb-to-sql/vulnerability/wordpress-wpdb-to-sql-plugin-1-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pqj9-qcr7-74fh/GHSA-pqj9-qcr7-74fh.json b/advisories/unreviewed/2025/01/GHSA-pqj9-qcr7-74fh/GHSA-pqj9-qcr7-74fh.json new file mode 100644 index 00000000000..ecdc45cadcc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pqj9-qcr7-74fh/GHSA-pqj9-qcr7-74fh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqj9-qcr7-74fh", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37014" + ], + "details": "Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37014" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-px86-7w9g-5j6m/GHSA-px86-7w9g-5j6m.json b/advisories/unreviewed/2025/01/GHSA-px86-7w9g-5j6m/GHSA-px86-7w9g-5j6m.json index e1f81109652..26a63dcbde2 100644 --- a/advisories/unreviewed/2025/01/GHSA-px86-7w9g-5j6m/GHSA-px86-7w9g-5j6m.json +++ b/advisories/unreviewed/2025/01/GHSA-px86-7w9g-5j6m/GHSA-px86-7w9g-5j6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px86-7w9g-5j6m", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49745" ], "details": "In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q7jg-p665-r7wq/GHSA-q7jg-p665-r7wq.json b/advisories/unreviewed/2025/01/GHSA-q7jg-p665-r7wq/GHSA-q7jg-p665-r7wq.json new file mode 100644 index 00000000000..3ec968523e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q7jg-p665-r7wq/GHSA-q7jg-p665-r7wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7jg-p665-r7wq", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23768" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound InFunding allows Reflected XSS. This issue affects InFunding: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23768" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/infunding/vulnerability/wordpress-infunding-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qcjc-qmxq-wf6x/GHSA-qcjc-qmxq-wf6x.json b/advisories/unreviewed/2025/01/GHSA-qcjc-qmxq-wf6x/GHSA-qcjc-qmxq-wf6x.json new file mode 100644 index 00000000000..92cae134387 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qcjc-qmxq-wf6x/GHSA-qcjc-qmxq-wf6x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcjc-qmxq-wf6x", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37017" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37017" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qjmq-8gw8-9273/GHSA-qjmq-8gw8-9273.json b/advisories/unreviewed/2025/01/GHSA-qjmq-8gw8-9273/GHSA-qjmq-8gw8-9273.json new file mode 100644 index 00000000000..4c05fa6d4ad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qjmq-8gw8-9273/GHSA-qjmq-8gw8-9273.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjmq-8gw8-9273", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23506" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP IMAP Auth allows Reflected XSS. This issue affects WP IMAP Auth: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-imap-authentication/vulnerability/wordpress-wp-imap-auth-plugin-4-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json b/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json new file mode 100644 index 00000000000..abe6af04e09 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qv2m-4wv2-f33h/GHSA-qv2m-4wv2-f33h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv2m-4wv2-f33h", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37004" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37004" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json b/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json new file mode 100644 index 00000000000..d1587c12a72 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r492-f75w-fpq9/GHSA-r492-f75w-fpq9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r492-f75w-fpq9", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37009" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37009" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r4h2-pqcr-8272/GHSA-r4h2-pqcr-8272.json b/advisories/unreviewed/2025/01/GHSA-r4h2-pqcr-8272/GHSA-r4h2-pqcr-8272.json new file mode 100644 index 00000000000..02f361dbf0d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r4h2-pqcr-8272/GHSA-r4h2-pqcr-8272.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4h2-pqcr-8272", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23643" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ReadMe Creator allows Reflected XSS. This issue affects ReadMe Creator: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/readme-creator/vulnerability/wordpress-readme-creator-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r8gm-64g7-7736/GHSA-r8gm-64g7-7736.json b/advisories/unreviewed/2025/01/GHSA-r8gm-64g7-7736/GHSA-r8gm-64g7-7736.json new file mode 100644 index 00000000000..75c62a7309c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r8gm-64g7-7736/GHSA-r8gm-64g7-7736.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8gm-64g7-7736", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23701" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Blackford, LimeSquare Pty Ltd Lime Developer Login allows Reflected XSS. This issue affects Lime Developer Login: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23701" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lime-developer-login/vulnerability/wordpress-lime-developer-login-plugin-1-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rgrx-5mj9-r82x/GHSA-rgrx-5mj9-r82x.json b/advisories/unreviewed/2025/01/GHSA-rgrx-5mj9-r82x/GHSA-rgrx-5mj9-r82x.json new file mode 100644 index 00000000000..74ea6d19ea9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rgrx-5mj9-r82x/GHSA-rgrx-5mj9-r82x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgrx-5mj9-r82x", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23746" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CMC MIGRATE allows Reflected XSS. This issue affects CMC MIGRATE: from n/a through 0.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23746" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cmc-migrate/vulnerability/wordpress-cmc-migrate-plugin-0-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rq53-4cvw-2q74/GHSA-rq53-4cvw-2q74.json b/advisories/unreviewed/2025/01/GHSA-rq53-4cvw-2q74/GHSA-rq53-4cvw-2q74.json new file mode 100644 index 00000000000..bd21f73e041 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rq53-4cvw-2q74/GHSA-rq53-4cvw-2q74.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq53-4cvw-2q74", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23966" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlaFalaki a Gateway for Pasargad Bank on WooCommerce allows Reflected XSS. This issue affects a Gateway for Pasargad Bank on WooCommerce: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23966" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/a-gateway-for-pasargad-bank-on-woocommerce/vulnerability/wordpress-a-gateway-for-pasargad-bank-on-woocommerce-plugin-2-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v339-89pg-gj89/GHSA-v339-89pg-gj89.json b/advisories/unreviewed/2025/01/GHSA-v339-89pg-gj89/GHSA-v339-89pg-gj89.json new file mode 100644 index 00000000000..94db4cee3bc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v339-89pg-gj89/GHSA-v339-89pg-gj89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v339-89pg-gj89", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23732" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Easy Filtering allows Reflected XSS. This issue affects Easy Filtering: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23732" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-filtering/vulnerability/wordpress-easy-filtering-plugin-2-5-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json b/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json new file mode 100644 index 00000000000..841bab3d18f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v4x5-x848-6pj8/GHSA-v4x5-x848-6pj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4x5-x848-6pj8", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23686" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Callum Richards Admin Menu Organizer allows Reflected XSS. This issue affects Admin Menu Organizer: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/admin-menu-organizer/vulnerability/wordpress-admin-menu-organizer-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vv53-gg69-w9q3/GHSA-vv53-gg69-w9q3.json b/advisories/unreviewed/2025/01/GHSA-vv53-gg69-w9q3/GHSA-vv53-gg69-w9q3.json new file mode 100644 index 00000000000..c4e0186a458 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vv53-gg69-w9q3/GHSA-vv53-gg69-w9q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv53-gg69-w9q3", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23679" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moshiur Rahman Mehedi FP RSS Category Excluder allows Reflected XSS. This issue affects FP RSS Category Excluder: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23679" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fp-rss-category-excluder/vulnerability/wordpress-fp-rss-category-excluder-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wfff-769x-fr8w/GHSA-wfff-769x-fr8w.json b/advisories/unreviewed/2025/01/GHSA-wfff-769x-fr8w/GHSA-wfff-769x-fr8w.json new file mode 100644 index 00000000000..98627c4c9e5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wfff-769x-fr8w/GHSA-wfff-769x-fr8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfff-769x-fr8w", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23910" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Menus Plus+ allows SQL Injection. This issue affects Menus Plus+: from n/a through 1.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23910" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/menus-plus/vulnerability/wordpress-menus-plus-plugin-1-9-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wfj2-2gqr-p45g/GHSA-wfj2-2gqr-p45g.json b/advisories/unreviewed/2025/01/GHSA-wfj2-2gqr-p45g/GHSA-wfj2-2gqr-p45g.json new file mode 100644 index 00000000000..39513047acf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wfj2-2gqr-p45g/GHSA-wfj2-2gqr-p45g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfj2-2gqr-p45g", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23610" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ultimate Events allows Reflected XSS. This issue affects Ultimate Events: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-events/vulnerability/wordpress-ultimate-events-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wg5v-689x-wgmp/GHSA-wg5v-689x-wgmp.json b/advisories/unreviewed/2025/01/GHSA-wg5v-689x-wgmp/GHSA-wg5v-689x-wgmp.json new file mode 100644 index 00000000000..3672dfde7d4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wg5v-689x-wgmp/GHSA-wg5v-689x-wgmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg5v-689x-wgmp", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23597" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riosis Private Limited Rio Photo Gallery allows Reflected XSS. This issue affects Rio Photo Gallery: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23597" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rio-photo-gallery/vulnerability/wordpress-rio-photo-gallery-plugin-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-whxf-qv83-4936/GHSA-whxf-qv83-4936.json b/advisories/unreviewed/2025/01/GHSA-whxf-qv83-4936/GHSA-whxf-qv83-4936.json new file mode 100644 index 00000000000..50673607027 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-whxf-qv83-4936/GHSA-whxf-qv83-4936.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whxf-qv83-4936", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37007" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Cancel` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37007" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wm2x-9fx6-qgf6/GHSA-wm2x-9fx6-qgf6.json b/advisories/unreviewed/2025/01/GHSA-wm2x-9fx6-qgf6/GHSA-wm2x-9fx6-qgf6.json new file mode 100644 index 00000000000..4297995362e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wm2x-9fx6-qgf6/GHSA-wm2x-9fx6-qgf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm2x-9fx6-qgf6", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23798" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliott Robson Mass Messaging in BuddyPress allows Reflected XSS. This issue affects Mass Messaging in BuddyPress: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mass-messaging-in-buddypress/vulnerability/wordpress-mass-messaging-in-buddypress-plugin-2-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wm3f-xqqj-vggp/GHSA-wm3f-xqqj-vggp.json b/advisories/unreviewed/2025/01/GHSA-wm3f-xqqj-vggp/GHSA-wm3f-xqqj-vggp.json new file mode 100644 index 00000000000..f2040a1c875 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wm3f-xqqj-vggp/GHSA-wm3f-xqqj-vggp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm3f-xqqj-vggp", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bilal TAS Responsivity allows Reflected XSS. This issue affects Responsivity: from n/a through 0.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsivity/vulnerability/wordpress-responsivity-plugin-0-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wp44-pvxx-4qfw/GHSA-wp44-pvxx-4qfw.json b/advisories/unreviewed/2025/01/GHSA-wp44-pvxx-4qfw/GHSA-wp44-pvxx-4qfw.json new file mode 100644 index 00000000000..9a22e4a2ad6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wp44-pvxx-4qfw/GHSA-wp44-pvxx-4qfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp44-pvxx-4qfw", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23674" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bit.ly linker allows Reflected XSS. This issue affects Bit.ly linker: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23674" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bitly-linker/vulnerability/wordpress-bit-ly-linker-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wq35-6cg9-m5mj/GHSA-wq35-6cg9-m5mj.json b/advisories/unreviewed/2025/01/GHSA-wq35-6cg9-m5mj/GHSA-wq35-6cg9-m5mj.json new file mode 100644 index 00000000000..eab0440ff23 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wq35-6cg9-m5mj/GHSA-wq35-6cg9-m5mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq35-6cg9-m5mj", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23948" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebArea Background animation blocks allows PHP Local File Inclusion. This issue affects Background animation blocks: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23948" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/background-animation-blocks/vulnerability/wordpress-background-animation-blocks-plugin-2-1-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wrhm-vqgx-q8p6/GHSA-wrhm-vqgx-q8p6.json b/advisories/unreviewed/2025/01/GHSA-wrhm-vqgx-q8p6/GHSA-wrhm-vqgx-q8p6.json index e7a4d2f4627..c3f1d1a5fa2 100644 --- a/advisories/unreviewed/2025/01/GHSA-wrhm-vqgx-q8p6/GHSA-wrhm-vqgx-q8p6.json +++ b/advisories/unreviewed/2025/01/GHSA-wrhm-vqgx-q8p6/GHSA-wrhm-vqgx-q8p6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wrhm-vqgx-q8p6", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49738" ], "details": "In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x22m-7748-229x/GHSA-x22m-7748-229x.json b/advisories/unreviewed/2025/01/GHSA-x22m-7748-229x/GHSA-x22m-7748-229x.json index e22af970fde..3aebe3c06c8 100644 --- a/advisories/unreviewed/2025/01/GHSA-x22m-7748-229x/GHSA-x22m-7748-229x.json +++ b/advisories/unreviewed/2025/01/GHSA-x22m-7748-229x/GHSA-x22m-7748-229x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x22m-7748-229x", - "modified": "2025-01-22T00:33:38Z", + "modified": "2025-01-22T15:32:34Z", "published": "2025-01-22T00:33:38Z", "aliases": [ "CVE-2024-49744" ], "details": "In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T23:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x39p-jxrw-mp33/GHSA-x39p-jxrw-mp33.json b/advisories/unreviewed/2025/01/GHSA-x39p-jxrw-mp33/GHSA-x39p-jxrw-mp33.json new file mode 100644 index 00000000000..53e9099df07 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x39p-jxrw-mp33/GHSA-x39p-jxrw-mp33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x39p-jxrw-mp33", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23682" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Preloader Quotes allows Reflected XSS. This issue affects Preloader Quotes: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23682" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/preloader-quotes/vulnerability/wordpress-preloader-quotes-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x6x7-wx46-gh2c/GHSA-x6x7-wx46-gh2c.json b/advisories/unreviewed/2025/01/GHSA-x6x7-wx46-gh2c/GHSA-x6x7-wx46-gh2c.json new file mode 100644 index 00000000000..d8c9eed3acd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x6x7-wx46-gh2c/GHSA-x6x7-wx46-gh2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6x7-wx46-gh2c", + "modified": "2025-01-22T15:32:37Z", + "published": "2025-01-22T15:32:37Z", + "aliases": [ + "CVE-2025-23921" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Multi Uploader for Gravity Forms allows Upload a Web Shell to a Web Server. This issue affects Multi Uploader for Gravity Forms: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23921" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gf-multi-uploader/vulnerability/wordpress-multi-uploader-for-gravity-forms-plugin-1-1-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json b/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json new file mode 100644 index 00000000000..a91ab92a4a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x76x-v36q-wqrf/GHSA-x76x-v36q-wqrf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x76x-v36q-wqrf", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37005" + ], + "details": "Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37005" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7pq-2j3f-24rv/GHSA-x7pq-2j3f-24rv.json b/advisories/unreviewed/2025/01/GHSA-x7pq-2j3f-24rv/GHSA-x7pq-2j3f-24rv.json new file mode 100644 index 00000000000..cf59643569f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x7pq-2j3f-24rv/GHSA-x7pq-2j3f-24rv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7pq-2j3f-24rv", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2023-37023" + ], + "details": "Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37023" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xcp6-3jg8-q26g/GHSA-xcp6-3jg8-q26g.json b/advisories/unreviewed/2025/01/GHSA-xcp6-3jg8-q26g/GHSA-xcp6-3jg8-q26g.json new file mode 100644 index 00000000000..23758ae818f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xcp6-3jg8-q26g/GHSA-xcp6-3jg8-q26g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcp6-3jg8-q26g", + "modified": "2025-01-22T15:32:35Z", + "published": "2025-01-22T15:32:35Z", + "aliases": [ + "CVE-2025-23495" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WooCommerce Order Search allows Reflected XSS. This issue affects WooCommerce Order Search: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23495" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-order-searching/vulnerability/wordpress-woocommerce-order-search-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xfgj-h6r5-fqg7/GHSA-xfgj-h6r5-fqg7.json b/advisories/unreviewed/2025/01/GHSA-xfgj-h6r5-fqg7/GHSA-xfgj-h6r5-fqg7.json new file mode 100644 index 00000000000..20ddd578943 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xfgj-h6r5-fqg7/GHSA-xfgj-h6r5-fqg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfgj-h6r5-fqg7", + "modified": "2025-01-22T15:32:36Z", + "published": "2025-01-22T15:32:36Z", + "aliases": [ + "CVE-2025-23695" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CtyGrid Hyp3rL0cal Search allows Reflected XSS. This issue affects CtyGrid Hyp3rL0cal Search: from n/a through 0.1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23695" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hyp3rl0cal-city-search/vulnerability/wordpress-ctygrid-hyp3rl0cal-search-plugin-0-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xh3r-5ccq-fg8p/GHSA-xh3r-5ccq-fg8p.json b/advisories/unreviewed/2025/01/GHSA-xh3r-5ccq-fg8p/GHSA-xh3r-5ccq-fg8p.json new file mode 100644 index 00000000000..8da5019a52a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xh3r-5ccq-fg8p/GHSA-xh3r-5ccq-fg8p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh3r-5ccq-fg8p", + "modified": "2025-01-22T15:32:34Z", + "published": "2025-01-22T15:32:34Z", + "aliases": [ + "CVE-2023-37008" + ], + "details": "Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37008" + }, + { + "type": "WEB", + "url": "https://cellularsecurity.org/ransacked" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-22T15:15:10Z" + } +} \ No newline at end of file