diff --git a/advisories/github-reviewed/2021/11/GHSA-896r-f27r-55mw/GHSA-896r-f27r-55mw.json b/advisories/github-reviewed/2021/11/GHSA-896r-f27r-55mw/GHSA-896r-f27r-55mw.json index 8f72e087f34..61a87df4a1a 100644 --- a/advisories/github-reviewed/2021/11/GHSA-896r-f27r-55mw/GHSA-896r-f27r-55mw.json +++ b/advisories/github-reviewed/2021/11/GHSA-896r-f27r-55mw/GHSA-896r-f27r-55mw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-896r-f27r-55mw", - "modified": "2022-08-10T23:36:10Z", + "modified": "2025-01-17T21:31:38Z", "published": "2021-11-19T20:16:17Z", "aliases": [ "CVE-2021-3918" @@ -68,6 +68,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00013.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0004" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json b/advisories/github-reviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json index 84f47c23777..7810dbaf864 100644 --- a/advisories/github-reviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json +++ b/advisories/github-reviewed/2024/02/GHSA-h24r-m9qc-pvpg/GHSA-h24r-m9qc-pvpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h24r-m9qc-pvpg", - "modified": "2024-05-22T18:30:39Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-02-06T12:30:31Z", "aliases": [ "CVE-2024-0690" @@ -125,6 +125,10 @@ { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible-core/PYSEC-2024-36.yaml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0001" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/04/GHSA-6qmx-42h2-j8h6/GHSA-6qmx-42h2-j8h6.json b/advisories/github-reviewed/2024/04/GHSA-6qmx-42h2-j8h6/GHSA-6qmx-42h2-j8h6.json index 0ea1b5f97c8..99ff2ec249c 100644 --- a/advisories/github-reviewed/2024/04/GHSA-6qmx-42h2-j8h6/GHSA-6qmx-42h2-j8h6.json +++ b/advisories/github-reviewed/2024/04/GHSA-6qmx-42h2-j8h6/GHSA-6qmx-42h2-j8h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6qmx-42h2-j8h6", - "modified": "2024-09-24T19:53:15Z", + "modified": "2025-01-17T21:31:39Z", "published": "2024-04-17T18:21:57Z", "aliases": [ "CVE-2024-21409" @@ -230,6 +230,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21409" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0002" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json b/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json index d8f74afe41b..364b0c6679e 100644 --- a/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json +++ b/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2p57-rm9w-gvfp", - "modified": "2024-09-03T19:59:01Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-06-02T22:29:29Z", "aliases": [ "CVE-2024-29415" @@ -55,6 +55,10 @@ { "type": "PACKAGE", "url": "https://github.com/indutny/node-ip" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0010" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/07/GHSA-4xqq-m2hx-25v8/GHSA-4xqq-m2hx-25v8.json b/advisories/github-reviewed/2024/07/GHSA-4xqq-m2hx-25v8/GHSA-4xqq-m2hx-25v8.json index 3c5340eb35e..90e6dd0196b 100644 --- a/advisories/github-reviewed/2024/07/GHSA-4xqq-m2hx-25v8/GHSA-4xqq-m2hx-25v8.json +++ b/advisories/github-reviewed/2024/07/GHSA-4xqq-m2hx-25v8/GHSA-4xqq-m2hx-25v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xqq-m2hx-25v8", - "modified": "2024-07-16T19:49:15Z", + "modified": "2025-01-17T21:31:39Z", "published": "2024-07-16T19:49:15Z", "aliases": [ "CVE-2024-39908" @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-39908.yml" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0008" + }, { "type": "WEB", "url": "https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908" diff --git a/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json b/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json index 592f097dd89..2d2afd1c175 100644 --- a/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json +++ b/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5866-49gr-22v4", - "modified": "2024-09-05T18:38:47Z", + "modified": "2025-01-17T21:31:39Z", "published": "2024-08-02T12:33:15Z", "aliases": [ "CVE-2024-41946" @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rexml/CVE-2024-41946.yml" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0007" + }, { "type": "WEB", "url": "https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml" diff --git a/advisories/github-reviewed/2024/08/GHSA-7cj3-x93g-gj76/GHSA-7cj3-x93g-gj76.json b/advisories/github-reviewed/2024/08/GHSA-7cj3-x93g-gj76/GHSA-7cj3-x93g-gj76.json index e50adc9b8be..e04143d618c 100644 --- a/advisories/github-reviewed/2024/08/GHSA-7cj3-x93g-gj76/GHSA-7cj3-x93g-gj76.json +++ b/advisories/github-reviewed/2024/08/GHSA-7cj3-x93g-gj76/GHSA-7cj3-x93g-gj76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cj3-x93g-gj76", - "modified": "2024-11-18T16:27:07Z", + "modified": "2025-01-17T21:31:39Z", "published": "2024-08-23T09:30:35Z", "aliases": [ "CVE-2024-38807" @@ -249,6 +249,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-boot" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0006" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-38807" diff --git a/advisories/unreviewed/2022/05/GHSA-7w6v-23gr-722w/GHSA-7w6v-23gr-722w.json b/advisories/unreviewed/2022/05/GHSA-7w6v-23gr-722w/GHSA-7w6v-23gr-722w.json index f061d49d2f7..293b86711a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w6v-23gr-722w/GHSA-7w6v-23gr-722w.json +++ b/advisories/unreviewed/2022/05/GHSA-7w6v-23gr-722w/GHSA-7w6v-23gr-722w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w6v-23gr-722w", - "modified": "2022-05-14T01:02:19Z", + "modified": "2025-01-17T21:31:35Z", "published": "2022-05-14T01:02:19Z", "aliases": [ "CVE-2015-2426" diff --git a/advisories/unreviewed/2023/01/GHSA-3j5g-pgw8-92vr/GHSA-3j5g-pgw8-92vr.json b/advisories/unreviewed/2023/01/GHSA-3j5g-pgw8-92vr/GHSA-3j5g-pgw8-92vr.json index e5719eb8d6d..032812b49e4 100644 --- a/advisories/unreviewed/2023/01/GHSA-3j5g-pgw8-92vr/GHSA-3j5g-pgw8-92vr.json +++ b/advisories/unreviewed/2023/01/GHSA-3j5g-pgw8-92vr/GHSA-3j5g-pgw8-92vr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3j5g-pgw8-92vr", - "modified": "2023-01-10T21:30:33Z", + "modified": "2025-01-17T21:31:38Z", "published": "2023-01-04T18:31:00Z", "aliases": [ "CVE-2023-0049" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://huntr.dev/bounties/5e6f325c-ba54-4bf0-b050-dca048fd3fd9" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3Y752EAVACVC5XY2TMGGOAIU25VQRPDW" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T33LLWHLH63XDCO5OME7NWN63RA4U5HF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3Y752EAVACVC5XY2TMGGOAIU25VQRPDW" @@ -39,6 +47,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202305-16" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0005" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT213670" diff --git a/advisories/unreviewed/2023/12/GHSA-g7mg-4vgp-5j3h/GHSA-g7mg-4vgp-5j3h.json b/advisories/unreviewed/2023/12/GHSA-g7mg-4vgp-5j3h/GHSA-g7mg-4vgp-5j3h.json index 82aba889f40..37b2150d80e 100644 --- a/advisories/unreviewed/2023/12/GHSA-g7mg-4vgp-5j3h/GHSA-g7mg-4vgp-5j3h.json +++ b/advisories/unreviewed/2023/12/GHSA-g7mg-4vgp-5j3h/GHSA-g7mg-4vgp-5j3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g7mg-4vgp-5j3h", - "modified": "2024-06-11T06:31:46Z", + "modified": "2025-01-17T21:31:38Z", "published": "2023-12-07T06:30:20Z", "aliases": [ "CVE-2023-41913" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPJZPYHBCRXUQGGKQE6TYH4J4RIJH6HO" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0003" + }, { "type": "WEB", "url": "https://www.strongswan.org/blog/2023/11/20/strongswan-vulnerability-%28cve-2023-41913%29.html" diff --git a/advisories/unreviewed/2024/02/GHSA-23gm-fr88-2r8c/GHSA-23gm-fr88-2r8c.json b/advisories/unreviewed/2024/02/GHSA-23gm-fr88-2r8c/GHSA-23gm-fr88-2r8c.json index 7f07b3cbae1..0e96e80d7cb 100644 --- a/advisories/unreviewed/2024/02/GHSA-23gm-fr88-2r8c/GHSA-23gm-fr88-2r8c.json +++ b/advisories/unreviewed/2024/02/GHSA-23gm-fr88-2r8c/GHSA-23gm-fr88-2r8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23gm-fr88-2r8c", - "modified": "2024-06-26T00:31:34Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-02-20T18:30:34Z", "aliases": [ "CVE-2023-52434" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250117-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-3gm7-x7gh-qcvp/GHSA-3gm7-x7gh-qcvp.json b/advisories/unreviewed/2024/03/GHSA-3gm7-x7gh-qcvp/GHSA-3gm7-x7gh-qcvp.json index 3693614d079..44fcd8c20df 100644 --- a/advisories/unreviewed/2024/03/GHSA-3gm7-x7gh-qcvp/GHSA-3gm7-x7gh-qcvp.json +++ b/advisories/unreviewed/2024/03/GHSA-3gm7-x7gh-qcvp/GHSA-3gm7-x7gh-qcvp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gm7-x7gh-qcvp", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1391" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4844-58hp-rqwx/GHSA-4844-58hp-rqwx.json b/advisories/unreviewed/2024/03/GHSA-4844-58hp-rqwx/GHSA-4844-58hp-rqwx.json index 67cdeec1d0a..d9a1bd02496 100644 --- a/advisories/unreviewed/2024/03/GHSA-4844-58hp-rqwx/GHSA-4844-58hp-rqwx.json +++ b/advisories/unreviewed/2024/03/GHSA-4844-58hp-rqwx/GHSA-4844-58hp-rqwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4844-58hp-rqwx", - "modified": "2024-03-14T00:31:06Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-03-14T00:31:06Z", "aliases": [ "CVE-2024-2242" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-7x5j-335w-jmw5/GHSA-7x5j-335w-jmw5.json b/advisories/unreviewed/2024/03/GHSA-7x5j-335w-jmw5/GHSA-7x5j-335w-jmw5.json index db9f9fc747f..762a02e0715 100644 --- a/advisories/unreviewed/2024/03/GHSA-7x5j-335w-jmw5/GHSA-7x5j-335w-jmw5.json +++ b/advisories/unreviewed/2024/03/GHSA-7x5j-335w-jmw5/GHSA-7x5j-335w-jmw5.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8m74-m7qg-gjxr/GHSA-8m74-m7qg-gjxr.json b/advisories/unreviewed/2024/03/GHSA-8m74-m7qg-gjxr/GHSA-8m74-m7qg-gjxr.json index 9d3901c23ec..441b35031ff 100644 --- a/advisories/unreviewed/2024/03/GHSA-8m74-m7qg-gjxr/GHSA-8m74-m7qg-gjxr.json +++ b/advisories/unreviewed/2024/03/GHSA-8m74-m7qg-gjxr/GHSA-8m74-m7qg-gjxr.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json b/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json index a7775a82722..8cd9f652225 100644 --- a/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json +++ b/advisories/unreviewed/2024/03/GHSA-9742-f8rf-87v4/GHSA-9742-f8rf-87v4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json b/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json index e42239e5bc4..63b238bd258 100644 --- a/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json +++ b/advisories/unreviewed/2024/03/GHSA-jvmw-753q-r77g/GHSA-jvmw-753q-r77g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json b/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json index 514090c53c6..0f8e867d410 100644 --- a/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json +++ b/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-v96h-qjwq-7qp6/GHSA-v96h-qjwq-7qp6.json b/advisories/unreviewed/2024/03/GHSA-v96h-qjwq-7qp6/GHSA-v96h-qjwq-7qp6.json index c095d6eadd5..42b547258c8 100644 --- a/advisories/unreviewed/2024/03/GHSA-v96h-qjwq-7qp6/GHSA-v96h-qjwq-7qp6.json +++ b/advisories/unreviewed/2024/03/GHSA-v96h-qjwq-7qp6/GHSA-v96h-qjwq-7qp6.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wgq3-32f4-m87w/GHSA-wgq3-32f4-m87w.json b/advisories/unreviewed/2024/03/GHSA-wgq3-32f4-m87w/GHSA-wgq3-32f4-m87w.json index fc68b47de03..06e225ada8f 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgq3-32f4-m87w/GHSA-wgq3-32f4-m87w.json +++ b/advisories/unreviewed/2024/03/GHSA-wgq3-32f4-m87w/GHSA-wgq3-32f4-m87w.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json b/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json index 52335b7ee29..d805b128b87 100644 --- a/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json +++ b/advisories/unreviewed/2024/04/GHSA-33m3-hvgx-q2v6/GHSA-33m3-hvgx-q2v6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-33m3-hvgx-q2v6", - "modified": "2024-04-09T21:31:59Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-04-09T21:31:59Z", "aliases": [ "CVE-2024-1990" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json b/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json index efcf568ee03..a8002bb8a32 100644 --- a/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json +++ b/advisories/unreviewed/2024/04/GHSA-7p7p-r9pc-pcmf/GHSA-7p7p-r9pc-pcmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p7p-r9pc-pcmf", - "modified": "2024-04-09T21:31:56Z", + "modified": "2025-01-17T21:31:38Z", "published": "2024-04-09T21:31:56Z", "aliases": [ "CVE-2024-0588" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json b/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json index 8c755d549a1..6fa39b07f86 100644 --- a/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json +++ b/advisories/unreviewed/2024/04/GHSA-82x8-6g4h-h5w3/GHSA-82x8-6g4h-h5w3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json b/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json index cbda3b03b65..4bb2c876ffc 100644 --- a/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json +++ b/advisories/unreviewed/2024/04/GHSA-9jc6-4356-gcv5/GHSA-9jc6-4356-gcv5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qxj9-r243-8955/GHSA-qxj9-r243-8955.json b/advisories/unreviewed/2024/04/GHSA-qxj9-r243-8955/GHSA-qxj9-r243-8955.json index 4769e45dc50..f659c97630f 100644 --- a/advisories/unreviewed/2024/04/GHSA-qxj9-r243-8955/GHSA-qxj9-r243-8955.json +++ b/advisories/unreviewed/2024/04/GHSA-qxj9-r243-8955/GHSA-qxj9-r243-8955.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json b/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json index 50f39734a91..586ae0af849 100644 --- a/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json +++ b/advisories/unreviewed/2024/04/GHSA-wjmr-v62x-4f45/GHSA-wjmr-v62x-4f45.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json b/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json index c0166d7dc30..7e425acd6b5 100644 --- a/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json +++ b/advisories/unreviewed/2024/11/GHSA-99w5-q9j7-6pjv/GHSA-99w5-q9j7-6pjv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-267" + "CWE-267", + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json b/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json index 77cc6279161..071c5b85411 100644 --- a/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json +++ b/advisories/unreviewed/2024/11/GHSA-jcjw-frm7-94f5/GHSA-jcjw-frm7-94f5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json b/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json index f4bdf2e93a9..3c44cbaabc8 100644 --- a/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json +++ b/advisories/unreviewed/2024/11/GHSA-pjmr-ff79-h6xp/GHSA-pjmr-ff79-h6xp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json b/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json index 23c0d57f3f6..eff3d5cc297 100644 --- a/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json +++ b/advisories/unreviewed/2024/11/GHSA-wp5x-8wxv-j7j2/GHSA-wp5x-8wxv-j7j2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-267" + "CWE-267", + "CWE-426" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-4hpg-vxh4-jm69/GHSA-4hpg-vxh4-jm69.json b/advisories/unreviewed/2024/12/GHSA-4hpg-vxh4-jm69/GHSA-4hpg-vxh4-jm69.json index 8ce07098750..75277c18071 100644 --- a/advisories/unreviewed/2024/12/GHSA-4hpg-vxh4-jm69/GHSA-4hpg-vxh4-jm69.json +++ b/advisories/unreviewed/2024/12/GHSA-4hpg-vxh4-jm69/GHSA-4hpg-vxh4-jm69.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-2235-g2f2-vp6c/GHSA-2235-g2f2-vp6c.json b/advisories/unreviewed/2025/01/GHSA-2235-g2f2-vp6c/GHSA-2235-g2f2-vp6c.json index f9eea868226..1d8d332e3b6 100644 --- a/advisories/unreviewed/2025/01/GHSA-2235-g2f2-vp6c/GHSA-2235-g2f2-vp6c.json +++ b/advisories/unreviewed/2025/01/GHSA-2235-g2f2-vp6c/GHSA-2235-g2f2-vp6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2235-g2f2-vp6c", - "modified": "2025-01-08T06:30:54Z", + "modified": "2025-01-17T21:31:39Z", "published": "2025-01-08T06:30:54Z", "aliases": [ "CVE-2024-11916" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json b/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json new file mode 100644 index 00000000000..b36b9fa6fce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3723-f7xr-2xgj", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57032" + ], + "details": "WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57032" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/blob/main/CVE-2024-57032" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json b/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json new file mode 100644 index 00000000000..7fc4e07578f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m2r-43mh-wr82", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2025-0534" + ], + "details": "A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0534" + }, + { + "type": "WEB", + "url": "https://github.com/onupset/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.292418" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.292418" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.479128" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4p2h-h982-8v2v/GHSA-4p2h-h982-8v2v.json b/advisories/unreviewed/2025/01/GHSA-4p2h-h982-8v2v/GHSA-4p2h-h982-8v2v.json new file mode 100644 index 00000000000..7a275187592 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4p2h-h982-8v2v/GHSA-4p2h-h982-8v2v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p2h-h982-8v2v", + "modified": "2025-01-17T21:31:40Z", + "published": "2025-01-17T21:31:40Z", + "aliases": [ + "CVE-2025-0538" + ], + "details": "A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation of the argument pgedetails leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0538" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/aaryan-11-x/My-CVEs/blob/main/Stored%20XSS%20-%20Code-Projects%20Tourism%20Management%20System%201.0.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.292422" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.292422" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.479895" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-56mc-fpwx-p947/GHSA-56mc-fpwx-p947.json b/advisories/unreviewed/2025/01/GHSA-56mc-fpwx-p947/GHSA-56mc-fpwx-p947.json new file mode 100644 index 00000000000..1d6ee21d3d4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-56mc-fpwx-p947/GHSA-56mc-fpwx-p947.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56mc-fpwx-p947", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2023-50738" + ], + "details": "A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to \noverride this downgrade protection has been identified.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50738" + }, + { + "type": "WEB", + "url": "https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-354" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5m78-3xp9-gmjm/GHSA-5m78-3xp9-gmjm.json b/advisories/unreviewed/2025/01/GHSA-5m78-3xp9-gmjm/GHSA-5m78-3xp9-gmjm.json new file mode 100644 index 00000000000..aa2e08664ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5m78-3xp9-gmjm/GHSA-5m78-3xp9-gmjm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m78-3xp9-gmjm", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57372" + ], + "details": "Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57372" + }, + { + "type": "WEB", + "url": "https://github.com/kaixin1995" + }, + { + "type": "WEB", + "url": "https://github.com/kaixin1995/InformationPush" + }, + { + "type": "WEB", + "url": "https://royblume.github.io/CVE-2024-57372" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6q3f-jmwm-286h/GHSA-6q3f-jmwm-286h.json b/advisories/unreviewed/2025/01/GHSA-6q3f-jmwm-286h/GHSA-6q3f-jmwm-286h.json new file mode 100644 index 00000000000..e817f86076e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6q3f-jmwm-286h/GHSA-6q3f-jmwm-286h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q3f-jmwm-286h", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57030" + ], + "details": "Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57030" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-57030" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json b/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json new file mode 100644 index 00000000000..54b6f10d0fc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-78xr-cmr3-fxq9/GHSA-78xr-cmr3-fxq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78xr-cmr3-fxq9", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2025-21399" + ], + "details": "Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21399" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21399" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-273" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-924c-vmpj-6rfg/GHSA-924c-vmpj-6rfg.json b/advisories/unreviewed/2025/01/GHSA-924c-vmpj-6rfg/GHSA-924c-vmpj-6rfg.json index a62c70f0ed6..3e9ab40d6b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-924c-vmpj-6rfg/GHSA-924c-vmpj-6rfg.json +++ b/advisories/unreviewed/2025/01/GHSA-924c-vmpj-6rfg/GHSA-924c-vmpj-6rfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-924c-vmpj-6rfg", - "modified": "2025-01-08T06:30:55Z", + "modified": "2025-01-17T21:31:39Z", "published": "2025-01-08T06:30:55Z", "aliases": [ "CVE-2024-11271" diff --git a/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json b/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json index a86b3bcecc8..3d6d4b60b12 100644 --- a/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json +++ b/advisories/unreviewed/2025/01/GHSA-fm3m-9484-8h7w/GHSA-fm3m-9484-8h7w.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json b/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json new file mode 100644 index 00000000000..41074cd5ce9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpv2-wmww-mxc8", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57031" + ], + "details": "WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57031" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-57031" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json b/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json new file mode 100644 index 00000000000..2d250c798e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv6j-x52x-7r32", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57035" + ], + "details": "WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57035" + }, + { + "type": "WEB", + "url": "https://github.com/nilsonLazarin/WeGIA/issues/827" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-57035" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g7wc-qp54-cppx/GHSA-g7wc-qp54-cppx.json b/advisories/unreviewed/2025/01/GHSA-g7wc-qp54-cppx/GHSA-g7wc-qp54-cppx.json new file mode 100644 index 00000000000..b65c66843e6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g7wc-qp54-cppx/GHSA-g7wc-qp54-cppx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7wc-qp54-cppx", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2025-0537" + ], + "details": "A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0537" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/aaryan-11-x/My-CVEs/blob/main/Stored%20XSS%20-%20Code-Projects%20Online%20Car%20Rental%20System%201.0.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.292421" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.292421" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.479864" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json b/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json new file mode 100644 index 00000000000..c48f13d17c4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp5f-6cr8-73qf", + "modified": "2025-01-17T21:31:40Z", + "published": "2025-01-17T21:31:40Z", + "aliases": [ + "CVE-2025-0540" + ], + "details": "A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The manipulation of the argument expcat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0540" + }, + { + "type": "WEB", + "url": "https://github.com/magic2353112890/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.292432" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.292432" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hp44-v4vf-23fq/GHSA-hp44-v4vf-23fq.json b/advisories/unreviewed/2025/01/GHSA-hp44-v4vf-23fq/GHSA-hp44-v4vf-23fq.json new file mode 100644 index 00000000000..a592d5ccc83 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hp44-v4vf-23fq/GHSA-hp44-v4vf-23fq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp44-v4vf-23fq", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-52870" + ], + "details": "Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52870" + }, + { + "type": "WEB", + "url": "https://chrismanson.com/CVE/cve-2024-52870.html" + }, + { + "type": "WEB", + "url": "https://www.teradata.com/trust-security-center/data-security" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json b/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json new file mode 100644 index 00000000000..357b7237efc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx65-9q68-4gq8", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2025-0536" + ], + "details": "A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0536" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/lan041221/cve/blob/main/Attendance_Tracking_Management_System_SQL_Injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.292420" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.292420" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.479251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json b/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json new file mode 100644 index 00000000000..da3f2c95bed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jqpc-q3rg-3f4f/GHSA-jqpc-q3rg-3f4f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqpc-q3rg-3f4f", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57369" + ], + "details": "Clickjacking vulnerability in typecho v1.2.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57369" + }, + { + "type": "WEB", + "url": "https://github.com/typecho/typecho" + }, + { + "type": "WEB", + "url": "https://royblume.github.io/CVE-2024-57369" + }, + { + "type": "WEB", + "url": "https://typecho.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mvrq-wf2x-8c9p/GHSA-mvrq-wf2x-8c9p.json b/advisories/unreviewed/2025/01/GHSA-mvrq-wf2x-8c9p/GHSA-mvrq-wf2x-8c9p.json new file mode 100644 index 00000000000..116806607aa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mvrq-wf2x-8c9p/GHSA-mvrq-wf2x-8c9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvrq-wf2x-8c9p", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-13026" + ], + "details": "A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:L/U:Clear" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13026" + }, + { + "type": "WEB", + "url": "https://diagnostics.roche.com/content/dam/diagnostics/Blueprint/en/pdf/Algo%20Edge%20-%20Authentication%20Vulnerability%20-%20Product%20Security%20Advisory.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json b/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json new file mode 100644 index 00000000000..d9cf5e6627f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p6qw-j3rw-2577/GHSA-p6qw-j3rw-2577.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6qw-j3rw-2577", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57370" + ], + "details": "Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57370" + }, + { + "type": "WEB", + "url": "https://github.com/sunnygkp10/Online-Exam-System" + }, + { + "type": "WEB", + "url": "https://royblume.github.io/CVE-2024-57370" + }, + { + "type": "WEB", + "url": "http://sunnygkp10.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json b/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json index f5984d2f7df..145d8f232fe 100644 --- a/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json +++ b/advisories/unreviewed/2025/01/GHSA-prrw-fgg2-wvfg/GHSA-prrw-fgg2-wvfg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json b/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json new file mode 100644 index 00000000000..89adf62de28 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4cc-rq78-hxf8", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57034" + ], + "details": "WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57034" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-57034" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rx9q-hw8f-rvr7/GHSA-rx9q-hw8f-rvr7.json b/advisories/unreviewed/2025/01/GHSA-rx9q-hw8f-rvr7/GHSA-rx9q-hw8f-rvr7.json new file mode 100644 index 00000000000..c24bc869aa4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rx9q-hw8f-rvr7/GHSA-rx9q-hw8f-rvr7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx9q-hw8f-rvr7", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57033" + ], + "details": "WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57033" + }, + { + "type": "WEB", + "url": "https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-57033" + }, + { + "type": "WEB", + "url": "https://www.wegia.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json b/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json new file mode 100644 index 00000000000..6cc6ab29ace --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v5j2-wgv7-q2cg/GHSA-v5j2-wgv7-q2cg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5j2-wgv7-q2cg", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2025-0535" + ], + "details": "A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0535" + }, + { + "type": "WEB", + "url": "https://github.com/lan041221/cve/blob/main/SQL_Injection_in_Gym_Management_System.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.292419" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.292419" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.479159" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T19:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v623-92c3-f29p/GHSA-v623-92c3-f29p.json b/advisories/unreviewed/2025/01/GHSA-v623-92c3-f29p/GHSA-v623-92c3-f29p.json new file mode 100644 index 00000000000..ef3051d28da --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v623-92c3-f29p/GHSA-v623-92c3-f29p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v623-92c3-f29p", + "modified": "2025-01-17T21:31:40Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2024-57252" + ], + "details": "OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57252" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/CVE-2024-57252" + }, + { + "type": "WEB", + "url": "https://github.com/J-0k3r/some/blob/main/ssrf.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vvqc-c7cm-52wp/GHSA-vvqc-c7cm-52wp.json b/advisories/unreviewed/2025/01/GHSA-vvqc-c7cm-52wp/GHSA-vvqc-c7cm-52wp.json new file mode 100644 index 00000000000..5988a6ea57a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vvqc-c7cm-52wp/GHSA-vvqc-c7cm-52wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqc-c7cm-52wp", + "modified": "2025-01-17T21:31:39Z", + "published": "2025-01-17T21:31:39Z", + "aliases": [ + "CVE-2025-21185" + ], + "details": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21185" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-17T20:15:30Z" + } +} \ No newline at end of file