diff --git a/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json b/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json index eda813b7026..6eac7f4acaa 100644 --- a/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json +++ b/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f48j-vwm8-858j", - "modified": "2025-01-08T00:30:49Z", + "modified": "2025-02-11T03:30:54Z", "published": "2025-01-06T21:30:51Z", "aliases": [ "CVE-2024-55408" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -23,13 +27,19 @@ "type": "WEB", "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55408/CVE-2024-55408_AsusSAIO.sys_README.md" }, + { + "type": "WEB", + "url": "https://www.asus.com/tw/support/myasus-deeplink" + }, { "type": "WEB", "url": "http://asus.com" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-224x-44xc-3gcf/GHSA-224x-44xc-3gcf.json b/advisories/unreviewed/2025/02/GHSA-224x-44xc-3gcf/GHSA-224x-44xc-3gcf.json new file mode 100644 index 00000000000..767ae85ebf0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-224x-44xc-3gcf/GHSA-224x-44xc-3gcf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-224x-44xc-3gcf", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-7393" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7393" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-22gv-43vq-fhjw/GHSA-22gv-43vq-fhjw.json b/advisories/unreviewed/2025/02/GHSA-22gv-43vq-fhjw/GHSA-22gv-43vq-fhjw.json new file mode 100644 index 00000000000..390c709f279 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-22gv-43vq-fhjw/GHSA-22gv-43vq-fhjw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22gv-43vq-fhjw", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-23187" + ], + "details": "Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23187" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3546470" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-22v4-3qpp-69q8/GHSA-22v4-3qpp-69q8.json b/advisories/unreviewed/2025/02/GHSA-22v4-3qpp-69q8/GHSA-22v4-3qpp-69q8.json new file mode 100644 index 00000000000..a5a946a419d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-22v4-3qpp-69q8/GHSA-22v4-3qpp-69q8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22v4-3qpp-69q8", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9196" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9196" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2c76-qm2v-h37j/GHSA-2c76-qm2v-h37j.json b/advisories/unreviewed/2025/02/GHSA-2c76-qm2v-h37j/GHSA-2c76-qm2v-h37j.json new file mode 100644 index 00000000000..c224d2ff786 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2c76-qm2v-h37j/GHSA-2c76-qm2v-h37j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c76-qm2v-h37j", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2025-25243" + ], + "details": "SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25243" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3567551" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2chh-8jf9-q8fm/GHSA-2chh-8jf9-q8fm.json b/advisories/unreviewed/2025/02/GHSA-2chh-8jf9-q8fm/GHSA-2chh-8jf9-q8fm.json new file mode 100644 index 00000000000..721234765cd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2chh-8jf9-q8fm/GHSA-2chh-8jf9-q8fm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2chh-8jf9-q8fm", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-5146" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5146" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2f4j-c232-x8x2/GHSA-2f4j-c232-x8x2.json b/advisories/unreviewed/2025/02/GHSA-2f4j-c232-x8x2/GHSA-2f4j-c232-x8x2.json new file mode 100644 index 00000000000..c720fd4a25a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2f4j-c232-x8x2/GHSA-2f4j-c232-x8x2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f4j-c232-x8x2", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9010" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9010" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-32w6-xw3w-3qh3/GHSA-32w6-xw3w-3qh3.json b/advisories/unreviewed/2025/02/GHSA-32w6-xw3w-3qh3/GHSA-32w6-xw3w-3qh3.json new file mode 100644 index 00000000000..0915b1ae3c6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-32w6-xw3w-3qh3/GHSA-32w6-xw3w-3qh3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32w6-xw3w-3qh3", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-10305" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10305" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3375-r84q-fqf2/GHSA-3375-r84q-fqf2.json b/advisories/unreviewed/2025/02/GHSA-3375-r84q-fqf2/GHSA-3375-r84q-fqf2.json new file mode 100644 index 00000000000..902c57f4d4b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3375-r84q-fqf2/GHSA-3375-r84q-fqf2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3375-r84q-fqf2", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2025-1169" + ], + "details": "A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The manipulation of the argument image leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1169" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295073" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295073" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494775" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-38j5-w774-x3rw/GHSA-38j5-w774-x3rw.json b/advisories/unreviewed/2025/02/GHSA-38j5-w774-x3rw/GHSA-38j5-w774-x3rw.json new file mode 100644 index 00000000000..f072978f216 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-38j5-w774-x3rw/GHSA-38j5-w774-x3rw.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38j5-w774-x3rw", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-4765" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4765" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3cv9-2r4x-c3c5/GHSA-3cv9-2r4x-c3c5.json b/advisories/unreviewed/2025/02/GHSA-3cv9-2r4x-c3c5/GHSA-3cv9-2r4x-c3c5.json new file mode 100644 index 00000000000..06673af3ae2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3cv9-2r4x-c3c5/GHSA-3cv9-2r4x-c3c5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cv9-2r4x-c3c5", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4276" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4276" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3gwj-3gp6-mvjv/GHSA-3gwj-3gp6-mvjv.json b/advisories/unreviewed/2025/02/GHSA-3gwj-3gp6-mvjv/GHSA-3gwj-3gp6-mvjv.json new file mode 100644 index 00000000000..89b30e7b09d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3gwj-3gp6-mvjv/GHSA-3gwj-3gp6-mvjv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gwj-3gp6-mvjv", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-3449" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3449" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3vpw-hprv-crm3/GHSA-3vpw-hprv-crm3.json b/advisories/unreviewed/2025/02/GHSA-3vpw-hprv-crm3/GHSA-3vpw-hprv-crm3.json new file mode 100644 index 00000000000..369ea584678 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3vpw-hprv-crm3/GHSA-3vpw-hprv-crm3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vpw-hprv-crm3", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-7880" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7880" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3w5w-f88w-pjxg/GHSA-3w5w-f88w-pjxg.json b/advisories/unreviewed/2025/02/GHSA-3w5w-f88w-pjxg/GHSA-3w5w-f88w-pjxg.json new file mode 100644 index 00000000000..24150083edc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3w5w-f88w-pjxg/GHSA-3w5w-f88w-pjxg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w5w-f88w-pjxg", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4880" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4880" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3x36-m92p-vv39/GHSA-3x36-m92p-vv39.json b/advisories/unreviewed/2025/02/GHSA-3x36-m92p-vv39/GHSA-3x36-m92p-vv39.json new file mode 100644 index 00000000000..7e4e77ee72b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3x36-m92p-vv39/GHSA-3x36-m92p-vv39.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x36-m92p-vv39", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-5164" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5164" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-46m2-8wh7-wq2m/GHSA-46m2-8wh7-wq2m.json b/advisories/unreviewed/2025/02/GHSA-46m2-8wh7-wq2m/GHSA-46m2-8wh7-wq2m.json new file mode 100644 index 00000000000..0ef70d5406c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-46m2-8wh7-wq2m/GHSA-46m2-8wh7-wq2m.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46m2-8wh7-wq2m", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2023-2238" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2238" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4g4p-rr9c-6r55/GHSA-4g4p-rr9c-6r55.json b/advisories/unreviewed/2025/02/GHSA-4g4p-rr9c-6r55/GHSA-4g4p-rr9c-6r55.json new file mode 100644 index 00000000000..e545a6d43ef --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4g4p-rr9c-6r55/GHSA-4g4p-rr9c-6r55.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g4p-rr9c-6r55", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-5308" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5308" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4g5c-r533-fvfw/GHSA-4g5c-r533-fvfw.json b/advisories/unreviewed/2025/02/GHSA-4g5c-r533-fvfw/GHSA-4g5c-r533-fvfw.json new file mode 100644 index 00000000000..f84376708c4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4g5c-r533-fvfw/GHSA-4g5c-r533-fvfw.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g5c-r533-fvfw", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-2114" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2114" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4jxq-w8rh-485r/GHSA-4jxq-w8rh-485r.json b/advisories/unreviewed/2025/02/GHSA-4jxq-w8rh-485r/GHSA-4jxq-w8rh-485r.json new file mode 100644 index 00000000000..4f6720f8c90 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4jxq-w8rh-485r/GHSA-4jxq-w8rh-485r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jxq-w8rh-485r", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2025-25241" + ], + "details": "Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25241" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3532025" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4xxh-23w4-wfr9/GHSA-4xxh-23w4-wfr9.json b/advisories/unreviewed/2025/02/GHSA-4xxh-23w4-wfr9/GHSA-4xxh-23w4-wfr9.json new file mode 100644 index 00000000000..6442aee8d4e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4xxh-23w4-wfr9/GHSA-4xxh-23w4-wfr9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xxh-23w4-wfr9", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-5850" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5850" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-545x-fpjg-j3cj/GHSA-545x-fpjg-j3cj.json b/advisories/unreviewed/2025/02/GHSA-545x-fpjg-j3cj/GHSA-545x-fpjg-j3cj.json new file mode 100644 index 00000000000..0b51946de99 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-545x-fpjg-j3cj/GHSA-545x-fpjg-j3cj.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-545x-fpjg-j3cj", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2023-1171" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1171" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5hch-xqwm-qw7j/GHSA-5hch-xqwm-qw7j.json b/advisories/unreviewed/2025/02/GHSA-5hch-xqwm-qw7j/GHSA-5hch-xqwm-qw7j.json new file mode 100644 index 00000000000..78ab54bd572 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5hch-xqwm-qw7j/GHSA-5hch-xqwm-qw7j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hch-xqwm-qw7j", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-24869" + ], + "details": "SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely SAP-internal as they are deployed with the server. In such a scenario, sensitive information could be exposed without compromising its integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24869" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3550027" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5pfx-h4jw-4x2c/GHSA-5pfx-h4jw-4x2c.json b/advisories/unreviewed/2025/02/GHSA-5pfx-h4jw-4x2c/GHSA-5pfx-h4jw-4x2c.json new file mode 100644 index 00000000000..ad8affa8725 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5pfx-h4jw-4x2c/GHSA-5pfx-h4jw-4x2c.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pfx-h4jw-4x2c", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12095" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12095" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-62m9-v7g3-w362/GHSA-62m9-v7g3-w362.json b/advisories/unreviewed/2025/02/GHSA-62m9-v7g3-w362/GHSA-62m9-v7g3-w362.json new file mode 100644 index 00000000000..b502e998947 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-62m9-v7g3-w362/GHSA-62m9-v7g3-w362.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62m9-v7g3-w362", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-23193" + ], + "details": "SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23193" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3561264" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-63gw-jq7m-3r99/GHSA-63gw-jq7m-3r99.json b/advisories/unreviewed/2025/02/GHSA-63gw-jq7m-3r99/GHSA-63gw-jq7m-3r99.json new file mode 100644 index 00000000000..7efc1fcba04 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-63gw-jq7m-3r99/GHSA-63gw-jq7m-3r99.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63gw-jq7m-3r99", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-10249" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10249" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6p5r-jjpf-g5xv/GHSA-6p5r-jjpf-g5xv.json b/advisories/unreviewed/2025/02/GHSA-6p5r-jjpf-g5xv/GHSA-6p5r-jjpf-g5xv.json new file mode 100644 index 00000000000..56f5796f94c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6p5r-jjpf-g5xv/GHSA-6p5r-jjpf-g5xv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p5r-jjpf-g5xv", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-24867" + ], + "details": "SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the link, the script will be executed in the browser, giving the attacker the ability to access and/or modify information related to the web client with no effect on availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24867" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3445708" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6vxh-3xgf-2w8m/GHSA-6vxh-3xgf-2w8m.json b/advisories/unreviewed/2025/02/GHSA-6vxh-3xgf-2w8m/GHSA-6vxh-3xgf-2w8m.json new file mode 100644 index 00000000000..e89c6ba1282 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6vxh-3xgf-2w8m/GHSA-6vxh-3xgf-2w8m.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vxh-3xgf-2w8m", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-2652" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2652" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-745w-w26v-3f45/GHSA-745w-w26v-3f45.json b/advisories/unreviewed/2025/02/GHSA-745w-w26v-3f45/GHSA-745w-w26v-3f45.json new file mode 100644 index 00000000000..2744a8d230d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-745w-w26v-3f45/GHSA-745w-w26v-3f45.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-745w-w26v-3f45", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3929" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3929" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-75jp-w68w-mqj8/GHSA-75jp-w68w-mqj8.json b/advisories/unreviewed/2025/02/GHSA-75jp-w68w-mqj8/GHSA-75jp-w68w-mqj8.json new file mode 100644 index 00000000000..d726eb3e24b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-75jp-w68w-mqj8/GHSA-75jp-w68w-mqj8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jp-w68w-mqj8", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3185" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3185" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-798f-57rp-g3wf/GHSA-798f-57rp-g3wf.json b/advisories/unreviewed/2025/02/GHSA-798f-57rp-g3wf/GHSA-798f-57rp-g3wf.json new file mode 100644 index 00000000000..1077b37e6d5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-798f-57rp-g3wf/GHSA-798f-57rp-g3wf.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-798f-57rp-g3wf", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2025-1168" + ], + "details": "A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php. The manipulation of the argument contact leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1168" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295072" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295072" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494766" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7h2j-6cxh-372j/GHSA-7h2j-6cxh-372j.json b/advisories/unreviewed/2025/02/GHSA-7h2j-6cxh-372j/GHSA-7h2j-6cxh-372j.json new file mode 100644 index 00000000000..4ecac6f4ba3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7h2j-6cxh-372j/GHSA-7h2j-6cxh-372j.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h2j-6cxh-372j", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-2388" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2388" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7j95-4chj-vpv5/GHSA-7j95-4chj-vpv5.json b/advisories/unreviewed/2025/02/GHSA-7j95-4chj-vpv5/GHSA-7j95-4chj-vpv5.json new file mode 100644 index 00000000000..66a087bae36 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7j95-4chj-vpv5/GHSA-7j95-4chj-vpv5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j95-4chj-vpv5", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12246" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12246" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7qj2-6p2x-36pq/GHSA-7qj2-6p2x-36pq.json b/advisories/unreviewed/2025/02/GHSA-7qj2-6p2x-36pq/GHSA-7qj2-6p2x-36pq.json new file mode 100644 index 00000000000..8deaec48bda --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7qj2-6p2x-36pq/GHSA-7qj2-6p2x-36pq.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qj2-6p2x-36pq", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-5738" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5738" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7qqx-qq6c-m3qg/GHSA-7qqx-qq6c-m3qg.json b/advisories/unreviewed/2025/02/GHSA-7qqx-qq6c-m3qg/GHSA-7qqx-qq6c-m3qg.json new file mode 100644 index 00000000000..a3ea3666cf6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7qqx-qq6c-m3qg/GHSA-7qqx-qq6c-m3qg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qqx-qq6c-m3qg", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-6081" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6081" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7x55-c3jm-cvhv/GHSA-7x55-c3jm-cvhv.json b/advisories/unreviewed/2025/02/GHSA-7x55-c3jm-cvhv/GHSA-7x55-c3jm-cvhv.json new file mode 100644 index 00000000000..ea6efd4a885 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7x55-c3jm-cvhv/GHSA-7x55-c3jm-cvhv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x55-c3jm-cvhv", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-1457" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1457" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-88m5-8mmh-3jp9/GHSA-88m5-8mmh-3jp9.json b/advisories/unreviewed/2025/02/GHSA-88m5-8mmh-3jp9/GHSA-88m5-8mmh-3jp9.json new file mode 100644 index 00000000000..475d9c13b63 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-88m5-8mmh-3jp9/GHSA-88m5-8mmh-3jp9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88m5-8mmh-3jp9", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3437" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3437" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-899r-8m2p-r4vc/GHSA-899r-8m2p-r4vc.json b/advisories/unreviewed/2025/02/GHSA-899r-8m2p-r4vc/GHSA-899r-8m2p-r4vc.json new file mode 100644 index 00000000000..dbeaccefc8d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-899r-8m2p-r4vc/GHSA-899r-8m2p-r4vc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-899r-8m2p-r4vc", + "modified": "2025-02-11T03:30:54Z", + "published": "2025-02-11T03:30:54Z", + "aliases": [ + "CVE-2024-11890" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11890" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-89vf-mf66-frgw/GHSA-89vf-mf66-frgw.json b/advisories/unreviewed/2025/02/GHSA-89vf-mf66-frgw/GHSA-89vf-mf66-frgw.json new file mode 100644 index 00000000000..830576534a7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-89vf-mf66-frgw/GHSA-89vf-mf66-frgw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vf-mf66-frgw", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-23190" + ], + "details": "Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23190" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3547581" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8c68-2g35-93cv/GHSA-8c68-2g35-93cv.json b/advisories/unreviewed/2025/02/GHSA-8c68-2g35-93cv/GHSA-8c68-2g35-93cv.json new file mode 100644 index 00000000000..7859e798b07 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8c68-2g35-93cv/GHSA-8c68-2g35-93cv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c68-2g35-93cv", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-11191" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11191" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8h8r-h4gj-97cr/GHSA-8h8r-h4gj-97cr.json b/advisories/unreviewed/2025/02/GHSA-8h8r-h4gj-97cr/GHSA-8h8r-h4gj-97cr.json new file mode 100644 index 00000000000..a0bae9563b0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8h8r-h4gj-97cr/GHSA-8h8r-h4gj-97cr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h8r-h4gj-97cr", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-3975" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3975" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8qhw-338v-3v5w/GHSA-8qhw-338v-3v5w.json b/advisories/unreviewed/2025/02/GHSA-8qhw-338v-3v5w/GHSA-8qhw-338v-3v5w.json new file mode 100644 index 00000000000..7dc5bf22bb6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8qhw-338v-3v5w/GHSA-8qhw-338v-3v5w.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qhw-338v-3v5w", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12764" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12764" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8r4p-3495-x9h5/GHSA-8r4p-3495-x9h5.json b/advisories/unreviewed/2025/02/GHSA-8r4p-3495-x9h5/GHSA-8r4p-3495-x9h5.json new file mode 100644 index 00000000000..0e99e533568 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8r4p-3495-x9h5/GHSA-8r4p-3495-x9h5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r4p-3495-x9h5", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-2037" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2037" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8x98-68p2-2f89/GHSA-8x98-68p2-2f89.json b/advisories/unreviewed/2025/02/GHSA-8x98-68p2-2f89/GHSA-8x98-68p2-2f89.json new file mode 100644 index 00000000000..55300e37548 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8x98-68p2-2f89/GHSA-8x98-68p2-2f89.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x98-68p2-2f89", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-8753" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8753" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-93rq-cpfq-gx27/GHSA-93rq-cpfq-gx27.json b/advisories/unreviewed/2025/02/GHSA-93rq-cpfq-gx27/GHSA-93rq-cpfq-gx27.json new file mode 100644 index 00000000000..22e24de3b8b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-93rq-cpfq-gx27/GHSA-93rq-cpfq-gx27.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93rq-cpfq-gx27", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9580" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9580" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-97hm-jjw3-5qc2/GHSA-97hm-jjw3-5qc2.json b/advisories/unreviewed/2025/02/GHSA-97hm-jjw3-5qc2/GHSA-97hm-jjw3-5qc2.json new file mode 100644 index 00000000000..b55e8144fdd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-97hm-jjw3-5qc2/GHSA-97hm-jjw3-5qc2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97hm-jjw3-5qc2", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4625" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4625" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9c74-ppcm-mjfw/GHSA-9c74-ppcm-mjfw.json b/advisories/unreviewed/2025/02/GHSA-9c74-ppcm-mjfw/GHSA-9c74-ppcm-mjfw.json new file mode 100644 index 00000000000..ce4d49aa735 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9c74-ppcm-mjfw/GHSA-9c74-ppcm-mjfw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c74-ppcm-mjfw", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2025-24875" + ], + "details": "SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24875" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3555364" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9r9v-644h-2p8g/GHSA-9r9v-644h-2p8g.json b/advisories/unreviewed/2025/02/GHSA-9r9v-644h-2p8g/GHSA-9r9v-644h-2p8g.json new file mode 100644 index 00000000000..116eec04ef8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9r9v-644h-2p8g/GHSA-9r9v-644h-2p8g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r9v-644h-2p8g", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2025-24874" + ], + "details": "SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24874" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3559510" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9vm4-vwj5-jr64/GHSA-9vm4-vwj5-jr64.json b/advisories/unreviewed/2025/02/GHSA-9vm4-vwj5-jr64/GHSA-9vm4-vwj5-jr64.json new file mode 100644 index 00000000000..0cce448f6c7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9vm4-vwj5-jr64/GHSA-9vm4-vwj5-jr64.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vm4-vwj5-jr64", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-5508" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5508" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9vxx-jgp8-vp28/GHSA-9vxx-jgp8-vp28.json b/advisories/unreviewed/2025/02/GHSA-9vxx-jgp8-vp28/GHSA-9vxx-jgp8-vp28.json new file mode 100644 index 00000000000..f2f0394a3df --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9vxx-jgp8-vp28/GHSA-9vxx-jgp8-vp28.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vxx-jgp8-vp28", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-8240" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8240" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9xc4-9x83-6hvf/GHSA-9xc4-9x83-6hvf.json b/advisories/unreviewed/2025/02/GHSA-9xc4-9x83-6hvf/GHSA-9xc4-9x83-6hvf.json new file mode 100644 index 00000000000..575d2bbc379 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9xc4-9x83-6hvf/GHSA-9xc4-9x83-6hvf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xc4-9x83-6hvf", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-5513" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5513" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9xq5-rrj3-9998/GHSA-9xq5-rrj3-9998.json b/advisories/unreviewed/2025/02/GHSA-9xq5-rrj3-9998/GHSA-9xq5-rrj3-9998.json new file mode 100644 index 00000000000..021b1331e2a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9xq5-rrj3-9998/GHSA-9xq5-rrj3-9998.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xq5-rrj3-9998", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-0644" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0644" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9xwg-3mgc-2p39/GHSA-9xwg-3mgc-2p39.json b/advisories/unreviewed/2025/02/GHSA-9xwg-3mgc-2p39/GHSA-9xwg-3mgc-2p39.json new file mode 100644 index 00000000000..73fed036f11 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9xwg-3mgc-2p39/GHSA-9xwg-3mgc-2p39.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xwg-3mgc-2p39", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-3103" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3103" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c828-78fx-xhg2/GHSA-c828-78fx-xhg2.json b/advisories/unreviewed/2025/02/GHSA-c828-78fx-xhg2/GHSA-c828-78fx-xhg2.json new file mode 100644 index 00000000000..c39ee47dfd2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c828-78fx-xhg2/GHSA-c828-78fx-xhg2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c828-78fx-xhg2", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3483" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3483" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ccg5-m54c-8rwh/GHSA-ccg5-m54c-8rwh.json b/advisories/unreviewed/2025/02/GHSA-ccg5-m54c-8rwh/GHSA-ccg5-m54c-8rwh.json new file mode 100644 index 00000000000..ca7f67585f8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ccg5-m54c-8rwh/GHSA-ccg5-m54c-8rwh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccg5-m54c-8rwh", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-11288" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11288" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ccv9-fh73-rrr3/GHSA-ccv9-fh73-rrr3.json b/advisories/unreviewed/2025/02/GHSA-ccv9-fh73-rrr3/GHSA-ccv9-fh73-rrr3.json new file mode 100644 index 00000000000..f79f0f4dfd4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ccv9-fh73-rrr3/GHSA-ccv9-fh73-rrr3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccv9-fh73-rrr3", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2023-1266" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1266" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cgxr-4wvm-4qrm/GHSA-cgxr-4wvm-4qrm.json b/advisories/unreviewed/2025/02/GHSA-cgxr-4wvm-4qrm/GHSA-cgxr-4wvm-4qrm.json new file mode 100644 index 00000000000..bd026c8cf41 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cgxr-4wvm-4qrm/GHSA-cgxr-4wvm-4qrm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgxr-4wvm-4qrm", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-6093" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6093" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cmcf-r9w7-qhj6/GHSA-cmcf-r9w7-qhj6.json b/advisories/unreviewed/2025/02/GHSA-cmcf-r9w7-qhj6/GHSA-cmcf-r9w7-qhj6.json new file mode 100644 index 00000000000..0e71f163b62 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cmcf-r9w7-qhj6/GHSA-cmcf-r9w7-qhj6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmcf-r9w7-qhj6", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-23189" + ], + "details": "Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23189" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3546470" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cpfx-964w-4jvp/GHSA-cpfx-964w-4jvp.json b/advisories/unreviewed/2025/02/GHSA-cpfx-964w-4jvp/GHSA-cpfx-964w-4jvp.json new file mode 100644 index 00000000000..0dc9db40afe --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cpfx-964w-4jvp/GHSA-cpfx-964w-4jvp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpfx-964w-4jvp", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2025-24876" + ], + "details": "The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24876" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3567974" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/@sap/approuter?activeTab=versions" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cpjq-gf3j-8v65/GHSA-cpjq-gf3j-8v65.json b/advisories/unreviewed/2025/02/GHSA-cpjq-gf3j-8v65/GHSA-cpjq-gf3j-8v65.json new file mode 100644 index 00000000000..65844363271 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cpjq-gf3j-8v65/GHSA-cpjq-gf3j-8v65.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpjq-gf3j-8v65", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3549" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3549" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cw43-6v89-qww5/GHSA-cw43-6v89-qww5.json b/advisories/unreviewed/2025/02/GHSA-cw43-6v89-qww5/GHSA-cw43-6v89-qww5.json new file mode 100644 index 00000000000..1a14d8d511d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cw43-6v89-qww5/GHSA-cw43-6v89-qww5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw43-6v89-qww5", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9015" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9015" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f26m-2q85-45q7/GHSA-f26m-2q85-45q7.json b/advisories/unreviewed/2025/02/GHSA-f26m-2q85-45q7/GHSA-f26m-2q85-45q7.json new file mode 100644 index 00000000000..886607d4a3d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f26m-2q85-45q7/GHSA-f26m-2q85-45q7.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f26m-2q85-45q7", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-6140" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6140" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f7m2-hmg3-hj3x/GHSA-f7m2-hmg3-hj3x.json b/advisories/unreviewed/2025/02/GHSA-f7m2-hmg3-hj3x/GHSA-f7m2-hmg3-hj3x.json new file mode 100644 index 00000000000..59daf6f3599 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f7m2-hmg3-hj3x/GHSA-f7m2-hmg3-hj3x.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7m2-hmg3-hj3x", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-0339" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0339" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fpch-6h78-9j42/GHSA-fpch-6h78-9j42.json b/advisories/unreviewed/2025/02/GHSA-fpch-6h78-9j42/GHSA-fpch-6h78-9j42.json new file mode 100644 index 00000000000..427533e8304 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fpch-6h78-9j42/GHSA-fpch-6h78-9j42.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpch-6h78-9j42", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-4014" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4014" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fq8j-xv59-wr36/GHSA-fq8j-xv59-wr36.json b/advisories/unreviewed/2025/02/GHSA-fq8j-xv59-wr36/GHSA-fq8j-xv59-wr36.json new file mode 100644 index 00000000000..351267abdad --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fq8j-xv59-wr36/GHSA-fq8j-xv59-wr36.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq8j-xv59-wr36", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-7298" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7298" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fw9q-7943-h3c4/GHSA-fw9q-7943-h3c4.json b/advisories/unreviewed/2025/02/GHSA-fw9q-7943-h3c4/GHSA-fw9q-7943-h3c4.json new file mode 100644 index 00000000000..34b199c1dd0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fw9q-7943-h3c4/GHSA-fw9q-7943-h3c4.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw9q-7943-h3c4", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-8351" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8351" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fwmp-9r85-c479/GHSA-fwmp-9r85-c479.json b/advisories/unreviewed/2025/02/GHSA-fwmp-9r85-c479/GHSA-fwmp-9r85-c479.json new file mode 100644 index 00000000000..2da4283bde2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fwmp-9r85-c479/GHSA-fwmp-9r85-c479.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwmp-9r85-c479", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4952" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4952" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fxgj-q29h-8p85/GHSA-fxgj-q29h-8p85.json b/advisories/unreviewed/2025/02/GHSA-fxgj-q29h-8p85/GHSA-fxgj-q29h-8p85.json new file mode 100644 index 00000000000..8acf6ded0dc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fxgj-q29h-8p85/GHSA-fxgj-q29h-8p85.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxgj-q29h-8p85", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-8674" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8674" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g3w2-9mc6-c9f2/GHSA-g3w2-9mc6-c9f2.json b/advisories/unreviewed/2025/02/GHSA-g3w2-9mc6-c9f2/GHSA-g3w2-9mc6-c9f2.json new file mode 100644 index 00000000000..56ff0b485b0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g3w2-9mc6-c9f2/GHSA-g3w2-9mc6-c9f2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3w2-9mc6-c9f2", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-8677" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8677" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g766-f6qx-6wx9/GHSA-g766-f6qx-6wx9.json b/advisories/unreviewed/2025/02/GHSA-g766-f6qx-6wx9/GHSA-g766-f6qx-6wx9.json new file mode 100644 index 00000000000..f1cfd6f25cb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g766-f6qx-6wx9/GHSA-g766-f6qx-6wx9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g766-f6qx-6wx9", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12904" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12904" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g9hp-6j55-xr8g/GHSA-g9hp-6j55-xr8g.json b/advisories/unreviewed/2025/02/GHSA-g9hp-6j55-xr8g/GHSA-g9hp-6j55-xr8g.json new file mode 100644 index 00000000000..1d29910c8c4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g9hp-6j55-xr8g/GHSA-g9hp-6j55-xr8g.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9hp-6j55-xr8g", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-6106" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6106" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h6px-f78v-j5xj/GHSA-h6px-f78v-j5xj.json b/advisories/unreviewed/2025/02/GHSA-h6px-f78v-j5xj/GHSA-h6px-f78v-j5xj.json new file mode 100644 index 00000000000..ed202cadb9f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h6px-f78v-j5xj/GHSA-h6px-f78v-j5xj.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6px-f78v-j5xj", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2025-1167" + ], + "details": "A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected by this issue is some unknown functionality of the file /hr_soft/admin/Update_User.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1167" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h736-59c9-428c/GHSA-h736-59c9-428c.json b/advisories/unreviewed/2025/02/GHSA-h736-59c9-428c/GHSA-h736-59c9-428c.json new file mode 100644 index 00000000000..3d1fea9cf42 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h736-59c9-428c/GHSA-h736-59c9-428c.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h736-59c9-428c", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2025-0499" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0499" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h8c7-4x96-9xrr/GHSA-h8c7-4x96-9xrr.json b/advisories/unreviewed/2025/02/GHSA-h8c7-4x96-9xrr/GHSA-h8c7-4x96-9xrr.json new file mode 100644 index 00000000000..d1ead4f07f6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h8c7-4x96-9xrr/GHSA-h8c7-4x96-9xrr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8c7-4x96-9xrr", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4101" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4101" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h8jr-hw2m-jff2/GHSA-h8jr-hw2m-jff2.json b/advisories/unreviewed/2025/02/GHSA-h8jr-hw2m-jff2/GHSA-h8jr-hw2m-jff2.json new file mode 100644 index 00000000000..d3ca8fef82f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h8jr-hw2m-jff2/GHSA-h8jr-hw2m-jff2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8jr-hw2m-jff2", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2023-2965" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2965" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hffm-4vfv-rh6x/GHSA-hffm-4vfv-rh6x.json b/advisories/unreviewed/2025/02/GHSA-hffm-4vfv-rh6x/GHSA-hffm-4vfv-rh6x.json new file mode 100644 index 00000000000..155fef0e7d2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hffm-4vfv-rh6x/GHSA-hffm-4vfv-rh6x.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hffm-4vfv-rh6x", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12242" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12242" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hmcq-p7v6-c6gh/GHSA-hmcq-p7v6-c6gh.json b/advisories/unreviewed/2025/02/GHSA-hmcq-p7v6-c6gh/GHSA-hmcq-p7v6-c6gh.json new file mode 100644 index 00000000000..e3892f3a90c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hmcq-p7v6-c6gh/GHSA-hmcq-p7v6-c6gh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmcq-p7v6-c6gh", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3908" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3908" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j5r6-9732-rhw2/GHSA-j5r6-9732-rhw2.json b/advisories/unreviewed/2025/02/GHSA-j5r6-9732-rhw2/GHSA-j5r6-9732-rhw2.json new file mode 100644 index 00000000000..418636d81c9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j5r6-9732-rhw2/GHSA-j5r6-9732-rhw2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r6-9732-rhw2", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-11264" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11264" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j79q-g52w-4crr/GHSA-j79q-g52w-4crr.json b/advisories/unreviewed/2025/02/GHSA-j79q-g52w-4crr/GHSA-j79q-g52w-4crr.json new file mode 100644 index 00000000000..a17f83a437d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j79q-g52w-4crr/GHSA-j79q-g52w-4crr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j79q-g52w-4crr", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4012" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4012" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j8pr-f6j6-rrfr/GHSA-j8pr-f6j6-rrfr.json b/advisories/unreviewed/2025/02/GHSA-j8pr-f6j6-rrfr/GHSA-j8pr-f6j6-rrfr.json new file mode 100644 index 00000000000..549aeed645c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j8pr-f6j6-rrfr/GHSA-j8pr-f6j6-rrfr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8pr-f6j6-rrfr", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3913" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3913" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jfr8-p329-x488/GHSA-jfr8-p329-x488.json b/advisories/unreviewed/2025/02/GHSA-jfr8-p329-x488/GHSA-jfr8-p329-x488.json new file mode 100644 index 00000000000..b28012a5da4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jfr8-p329-x488/GHSA-jfr8-p329-x488.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfr8-p329-x488", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-11397" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11397" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jjq7-xc67-vrv3/GHSA-jjq7-xc67-vrv3.json b/advisories/unreviewed/2025/02/GHSA-jjq7-xc67-vrv3/GHSA-jjq7-xc67-vrv3.json new file mode 100644 index 00000000000..2c13fd62a40 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jjq7-xc67-vrv3/GHSA-jjq7-xc67-vrv3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjq7-xc67-vrv3", + "modified": "2025-02-11T03:30:54Z", + "published": "2025-02-11T03:30:54Z", + "aliases": [ + "CVE-2025-0054" + ], + "details": "SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0054" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3526203" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jqv4-r373-5mmg/GHSA-jqv4-r373-5mmg.json b/advisories/unreviewed/2025/02/GHSA-jqv4-r373-5mmg/GHSA-jqv4-r373-5mmg.json new file mode 100644 index 00000000000..1e264ddddee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jqv4-r373-5mmg/GHSA-jqv4-r373-5mmg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqv4-r373-5mmg", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9185" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9185" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jrq4-hxmj-whf7/GHSA-jrq4-hxmj-whf7.json b/advisories/unreviewed/2025/02/GHSA-jrq4-hxmj-whf7/GHSA-jrq4-hxmj-whf7.json new file mode 100644 index 00000000000..08cf6e26213 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jrq4-hxmj-whf7/GHSA-jrq4-hxmj-whf7.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrq4-hxmj-whf7", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-1964" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1964" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m3h2-9w5r-43m3/GHSA-m3h2-9w5r-43m3.json b/advisories/unreviewed/2025/02/GHSA-m3h2-9w5r-43m3/GHSA-m3h2-9w5r-43m3.json new file mode 100644 index 00000000000..07b9924bed4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m3h2-9w5r-43m3/GHSA-m3h2-9w5r-43m3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3h2-9w5r-43m3", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2023-6167" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6167" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m6cq-73g8-w4jh/GHSA-m6cq-73g8-w4jh.json b/advisories/unreviewed/2025/02/GHSA-m6cq-73g8-w4jh/GHSA-m6cq-73g8-w4jh.json new file mode 100644 index 00000000000..9025bc62847 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m6cq-73g8-w4jh/GHSA-m6cq-73g8-w4jh.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6cq-73g8-w4jh", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2025-1166" + ], + "details": "A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file endpoint/update.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1166" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jmx0hxq/0ce2c97ca11b2423a203b5719438c9f8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494567" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m79q-fc2f-ghrw/GHSA-m79q-fc2f-ghrw.json b/advisories/unreviewed/2025/02/GHSA-m79q-fc2f-ghrw/GHSA-m79q-fc2f-ghrw.json new file mode 100644 index 00000000000..3533b9a7a5e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m79q-fc2f-ghrw/GHSA-m79q-fc2f-ghrw.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m79q-fc2f-ghrw", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12161" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12161" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mmrc-9g5j-r2hx/GHSA-mmrc-9g5j-r2hx.json b/advisories/unreviewed/2025/02/GHSA-mmrc-9g5j-r2hx/GHSA-mmrc-9g5j-r2hx.json new file mode 100644 index 00000000000..8bc3ada3934 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mmrc-9g5j-r2hx/GHSA-mmrc-9g5j-r2hx.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmrc-9g5j-r2hx", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-5747" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5747" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mrfr-mmmc-vx6h/GHSA-mrfr-mmmc-vx6h.json b/advisories/unreviewed/2025/02/GHSA-mrfr-mmmc-vx6h/GHSA-mrfr-mmmc-vx6h.json new file mode 100644 index 00000000000..c472f9c4b13 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mrfr-mmmc-vx6h/GHSA-mrfr-mmmc-vx6h.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrfr-mmmc-vx6h", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-2396" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2396" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mw9p-cf3j-5fjf/GHSA-mw9p-cf3j-5fjf.json b/advisories/unreviewed/2025/02/GHSA-mw9p-cf3j-5fjf/GHSA-mw9p-cf3j-5fjf.json new file mode 100644 index 00000000000..5ae3685e67b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mw9p-cf3j-5fjf/GHSA-mw9p-cf3j-5fjf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9p-cf3j-5fjf", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3911" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3911" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mwqj-49wx-542h/GHSA-mwqj-49wx-542h.json b/advisories/unreviewed/2025/02/GHSA-mwqj-49wx-542h/GHSA-mwqj-49wx-542h.json new file mode 100644 index 00000000000..7d43c8814a2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mwqj-49wx-542h/GHSA-mwqj-49wx-542h.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwqj-49wx-542h", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-6304" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6304" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mx5q-637c-cwj6/GHSA-mx5q-637c-cwj6.json b/advisories/unreviewed/2025/02/GHSA-mx5q-637c-cwj6/GHSA-mx5q-637c-cwj6.json new file mode 100644 index 00000000000..2158f3ccff5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mx5q-637c-cwj6/GHSA-mx5q-637c-cwj6.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx5q-637c-cwj6", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3963" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3963" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p9qr-94jp-w6r4/GHSA-p9qr-94jp-w6r4.json b/advisories/unreviewed/2025/02/GHSA-p9qr-94jp-w6r4/GHSA-p9qr-94jp-w6r4.json new file mode 100644 index 00000000000..ed80c07558c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p9qr-94jp-w6r4/GHSA-p9qr-94jp-w6r4.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9qr-94jp-w6r4", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-4210" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4210" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pfw6-w64x-2pxf/GHSA-pfw6-w64x-2pxf.json b/advisories/unreviewed/2025/02/GHSA-pfw6-w64x-2pxf/GHSA-pfw6-w64x-2pxf.json new file mode 100644 index 00000000000..19c532b86d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pfw6-w64x-2pxf/GHSA-pfw6-w64x-2pxf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfw6-w64x-2pxf", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4108" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4108" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pg48-xqfr-28r3/GHSA-pg48-xqfr-28r3.json b/advisories/unreviewed/2025/02/GHSA-pg48-xqfr-28r3/GHSA-pg48-xqfr-28r3.json new file mode 100644 index 00000000000..8afdf956b42 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pg48-xqfr-28r3/GHSA-pg48-xqfr-28r3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg48-xqfr-28r3", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2025-1170" + ], + "details": "A vulnerability classified as problematic has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/Category.php. The manipulation of the argument Desc leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1170" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/J0hnFFFF/j0hn_upload_five/blob/main/web2.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295074" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295074" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494829" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-phgp-v23p-rmp3/GHSA-phgp-v23p-rmp3.json b/advisories/unreviewed/2025/02/GHSA-phgp-v23p-rmp3/GHSA-phgp-v23p-rmp3.json new file mode 100644 index 00000000000..752e84fcc98 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-phgp-v23p-rmp3/GHSA-phgp-v23p-rmp3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phgp-v23p-rmp3", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2022-2283" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2283" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pww5-3pw8-23mf/GHSA-pww5-3pw8-23mf.json b/advisories/unreviewed/2025/02/GHSA-pww5-3pw8-23mf/GHSA-pww5-3pw8-23mf.json new file mode 100644 index 00000000000..cce9a0abd23 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pww5-3pw8-23mf/GHSA-pww5-3pw8-23mf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pww5-3pw8-23mf", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-4656" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4656" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pxx9-h38c-8jf2/GHSA-pxx9-h38c-8jf2.json b/advisories/unreviewed/2025/02/GHSA-pxx9-h38c-8jf2/GHSA-pxx9-h38c-8jf2.json new file mode 100644 index 00000000000..f05c28a4c94 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pxx9-h38c-8jf2/GHSA-pxx9-h38c-8jf2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxx9-h38c-8jf2", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3919" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3919" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qgvm-5vwm-h835/GHSA-qgvm-5vwm-h835.json b/advisories/unreviewed/2025/02/GHSA-qgvm-5vwm-h835/GHSA-qgvm-5vwm-h835.json new file mode 100644 index 00000000000..839077917bf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qgvm-5vwm-h835/GHSA-qgvm-5vwm-h835.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgvm-5vwm-h835", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4285" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4285" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qjvc-xv7p-qq4h/GHSA-qjvc-xv7p-qq4h.json b/advisories/unreviewed/2025/02/GHSA-qjvc-xv7p-qq4h/GHSA-qjvc-xv7p-qq4h.json new file mode 100644 index 00000000000..7c4fcdeecc9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qjvc-xv7p-qq4h/GHSA-qjvc-xv7p-qq4h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjvc-xv7p-qq4h", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-23191" + ], + "details": "Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful exploitation could cause low impact on integrity of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23191" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3426825" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qm9w-gw5g-fvmc/GHSA-qm9w-gw5g-fvmc.json b/advisories/unreviewed/2025/02/GHSA-qm9w-gw5g-fvmc/GHSA-qm9w-gw5g-fvmc.json new file mode 100644 index 00000000000..31fee60a5ae --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qm9w-gw5g-fvmc/GHSA-qm9w-gw5g-fvmc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm9w-gw5g-fvmc", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-3702" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3702" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qvfq-26w4-9f8v/GHSA-qvfq-26w4-9f8v.json b/advisories/unreviewed/2025/02/GHSA-qvfq-26w4-9f8v/GHSA-qvfq-26w4-9f8v.json new file mode 100644 index 00000000000..b451d30854a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qvfq-26w4-9f8v/GHSA-qvfq-26w4-9f8v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvfq-26w4-9f8v", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-24870" + ], + "details": "SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24870" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3562336" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-921" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r4wx-cf75-5xhr/GHSA-r4wx-cf75-5xhr.json b/advisories/unreviewed/2025/02/GHSA-r4wx-cf75-5xhr/GHSA-r4wx-cf75-5xhr.json new file mode 100644 index 00000000000..644830df96f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r4wx-cf75-5xhr/GHSA-r4wx-cf75-5xhr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4wx-cf75-5xhr", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-4784" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4784" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r7pm-3rhw-gv3g/GHSA-r7pm-3rhw-gv3g.json b/advisories/unreviewed/2025/02/GHSA-r7pm-3rhw-gv3g/GHSA-r7pm-3rhw-gv3g.json new file mode 100644 index 00000000000..14847140034 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r7pm-3rhw-gv3g/GHSA-r7pm-3rhw-gv3g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7pm-3rhw-gv3g", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-0064" + ], + "details": "Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0064" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3525794" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r9jv-gf8f-82q8/GHSA-r9jv-gf8f-82q8.json b/advisories/unreviewed/2025/02/GHSA-r9jv-gf8f-82q8/GHSA-r9jv-gf8f-82q8.json new file mode 100644 index 00000000000..8793818ac5f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r9jv-gf8f-82q8/GHSA-r9jv-gf8f-82q8.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9jv-gf8f-82q8", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-6060" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rchf-pgq4-j942/GHSA-rchf-pgq4-j942.json b/advisories/unreviewed/2025/02/GHSA-rchf-pgq4-j942/GHSA-rchf-pgq4-j942.json new file mode 100644 index 00000000000..183d489d309 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rchf-pgq4-j942/GHSA-rchf-pgq4-j942.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rchf-pgq4-j942", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9688" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9688" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rfg6-27wf-jv56/GHSA-rfg6-27wf-jv56.json b/advisories/unreviewed/2025/02/GHSA-rfg6-27wf-jv56/GHSA-rfg6-27wf-jv56.json new file mode 100644 index 00000000000..e9dc127fe6d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rfg6-27wf-jv56/GHSA-rfg6-27wf-jv56.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfg6-27wf-jv56", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-7566" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7566" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rjcm-vx5r-p83h/GHSA-rjcm-vx5r-p83h.json b/advisories/unreviewed/2025/02/GHSA-rjcm-vx5r-p83h/GHSA-rjcm-vx5r-p83h.json new file mode 100644 index 00000000000..3210caf509f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rjcm-vx5r-p83h/GHSA-rjcm-vx5r-p83h.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjcm-vx5r-p83h", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-6819" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6819" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rqf6-7jcm-ghjp/GHSA-rqf6-7jcm-ghjp.json b/advisories/unreviewed/2025/02/GHSA-rqf6-7jcm-ghjp/GHSA-rqf6-7jcm-ghjp.json new file mode 100644 index 00000000000..b42efbb193a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rqf6-7jcm-ghjp/GHSA-rqf6-7jcm-ghjp.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqf6-7jcm-ghjp", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3402" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3402" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rvrw-q6hf-fq9h/GHSA-rvrw-q6hf-fq9h.json b/advisories/unreviewed/2025/02/GHSA-rvrw-q6hf-fq9h/GHSA-rvrw-q6hf-fq9h.json new file mode 100644 index 00000000000..01aa4448b77 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rvrw-q6hf-fq9h/GHSA-rvrw-q6hf-fq9h.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvrw-q6hf-fq9h", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-1165" + ], + "details": "A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1165" + }, + { + "type": "WEB", + "url": "https://github.com/Rain1er/report/blob/main/Lserp/fileUpload_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.494516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rw6v-f839-vw24/GHSA-rw6v-f839-vw24.json b/advisories/unreviewed/2025/02/GHSA-rw6v-f839-vw24/GHSA-rw6v-f839-vw24.json new file mode 100644 index 00000000000..ee67822fe57 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rw6v-f839-vw24/GHSA-rw6v-f839-vw24.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw6v-f839-vw24", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12765" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12765" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rwxg-79m3-6gqr/GHSA-rwxg-79m3-6gqr.json b/advisories/unreviewed/2025/02/GHSA-rwxg-79m3-6gqr/GHSA-rwxg-79m3-6gqr.json new file mode 100644 index 00000000000..23c6da09f5b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rwxg-79m3-6gqr/GHSA-rwxg-79m3-6gqr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxg-79m3-6gqr", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-10042" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10042" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v2qx-jchg-cgm5/GHSA-v2qx-jchg-cgm5.json b/advisories/unreviewed/2025/02/GHSA-v2qx-jchg-cgm5/GHSA-v2qx-jchg-cgm5.json new file mode 100644 index 00000000000..5cddcd42a34 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v2qx-jchg-cgm5/GHSA-v2qx-jchg-cgm5.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2qx-jchg-cgm5", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9625" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9625" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v56p-h642-3h7c/GHSA-v56p-h642-3h7c.json b/advisories/unreviewed/2025/02/GHSA-v56p-h642-3h7c/GHSA-v56p-h642-3h7c.json new file mode 100644 index 00000000000..8574850b449 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v56p-h642-3h7c/GHSA-v56p-h642-3h7c.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v56p-h642-3h7c", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3448" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3448" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v5pc-m34f-7rgx/GHSA-v5pc-m34f-7rgx.json b/advisories/unreviewed/2025/02/GHSA-v5pc-m34f-7rgx/GHSA-v5pc-m34f-7rgx.json new file mode 100644 index 00000000000..5eb7223f743 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v5pc-m34f-7rgx/GHSA-v5pc-m34f-7rgx.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5pc-m34f-7rgx", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-3069" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3069" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v72g-8mcg-6xfh/GHSA-v72g-8mcg-6xfh.json b/advisories/unreviewed/2025/02/GHSA-v72g-8mcg-6xfh/GHSA-v72g-8mcg-6xfh.json new file mode 100644 index 00000000000..a9204204fef --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v72g-8mcg-6xfh/GHSA-v72g-8mcg-6xfh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v72g-8mcg-6xfh", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-4951" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4951" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vj29-5qr3-qpc2/GHSA-vj29-5qr3-qpc2.json b/advisories/unreviewed/2025/02/GHSA-vj29-5qr3-qpc2/GHSA-vj29-5qr3-qpc2.json new file mode 100644 index 00000000000..00696a14868 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vj29-5qr3-qpc2/GHSA-vj29-5qr3-qpc2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj29-5qr3-qpc2", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-10347" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10347" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vj98-79pv-wc57/GHSA-vj98-79pv-wc57.json b/advisories/unreviewed/2025/02/GHSA-vj98-79pv-wc57/GHSA-vj98-79pv-wc57.json new file mode 100644 index 00000000000..7d76410a8d5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vj98-79pv-wc57/GHSA-vj98-79pv-wc57.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj98-79pv-wc57", + "modified": "2025-02-11T03:31:00Z", + "published": "2025-02-11T03:31:00Z", + "aliases": [ + "CVE-2024-9181" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9181" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vrmm-4vwc-ph4h/GHSA-vrmm-4vwc-ph4h.json b/advisories/unreviewed/2025/02/GHSA-vrmm-4vwc-ph4h/GHSA-vrmm-4vwc-ph4h.json new file mode 100644 index 00000000000..cafd7c35944 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vrmm-4vwc-ph4h/GHSA-vrmm-4vwc-ph4h.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrmm-4vwc-ph4h", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-6105" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6105" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wh3f-976p-qfcj/GHSA-wh3f-976p-qfcj.json b/advisories/unreviewed/2025/02/GHSA-wh3f-976p-qfcj/GHSA-wh3f-976p-qfcj.json new file mode 100644 index 00000000000..7189b5ee1e4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wh3f-976p-qfcj/GHSA-wh3f-976p-qfcj.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh3f-976p-qfcj", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-1734" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1734" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wjx4-3mmx-85jf/GHSA-wjx4-3mmx-85jf.json b/advisories/unreviewed/2025/02/GHSA-wjx4-3mmx-85jf/GHSA-wjx4-3mmx-85jf.json new file mode 100644 index 00000000000..ecfde316a17 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wjx4-3mmx-85jf/GHSA-wjx4-3mmx-85jf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjx4-3mmx-85jf", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2023-7182" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7182" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wp4j-m7fj-42vm/GHSA-wp4j-m7fj-42vm.json b/advisories/unreviewed/2025/02/GHSA-wp4j-m7fj-42vm/GHSA-wp4j-m7fj-42vm.json new file mode 100644 index 00000000000..a6a55b9abb8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wp4j-m7fj-42vm/GHSA-wp4j-m7fj-42vm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp4j-m7fj-42vm", + "modified": "2025-02-11T03:30:59Z", + "published": "2025-02-11T03:30:59Z", + "aliases": [ + "CVE-2024-8545" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8545" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wpqp-q775-rc59/GHSA-wpqp-q775-rc59.json b/advisories/unreviewed/2025/02/GHSA-wpqp-q775-rc59/GHSA-wpqp-q775-rc59.json new file mode 100644 index 00000000000..723c2fc3c46 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wpqp-q775-rc59/GHSA-wpqp-q775-rc59.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpqp-q775-rc59", + "modified": "2025-02-11T03:30:57Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3928" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3928" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wv7q-fx3c-2828/GHSA-wv7q-fx3c-2828.json b/advisories/unreviewed/2025/02/GHSA-wv7q-fx3c-2828/GHSA-wv7q-fx3c-2828.json new file mode 100644 index 00000000000..6569720d027 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wv7q-fx3c-2828/GHSA-wv7q-fx3c-2828.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv7q-fx3c-2828", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-3260" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3260" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wvhh-296q-q9hx/GHSA-wvhh-296q-q9hx.json b/advisories/unreviewed/2025/02/GHSA-wvhh-296q-q9hx/GHSA-wvhh-296q-q9hx.json new file mode 100644 index 00000000000..298e0dbc27a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wvhh-296q-q9hx/GHSA-wvhh-296q-q9hx.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvhh-296q-q9hx", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-3930" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3930" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x2gh-hgcj-q83q/GHSA-x2gh-hgcj-q83q.json b/advisories/unreviewed/2025/02/GHSA-x2gh-hgcj-q83q/GHSA-x2gh-hgcj-q83q.json new file mode 100644 index 00000000000..00bf8624cf8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x2gh-hgcj-q83q/GHSA-x2gh-hgcj-q83q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2gh-hgcj-q83q", + "modified": "2025-02-11T03:30:56Z", + "published": "2025-02-11T03:30:56Z", + "aliases": [ + "CVE-2025-24872" + ], + "details": "The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction and view its details. This has a limited impact on the confidentiality of the application with no effect on the integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24872" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3553753" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x64p-274c-6633/GHSA-x64p-274c-6633.json b/advisories/unreviewed/2025/02/GHSA-x64p-274c-6633/GHSA-x64p-274c-6633.json new file mode 100644 index 00000000000..f2969ef4ce0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x64p-274c-6633/GHSA-x64p-274c-6633.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x64p-274c-6633", + "modified": "2025-02-11T03:30:55Z", + "published": "2025-02-11T03:30:55Z", + "aliases": [ + "CVE-2025-24868" + ], + "details": "The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and availability of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24868" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3563929" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x9g8-262m-9624/GHSA-x9g8-262m-9624.json b/advisories/unreviewed/2025/02/GHSA-x9g8-262m-9624/GHSA-x9g8-262m-9624.json new file mode 100644 index 00000000000..1861a88bb64 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x9g8-262m-9624/GHSA-x9g8-262m-9624.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9g8-262m-9624", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2023-5510" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5510" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xh7w-9mrf-9mqf/GHSA-xh7w-9mrf-9mqf.json b/advisories/unreviewed/2025/02/GHSA-xh7w-9mrf-9mqf/GHSA-xh7w-9mrf-9mqf.json new file mode 100644 index 00000000000..868d9569812 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xh7w-9mrf-9mqf/GHSA-xh7w-9mrf-9mqf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh7w-9mrf-9mqf", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-1944" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1944" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xjr2-5jrg-45g7/GHSA-xjr2-5jrg-45g7.json b/advisories/unreviewed/2025/02/GHSA-xjr2-5jrg-45g7/GHSA-xjr2-5jrg-45g7.json new file mode 100644 index 00000000000..22dc00a8100 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xjr2-5jrg-45g7/GHSA-xjr2-5jrg-45g7.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjr2-5jrg-45g7", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:57Z", + "aliases": [ + "CVE-2024-0198" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0198" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xp64-g89q-372r/GHSA-xp64-g89q-372r.json b/advisories/unreviewed/2025/02/GHSA-xp64-g89q-372r/GHSA-xp64-g89q-372r.json new file mode 100644 index 00000000000..d1259811074 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xp64-g89q-372r/GHSA-xp64-g89q-372r.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp64-g89q-372r", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2023-4998" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4998" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xx59-vqq3-39m7/GHSA-xx59-vqq3-39m7.json b/advisories/unreviewed/2025/02/GHSA-xx59-vqq3-39m7/GHSA-xx59-vqq3-39m7.json new file mode 100644 index 00000000000..506bd98b687 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xx59-vqq3-39m7/GHSA-xx59-vqq3-39m7.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx59-vqq3-39m7", + "modified": "2025-02-11T03:30:58Z", + "published": "2025-02-11T03:30:58Z", + "aliases": [ + "CVE-2024-12763" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12763" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T02:15:33Z" + } +} \ No newline at end of file