From 6954e467b041a584c9ccd6ba44e7a0045fa7ac54 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Feb 2025 18:32:45 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cw6j-2v5x-f5m2.json | 4 +- .../GHSA-cxcv-gvhj-5xxg.json | 4 +- .../GHSA-q5xp-jm46-h2x4.json | 4 +- .../GHSA-366g-cg6r-xmp2.json | 6 ++- .../GHSA-3jvh-pgp8-6866.json | 7 +++- .../GHSA-6484-6mhx-vr77.json | 6 ++- .../GHSA-6ff3-gqc7-rp56.json | 6 ++- .../GHSA-7jp5-5rh9-4q92.json | 6 ++- .../GHSA-f9qv-x24h-c8g8.json | 9 ++++- .../GHSA-jvcm-pc6m-g646.json | 6 ++- .../GHSA-rx2j-whx7-3jv5.json | 6 ++- .../GHSA-x348-5vv2-6fqv.json | 6 ++- .../GHSA-jwc3-mm8j-j745.json | 3 +- .../GHSA-62q4-hc79-94qj.json | 1 + .../GHSA-222j-rx46-g89g.json | 15 +++++-- .../GHSA-22ww-35pw-64c4.json | 29 ++++++++++++++ .../GHSA-2fvw-qmcc-8m37.json | 38 ++++++++++++++++++ .../GHSA-2v3m-p433-pwh8.json | 15 +++++-- .../GHSA-39j3-r3vp-hgfh.json | 29 ++++++++++++++ .../GHSA-3mjx-h33f-j53j.json | 40 +++++++++++++++++++ .../GHSA-3q79-qjgh-rgjv.json | 29 ++++++++++++++ .../GHSA-4346-23fm-8jv5.json | 29 ++++++++++++++ .../GHSA-44hx-fmcp-x4qh.json | 15 +++++-- .../GHSA-4797-mjw6-28fm.json | 15 +++++-- .../GHSA-4cmp-m2j4-4727.json | 29 ++++++++++++++ .../GHSA-4fg5-759r-24x3.json | 33 +++++++++++++++ .../GHSA-4rhc-2pqf-hqj3.json | 33 +++++++++++++++ .../GHSA-52f7-5prx-xwxq.json | 29 ++++++++++++++ .../GHSA-54m8-fp97-8pgr.json | 2 +- .../GHSA-582h-7xj3-j2rp.json | 2 +- .../GHSA-5mxv-j9vc-66x9.json | 33 +++++++++++++++ .../GHSA-5xxj-pf2m-pqvc.json | 3 +- .../GHSA-6c6v-3v49-q93r.json | 33 +++++++++++++++ .../GHSA-6pc6-7fmg-34vv.json | 33 +++++++++++++++ .../GHSA-7q78-98r8-9mh7.json | 29 ++++++++++++++ .../GHSA-7v2p-6g6r-9hjw.json | 29 ++++++++++++++ .../GHSA-826p-m378-hr47.json | 25 ++++++++++++ .../GHSA-82x8-7f5g-jqhm.json | 29 ++++++++++++++ .../GHSA-846x-232r-8564.json | 29 ++++++++++++++ .../GHSA-93jg-3qrg-49hq.json | 15 +++++-- .../GHSA-988j-96m5-5f85.json | 15 +++++-- .../GHSA-995j-3cj2-3p49.json | 33 +++++++++++++++ .../GHSA-9fmx-g36w-qhc9.json | 4 +- .../GHSA-9hm7-j2jc-wh96.json | 4 +- .../GHSA-9m2c-327v-gghq.json | 4 +- .../GHSA-ch24-jfhg-w5qp.json | 29 ++++++++++++++ .../GHSA-f4fr-x852-8ppx.json | 40 +++++++++++++++++++ .../GHSA-fq4q-m37q-rfrh.json | 33 +++++++++++++++ .../GHSA-g6m2-22qr-9mgq.json | 2 +- .../GHSA-g7x3-m53h-j2jq.json | 33 +++++++++++++++ .../GHSA-gmw5-xjxq-3255.json | 33 +++++++++++++++ .../GHSA-hf3x-74c5-wrcm.json | 33 +++++++++++++++ .../GHSA-hq6p-qj55-2rrc.json | 40 +++++++++++++++++++ .../GHSA-j946-qf4c-jrjh.json | 33 +++++++++++++++ .../GHSA-jc5r-26g5-fr8w.json | 29 ++++++++++++++ .../GHSA-m4mm-534h-5cp5.json | 33 +++++++++++++++ .../GHSA-p6g2-26xx-9595.json | 15 +++++-- .../GHSA-ppv4-h8g5-c5h4.json | 3 +- .../GHSA-pqch-79w5-3vfc.json | 11 +++-- .../GHSA-rw8h-38j7-m52m.json | 33 +++++++++++++++ .../GHSA-v5gw-52qq-f42h.json | 33 +++++++++++++++ .../GHSA-v685-v3qp-pgjp.json | 15 +++++-- .../GHSA-v93v-q555-chw5.json | 40 +++++++++++++++++++ .../GHSA-vmh9-7gfq-4r2p.json | 33 +++++++++++++++ .../GHSA-vr7m-6pgw-3493.json | 29 ++++++++++++++ .../GHSA-wq23-w7cm-hgg8.json | 15 +++++-- .../GHSA-wvmg-vpvj-gpv6.json | 36 +++++++++++++++++ .../GHSA-x699-5cwx-5543.json | 15 +++++-- .../GHSA-x8q5-c934-chcc.json | 15 +++++-- 69 files changed, 1336 insertions(+), 69 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-22ww-35pw-64c4/GHSA-22ww-35pw-64c4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2fvw-qmcc-8m37/GHSA-2fvw-qmcc-8m37.json create mode 100644 advisories/unreviewed/2025/02/GHSA-39j3-r3vp-hgfh/GHSA-39j3-r3vp-hgfh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3mjx-h33f-j53j/GHSA-3mjx-h33f-j53j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3q79-qjgh-rgjv/GHSA-3q79-qjgh-rgjv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4346-23fm-8jv5/GHSA-4346-23fm-8jv5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4cmp-m2j4-4727/GHSA-4cmp-m2j4-4727.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4fg5-759r-24x3/GHSA-4fg5-759r-24x3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-52f7-5prx-xwxq/GHSA-52f7-5prx-xwxq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6pc6-7fmg-34vv/GHSA-6pc6-7fmg-34vv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7q78-98r8-9mh7/GHSA-7q78-98r8-9mh7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-826p-m378-hr47/GHSA-826p-m378-hr47.json create mode 100644 advisories/unreviewed/2025/02/GHSA-82x8-7f5g-jqhm/GHSA-82x8-7f5g-jqhm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json create mode 100644 advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ch24-jfhg-w5qp/GHSA-ch24-jfhg-w5qp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f4fr-x852-8ppx/GHSA-f4fr-x852-8ppx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gmw5-xjxq-3255/GHSA-gmw5-xjxq-3255.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hf3x-74c5-wrcm/GHSA-hf3x-74c5-wrcm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hq6p-qj55-2rrc/GHSA-hq6p-qj55-2rrc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jc5r-26g5-fr8w/GHSA-jc5r-26g5-fr8w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m4mm-534h-5cp5/GHSA-m4mm-534h-5cp5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rw8h-38j7-m52m/GHSA-rw8h-38j7-m52m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v5gw-52qq-f42h/GHSA-v5gw-52qq-f42h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v93v-q555-chw5/GHSA-v93v-q555-chw5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wvmg-vpvj-gpv6/GHSA-wvmg-vpvj-gpv6.json diff --git a/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json b/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json index f51535fa48c..e4b972a1556 100644 --- a/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json +++ b/advisories/unreviewed/2023/03/GHSA-cw6j-2v5x-f5m2/GHSA-cw6j-2v5x-f5m2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json b/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json index ba25654551e..9f5f233f4fa 100644 --- a/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json +++ b/advisories/unreviewed/2023/03/GHSA-cxcv-gvhj-5xxg/GHSA-cxcv-gvhj-5xxg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-q5xp-jm46-h2x4/GHSA-q5xp-jm46-h2x4.json b/advisories/unreviewed/2023/03/GHSA-q5xp-jm46-h2x4/GHSA-q5xp-jm46-h2x4.json index ef2a328c432..758031f0a7f 100644 --- a/advisories/unreviewed/2023/03/GHSA-q5xp-jm46-h2x4/GHSA-q5xp-jm46-h2x4.json +++ b/advisories/unreviewed/2023/03/GHSA-q5xp-jm46-h2x4/GHSA-q5xp-jm46-h2x4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-366g-cg6r-xmp2/GHSA-366g-cg6r-xmp2.json b/advisories/unreviewed/2024/05/GHSA-366g-cg6r-xmp2/GHSA-366g-cg6r-xmp2.json index bbdc5a0ea4c..de57fcd13f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-366g-cg6r-xmp2/GHSA-366g-cg6r-xmp2.json +++ b/advisories/unreviewed/2024/05/GHSA-366g-cg6r-xmp2/GHSA-366g-cg6r-xmp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-366g-cg6r-xmp2", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:14Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4793" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-3jvh-pgp8-6866/GHSA-3jvh-pgp8-6866.json b/advisories/unreviewed/2024/05/GHSA-3jvh-pgp8-6866/GHSA-3jvh-pgp8-6866.json index 82cf493d947..4420428b98c 100644 --- a/advisories/unreviewed/2024/05/GHSA-3jvh-pgp8-6866/GHSA-3jvh-pgp8-6866.json +++ b/advisories/unreviewed/2024/05/GHSA-3jvh-pgp8-6866/GHSA-3jvh-pgp8-6866.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3jvh-pgp8-6866", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4817" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-99" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-6484-6mhx-vr77/GHSA-6484-6mhx-vr77.json b/advisories/unreviewed/2024/05/GHSA-6484-6mhx-vr77/GHSA-6484-6mhx-vr77.json index ceda676dfef..0259f0481e8 100644 --- a/advisories/unreviewed/2024/05/GHSA-6484-6mhx-vr77/GHSA-6484-6mhx-vr77.json +++ b/advisories/unreviewed/2024/05/GHSA-6484-6mhx-vr77/GHSA-6484-6mhx-vr77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6484-6mhx-vr77", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4797" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-6ff3-gqc7-rp56/GHSA-6ff3-gqc7-rp56.json b/advisories/unreviewed/2024/05/GHSA-6ff3-gqc7-rp56/GHSA-6ff3-gqc7-rp56.json index 7cfac199c94..68191a500a0 100644 --- a/advisories/unreviewed/2024/05/GHSA-6ff3-gqc7-rp56/GHSA-6ff3-gqc7-rp56.json +++ b/advisories/unreviewed/2024/05/GHSA-6ff3-gqc7-rp56/GHSA-6ff3-gqc7-rp56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6ff3-gqc7-rp56", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4818" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7jp5-5rh9-4q92/GHSA-7jp5-5rh9-4q92.json b/advisories/unreviewed/2024/05/GHSA-7jp5-5rh9-4q92/GHSA-7jp5-5rh9-4q92.json index 31031479346..bb7a8467c6d 100644 --- a/advisories/unreviewed/2024/05/GHSA-7jp5-5rh9-4q92/GHSA-7jp5-5rh9-4q92.json +++ b/advisories/unreviewed/2024/05/GHSA-7jp5-5rh9-4q92/GHSA-7jp5-5rh9-4q92.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jp5-5rh9-4q92", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:14Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4792" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-f9qv-x24h-c8g8/GHSA-f9qv-x24h-c8g8.json b/advisories/unreviewed/2024/05/GHSA-f9qv-x24h-c8g8/GHSA-f9qv-x24h-c8g8.json index 3551abdaaf7..824ac896fa5 100644 --- a/advisories/unreviewed/2024/05/GHSA-f9qv-x24h-c8g8/GHSA-f9qv-x24h-c8g8.json +++ b/advisories/unreviewed/2024/05/GHSA-f9qv-x24h-c8g8/GHSA-f9qv-x24h-c8g8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f9qv-x24h-c8g8", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4819" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -38,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-jvcm-pc6m-g646/GHSA-jvcm-pc6m-g646.json b/advisories/unreviewed/2024/05/GHSA-jvcm-pc6m-g646/GHSA-jvcm-pc6m-g646.json index 6134c102ef2..0175ed5aa35 100644 --- a/advisories/unreviewed/2024/05/GHSA-jvcm-pc6m-g646/GHSA-jvcm-pc6m-g646.json +++ b/advisories/unreviewed/2024/05/GHSA-jvcm-pc6m-g646/GHSA-jvcm-pc6m-g646.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jvcm-pc6m-g646", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:14Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4795" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-rx2j-whx7-3jv5/GHSA-rx2j-whx7-3jv5.json b/advisories/unreviewed/2024/05/GHSA-rx2j-whx7-3jv5/GHSA-rx2j-whx7-3jv5.json index 6d78e2ef2bc..81267592fd0 100644 --- a/advisories/unreviewed/2024/05/GHSA-rx2j-whx7-3jv5/GHSA-rx2j-whx7-3jv5.json +++ b/advisories/unreviewed/2024/05/GHSA-rx2j-whx7-3jv5/GHSA-rx2j-whx7-3jv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rx2j-whx7-3jv5", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:14Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4794" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-x348-5vv2-6fqv/GHSA-x348-5vv2-6fqv.json b/advisories/unreviewed/2024/05/GHSA-x348-5vv2-6fqv/GHSA-x348-5vv2-6fqv.json index 5cd8b5918e9..a9ce46b2c72 100644 --- a/advisories/unreviewed/2024/05/GHSA-x348-5vv2-6fqv/GHSA-x348-5vv2-6fqv.json +++ b/advisories/unreviewed/2024/05/GHSA-x348-5vv2-6fqv/GHSA-x348-5vv2-6fqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x348-5vv2-6fqv", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-20T18:31:15Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4796" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/10/GHSA-jwc3-mm8j-j745/GHSA-jwc3-mm8j-j745.json b/advisories/unreviewed/2024/10/GHSA-jwc3-mm8j-j745/GHSA-jwc3-mm8j-j745.json index a09c49c4e0b..f15ad92c59e 100644 --- a/advisories/unreviewed/2024/10/GHSA-jwc3-mm8j-j745/GHSA-jwc3-mm8j-j745.json +++ b/advisories/unreviewed/2024/10/GHSA-jwc3-mm8j-j745/GHSA-jwc3-mm8j-j745.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-62q4-hc79-94qj/GHSA-62q4-hc79-94qj.json b/advisories/unreviewed/2024/11/GHSA-62q4-hc79-94qj/GHSA-62q4-hc79-94qj.json index 2157a079411..1801cdee2dd 100644 --- a/advisories/unreviewed/2024/11/GHSA-62q4-hc79-94qj/GHSA-62q4-hc79-94qj.json +++ b/advisories/unreviewed/2024/11/GHSA-62q4-hc79-94qj/GHSA-62q4-hc79-94qj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-345", "CWE-348" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/02/GHSA-222j-rx46-g89g/GHSA-222j-rx46-g89g.json b/advisories/unreviewed/2025/02/GHSA-222j-rx46-g89g/GHSA-222j-rx46-g89g.json index 5501a0bf55f..761d72d312e 100644 --- a/advisories/unreviewed/2025/02/GHSA-222j-rx46-g89g/GHSA-222j-rx46-g89g.json +++ b/advisories/unreviewed/2025/02/GHSA-222j-rx46-g89g/GHSA-222j-rx46-g89g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-222j-rx46-g89g", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-19T21:31:37Z", "aliases": [ "CVE-2023-46271" ], "details": "Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T19:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-22ww-35pw-64c4/GHSA-22ww-35pw-64c4.json b/advisories/unreviewed/2025/02/GHSA-22ww-35pw-64c4/GHSA-22ww-35pw-64c4.json new file mode 100644 index 00000000000..201a0f79e08 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-22ww-35pw-64c4/GHSA-22ww-35pw-64c4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22ww-35pw-64c4", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2024-54959" + ], + "details": "Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54959" + }, + { + "type": "WEB", + "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-54959" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2fvw-qmcc-8m37/GHSA-2fvw-qmcc-8m37.json b/advisories/unreviewed/2025/02/GHSA-2fvw-qmcc-8m37/GHSA-2fvw-qmcc-8m37.json new file mode 100644 index 00000000000..0ef7968c9ee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2fvw-qmcc-8m37/GHSA-2fvw-qmcc-8m37.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fvw-qmcc-8m37", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2024-46933" + ], + "details": "An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46933" + }, + { + "type": "WEB", + "url": "https://eviden.com" + }, + { + "type": "WEB", + "url": "https://support.bull.com/ols/product/security/psirt/security-bulletins/ast2600-left-unconfigured-in-bullsequana-xh2140-psirt-270-tlp-clear-version-2-7-cve-2024-46933/view" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json b/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json index 2cd779339db..ed29436f17f 100644 --- a/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json +++ b/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2v3m-p433-pwh8", - "modified": "2025-02-20T15:31:09Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-20T15:31:09Z", "aliases": [ "CVE-2023-51309" ], "details": "A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T15:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-39j3-r3vp-hgfh/GHSA-39j3-r3vp-hgfh.json b/advisories/unreviewed/2025/02/GHSA-39j3-r3vp-hgfh/GHSA-39j3-r3vp-hgfh.json new file mode 100644 index 00000000000..92684b5bf05 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-39j3-r3vp-hgfh/GHSA-39j3-r3vp-hgfh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39j3-r3vp-hgfh", + "modified": "2025-02-20T18:31:25Z", + "published": "2025-02-20T18:31:25Z", + "aliases": [ + "CVE-2024-54961" + ], + "details": "Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54961" + }, + { + "type": "WEB", + "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-54961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3mjx-h33f-j53j/GHSA-3mjx-h33f-j53j.json b/advisories/unreviewed/2025/02/GHSA-3mjx-h33f-j53j/GHSA-3mjx-h33f-j53j.json new file mode 100644 index 00000000000..d4a89c13084 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3mjx-h33f-j53j/GHSA-3mjx-h33f-j53j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mjx-h33f-j53j", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51332" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51332" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176510" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/meeting-room-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3q79-qjgh-rgjv/GHSA-3q79-qjgh-rgjv.json b/advisories/unreviewed/2025/02/GHSA-3q79-qjgh-rgjv/GHSA-3q79-qjgh-rgjv.json new file mode 100644 index 00000000000..83b2ebeb36c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3q79-qjgh-rgjv/GHSA-3q79-qjgh-rgjv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q79-qjgh-rgjv", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2024-54958" + ], + "details": "Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54958" + }, + { + "type": "WEB", + "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-54958" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4346-23fm-8jv5/GHSA-4346-23fm-8jv5.json b/advisories/unreviewed/2025/02/GHSA-4346-23fm-8jv5/GHSA-4346-23fm-8jv5.json new file mode 100644 index 00000000000..b04a9707d86 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4346-23fm-8jv5/GHSA-4346-23fm-8jv5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4346-23fm-8jv5", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26306" + ], + "details": "A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26306" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/324" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json b/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json index b0bf98e60a8..64464acfdd6 100644 --- a/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json +++ b/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-44hx-fmcp-x4qh", - "modified": "2025-02-20T15:31:09Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-20T15:31:09Z", "aliases": [ "CVE-2023-51306" ], "details": "PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"name, title\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T15:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json b/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json index a1444374e60..f5d6d8c18d7 100644 --- a/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json +++ b/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4797-mjw6-28fm", - "modified": "2025-02-20T15:31:10Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-20T15:31:09Z", "aliases": [ "CVE-2023-51312" ], "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T15:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4cmp-m2j4-4727/GHSA-4cmp-m2j4-4727.json b/advisories/unreviewed/2025/02/GHSA-4cmp-m2j4-4727/GHSA-4cmp-m2j4-4727.json new file mode 100644 index 00000000000..00201d2ecea --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4cmp-m2j4-4727/GHSA-4cmp-m2j4-4727.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cmp-m2j4-4727", + "modified": "2025-02-20T18:31:25Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2024-54960" + ], + "details": "A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54960" + }, + { + "type": "WEB", + "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-54960" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4fg5-759r-24x3/GHSA-4fg5-759r-24x3.json b/advisories/unreviewed/2025/02/GHSA-4fg5-759r-24x3/GHSA-4fg5-759r-24x3.json new file mode 100644 index 00000000000..1a8b1d81dcc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4fg5-759r-24x3/GHSA-4fg5-759r-24x3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fg5-759r-24x3", + "modified": "2025-02-20T18:31:25Z", + "published": "2025-02-20T18:31:25Z", + "aliases": [ + "CVE-2025-25968" + ], + "details": "DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml), attackers can bypass access controls, leading to account takeover and potential privilege escalation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25968" + }, + { + "type": "WEB", + "url": "https://github.com/padayali-JD/CVE-2025-25968" + }, + { + "type": "WEB", + "url": "http://ddsn.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json b/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json new file mode 100644 index 00000000000..a91763bdb17 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rhc-2pqf-hqj3", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51321" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51321" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176502" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/night-club-booking-software/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-52f7-5prx-xwxq/GHSA-52f7-5prx-xwxq.json b/advisories/unreviewed/2025/02/GHSA-52f7-5prx-xwxq/GHSA-52f7-5prx-xwxq.json new file mode 100644 index 00000000000..5de2470707c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-52f7-5prx-xwxq/GHSA-52f7-5prx-xwxq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52f7-5prx-xwxq", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26308" + ], + "details": "A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26308" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/326" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-54m8-fp97-8pgr/GHSA-54m8-fp97-8pgr.json b/advisories/unreviewed/2025/02/GHSA-54m8-fp97-8pgr/GHSA-54m8-fp97-8pgr.json index f81b93a39db..81895a68f22 100644 --- a/advisories/unreviewed/2025/02/GHSA-54m8-fp97-8pgr/GHSA-54m8-fp97-8pgr.json +++ b/advisories/unreviewed/2025/02/GHSA-54m8-fp97-8pgr/GHSA-54m8-fp97-8pgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54m8-fp97-8pgr", - "modified": "2025-02-12T12:30:48Z", + "modified": "2025-02-20T18:31:21Z", "published": "2025-02-12T12:30:47Z", "aliases": [ "CVE-2024-13477" diff --git a/advisories/unreviewed/2025/02/GHSA-582h-7xj3-j2rp/GHSA-582h-7xj3-j2rp.json b/advisories/unreviewed/2025/02/GHSA-582h-7xj3-j2rp/GHSA-582h-7xj3-j2rp.json index e259944ba1f..2ee10553f66 100644 --- a/advisories/unreviewed/2025/02/GHSA-582h-7xj3-j2rp/GHSA-582h-7xj3-j2rp.json +++ b/advisories/unreviewed/2025/02/GHSA-582h-7xj3-j2rp/GHSA-582h-7xj3-j2rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-582h-7xj3-j2rp", - "modified": "2025-02-01T15:32:58Z", + "modified": "2025-02-20T18:31:17Z", "published": "2025-02-01T15:32:58Z", "aliases": [ "CVE-2024-13612" diff --git a/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json b/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json new file mode 100644 index 00000000000..c37d3919ee1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mxv-j9vc-66x9", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51324" + ], + "details": "PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51324" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176504" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/shared-asset-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5xxj-pf2m-pqvc/GHSA-5xxj-pf2m-pqvc.json b/advisories/unreviewed/2025/02/GHSA-5xxj-pf2m-pqvc/GHSA-5xxj-pf2m-pqvc.json index 14fb718afad..3266eafc89b 100644 --- a/advisories/unreviewed/2025/02/GHSA-5xxj-pf2m-pqvc/GHSA-5xxj-pf2m-pqvc.json +++ b/advisories/unreviewed/2025/02/GHSA-5xxj-pf2m-pqvc/GHSA-5xxj-pf2m-pqvc.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json b/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json new file mode 100644 index 00000000000..68bc35ad6da --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c6v-3v49-q93r", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51326" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51326" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176506" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cleaning-business-software/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6pc6-7fmg-34vv/GHSA-6pc6-7fmg-34vv.json b/advisories/unreviewed/2025/02/GHSA-6pc6-7fmg-34vv/GHSA-6pc6-7fmg-34vv.json new file mode 100644 index 00000000000..c30d4136649 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6pc6-7fmg-34vv/GHSA-6pc6-7fmg-34vv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pc6-7fmg-34vv", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2023-51333" + ], + "details": "PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51333" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176511" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7q78-98r8-9mh7/GHSA-7q78-98r8-9mh7.json b/advisories/unreviewed/2025/02/GHSA-7q78-98r8-9mh7/GHSA-7q78-98r8-9mh7.json new file mode 100644 index 00000000000..c2891b9c708 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7q78-98r8-9mh7/GHSA-7q78-98r8-9mh7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q78-98r8-9mh7", + "modified": "2025-02-20T18:31:25Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2024-55457" + ], + "details": "MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially exposing sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55457" + }, + { + "type": "WEB", + "url": "https://github.com/h13nh04ng/CVE-2024-55457-PoC" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json b/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json new file mode 100644 index 00000000000..bb611caaf8b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v2p-6g6r-9hjw", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26305" + ], + "details": "A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26305" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/322" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-826p-m378-hr47/GHSA-826p-m378-hr47.json b/advisories/unreviewed/2025/02/GHSA-826p-m378-hr47/GHSA-826p-m378-hr47.json new file mode 100644 index 00000000000..e5a9bfb9bae --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-826p-m378-hr47/GHSA-826p-m378-hr47.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-826p-m378-hr47", + "modified": "2025-02-20T18:31:25Z", + "published": "2025-02-20T18:31:25Z", + "aliases": [ + "CVE-2025-1258" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1258" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-82x8-7f5g-jqhm/GHSA-82x8-7f5g-jqhm.json b/advisories/unreviewed/2025/02/GHSA-82x8-7f5g-jqhm/GHSA-82x8-7f5g-jqhm.json new file mode 100644 index 00000000000..0677a7a8136 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-82x8-7f5g-jqhm/GHSA-82x8-7f5g-jqhm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82x8-7f5g-jqhm", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26309" + ], + "details": "A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26309" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/327" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json b/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json new file mode 100644 index 00000000000..e5b16831778 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-846x-232r-8564/GHSA-846x-232r-8564.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-846x-232r-8564", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26307" + ], + "details": "A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26307" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/325" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json b/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json index 6a3a667bbb1..b194f7eb1e9 100644 --- a/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json +++ b/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-93jg-3qrg-49hq", - "modified": "2025-02-20T15:31:10Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-20T15:31:10Z", "aliases": [ "CVE-2023-51315" ], "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T15:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-988j-96m5-5f85/GHSA-988j-96m5-5f85.json b/advisories/unreviewed/2025/02/GHSA-988j-96m5-5f85/GHSA-988j-96m5-5f85.json index fe44af10699..38031bb19fe 100644 --- a/advisories/unreviewed/2025/02/GHSA-988j-96m5-5f85/GHSA-988j-96m5-5f85.json +++ b/advisories/unreviewed/2025/02/GHSA-988j-96m5-5f85/GHSA-988j-96m5-5f85.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-988j-96m5-5f85", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T18:31:21Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2020-13481" ], "details": "Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T19:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json b/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json new file mode 100644 index 00000000000..0388a8eca06 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-995j-3cj2-3p49", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51327" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51327" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176506" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cleaning-business-software/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json b/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json index 4e7a09529fd..65772f7318a 100644 --- a/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json +++ b/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json b/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json index d3ab2621241..80e70d955b8 100644 --- a/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json +++ b/advisories/unreviewed/2025/02/GHSA-9hm7-j2jc-wh96/GHSA-9hm7-j2jc-wh96.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json b/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json index 6ac827d9d13..c6600d59b7e 100644 --- a/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json +++ b/advisories/unreviewed/2025/02/GHSA-9m2c-327v-gghq/GHSA-9m2c-327v-gghq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-ch24-jfhg-w5qp/GHSA-ch24-jfhg-w5qp.json b/advisories/unreviewed/2025/02/GHSA-ch24-jfhg-w5qp/GHSA-ch24-jfhg-w5qp.json new file mode 100644 index 00000000000..db09772b857 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ch24-jfhg-w5qp/GHSA-ch24-jfhg-w5qp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch24-jfhg-w5qp", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26310" + ], + "details": "Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted ABC file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26310" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/328" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f4fr-x852-8ppx/GHSA-f4fr-x852-8ppx.json b/advisories/unreviewed/2025/02/GHSA-f4fr-x852-8ppx/GHSA-f4fr-x852-8ppx.json new file mode 100644 index 00000000000..efdeb10b025 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f4fr-x852-8ppx/GHSA-f4fr-x852-8ppx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4fr-x852-8ppx", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51330" + ], + "details": "PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu \"date\" parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51330" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176508" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json b/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json new file mode 100644 index 00000000000..c59977d7e83 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq4q-m37q-rfrh", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51331" + ], + "details": "PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51331" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176509" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cleaning-business-software/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g6m2-22qr-9mgq/GHSA-g6m2-22qr-9mgq.json b/advisories/unreviewed/2025/02/GHSA-g6m2-22qr-9mgq/GHSA-g6m2-22qr-9mgq.json index 33b3aa3ab20..4e45f43f5f5 100644 --- a/advisories/unreviewed/2025/02/GHSA-g6m2-22qr-9mgq/GHSA-g6m2-22qr-9mgq.json +++ b/advisories/unreviewed/2025/02/GHSA-g6m2-22qr-9mgq/GHSA-g6m2-22qr-9mgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g6m2-22qr-9mgq", - "modified": "2025-02-12T12:30:48Z", + "modified": "2025-02-20T18:31:20Z", "published": "2025-02-12T12:30:48Z", "aliases": [ "CVE-2024-10960" diff --git a/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json b/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json new file mode 100644 index 00000000000..c1871d7d6bf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7x3-m53h-j2jq", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51320" + ], + "details": "PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51320" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176501" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/night-club-booking-software/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gmw5-xjxq-3255/GHSA-gmw5-xjxq-3255.json b/advisories/unreviewed/2025/02/GHSA-gmw5-xjxq-3255/GHSA-gmw5-xjxq-3255.json new file mode 100644 index 00000000000..b54a80a6a42 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gmw5-xjxq-3255/GHSA-gmw5-xjxq-3255.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmw5-xjxq-3255", + "modified": "2025-02-20T18:31:25Z", + "published": "2025-02-20T18:31:25Z", + "aliases": [ + "CVE-2025-25973" + ], + "details": "A stored Cross Site Scripting vulnerability in the \"related recommendations\" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25973" + }, + { + "type": "WEB", + "url": "https://github.com/yandaozi/PPress/issues/3" + }, + { + "type": "WEB", + "url": "https://gist.github.com/coleak2021/512acaa12ba0987499d560967acff1d1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hf3x-74c5-wrcm/GHSA-hf3x-74c5-wrcm.json b/advisories/unreviewed/2025/02/GHSA-hf3x-74c5-wrcm/GHSA-hf3x-74c5-wrcm.json new file mode 100644 index 00000000000..90348ab94c6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hf3x-74c5-wrcm/GHSA-hf3x-74c5-wrcm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf3x-74c5-wrcm", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2023-51334" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51334" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176512" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hq6p-qj55-2rrc/GHSA-hq6p-qj55-2rrc.json b/advisories/unreviewed/2025/02/GHSA-hq6p-qj55-2rrc/GHSA-hq6p-qj55-2rrc.json new file mode 100644 index 00000000000..9e3ab796f45 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hq6p-qj55-2rrc/GHSA-hq6p-qj55-2rrc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq6p-qj55-2rrc", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51318" + ], + "details": "PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"title, name\" parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51318" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176499" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/bus-reservation-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json b/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json new file mode 100644 index 00000000000..e78b4ad873f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j946-qf4c-jrjh", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51323" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51323" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176503" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/shared-asset-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jc5r-26g5-fr8w/GHSA-jc5r-26g5-fr8w.json b/advisories/unreviewed/2025/02/GHSA-jc5r-26g5-fr8w/GHSA-jc5r-26g5-fr8w.json new file mode 100644 index 00000000000..937c8abc66e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jc5r-26g5-fr8w/GHSA-jc5r-26g5-fr8w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc5r-26g5-fr8w", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26311" + ], + "details": "Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted SWF file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26311" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/329" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4mm-534h-5cp5/GHSA-m4mm-534h-5cp5.json b/advisories/unreviewed/2025/02/GHSA-m4mm-534h-5cp5/GHSA-m4mm-534h-5cp5.json new file mode 100644 index 00000000000..1b31a9d1b6b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4mm-534h-5cp5/GHSA-m4mm-534h-5cp5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4mm-534h-5cp5", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2024-57716" + ], + "details": "An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57716" + }, + { + "type": "WEB", + "url": "https://github.com/pentesttoolscom/vulnerability-research/tree/master/CVE-2024-57716" + }, + { + "type": "WEB", + "url": "https://github.com/trenoncourt/AutoQueryable" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p6g2-26xx-9595/GHSA-p6g2-26xx-9595.json b/advisories/unreviewed/2025/02/GHSA-p6g2-26xx-9595/GHSA-p6g2-26xx-9595.json index ac47d4366cc..fcca141197f 100644 --- a/advisories/unreviewed/2025/02/GHSA-p6g2-26xx-9595/GHSA-p6g2-26xx-9595.json +++ b/advisories/unreviewed/2025/02/GHSA-p6g2-26xx-9595/GHSA-p6g2-26xx-9595.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p6g2-26xx-9595", - "modified": "2025-02-19T18:32:24Z", + "modified": "2025-02-20T18:31:21Z", "published": "2025-02-19T18:32:24Z", "aliases": [ "CVE-2020-10095" ], "details": "Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T18:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-ppv4-h8g5-c5h4/GHSA-ppv4-h8g5-c5h4.json b/advisories/unreviewed/2025/02/GHSA-ppv4-h8g5-c5h4/GHSA-ppv4-h8g5-c5h4.json index bc0c052501e..09b4a3257f5 100644 --- a/advisories/unreviewed/2025/02/GHSA-ppv4-h8g5-c5h4/GHSA-ppv4-h8g5-c5h4.json +++ b/advisories/unreviewed/2025/02/GHSA-ppv4-h8g5-c5h4/GHSA-ppv4-h8g5-c5h4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json b/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json index ee5cf21219b..8ef462f14fb 100644 --- a/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json +++ b/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pqch-79w5-3vfc", - "modified": "2025-02-19T06:35:15Z", + "modified": "2025-02-20T18:31:21Z", "published": "2025-02-19T06:35:15Z", "aliases": [ "CVE-2024-12173" ], "details": "The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T06:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rw8h-38j7-m52m/GHSA-rw8h-38j7-m52m.json b/advisories/unreviewed/2025/02/GHSA-rw8h-38j7-m52m/GHSA-rw8h-38j7-m52m.json new file mode 100644 index 00000000000..cd17a4a7e63 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rw8h-38j7-m52m/GHSA-rw8h-38j7-m52m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw8h-38j7-m52m", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2023-51335" + ], + "details": "PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"title, name\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51335" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176508" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v5gw-52qq-f42h/GHSA-v5gw-52qq-f42h.json b/advisories/unreviewed/2025/02/GHSA-v5gw-52qq-f42h/GHSA-v5gw-52qq-f42h.json new file mode 100644 index 00000000000..edaf9672fd6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v5gw-52qq-f42h/GHSA-v5gw-52qq-f42h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5gw-52qq-f42h", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51319" + ], + "details": "PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51319" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176500" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/bus-reservation-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json b/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json index ee6b2ed0b00..6a703f4ca08 100644 --- a/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json +++ b/advisories/unreviewed/2025/02/GHSA-v685-v3qp-pgjp/GHSA-v685-v3qp-pgjp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v685-v3qp-pgjp", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51293" ], "details": "A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T19:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v93v-q555-chw5/GHSA-v93v-q555-chw5.json b/advisories/unreviewed/2025/02/GHSA-v93v-q555-chw5/GHSA-v93v-q555-chw5.json new file mode 100644 index 00000000000..75566d215f8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v93v-q555-chw5/GHSA-v93v-q555-chw5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v93v-q555-chw5", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2023-51325" + ], + "details": "PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"title, name\" parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51325" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176505" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/shared-asset-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json b/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json new file mode 100644 index 00000000000..f09fe783088 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmh9-7gfq-4r2p", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:22Z", + "aliases": [ + "CVE-2023-51317" + ], + "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51317" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176493" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/restaurant-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json b/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json new file mode 100644 index 00000000000..4c6c92f8e27 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr7m-6pgw-3493", + "modified": "2025-02-20T18:31:24Z", + "published": "2025-02-20T18:31:24Z", + "aliases": [ + "CVE-2025-26304" + ], + "details": "A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26304" + }, + { + "type": "WEB", + "url": "https://github.com/libming/libming/issues/323" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json b/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json index 9e7f37ead4b..b7c4abf51d6 100644 --- a/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json +++ b/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wq23-w7cm-hgg8", - "modified": "2025-02-20T15:31:09Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-20T15:31:09Z", "aliases": [ "CVE-2023-51310" ], "details": "A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T15:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-wvmg-vpvj-gpv6/GHSA-wvmg-vpvj-gpv6.json b/advisories/unreviewed/2025/02/GHSA-wvmg-vpvj-gpv6/GHSA-wvmg-vpvj-gpv6.json new file mode 100644 index 00000000000..288a1dd7eb8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wvmg-vpvj-gpv6/GHSA-wvmg-vpvj-gpv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvmg-vpvj-gpv6", + "modified": "2025-02-20T18:31:23Z", + "published": "2025-02-20T18:31:23Z", + "aliases": [ + "CVE-2025-0161" + ], + "details": "IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0161" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7183788" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x699-5cwx-5543/GHSA-x699-5cwx-5543.json b/advisories/unreviewed/2025/02/GHSA-x699-5cwx-5543/GHSA-x699-5cwx-5543.json index 87c6876d7c4..590ed11293a 100644 --- a/advisories/unreviewed/2025/02/GHSA-x699-5cwx-5543/GHSA-x699-5cwx-5543.json +++ b/advisories/unreviewed/2025/02/GHSA-x699-5cwx-5543/GHSA-x699-5cwx-5543.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x699-5cwx-5543", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T18:31:22Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-46272" ], "details": "Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T19:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-x8q5-c934-chcc/GHSA-x8q5-c934-chcc.json b/advisories/unreviewed/2025/02/GHSA-x8q5-c934-chcc/GHSA-x8q5-c934-chcc.json index 022cee5a8ef..d843f919fbb 100644 --- a/advisories/unreviewed/2025/02/GHSA-x8q5-c934-chcc/GHSA-x8q5-c934-chcc.json +++ b/advisories/unreviewed/2025/02/GHSA-x8q5-c934-chcc/GHSA-x8q5-c934-chcc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8q5-c934-chcc", - "modified": "2025-02-19T21:31:37Z", + "modified": "2025-02-20T18:31:21Z", "published": "2025-02-19T21:31:37Z", "aliases": [ "CVE-2020-35546" ], "details": "Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T19:15:10Z"