From 727bf1a2d54db04b1ce8143dd76724eee5b0cbff Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Mar 2025 15:32:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-q7jg-7ww6-99x3.json | 6 +- .../GHSA-hpgv-925g-4mjf.json | 2 +- .../GHSA-787r-j94j-7wpv.json | 2 +- .../GHSA-h929-hv54-38w3.json | 8 ++- .../GHSA-5r3q-45rq-jqw2.json | 4 +- .../GHSA-fv9f-467f-xm3f.json | 4 +- .../GHSA-cjqq-r96c-pwrf.json | 8 ++- .../GHSA-pvfc-97vc-2gh2.json | 11 +++- .../GHSA-72mh-pf6c-wq87.json | 4 +- .../GHSA-7q4j-f74f-6h5j.json | 10 +++- .../GHSA-fc77-f4hm-5777.json | 3 +- .../GHSA-q25c-28ww-34p7.json | 4 +- .../GHSA-qw4m-qq5c-43c6.json | 4 +- .../GHSA-rvvh-69h4-9624.json | 4 +- .../GHSA-vvjf-wxwg-9pcv.json | 4 +- .../GHSA-65q8-wrmh-rrcm.json | 4 +- .../GHSA-8x82-8rpw-g64h.json | 4 +- .../GHSA-93r2-j783-g4wf.json | 4 +- .../GHSA-9rg3-9338-mwcv.json | 4 +- .../GHSA-qcjx-5p37-v6hf.json | 4 +- .../GHSA-5749-g4w5-q5jv.json | 15 +++-- .../GHSA-2gcq-cww3-j4hr.json | 3 +- .../GHSA-3jfq-4f5c-mp6v.json | 1 + .../GHSA-7jvg-x7c5-xw29.json | 1 + .../GHSA-2j99-5q75-3f57.json | 18 +++++- .../GHSA-5p7f-cf35-c9jf.json | 33 ++++++++++ .../GHSA-694q-974v-33w7.json | 33 ++++++++++ .../GHSA-7f92-xqqr-xjhw.json | 29 +++++++++ .../GHSA-9h83-mr4r-fjq2.json | 36 +++++++++++ .../GHSA-jxrw-5fgg-2485.json | 1 + .../GHSA-mqcq-x9x6-xrvj.json | 60 +++++++++++++++++++ .../GHSA-pvrp-6fjq-x9rj.json | 29 +++++++++ .../GHSA-q7g9-5h8f-gjrc.json | 33 ++++++++++ .../GHSA-v4v8-93mw-cjfm.json | 40 +++++++++++++ .../GHSA-whf8-w5vj-q4w6.json | 29 +++++++++ 35 files changed, 426 insertions(+), 33 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7f92-xqqr-xjhw/GHSA-7f92-xqqr-xjhw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9h83-mr4r-fjq2/GHSA-9h83-mr4r-fjq2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mqcq-x9x6-xrvj/GHSA-mqcq-x9x6-xrvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pvrp-6fjq-x9rj/GHSA-pvrp-6fjq-x9rj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q7g9-5h8f-gjrc/GHSA-q7g9-5h8f-gjrc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v4v8-93mw-cjfm/GHSA-v4v8-93mw-cjfm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json diff --git a/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json b/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json index ea9f28ae204..688fbf79c9f 100644 --- a/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json +++ b/advisories/unreviewed/2022/05/GHSA-q7jg-7ww6-99x3/GHSA-q7jg-7ww6-99x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q7jg-7ww6-99x3", - "modified": "2024-04-04T01:55:47Z", + "modified": "2025-03-20T15:30:23Z", "published": "2022-05-24T16:56:04Z", "aliases": [ "CVE-2019-16261" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://blog.korelogic.com/blog/2019/08/19/unpatched_fringe_infrastructure_bits" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Mar/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/02/GHSA-hpgv-925g-4mjf/GHSA-hpgv-925g-4mjf.json b/advisories/unreviewed/2023/02/GHSA-hpgv-925g-4mjf/GHSA-hpgv-925g-4mjf.json index 83042c63f12..ec599a952d2 100644 --- a/advisories/unreviewed/2023/02/GHSA-hpgv-925g-4mjf/GHSA-hpgv-925g-4mjf.json +++ b/advisories/unreviewed/2023/02/GHSA-hpgv-925g-4mjf/GHSA-hpgv-925g-4mjf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hpgv-925g-4mjf", - "modified": "2023-02-23T06:30:18Z", + "modified": "2025-03-20T15:30:25Z", "published": "2023-02-16T00:30:27Z", "aliases": [ "CVE-2021-34117" diff --git a/advisories/unreviewed/2023/03/GHSA-787r-j94j-7wpv/GHSA-787r-j94j-7wpv.json b/advisories/unreviewed/2023/03/GHSA-787r-j94j-7wpv/GHSA-787r-j94j-7wpv.json index 6f057df2952..ee0cb516e61 100644 --- a/advisories/unreviewed/2023/03/GHSA-787r-j94j-7wpv/GHSA-787r-j94j-7wpv.json +++ b/advisories/unreviewed/2023/03/GHSA-787r-j94j-7wpv/GHSA-787r-j94j-7wpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-787r-j94j-7wpv", - "modified": "2023-03-10T03:30:14Z", + "modified": "2025-03-20T15:30:25Z", "published": "2023-03-01T21:30:18Z", "aliases": [ "CVE-2023-23003" diff --git a/advisories/unreviewed/2024/03/GHSA-h929-hv54-38w3/GHSA-h929-hv54-38w3.json b/advisories/unreviewed/2024/03/GHSA-h929-hv54-38w3/GHSA-h929-hv54-38w3.json index dae3e96827b..5697a0eb931 100644 --- a/advisories/unreviewed/2024/03/GHSA-h929-hv54-38w3/GHSA-h929-hv54-38w3.json +++ b/advisories/unreviewed/2024/03/GHSA-h929-hv54-38w3/GHSA-h929-hv54-38w3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h929-hv54-38w3", - "modified": "2024-03-28T18:30:46Z", + "modified": "2025-03-20T15:30:25Z", "published": "2024-03-28T18:30:46Z", "aliases": [ "CVE-2023-29162" ], - "details": "Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.\n\n", + "details": "Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5r3q-45rq-jqw2/GHSA-5r3q-45rq-jqw2.json b/advisories/unreviewed/2024/04/GHSA-5r3q-45rq-jqw2/GHSA-5r3q-45rq-jqw2.json index 7cfd1af144d..c8000c2df22 100644 --- a/advisories/unreviewed/2024/04/GHSA-5r3q-45rq-jqw2/GHSA-5r3q-45rq-jqw2.json +++ b/advisories/unreviewed/2024/04/GHSA-5r3q-45rq-jqw2/GHSA-5r3q-45rq-jqw2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json b/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json index eebb7ce6fe1..1d3c6442dd3 100644 --- a/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json +++ b/advisories/unreviewed/2024/04/GHSA-fv9f-467f-xm3f/GHSA-fv9f-467f-xm3f.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cjqq-r96c-pwrf/GHSA-cjqq-r96c-pwrf.json b/advisories/unreviewed/2024/05/GHSA-cjqq-r96c-pwrf/GHSA-cjqq-r96c-pwrf.json index ad929806004..25a4c759582 100644 --- a/advisories/unreviewed/2024/05/GHSA-cjqq-r96c-pwrf/GHSA-cjqq-r96c-pwrf.json +++ b/advisories/unreviewed/2024/05/GHSA-cjqq-r96c-pwrf/GHSA-cjqq-r96c-pwrf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cjqq-r96c-pwrf", - "modified": "2025-02-13T18:32:29Z", + "modified": "2025-03-20T15:30:26Z", "published": "2024-05-14T18:30:58Z", "aliases": [ "CVE-2024-0762" ], - "details": "Potential buffer overflow \nin unsafe UEFI variable handling \n\nin Phoenix SecureCore™ for select Intel platforms\n\nThis issue affects:\n\nPhoenix \n\nSecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998;\n\nPhoenix \n\nSecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562;\n\nPhoenix \n\nSecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323;\n\nPhoenix \n\nSecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287;\n\nPhoenix \n\nSecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236;\n\nPhoenix \n\nSecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184;\n\nPhoenix \n\nSecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269;\n\nPhoenix \n\nSecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218;\n\nPhoenix \n\nSecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.\n\n", + "details": "Potential buffer overflow \nin unsafe UEFI variable handling \n\nin Phoenix SecureCore™ for select Intel platforms\n\nThis issue affects:\n\nPhoenix \n\nSecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998;\n\nPhoenix \n\nSecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562;\n\nPhoenix \n\nSecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323;\n\nPhoenix \n\nSecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287;\n\nPhoenix \n\nSecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236;\n\nPhoenix \n\nSecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184;\n\nPhoenix \n\nSecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269;\n\nPhoenix \n\nSecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218;\n\nPhoenix \n\nSecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.", "severity": [ { "type": "CVSS_V3", @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json b/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json index bc8f057dad2..718a4011213 100644 --- a/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json +++ b/advisories/unreviewed/2024/05/GHSA-pvfc-97vc-2gh2/GHSA-pvfc-97vc-2gh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvfc-97vc-2gh2", - "modified": "2024-05-03T06:30:35Z", + "modified": "2025-03-20T15:30:26Z", "published": "2024-05-03T06:30:35Z", "aliases": [ "CVE-2024-3637" ], "details": "The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-03T06:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json b/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json index ede9c539e9d..5e2d658c962 100644 --- a/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json +++ b/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7q4j-f74f-6h5j/GHSA-7q4j-f74f-6h5j.json b/advisories/unreviewed/2024/07/GHSA-7q4j-f74f-6h5j/GHSA-7q4j-f74f-6h5j.json index ef679227cb8..e8899bcadbf 100644 --- a/advisories/unreviewed/2024/07/GHSA-7q4j-f74f-6h5j/GHSA-7q4j-f74f-6h5j.json +++ b/advisories/unreviewed/2024/07/GHSA-7q4j-f74f-6h5j/GHSA-7q4j-f74f-6h5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q4j-f74f-6h5j", - "modified": "2024-07-08T18:31:15Z", + "modified": "2025-03-20T15:30:26Z", "published": "2024-07-05T03:30:41Z", "aliases": [ "CVE-2023-52340" @@ -26,10 +26,16 @@ { "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=af6d10345ca76670c1b7c37799f0d5576ccef277" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240816-0005" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-fc77-f4hm-5777/GHSA-fc77-f4hm-5777.json b/advisories/unreviewed/2024/07/GHSA-fc77-f4hm-5777/GHSA-fc77-f4hm-5777.json index 06eebbffae7..291769d7276 100644 --- a/advisories/unreviewed/2024/07/GHSA-fc77-f4hm-5777/GHSA-fc77-f4hm-5777.json +++ b/advisories/unreviewed/2024/07/GHSA-fc77-f4hm-5777/GHSA-fc77-f4hm-5777.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1284" + "CWE-1284", + "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json b/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json index 49de6dda505..3074e038e7e 100644 --- a/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json +++ b/advisories/unreviewed/2024/07/GHSA-q25c-28ww-34p7/GHSA-q25c-28ww-34p7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-qw4m-qq5c-43c6/GHSA-qw4m-qq5c-43c6.json b/advisories/unreviewed/2024/07/GHSA-qw4m-qq5c-43c6/GHSA-qw4m-qq5c-43c6.json index 7368ae0aafd..a6fe457bfd3 100644 --- a/advisories/unreviewed/2024/07/GHSA-qw4m-qq5c-43c6/GHSA-qw4m-qq5c-43c6.json +++ b/advisories/unreviewed/2024/07/GHSA-qw4m-qq5c-43c6/GHSA-qw4m-qq5c-43c6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rvvh-69h4-9624/GHSA-rvvh-69h4-9624.json b/advisories/unreviewed/2024/07/GHSA-rvvh-69h4-9624/GHSA-rvvh-69h4-9624.json index 900907ecdb4..d5a1f111b1b 100644 --- a/advisories/unreviewed/2024/07/GHSA-rvvh-69h4-9624/GHSA-rvvh-69h4-9624.json +++ b/advisories/unreviewed/2024/07/GHSA-rvvh-69h4-9624/GHSA-rvvh-69h4-9624.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vvjf-wxwg-9pcv/GHSA-vvjf-wxwg-9pcv.json b/advisories/unreviewed/2024/07/GHSA-vvjf-wxwg-9pcv/GHSA-vvjf-wxwg-9pcv.json index ea09aeac1a6..738678a06c0 100644 --- a/advisories/unreviewed/2024/07/GHSA-vvjf-wxwg-9pcv/GHSA-vvjf-wxwg-9pcv.json +++ b/advisories/unreviewed/2024/07/GHSA-vvjf-wxwg-9pcv/GHSA-vvjf-wxwg-9pcv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json b/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json index be372166583..5b28b79c4fb 100644 --- a/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json +++ b/advisories/unreviewed/2024/08/GHSA-65q8-wrmh-rrcm/GHSA-65q8-wrmh-rrcm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-259" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json b/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json index b2a390e5ae5..f0875415a61 100644 --- a/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json +++ b/advisories/unreviewed/2024/09/GHSA-8x82-8rpw-g64h/GHSA-8x82-8rpw-g64h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json b/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json index a9e65a91eee..83d43a27120 100644 --- a/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json +++ b/advisories/unreviewed/2024/09/GHSA-93r2-j783-g4wf/GHSA-93r2-j783-g4wf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json b/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json index 226288f7ec3..75b59d00b2a 100644 --- a/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json +++ b/advisories/unreviewed/2024/09/GHSA-9rg3-9338-mwcv/GHSA-9rg3-9338-mwcv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json b/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json index 16345ee45fb..0ab7b75c14f 100644 --- a/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json +++ b/advisories/unreviewed/2024/09/GHSA-qcjx-5p37-v6hf/GHSA-qcjx-5p37-v6hf.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json b/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json index f1c54f313ed..3500b7206b3 100644 --- a/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json +++ b/advisories/unreviewed/2024/11/GHSA-5749-g4w5-q5jv/GHSA-5749-g4w5-q5jv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5749-g4w5-q5jv", - "modified": "2024-11-18T18:30:59Z", + "modified": "2025-03-20T15:30:28Z", "published": "2024-11-18T18:30:59Z", "aliases": [ "CVE-2024-44756" ], "details": "NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-18T17:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2gcq-cww3-j4hr/GHSA-2gcq-cww3-j4hr.json b/advisories/unreviewed/2025/01/GHSA-2gcq-cww3-j4hr/GHSA-2gcq-cww3-j4hr.json index 71c36c38b6b..41ffd5592d5 100644 --- a/advisories/unreviewed/2025/01/GHSA-2gcq-cww3-j4hr/GHSA-2gcq-cww3-j4hr.json +++ b/advisories/unreviewed/2025/01/GHSA-2gcq-cww3-j4hr/GHSA-2gcq-cww3-j4hr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-843" + "CWE-843", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json b/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json index 96a9d01cbb2..b072525e5b9 100644 --- a/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json +++ b/advisories/unreviewed/2025/01/GHSA-3jfq-4f5c-mp6v/GHSA-3jfq-4f5c-mp6v.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json b/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json index 43ad7d650d5..f268cf869fc 100644 --- a/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json +++ b/advisories/unreviewed/2025/01/GHSA-7jvg-x7c5-xw29/GHSA-7jvg-x7c5-xw29.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-703", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json index 7187eab78d5..f00e185efa6 100644 --- a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json +++ b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j99-5q75-3f57", - "modified": "2025-03-12T21:31:29Z", + "modified": "2025-03-20T15:30:31Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2025-24201" @@ -34,6 +34,22 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/122285" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Mar/2" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Mar/3" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Mar/4" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/Mar/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json b/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json new file mode 100644 index 00000000000..fe304702208 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p7f-cf35-c9jf", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2025-29412" + ], + "details": "A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29412" + }, + { + "type": "WEB", + "url": "https://github.com/MartMbithi/iBanking/issues/11" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-29412-cross-site-scripting-xss-vulnerability-in-ibanking-v2-0-0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json b/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json new file mode 100644 index 00000000000..23c67d92028 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-694q-974v-33w7", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2025-29410" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29410" + }, + { + "type": "WEB", + "url": "https://github.com/kishan0725/Hospital-Management-System/issues/49" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-29410-hospital-management-system-xss-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7f92-xqqr-xjhw/GHSA-7f92-xqqr-xjhw.json b/advisories/unreviewed/2025/03/GHSA-7f92-xqqr-xjhw/GHSA-7f92-xqqr-xjhw.json new file mode 100644 index 00000000000..bf8e08ff773 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7f92-xqqr-xjhw/GHSA-7f92-xqqr-xjhw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f92-xqqr-xjhw", + "modified": "2025-03-20T15:30:35Z", + "published": "2025-03-20T15:30:35Z", + "aliases": [ + "CVE-2025-29101" + ], + "details": "Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29101" + }, + { + "type": "WEB", + "url": "https://github.com/Raining-101/IOT_cve/blob/main/tenda-ac8_get_parentControl_list_Info_overflow.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9h83-mr4r-fjq2/GHSA-9h83-mr4r-fjq2.json b/advisories/unreviewed/2025/03/GHSA-9h83-mr4r-fjq2/GHSA-9h83-mr4r-fjq2.json new file mode 100644 index 00000000000..99c2a85ff78 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9h83-mr4r-fjq2/GHSA-9h83-mr4r-fjq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h83-mr4r-fjq2", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2025-0254" + ], + "details": "HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0254" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120000" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json b/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json index a798c44adc9..298f6ff81e5 100644 --- a/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json +++ b/advisories/unreviewed/2025/03/GHSA-jxrw-5fgg-2485/GHSA-jxrw-5fgg-2485.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-201", "CWE-281" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/03/GHSA-mqcq-x9x6-xrvj/GHSA-mqcq-x9x6-xrvj.json b/advisories/unreviewed/2025/03/GHSA-mqcq-x9x6-xrvj/GHSA-mqcq-x9x6-xrvj.json new file mode 100644 index 00000000000..53dd683a15c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mqcq-x9x6-xrvj/GHSA-mqcq-x9x6-xrvj.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqcq-x9x6-xrvj", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2025-2546" + ], + "details": "A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The manipulation leads to improper access controls. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2546" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/D-Link-DIR-605L-formAdvFirewall-1b153a41781f80aca28ec11da787f0e8?pvs=4" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/D-Link-DIR-618-formAdvFirewall-1b053a41781f801ca1a5e09bb83a22c5?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300160" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300160" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516788" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pvrp-6fjq-x9rj/GHSA-pvrp-6fjq-x9rj.json b/advisories/unreviewed/2025/03/GHSA-pvrp-6fjq-x9rj/GHSA-pvrp-6fjq-x9rj.json new file mode 100644 index 00000000000..73d28bfaa56 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pvrp-6fjq-x9rj/GHSA-pvrp-6fjq-x9rj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvrp-6fjq-x9rj", + "modified": "2025-03-20T15:30:35Z", + "published": "2025-03-20T15:30:35Z", + "aliases": [ + "CVE-2024-48590" + ], + "details": "Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48590" + }, + { + "type": "WEB", + "url": "https://github.com/GCatt-AS/CVE-2024-48590/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q7g9-5h8f-gjrc/GHSA-q7g9-5h8f-gjrc.json b/advisories/unreviewed/2025/03/GHSA-q7g9-5h8f-gjrc/GHSA-q7g9-5h8f-gjrc.json new file mode 100644 index 00000000000..e2bd5710ae1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q7g9-5h8f-gjrc/GHSA-q7g9-5h8f-gjrc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7g9-5h8f-gjrc", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2025-29411" + ], + "details": "An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29411" + }, + { + "type": "WEB", + "url": "https://github.com/MartMbithi/iBanking/issues/12" + }, + { + "type": "WEB", + "url": "https://www.simonjuguna.com/cve-2025-29411-authenticated-remote-code-execution-rce-via-arbitrary-file-upload" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v4v8-93mw-cjfm/GHSA-v4v8-93mw-cjfm.json b/advisories/unreviewed/2025/03/GHSA-v4v8-93mw-cjfm/GHSA-v4v8-93mw-cjfm.json new file mode 100644 index 00000000000..51f2e1c0627 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v4v8-93mw-cjfm/GHSA-v4v8-93mw-cjfm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4v8-93mw-cjfm", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2025-1496" + ], + "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1496" + }, + { + "type": "WEB", + "url": "https://www.coslat.com/tr/blog/28-02-2025-guncelleme" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0075" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json b/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json new file mode 100644 index 00000000000..009a20600ea --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whf8-w5vj-q4w6", + "modified": "2025-03-20T15:30:36Z", + "published": "2025-03-20T15:30:36Z", + "aliases": [ + "CVE-2024-48591" + ], + "details": "Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48591" + }, + { + "type": "WEB", + "url": "https://github.com/GCatt-AS/CVE-2024-48591" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T15:15:43Z" + } +} \ No newline at end of file