diff --git a/advisories/unreviewed/2022/02/GHSA-7qf7-6m7f-hv3w/GHSA-7qf7-6m7f-hv3w.json b/advisories/unreviewed/2022/02/GHSA-7qf7-6m7f-hv3w/GHSA-7qf7-6m7f-hv3w.json index efdb5b159d8..a1dec9a5be7 100644 --- a/advisories/unreviewed/2022/02/GHSA-7qf7-6m7f-hv3w/GHSA-7qf7-6m7f-hv3w.json +++ b/advisories/unreviewed/2022/02/GHSA-7qf7-6m7f-hv3w/GHSA-7qf7-6m7f-hv3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7qf7-6m7f-hv3w", - "modified": "2022-02-19T00:01:50Z", + "modified": "2025-02-06T18:30:58Z", "published": "2022-02-12T00:00:44Z", "aliases": [ "CVE-2021-34235" ], "details": "Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-cmw5-mmg8-r4fr/GHSA-cmw5-mmg8-r4fr.json b/advisories/unreviewed/2022/05/GHSA-cmw5-mmg8-r4fr/GHSA-cmw5-mmg8-r4fr.json index c2a9c99bbf9..18faf96ed18 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmw5-mmg8-r4fr/GHSA-cmw5-mmg8-r4fr.json +++ b/advisories/unreviewed/2022/05/GHSA-cmw5-mmg8-r4fr/GHSA-cmw5-mmg8-r4fr.json @@ -31,7 +31,8 @@ "database_specific": { "cwe_ids": [ "CWE-119", - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-j8w2-wx5p-fvx4/GHSA-j8w2-wx5p-fvx4.json b/advisories/unreviewed/2022/05/GHSA-j8w2-wx5p-fvx4/GHSA-j8w2-wx5p-fvx4.json index a3880ee6c9f..52c67dafaa0 100644 --- a/advisories/unreviewed/2022/05/GHSA-j8w2-wx5p-fvx4/GHSA-j8w2-wx5p-fvx4.json +++ b/advisories/unreviewed/2022/05/GHSA-j8w2-wx5p-fvx4/GHSA-j8w2-wx5p-fvx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8w2-wx5p-fvx4", - "modified": "2022-05-13T01:14:58Z", + "modified": "2025-02-06T18:30:58Z", "published": "2022-05-13T01:14:58Z", "aliases": [ "CVE-2019-1653" @@ -82,7 +82,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json b/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json index 437b8ef8c36..d3dc624344a 100644 --- a/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json +++ b/advisories/unreviewed/2022/05/GHSA-v2fr-wv49-j53x/GHSA-v2fr-wv49-j53x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v2fr-wv49-j53x", - "modified": "2022-05-24T17:36:06Z", + "modified": "2025-02-06T18:30:58Z", "published": "2022-05-24T17:36:06Z", "aliases": [ "CVE-2020-29574" ], "details": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-x7vj-wqq4-cq4v/GHSA-x7vj-wqq4-cq4v.json b/advisories/unreviewed/2022/05/GHSA-x7vj-wqq4-cq4v/GHSA-x7vj-wqq4-cq4v.json index ba91d87ffe7..2dde9337581 100644 --- a/advisories/unreviewed/2022/05/GHSA-x7vj-wqq4-cq4v/GHSA-x7vj-wqq4-cq4v.json +++ b/advisories/unreviewed/2022/05/GHSA-x7vj-wqq4-cq4v/GHSA-x7vj-wqq4-cq4v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x7vj-wqq4-cq4v", - "modified": "2022-05-24T17:22:02Z", + "modified": "2025-02-06T18:30:58Z", "published": "2022-05-24T17:22:02Z", "aliases": [ "CVE-2020-15069" ], "details": "Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json b/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json index 9a331eb581c..a80ff883b44 100644 --- a/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json +++ b/advisories/unreviewed/2022/11/GHSA-rc8f-8m86-p4vm/GHSA-rc8f-8m86-p4vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rc8f-8m86-p4vm", - "modified": "2022-11-22T21:30:18Z", + "modified": "2025-02-06T18:30:58Z", "published": "2022-11-18T00:30:19Z", "aliases": [ "CVE-2022-23748" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://cpr-zero.checkpoint.com/vulns/cprid-2193" }, + { + "type": "WEB", + "url": "https://cpr-zero.checkpoint.com/vulns/cprid-2193/%2C" + }, { "type": "WEB", "url": "https://cpr-zero.checkpoint.com/vulns/cprid-2193/," @@ -34,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-114", "CWE-426" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/04/GHSA-58vw-h3cv-wwrh/GHSA-58vw-h3cv-wwrh.json b/advisories/unreviewed/2023/04/GHSA-58vw-h3cv-wwrh/GHSA-58vw-h3cv-wwrh.json index 587a4c807b9..fc37aadacd6 100644 --- a/advisories/unreviewed/2023/04/GHSA-58vw-h3cv-wwrh/GHSA-58vw-h3cv-wwrh.json +++ b/advisories/unreviewed/2023/04/GHSA-58vw-h3cv-wwrh/GHSA-58vw-h3cv-wwrh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-6593-25jw-qmhp/GHSA-6593-25jw-qmhp.json b/advisories/unreviewed/2023/04/GHSA-6593-25jw-qmhp/GHSA-6593-25jw-qmhp.json index f4a1f590914..8a091339351 100644 --- a/advisories/unreviewed/2023/04/GHSA-6593-25jw-qmhp/GHSA-6593-25jw-qmhp.json +++ b/advisories/unreviewed/2023/04/GHSA-6593-25jw-qmhp/GHSA-6593-25jw-qmhp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-xj5r-2vxf-3ch7/GHSA-xj5r-2vxf-3ch7.json b/advisories/unreviewed/2023/04/GHSA-xj5r-2vxf-3ch7/GHSA-xj5r-2vxf-3ch7.json index cd078cb42f3..7b26dbb4156 100644 --- a/advisories/unreviewed/2023/04/GHSA-xj5r-2vxf-3ch7/GHSA-xj5r-2vxf-3ch7.json +++ b/advisories/unreviewed/2023/04/GHSA-xj5r-2vxf-3ch7/GHSA-xj5r-2vxf-3ch7.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json b/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json index 3bb76a0979b..d1856b42744 100644 --- a/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json +++ b/advisories/unreviewed/2023/07/GHSA-36g9-fjvv-qmj3/GHSA-36g9-fjvv-qmj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36g9-fjvv-qmj3", - "modified": "2024-04-04T05:36:39Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:15Z", "aliases": [ "CVE-2023-27909" diff --git a/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json b/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json index a357d759be6..3e41670bd2f 100644 --- a/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json +++ b/advisories/unreviewed/2023/07/GHSA-7xr3-6fgq-rv6h/GHSA-7xr3-6fgq-rv6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xr3-6fgq-rv6h", - "modified": "2024-04-04T05:36:44Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:16Z", "aliases": [ "CVE-2023-24501" diff --git a/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json b/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json index 5b8d8926d49..0b78e4eb61b 100644 --- a/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json +++ b/advisories/unreviewed/2023/07/GHSA-ffrf-xcmj-f59q/GHSA-ffrf-xcmj-f59q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffrf-xcmj-f59q", - "modified": "2024-04-04T05:36:41Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:15Z", "aliases": [ "CVE-2023-27911" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json b/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json index faa459d5304..34f1d0e8b9e 100644 --- a/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json +++ b/advisories/unreviewed/2023/07/GHSA-fqm3-34q3-vw23/GHSA-fqm3-34q3-vw23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqm3-34q3-vw23", - "modified": "2024-04-04T05:36:45Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:16Z", "aliases": [ "CVE-2023-24502" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-326" + "CWE-326", + "CWE-521" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json b/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json index 8836961c4a8..c745bb8dffd 100644 --- a/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json +++ b/advisories/unreviewed/2023/07/GHSA-fww7-pq4g-vxx7/GHSA-fww7-pq4g-vxx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fww7-pq4g-vxx7", - "modified": "2024-04-04T05:36:43Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:16Z", "aliases": [ "CVE-2023-24500" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-494" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json b/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json index f13c70ef81a..58d0a9cd04c 100644 --- a/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json +++ b/advisories/unreviewed/2023/07/GHSA-gjg3-8mx2-7f8f/GHSA-gjg3-8mx2-7f8f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjg3-8mx2-7f8f", - "modified": "2024-04-04T05:36:22Z", + "modified": "2025-02-06T18:30:59Z", "published": "2023-07-06T19:24:15Z", "aliases": [ "CVE-2022-38840" diff --git a/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json b/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json index 72c5f5a0a5a..b4eea40d6b7 100644 --- a/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json +++ b/advisories/unreviewed/2023/07/GHSA-m3qp-4rm3-pr3q/GHSA-m3qp-4rm3-pr3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3qp-4rm3-pr3q", - "modified": "2024-04-04T05:36:47Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:16Z", "aliases": [ "CVE-2023-24503" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-494" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json b/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json index 0c93ef751b8..aed3bc9df9b 100644 --- a/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json +++ b/advisories/unreviewed/2023/07/GHSA-pgrf-qrwj-3vf5/GHSA-pgrf-qrwj-3vf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgrf-qrwj-3vf5", - "modified": "2024-04-04T05:36:40Z", + "modified": "2025-02-06T18:31:00Z", "published": "2023-07-06T19:24:15Z", "aliases": [ "CVE-2023-27910" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-24g5-r7q6-hhmg/GHSA-24g5-r7q6-hhmg.json b/advisories/unreviewed/2024/04/GHSA-24g5-r7q6-hhmg/GHSA-24g5-r7q6-hhmg.json index 97eaea7b7ca..b5429abbe12 100644 --- a/advisories/unreviewed/2024/04/GHSA-24g5-r7q6-hhmg/GHSA-24g5-r7q6-hhmg.json +++ b/advisories/unreviewed/2024/04/GHSA-24g5-r7q6-hhmg/GHSA-24g5-r7q6-hhmg.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-24g5-r7q6-hhmg", - "modified": "2024-05-16T21:31:56Z", + "modified": "2025-02-06T18:31:01Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-21605" ], - "details": "An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\n\n\nSpecific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the device. This leads to excessive resource consumption and in turn severe impact on all control and management protocols of the device.\n\n\n\nThis issue affects Juniper Networks Junos OS:\n * 21.2 version 21.2R3-S3 and later versions earlier than 21.2R3-S6;\n * 22.1 version 22.1R3 and later versions earlier than 22.1R3-S4;\n * 22.2 version \n\n22.2R2\n\nand later versions earlier than 22.2R3-S2;\n * 22.3 version \n\n22.3R2 \n\nand later versions earlier than 22.3R3-S1;\n\n * 22.4 versions earlier than 22.4R2-S2, 22.4R3;\n * 23.2 versions earlier than 23.2R1-S1, 23.2R2.\n\n\n\n\nThis issue does not affect Juniper Networks Junos OS 21.4R1 and later versions of 21.4.\n\n", + "details": "An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).\n\n\n\nSpecific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the device. This leads to excessive resource consumption and in turn severe impact on all control and management protocols of the device.\n\n\n\nThis issue affects Juniper Networks Junos OS:\n * 21.2 version 21.2R3-S3 and later versions earlier than 21.2R3-S6;\n * 22.1 version 22.1R3 and later versions earlier than 22.1R3-S4;\n * 22.2 version \n\n22.2R2\n\nand later versions earlier than 22.2R3-S2;\n * 22.3 version \n\n22.3R2 \n\nand later versions earlier than 22.3R3-S1;\n\n * 22.4 versions earlier than 22.4R2-S2, 22.4R3;\n * 23.2 versions earlier than 23.2R1-S1, 23.2R2.\n\n\n\n\nThis issue does not affect Juniper Networks Junos OS 21.4R1 and later versions of 21.4.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/04/GHSA-26w9-32mp-48g9/GHSA-26w9-32mp-48g9.json b/advisories/unreviewed/2024/04/GHSA-26w9-32mp-48g9/GHSA-26w9-32mp-48g9.json index e93fa828310..178d4e12893 100644 --- a/advisories/unreviewed/2024/04/GHSA-26w9-32mp-48g9/GHSA-26w9-32mp-48g9.json +++ b/advisories/unreviewed/2024/04/GHSA-26w9-32mp-48g9/GHSA-26w9-32mp-48g9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-26w9-32mp-48g9", - "modified": "2024-04-25T06:30:35Z", + "modified": "2025-02-06T18:31:01Z", "published": "2024-04-25T06:30:35Z", "aliases": [ "CVE-2024-4159" ], - "details": "\nBrocade SANnav before Brocade SANnav v2.3.1 lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated, remote attacker to reach Kafka APIs and send malicious data.\n\n", + "details": "Brocade SANnav before Brocade SANnav v2.3.1 lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated, remote attacker to reach Kafka APIs and send malicious data.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json b/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json index dbff421b1d5..5249d916c60 100644 --- a/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json +++ b/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xr5-7rvh-x3v2", - "modified": "2025-01-30T18:32:04Z", + "modified": "2025-02-06T18:31:01Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25705" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/portal-for-arcgis-security-2024-update-2" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/the-portal-for-arcgis-security-2024-update-2-is-available-install-these-patches-at-your-earliest-opportunity-to-address-these-vulnerabilities" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json b/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json index 9d0a779d28a..42e5746ce91 100644 --- a/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json +++ b/advisories/unreviewed/2024/04/GHSA-838g-cpgm-j985/GHSA-838g-cpgm-j985.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-838g-cpgm-j985", - "modified": "2024-04-24T18:30:33Z", + "modified": "2025-02-06T18:31:01Z", "published": "2024-04-24T18:30:33Z", "aliases": [ "CVE-2024-3371" ], - "details": "MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.40.5.\n", + "details": "MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.40.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-96r2-52xr-8x9x/GHSA-96r2-52xr-8x9x.json b/advisories/unreviewed/2024/04/GHSA-96r2-52xr-8x9x/GHSA-96r2-52xr-8x9x.json index 3d9e1232a3e..efd45c769a2 100644 --- a/advisories/unreviewed/2024/04/GHSA-96r2-52xr-8x9x/GHSA-96r2-52xr-8x9x.json +++ b/advisories/unreviewed/2024/04/GHSA-96r2-52xr-8x9x/GHSA-96r2-52xr-8x9x.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-96r2-52xr-8x9x", - "modified": "2024-05-16T21:31:57Z", + "modified": "2025-02-06T18:31:01Z", "published": "2024-04-12T15:37:22Z", "aliases": [ "CVE-2024-30410" ], - "details": "An Incorrect Behavior Order in the routing engine (RE) of Juniper Networks Junos OS on EX4300 Series allows traffic intended to the device to reach the RE instead of being discarded when the discard term is set in loopback (lo0) interface. The intended function is that the lo0 firewall filter takes precedence over the revenue interface firewall filter. \n\nThis issue affects only IPv6 firewall filter.\n\nThis issue only affects the EX4300 switch. No other products or platforms are affected by this vulnerability. \n\nThis issue affects Juniper Networks Junos OS:\n\n * All versions before 20.4R3-S10,\n * from 21.2 before 21.2R3-S7,\n * from 21.4 before 21.4R3-S6. \n\n\n\n\n", + "details": "An Incorrect Behavior Order in the routing engine (RE) of Juniper Networks Junos OS on EX4300 Series allows traffic intended to the device to reach the RE instead of being discarded when the discard term is set in loopback (lo0) interface. The intended function is that the lo0 firewall filter takes precedence over the revenue interface firewall filter. \n\nThis issue affects only IPv6 firewall filter.\n\nThis issue only affects the EX4300 switch. No other products or platforms are affected by this vulnerability. \n\nThis issue affects Juniper Networks Junos OS:\n\n * All versions before 20.4R3-S10,\n * from 21.2 before 21.2R3-S7,\n * from 21.4 before 21.4R3-S6. ", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/04/GHSA-h97r-v79m-2vcf/GHSA-h97r-v79m-2vcf.json b/advisories/unreviewed/2024/04/GHSA-h97r-v79m-2vcf/GHSA-h97r-v79m-2vcf.json index 961d4da487d..4b204221f7e 100644 --- a/advisories/unreviewed/2024/04/GHSA-h97r-v79m-2vcf/GHSA-h97r-v79m-2vcf.json +++ b/advisories/unreviewed/2024/04/GHSA-h97r-v79m-2vcf/GHSA-h97r-v79m-2vcf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h97r-v79m-2vcf", - "modified": "2024-04-25T06:30:35Z", + "modified": "2025-02-06T18:31:02Z", "published": "2024-04-25T06:30:35Z", "aliases": [ "CVE-2024-4161" ], - "details": "In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received\n clear text. This could allow an unauthenticated, remote attacker to \ncapture sensitive information.\n\n", + "details": "In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received\n clear text. This could allow an unauthenticated, remote attacker to \ncapture sensitive information.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json b/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json index acdd1052210..6a3f6ffae83 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json +++ b/advisories/unreviewed/2024/04/GHSA-p5h3-wwqf-f5rv/GHSA-p5h3-wwqf-f5rv.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-p5h3-wwqf-f5rv", - "modified": "2024-04-16T18:31:34Z", + "modified": "2025-02-06T18:31:01Z", "published": "2024-04-12T15:37:21Z", "aliases": [ "CVE-2024-21598" ], - "details": "An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\n\nIf a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart.\n\nThis issue affects Juniper Networks\nJunos OS:\n * 20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9;\n * 21.2 versions earlier than 21.2R3-S7;\n * 21.3 versions earlier than 21.3R3-S5;\n * 21.4 versions earlier than 21.4R3-S5;\n * 22.1 versions earlier than 22.1R3-S4;\n * 22.2 versions earlier than 22.2R3-S3;\n * 22.3 versions earlier than 22.3R3-S1;\n * 22.4 versions earlier than 22.4R3;\n * 23.2 versions earlier than 23.2R1-S2, 23.2R2;\n\n\n\nJunos OS Evolved:\n * 20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO;\n * 21.2-EVO versions earlier than 21.2R3-S7-EVO;\n * 21.3-EVO versions earlier than 21.3R3-S5-EVO;\n * 21.4-EVO versions earlier than 21.4R3-S5-EVO;\n * 22.1-EVO versions earlier than 22.1R3-S4-EVO;\n * 22.2-EVO versions earlier than 22.2R3-S3-EVO;\n * 22.3-EVO versions earlier than 22.3R3-S1-EVO;\n * 22.4-EVO versions earlier than 22.4R3-EVO;\n * 23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO;\n\n\n\nThis issue does not affect Juniper Networks\n * Junos OS versions earlier than 20.4R1;\n * Junos OS Evolved versions earlier than 20.4R1-EVO.\n\n\n\nThis is a related but separate issue than the one described in JSA79095.\n", + "details": "An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).\n\nIf a BGP update is received over an established BGP session which contains a tunnel encapsulation attribute with a specifically malformed TLV, rpd will crash and restart.\n\nThis issue affects Juniper Networks\nJunos OS:\n * 20.4 versions 20.4R1 and later versions earlier than 20.4R3-S9;\n * 21.2 versions earlier than 21.2R3-S7;\n * 21.3 versions earlier than 21.3R3-S5;\n * 21.4 versions earlier than 21.4R3-S5;\n * 22.1 versions earlier than 22.1R3-S4;\n * 22.2 versions earlier than 22.2R3-S3;\n * 22.3 versions earlier than 22.3R3-S1;\n * 22.4 versions earlier than 22.4R3;\n * 23.2 versions earlier than 23.2R1-S2, 23.2R2;\n\n\n\nJunos OS Evolved:\n * 20.4-EVO versions 20.4R1-EVO and later versions earlier than 20.4R3-S9-EVO;\n * 21.2-EVO versions earlier than 21.2R3-S7-EVO;\n * 21.3-EVO versions earlier than 21.3R3-S5-EVO;\n * 21.4-EVO versions earlier than 21.4R3-S5-EVO;\n * 22.1-EVO versions earlier than 22.1R3-S4-EVO;\n * 22.2-EVO versions earlier than 22.2R3-S3-EVO;\n * 22.3-EVO versions earlier than 22.3R3-S1-EVO;\n * 22.4-EVO versions earlier than 22.4R3-EVO;\n * 23.2-EVO versions earlier than 23.2R1-S2-EVO, 23.2R2-EVO;\n\n\n\nThis issue does not affect Juniper Networks\n * Junos OS versions earlier than 20.4R1;\n * Junos OS Evolved versions earlier than 20.4R1-EVO.\n\n\n\nThis is a related but separate issue than the one described in JSA79095.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/04/GHSA-pm6f-4pg9-fmg4/GHSA-pm6f-4pg9-fmg4.json b/advisories/unreviewed/2024/04/GHSA-pm6f-4pg9-fmg4/GHSA-pm6f-4pg9-fmg4.json index 92ed71fc44a..9db91c5431f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pm6f-4pg9-fmg4/GHSA-pm6f-4pg9-fmg4.json +++ b/advisories/unreviewed/2024/04/GHSA-pm6f-4pg9-fmg4/GHSA-pm6f-4pg9-fmg4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pm6f-4pg9-fmg4", - "modified": "2024-04-25T09:32:09Z", + "modified": "2025-02-06T18:31:02Z", "published": "2024-04-25T09:32:09Z", "aliases": [ "CVE-2024-4173" ], - "details": "\nA vulnerability in Brocade SANnav ova versions before Brocade SANnav v2.3.1 and v2.3.0a exposes Kafka in the wan interface.\n\nThe vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS, the Brocade SANnav appliance.\n\n", + "details": "A vulnerability in Brocade SANnav ova versions before Brocade SANnav v2.3.1 and v2.3.0a exposes Kafka in the wan interface.\n\nThe vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS, the Brocade SANnav appliance.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json b/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json index 8486fca0abf..2f490407dd3 100644 --- a/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json +++ b/advisories/unreviewed/2024/05/GHSA-3h5f-xp24-j3p4/GHSA-3h5f-xp24-j3p4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3h5f-xp24-j3p4", - "modified": "2024-05-08T03:30:37Z", + "modified": "2025-02-06T18:31:03Z", "published": "2024-05-08T03:30:37Z", "aliases": [ "CVE-2024-2860" ], - "details": "The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.\n ", + "details": "The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-5qjg-g4mj-x7h7/GHSA-5qjg-g4mj-x7h7.json b/advisories/unreviewed/2024/05/GHSA-5qjg-g4mj-x7h7/GHSA-5qjg-g4mj-x7h7.json index 8bd30799a8b..a3b157e7690 100644 --- a/advisories/unreviewed/2024/05/GHSA-5qjg-g4mj-x7h7/GHSA-5qjg-g4mj-x7h7.json +++ b/advisories/unreviewed/2024/05/GHSA-5qjg-g4mj-x7h7/GHSA-5qjg-g4mj-x7h7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qjg-g4mj-x7h7", - "modified": "2024-05-02T18:30:53Z", + "modified": "2025-02-06T18:31:02Z", "published": "2024-05-02T18:30:53Z", "aliases": [ "CVE-2024-2667" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6r9h-2p8r-jf6r/GHSA-6r9h-2p8r-jf6r.json b/advisories/unreviewed/2024/05/GHSA-6r9h-2p8r-jf6r/GHSA-6r9h-2p8r-jf6r.json index d59ab66a6b6..15db5bc6d4e 100644 --- a/advisories/unreviewed/2024/05/GHSA-6r9h-2p8r-jf6r/GHSA-6r9h-2p8r-jf6r.json +++ b/advisories/unreviewed/2024/05/GHSA-6r9h-2p8r-jf6r/GHSA-6r9h-2p8r-jf6r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-73" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-7pwx-w32q-3p7r/GHSA-7pwx-w32q-3p7r.json b/advisories/unreviewed/2024/05/GHSA-7pwx-w32q-3p7r/GHSA-7pwx-w32q-3p7r.json index 2808d770ff1..eb1f18debc6 100644 --- a/advisories/unreviewed/2024/05/GHSA-7pwx-w32q-3p7r/GHSA-7pwx-w32q-3p7r.json +++ b/advisories/unreviewed/2024/05/GHSA-7pwx-w32q-3p7r/GHSA-7pwx-w32q-3p7r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-73" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-928h-v43x-jjq6/GHSA-928h-v43x-jjq6.json b/advisories/unreviewed/2024/05/GHSA-928h-v43x-jjq6/GHSA-928h-v43x-jjq6.json index a31ecea84b5..214e0513826 100644 --- a/advisories/unreviewed/2024/05/GHSA-928h-v43x-jjq6/GHSA-928h-v43x-jjq6.json +++ b/advisories/unreviewed/2024/05/GHSA-928h-v43x-jjq6/GHSA-928h-v43x-jjq6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-73" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-r88h-5mx3-fj3x/GHSA-r88h-5mx3-fj3x.json b/advisories/unreviewed/2024/05/GHSA-r88h-5mx3-fj3x/GHSA-r88h-5mx3-fj3x.json index fb4d45d2cf6..8da382a7056 100644 --- a/advisories/unreviewed/2024/05/GHSA-r88h-5mx3-fj3x/GHSA-r88h-5mx3-fj3x.json +++ b/advisories/unreviewed/2024/05/GHSA-r88h-5mx3-fj3x/GHSA-r88h-5mx3-fj3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r88h-5mx3-fj3x", - "modified": "2024-05-02T18:30:53Z", + "modified": "2025-02-06T18:31:02Z", "published": "2024-05-02T18:30:53Z", "aliases": [ "CVE-2024-3107" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json b/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json index b14df5746bb..cd3e2cb82fb 100644 --- a/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json +++ b/advisories/unreviewed/2024/12/GHSA-4qgc-h55q-cm8r/GHSA-4qgc-h55q-cm8r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-898p-89pm-w9hr/GHSA-898p-89pm-w9hr.json b/advisories/unreviewed/2024/12/GHSA-898p-89pm-w9hr/GHSA-898p-89pm-w9hr.json index 2b28107c7f2..1a927f9ce18 100644 --- a/advisories/unreviewed/2024/12/GHSA-898p-89pm-w9hr/GHSA-898p-89pm-w9hr.json +++ b/advisories/unreviewed/2024/12/GHSA-898p-89pm-w9hr/GHSA-898p-89pm-w9hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-898p-89pm-w9hr", - "modified": "2024-12-10T21:30:52Z", + "modified": "2025-02-06T18:31:04Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-49532" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-92.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2064" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-mhf9-wh2j-ccvq/GHSA-mhf9-wh2j-ccvq.json b/advisories/unreviewed/2024/12/GHSA-mhf9-wh2j-ccvq/GHSA-mhf9-wh2j-ccvq.json index 5a7dbff9594..d42bc4b926f 100644 --- a/advisories/unreviewed/2024/12/GHSA-mhf9-wh2j-ccvq/GHSA-mhf9-wh2j-ccvq.json +++ b/advisories/unreviewed/2024/12/GHSA-mhf9-wh2j-ccvq/GHSA-mhf9-wh2j-ccvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhf9-wh2j-ccvq", - "modified": "2024-12-13T06:30:59Z", + "modified": "2025-02-06T18:31:04Z", "published": "2024-12-13T06:30:59Z", "aliases": [ "CVE-2024-12581" diff --git a/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json b/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json index b7e75174d4a..bc0341557e6 100644 --- a/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json +++ b/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-75fm-2jm9-p338", - "modified": "2025-01-28T15:31:57Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-01-28T15:31:57Z", "aliases": [ "CVE-2024-7881" ], "details": "An unprivileged context can trigger a data\nmemory-dependent prefetch engine to fetch the contents of a privileged location\nand consume those contents as an address that is also dereferenced.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T15:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json b/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json index 6918e7e2f17..f626252547a 100644 --- a/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json +++ b/advisories/unreviewed/2025/01/GHSA-88q7-6vxh-w5q7/GHSA-88q7-6vxh-w5q7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88q7-6vxh-w5q7", - "modified": "2025-01-28T21:31:04Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-01-28T21:31:04Z", "aliases": [ "CVE-2024-40676" ], "details": "In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T20:15:49Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json b/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json index fb9e61139f7..e2d69471b13 100644 --- a/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json +++ b/advisories/unreviewed/2025/01/GHSA-gvc8-8jhg-7556/GHSA-gvc8-8jhg-7556.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvc8-8jhg-7556", - "modified": "2025-01-28T21:31:03Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2024-57373" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/cypherdavy/CVE-2024-57373" + }, + { + "type": "WEB", + "url": "https://github.com/sajalagrawal/LifestyleStore" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json b/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json index 8724d3c74f8..7901afc5afa 100644 --- a/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json +++ b/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxmw-34m7-64r8", - "modified": "2025-01-25T00:33:10Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-01-25T00:33:10Z", "aliases": [ "CVE-2024-50692" ], "details": "SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are vulnerable to MitM attacks at the TCP/IP level.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -17,11 +22,17 @@ { "type": "WEB", "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + }, + { + "type": "WEB", + "url": "https://mqtt-pwn.readthedocs.io/en/latest/intro.html" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-24T23:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json b/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json index 00bb7d9bb86..02a03258273 100644 --- a/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json +++ b/advisories/unreviewed/2025/01/GHSA-wq23-xq9q-wf8w/GHSA-wq23-xq9q-wf8w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wq23-xq9q-wf8w", - "modified": "2025-01-28T21:31:04Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-01-28T21:31:04Z", "aliases": [ "CVE-2024-40675" ], "details": "In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-835" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T20:15:49Z" diff --git a/advisories/unreviewed/2025/02/GHSA-2hjh-495w-hmxc/GHSA-2hjh-495w-hmxc.json b/advisories/unreviewed/2025/02/GHSA-2hjh-495w-hmxc/GHSA-2hjh-495w-hmxc.json new file mode 100644 index 00000000000..c0eaf4dcdf9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2hjh-495w-hmxc/GHSA-2hjh-495w-hmxc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hjh-495w-hmxc", + "modified": "2025-02-06T18:31:06Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-57610" + ], + "details": "A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57610" + }, + { + "type": "WEB", + "url": "https://github.com/Sylius/Sylius" + }, + { + "type": "WEB", + "url": "https://github.com/nca785/CVE-2024-57610" + }, + { + "type": "WEB", + "url": "https://sylius.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json b/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json new file mode 100644 index 00000000000..be49532d551 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2r8x-g2v5-x892/GHSA-2r8x-g2v5-x892.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r8x-g2v5-x892", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-36557" + ], + "details": "The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36557" + }, + { + "type": "WEB", + "url": "https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2wm4-f538-3x27/GHSA-2wm4-f538-3x27.json b/advisories/unreviewed/2025/02/GHSA-2wm4-f538-3x27/GHSA-2wm4-f538-3x27.json index b6d4239d26c..b21ca9a09e9 100644 --- a/advisories/unreviewed/2025/02/GHSA-2wm4-f538-3x27/GHSA-2wm4-f538-3x27.json +++ b/advisories/unreviewed/2025/02/GHSA-2wm4-f538-3x27/GHSA-2wm4-f538-3x27.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wm4-f538-3x27", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-54853" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3whm-j4xm-rv8x/GHSA-3whm-j4xm-rv8x.json b/advisories/unreviewed/2025/02/GHSA-3whm-j4xm-rv8x/GHSA-3whm-j4xm-rv8x.json new file mode 100644 index 00000000000..48bc1700091 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3whm-j4xm-rv8x/GHSA-3whm-j4xm-rv8x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3whm-j4xm-rv8x", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2025-22866" + ], + "details": "Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22866" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/643735" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/71383" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/xU1ZCHUZw3k" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3447" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-455w-hgxv-564m/GHSA-455w-hgxv-564m.json b/advisories/unreviewed/2025/02/GHSA-455w-hgxv-564m/GHSA-455w-hgxv-564m.json index cad8efb9327..b905a9ec5b9 100644 --- a/advisories/unreviewed/2025/02/GHSA-455w-hgxv-564m/GHSA-455w-hgxv-564m.json +++ b/advisories/unreviewed/2025/02/GHSA-455w-hgxv-564m/GHSA-455w-hgxv-564m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-455w-hgxv-564m", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-48394" ], "details": "A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. The vulnerability affects version 5.24.3 and before of the software.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4m27-833c-75q4/GHSA-4m27-833c-75q4.json b/advisories/unreviewed/2025/02/GHSA-4m27-833c-75q4/GHSA-4m27-833c-75q4.json index 5873ede17c1..0399ac44bf4 100644 --- a/advisories/unreviewed/2025/02/GHSA-4m27-833c-75q4/GHSA-4m27-833c-75q4.json +++ b/advisories/unreviewed/2025/02/GHSA-4m27-833c-75q4/GHSA-4m27-833c-75q4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4m27-833c-75q4", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57520" ], "details": "Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json b/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json index 979250f171e..55db9b164ff 100644 --- a/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json +++ b/advisories/unreviewed/2025/02/GHSA-52hm-37gj-qx5h/GHSA-52hm-37gj-qx5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-52hm-37gj-qx5h", - "modified": "2025-02-05T18:34:46Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-05T18:34:46Z", "aliases": [ "CVE-2024-7595" ], "details": "GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.\n\nThis can be considered similar to CVE-2020-10136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T18:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5h75-c9mf-fpv6/GHSA-5h75-c9mf-fpv6.json b/advisories/unreviewed/2025/02/GHSA-5h75-c9mf-fpv6/GHSA-5h75-c9mf-fpv6.json new file mode 100644 index 00000000000..b9d214a3459 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5h75-c9mf-fpv6/GHSA-5h75-c9mf-fpv6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h75-c9mf-fpv6", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-36556" + ], + "details": "Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36556" + }, + { + "type": "WEB", + "url": "https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-62gw-4h79-3mj6/GHSA-62gw-4h79-3mj6.json b/advisories/unreviewed/2025/02/GHSA-62gw-4h79-3mj6/GHSA-62gw-4h79-3mj6.json new file mode 100644 index 00000000000..029e1fce1fa --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-62gw-4h79-3mj6/GHSA-62gw-4h79-3mj6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gw-4h79-3mj6", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2022-40490" + ], + "details": "Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40490" + }, + { + "type": "WEB", + "url": "https://github.com/prasathmani/tinyfilemanager" + }, + { + "type": "WEB", + "url": "https://github.com/whitej3rry/CVE-2022-40490/blob/main/PoC.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-664g-9vm2-r26f/GHSA-664g-9vm2-r26f.json b/advisories/unreviewed/2025/02/GHSA-664g-9vm2-r26f/GHSA-664g-9vm2-r26f.json new file mode 100644 index 00000000000..4813cf9948d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-664g-9vm2-r26f/GHSA-664g-9vm2-r26f.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-664g-9vm2-r26f", + "modified": "2025-02-06T18:31:06Z", + "published": "2025-02-06T18:31:06Z", + "aliases": [ + "CVE-2025-22867" + ], + "details": "On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a \"#cgo LDFLAGS\" directive. This issue only affected go1.24rc2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22867" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/646996" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/71476" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-dev/c/TYzikTgHK6Y" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3428" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6g37-4665-5v4w/GHSA-6g37-4665-5v4w.json b/advisories/unreviewed/2025/02/GHSA-6g37-4665-5v4w/GHSA-6g37-4665-5v4w.json index 5a735e125fa..a1ab3850660 100644 --- a/advisories/unreviewed/2025/02/GHSA-6g37-4665-5v4w/GHSA-6g37-4665-5v4w.json +++ b/advisories/unreviewed/2025/02/GHSA-6g37-4665-5v4w/GHSA-6g37-4665-5v4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6g37-4665-5v4w", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2025-25181" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://intezer.com/blog/research/xe-group-exploiting-zero-days" + }, + { + "type": "WEB", + "url": "https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-6r5f-5cgm-ff5g/GHSA-6r5f-5cgm-ff5g.json b/advisories/unreviewed/2025/02/GHSA-6r5f-5cgm-ff5g/GHSA-6r5f-5cgm-ff5g.json new file mode 100644 index 00000000000..1d0bb308903 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6r5f-5cgm-ff5g/GHSA-6r5f-5cgm-ff5g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r5f-5cgm-ff5g", + "modified": "2025-02-06T18:31:06Z", + "published": "2025-02-06T18:31:06Z", + "aliases": [ + "CVE-2024-36558" + ], + "details": "Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36558" + }, + { + "type": "WEB", + "url": "https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-78r2-7ff2-3mcr/GHSA-78r2-7ff2-3mcr.json b/advisories/unreviewed/2025/02/GHSA-78r2-7ff2-3mcr/GHSA-78r2-7ff2-3mcr.json new file mode 100644 index 00000000000..3f27faad798 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-78r2-7ff2-3mcr/GHSA-78r2-7ff2-3mcr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78r2-7ff2-3mcr", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-39033" + ], + "details": "In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39033" + }, + { + "type": "WEB", + "url": "https://pastebin.com/SHExsfh6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-79h2-v6hh-wq23/GHSA-79h2-v6hh-wq23.json b/advisories/unreviewed/2025/02/GHSA-79h2-v6hh-wq23/GHSA-79h2-v6hh-wq23.json index 60bd5d4cb4e..92565295746 100644 --- a/advisories/unreviewed/2025/02/GHSA-79h2-v6hh-wq23/GHSA-79h2-v6hh-wq23.json +++ b/advisories/unreviewed/2025/02/GHSA-79h2-v6hh-wq23/GHSA-79h2-v6hh-wq23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79h2-v6hh-wq23", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57066" ], "details": "A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7ghx-59p7-w2w6/GHSA-7ghx-59p7-w2w6.json b/advisories/unreviewed/2025/02/GHSA-7ghx-59p7-w2w6/GHSA-7ghx-59p7-w2w6.json new file mode 100644 index 00000000000..9d346b2726b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7ghx-59p7-w2w6/GHSA-7ghx-59p7-w2w6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghx-59p7-w2w6", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-57599" + ], + "details": "Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57599" + }, + { + "type": "WEB", + "url": "https://github.com/Arykon/cve/blob/main/douphp.pdf" + }, + { + "type": "WEB", + "url": "https://www.douphp.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-89fp-f5mx-748x/GHSA-89fp-f5mx-748x.json b/advisories/unreviewed/2025/02/GHSA-89fp-f5mx-748x/GHSA-89fp-f5mx-748x.json index 7febab525f6..3bb9697de47 100644 --- a/advisories/unreviewed/2025/02/GHSA-89fp-f5mx-748x/GHSA-89fp-f5mx-748x.json +++ b/advisories/unreviewed/2025/02/GHSA-89fp-f5mx-748x/GHSA-89fp-f5mx-748x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89fp-f5mx-748x", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57080" ], "details": "A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-965p-68x5-j8vf/GHSA-965p-68x5-j8vf.json b/advisories/unreviewed/2025/02/GHSA-965p-68x5-j8vf/GHSA-965p-68x5-j8vf.json new file mode 100644 index 00000000000..518ee006536 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-965p-68x5-j8vf/GHSA-965p-68x5-j8vf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-965p-68x5-j8vf", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-36553" + ], + "details": "Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36553" + }, + { + "type": "WEB", + "url": "https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9p8p-c44x-848h/GHSA-9p8p-c44x-848h.json b/advisories/unreviewed/2025/02/GHSA-9p8p-c44x-848h/GHSA-9p8p-c44x-848h.json new file mode 100644 index 00000000000..d997299ef89 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9p8p-c44x-848h/GHSA-9p8p-c44x-848h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p8p-c44x-848h", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-57428" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57428" + }, + { + "type": "WEB", + "url": "https://github.com/ahrixia/CVE-2024-57428" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c5cp-pf7w-rg5w/GHSA-c5cp-pf7w-rg5w.json b/advisories/unreviewed/2025/02/GHSA-c5cp-pf7w-rg5w/GHSA-c5cp-pf7w-rg5w.json index 550dbbbfd8f..49f2f3e4b23 100644 --- a/advisories/unreviewed/2025/02/GHSA-c5cp-pf7w-rg5w/GHSA-c5cp-pf7w-rg5w.json +++ b/advisories/unreviewed/2025/02/GHSA-c5cp-pf7w-rg5w/GHSA-c5cp-pf7w-rg5w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c5cp-pf7w-rg5w", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57071" ], "details": "A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c6cx-89c4-f7wj/GHSA-c6cx-89c4-f7wj.json b/advisories/unreviewed/2025/02/GHSA-c6cx-89c4-f7wj/GHSA-c6cx-89c4-f7wj.json index f5698f2025c..5a8186056f4 100644 --- a/advisories/unreviewed/2025/02/GHSA-c6cx-89c4-f7wj/GHSA-c6cx-89c4-f7wj.json +++ b/advisories/unreviewed/2025/02/GHSA-c6cx-89c4-f7wj/GHSA-c6cx-89c4-f7wj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c6cx-89c4-f7wj", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57598" ], "details": "A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-369" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:33Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json b/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json index 8c1678bece7..b51910b25d1 100644 --- a/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json +++ b/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvr-gqfv-x5mj", - "modified": "2025-02-05T12:33:06Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-05T12:33:06Z", "aliases": [ "CVE-2023-52925" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: don't fail inserts if duplicate has expired\n\nnftables selftests fail:\nrun-tests.sh testcases/sets/0044interval_overlap_0\nExpected: 0-2 . 0-3, got:\nW: [FAILED] ./testcases/sets/0044interval_overlap_0: got 1\n\nInsertion must ignore duplicate but expired entries.\n\nMoreover, there is a strange asymmetry in nft_pipapo_activate:\n\nIt refetches the current element, whereas the other ->activate callbacks\n(bitmap, hash, rhash, rbtree) use elem->priv.\nSame for .remove: other set implementations take elem->priv,\nnft_pipapo_remove fetches elem->priv, then does a relookup,\nremove this.\n\nI suspect this was the reason for the change that prompted the\nremoval of the expired check in pipapo_get() in the first place,\nbut skipping exired elements there makes no sense to me, this helper\nis used for normal get requests, insertions (duplicate check)\nand deactivate callback.\n\nIn first two cases expired elements must be skipped.\n\nFor ->deactivate(), this gets called for DELSETELEM, so it\nseems to me that expired elements should be skipped as well, i.e.\ndelete request should fail with -ENOENT error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T10:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-f74f-3rwg-525w/GHSA-f74f-3rwg-525w.json b/advisories/unreviewed/2025/02/GHSA-f74f-3rwg-525w/GHSA-f74f-3rwg-525w.json index 1d24a480d72..08994828b4a 100644 --- a/advisories/unreviewed/2025/02/GHSA-f74f-3rwg-525w/GHSA-f74f-3rwg-525w.json +++ b/advisories/unreviewed/2025/02/GHSA-f74f-3rwg-525w/GHSA-f74f-3rwg-525w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f74f-3rwg-525w", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57064" ], "details": "A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-g29h-75vc-hv25/GHSA-g29h-75vc-hv25.json b/advisories/unreviewed/2025/02/GHSA-g29h-75vc-hv25/GHSA-g29h-75vc-hv25.json new file mode 100644 index 00000000000..2258c6b43da --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g29h-75vc-hv25/GHSA-g29h-75vc-hv25.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g29h-75vc-hv25", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-57430" + ], + "details": "An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57430" + }, + { + "type": "WEB", + "url": "https://github.com/ahrixia/CVE-2024-57430" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ggv3-vmgw-xv2q/GHSA-ggv3-vmgw-xv2q.json b/advisories/unreviewed/2025/02/GHSA-ggv3-vmgw-xv2q/GHSA-ggv3-vmgw-xv2q.json index 62c806596e5..9517ceeec64 100644 --- a/advisories/unreviewed/2025/02/GHSA-ggv3-vmgw-xv2q/GHSA-ggv3-vmgw-xv2q.json +++ b/advisories/unreviewed/2025/02/GHSA-ggv3-vmgw-xv2q/GHSA-ggv3-vmgw-xv2q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ggv3-vmgw-xv2q", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57068" ], "details": "A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-ghgh-mc9f-w47r/GHSA-ghgh-mc9f-w47r.json b/advisories/unreviewed/2025/02/GHSA-ghgh-mc9f-w47r/GHSA-ghgh-mc9f-w47r.json index 49706a1e367..59110ef3d6f 100644 --- a/advisories/unreviewed/2025/02/GHSA-ghgh-mc9f-w47r/GHSA-ghgh-mc9f-w47r.json +++ b/advisories/unreviewed/2025/02/GHSA-ghgh-mc9f-w47r/GHSA-ghgh-mc9f-w47r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ghgh-mc9f-w47r", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57069" ], "details": "A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gvwq-6fmx-28xm/GHSA-gvwq-6fmx-28xm.json b/advisories/unreviewed/2025/02/GHSA-gvwq-6fmx-28xm/GHSA-gvwq-6fmx-28xm.json index fc4ac6d93e4..c6c783ad202 100644 --- a/advisories/unreviewed/2025/02/GHSA-gvwq-6fmx-28xm/GHSA-gvwq-6fmx-28xm.json +++ b/advisories/unreviewed/2025/02/GHSA-gvwq-6fmx-28xm/GHSA-gvwq-6fmx-28xm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvwq-6fmx-28xm", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57086" ], "details": "A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gx78-3r6j-qx7f/GHSA-gx78-3r6j-qx7f.json b/advisories/unreviewed/2025/02/GHSA-gx78-3r6j-qx7f/GHSA-gx78-3r6j-qx7f.json index 3a2b01c58b4..f6f141aeacb 100644 --- a/advisories/unreviewed/2025/02/GHSA-gx78-3r6j-qx7f/GHSA-gx78-3r6j-qx7f.json +++ b/advisories/unreviewed/2025/02/GHSA-gx78-3r6j-qx7f/GHSA-gx78-3r6j-qx7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx78-3r6j-qx7f", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-06T18:31:04Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-57968" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://intezer.com/blog/research/xe-group-exploiting-zero-days" + }, + { + "type": "WEB", + "url": "https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-j3pc-x8m6-wm8p/GHSA-j3pc-x8m6-wm8p.json b/advisories/unreviewed/2025/02/GHSA-j3pc-x8m6-wm8p/GHSA-j3pc-x8m6-wm8p.json index 90c0d50dcab..38b8df91168 100644 --- a/advisories/unreviewed/2025/02/GHSA-j3pc-x8m6-wm8p/GHSA-j3pc-x8m6-wm8p.json +++ b/advisories/unreviewed/2025/02/GHSA-j3pc-x8m6-wm8p/GHSA-j3pc-x8m6-wm8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3pc-x8m6-wm8p", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2020-36084" ], "details": "SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:27Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json b/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json index 48d5d08c3c0..103f358be15 100644 --- a/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json +++ b/advisories/unreviewed/2025/02/GHSA-jff7-8p33-28j3/GHSA-jff7-8p33-28j3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jff7-8p33-28j3", - "modified": "2025-02-05T18:34:46Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-05T18:34:46Z", "aliases": [ "CVE-2024-7596" ], "details": "Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.\n\nThis can be considered similar to CVE-2020-10136.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T18:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m2rr-82cc-gh7r/GHSA-m2rr-82cc-gh7r.json b/advisories/unreviewed/2025/02/GHSA-m2rr-82cc-gh7r/GHSA-m2rr-82cc-gh7r.json index c354e8c630a..c4027852d93 100644 --- a/advisories/unreviewed/2025/02/GHSA-m2rr-82cc-gh7r/GHSA-m2rr-82cc-gh7r.json +++ b/advisories/unreviewed/2025/02/GHSA-m2rr-82cc-gh7r/GHSA-m2rr-82cc-gh7r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m2rr-82cc-gh7r", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57065" ], "details": "A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json b/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json new file mode 100644 index 00000000000..1387343ed38 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5q8-8x36-w25p", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2025-0994" + ], + "details": "Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0994" + }, + { + "type": "WEB", + "url": "https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json b/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json new file mode 100644 index 00000000000..00b8b67bac2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mr5r-6xxx-6h84/GHSA-mr5r-6xxx-6h84.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr5r-6xxx-6h84", + "modified": "2025-02-06T18:31:06Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-36554" + ], + "details": "Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36554" + }, + { + "type": "WEB", + "url": "https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p8pr-5qmg-85fr/GHSA-p8pr-5qmg-85fr.json b/advisories/unreviewed/2025/02/GHSA-p8pr-5qmg-85fr/GHSA-p8pr-5qmg-85fr.json new file mode 100644 index 00000000000..bd82b25828b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p8pr-5qmg-85fr/GHSA-p8pr-5qmg-85fr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8pr-5qmg-85fr", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-57429" + ], + "details": "A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57429" + }, + { + "type": "WEB", + "url": "https://github.com/ahrixia/CVE-2024-57429" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pr8f-278h-qxq5/GHSA-pr8f-278h-qxq5.json b/advisories/unreviewed/2025/02/GHSA-pr8f-278h-qxq5/GHSA-pr8f-278h-qxq5.json new file mode 100644 index 00000000000..eef185d0f37 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pr8f-278h-qxq5/GHSA-pr8f-278h-qxq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr8f-278h-qxq5", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-13614" + ], + "details": "Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Security Cloud, Kaspersky Safe Kids, Kaspersky Anti-Ransomware Tool that could allow an authenticated attacker to write data to a limited area outside the allocated kernel memory buffer. The fix was installed automatically for all Kaspersky Endpoint products.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13614" + }, + { + "type": "WEB", + "url": "https://support.kaspersky.com/vulnerability/list-of-advisories/12430#060225" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q53q-67p3-fpjw/GHSA-q53q-67p3-fpjw.json b/advisories/unreviewed/2025/02/GHSA-q53q-67p3-fpjw/GHSA-q53q-67p3-fpjw.json new file mode 100644 index 00000000000..7af80cba645 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q53q-67p3-fpjw/GHSA-q53q-67p3-fpjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q53q-67p3-fpjw", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-39272" + ], + "details": "A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An attacker can send a series of HTTP requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39272" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q5j8-9m9g-x2jh/GHSA-q5j8-9m9g-x2jh.json b/advisories/unreviewed/2025/02/GHSA-q5j8-9m9g-x2jh/GHSA-q5j8-9m9g-x2jh.json index 2836806ebe3..153033c4df3 100644 --- a/advisories/unreviewed/2025/02/GHSA-q5j8-9m9g-x2jh/GHSA-q5j8-9m9g-x2jh.json +++ b/advisories/unreviewed/2025/02/GHSA-q5j8-9m9g-x2jh/GHSA-q5j8-9m9g-x2jh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q5j8-9m9g-x2jh", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57072" ], "details": "A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json b/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json new file mode 100644 index 00000000000..112f3c34c08 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r3wg-39gf-vffc/GHSA-r3wg-39gf-vffc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3wg-39gf-vffc", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-36555" + ], + "details": "Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity of the device.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36555" + }, + { + "type": "WEB", + "url": "https://www.diva-portal.org/smash/record.jsf?aq2=%5B%5B%5D%5D&c=1&af=%5B%5D&searchType=SIMPLE&sortOrder2=title_sort_asc&query=Exploiting+Vulnerabilities+to+Remotely+Hijack+Children%E2%80%99s+Smartwatches&language=en&pid=diva2%3A1933447&aq=%5B%5B%5D%5D&sf=undergraduate&aqe=%5B%5D&sortOrder=author_sort_asc&onlyFullText=false&noOfRows=50&dswid=-8296" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json b/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json index 82074fe7fec..3f217f3f633 100644 --- a/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json +++ b/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5mv-57ph-669q", - "modified": "2025-02-06T15:32:53Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T15:32:53Z", "aliases": [ "CVE-2022-31764" ], "details": "The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2.\nThe premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-913" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T15:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rmrj-5wj3-q8fr/GHSA-rmrj-5wj3-q8fr.json b/advisories/unreviewed/2025/02/GHSA-rmrj-5wj3-q8fr/GHSA-rmrj-5wj3-q8fr.json index b3b7bd8bf78..f03e3f778a5 100644 --- a/advisories/unreviewed/2025/02/GHSA-rmrj-5wj3-q8fr/GHSA-rmrj-5wj3-q8fr.json +++ b/advisories/unreviewed/2025/02/GHSA-rmrj-5wj3-q8fr/GHSA-rmrj-5wj3-q8fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rmrj-5wj3-q8fr", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57067" ], "details": "A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rppw-jjg7-2jhr/GHSA-rppw-jjg7-2jhr.json b/advisories/unreviewed/2025/02/GHSA-rppw-jjg7-2jhr/GHSA-rppw-jjg7-2jhr.json index e3cda8e8a02..06705e62a8a 100644 --- a/advisories/unreviewed/2025/02/GHSA-rppw-jjg7-2jhr/GHSA-rppw-jjg7-2jhr.json +++ b/advisories/unreviewed/2025/02/GHSA-rppw-jjg7-2jhr/GHSA-rppw-jjg7-2jhr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rppw-jjg7-2jhr", - "modified": "2025-02-06T06:31:25Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:25Z", "aliases": [ "CVE-2024-57063" ], "details": "A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rr8c-q6pv-gq4j/GHSA-rr8c-q6pv-gq4j.json b/advisories/unreviewed/2025/02/GHSA-rr8c-q6pv-gq4j/GHSA-rr8c-q6pv-gq4j.json new file mode 100644 index 00000000000..b596ea6b388 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rr8c-q6pv-gq4j/GHSA-rr8c-q6pv-gq4j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr8c-q6pv-gq4j", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2022-40916" + ], + "details": "Tiny File Manager v2.4.7 and below is vulnerable to session fixation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40916" + }, + { + "type": "WEB", + "url": "https://github.com/prasathmani/tinyfilemanager" + }, + { + "type": "WEB", + "url": "https://github.com/whitej3rry/CVE-2022-40916/blob/main/PoC.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v6jv-x2rf-449c/GHSA-v6jv-x2rf-449c.json b/advisories/unreviewed/2025/02/GHSA-v6jv-x2rf-449c/GHSA-v6jv-x2rf-449c.json new file mode 100644 index 00000000000..8c3ff673ac9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v6jv-x2rf-449c/GHSA-v6jv-x2rf-449c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6jv-x2rf-449c", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-43779" + ], + "details": "An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43779" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wcww-7w24-2j6v/GHSA-wcww-7w24-2j6v.json b/advisories/unreviewed/2025/02/GHSA-wcww-7w24-2j6v/GHSA-wcww-7w24-2j6v.json new file mode 100644 index 00000000000..04a34f3250b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wcww-7w24-2j6v/GHSA-wcww-7w24-2j6v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcww-7w24-2j6v", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2024-57427" + ], + "details": "PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57427" + }, + { + "type": "WEB", + "url": "https://github.com/ahrixia/CVE-2024-57427" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/cinema-booking-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wqpm-vffm-39w4/GHSA-wqpm-vffm-39w4.json b/advisories/unreviewed/2025/02/GHSA-wqpm-vffm-39w4/GHSA-wqpm-vffm-39w4.json index 5e715795669..d04d64d69eb 100644 --- a/advisories/unreviewed/2025/02/GHSA-wqpm-vffm-39w4/GHSA-wqpm-vffm-39w4.json +++ b/advisories/unreviewed/2025/02/GHSA-wqpm-vffm-39w4/GHSA-wqpm-vffm-39w4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wqpm-vffm-39w4", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T18:31:05Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57078" ], "details": "A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xfgc-qg25-x5jw/GHSA-xfgc-qg25-x5jw.json b/advisories/unreviewed/2025/02/GHSA-xfgc-qg25-x5jw/GHSA-xfgc-qg25-x5jw.json new file mode 100644 index 00000000000..13cadd8ea92 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xfgc-qg25-x5jw/GHSA-xfgc-qg25-x5jw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfgc-qg25-x5jw", + "modified": "2025-02-06T18:31:05Z", + "published": "2025-02-06T18:31:05Z", + "aliases": [ + "CVE-2025-1078" + ], + "details": "A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper of the component XPC Service. The manipulation leads to improper authorization. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 1.30 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure and acted very professional.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1078" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294844" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294844" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.492529" + }, + { + "type": "WEB", + "url": "https://winslow1984.com/books/cve-collection/page/aldente-charge-limiter-130-unauthorized-privileged-hardware-operations" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T17:15:21Z" + } +} \ No newline at end of file