diff --git a/advisories/unreviewed/2023/03/GHSA-29ph-8jj3-f6p6/GHSA-29ph-8jj3-f6p6.json b/advisories/unreviewed/2023/03/GHSA-29ph-8jj3-f6p6/GHSA-29ph-8jj3-f6p6.json index 745874501c1..559ae5f12f1 100644 --- a/advisories/unreviewed/2023/03/GHSA-29ph-8jj3-f6p6/GHSA-29ph-8jj3-f6p6.json +++ b/advisories/unreviewed/2023/03/GHSA-29ph-8jj3-f6p6/GHSA-29ph-8jj3-f6p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29ph-8jj3-f6p6", - "modified": "2023-03-17T06:30:35Z", + "modified": "2025-03-03T21:30:55Z", "published": "2023-03-13T15:30:19Z", "aliases": [ "CVE-2023-26074" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html" }, + { + "type": "WEB", + "url": "https://project-zero.issues.chromium.org/issues/42451536" + }, { "type": "WEB", "url": "https://semiconductor.samsung.com/processor/mobile-processor" diff --git a/advisories/unreviewed/2023/03/GHSA-5pgr-37hm-gqpw/GHSA-5pgr-37hm-gqpw.json b/advisories/unreviewed/2023/03/GHSA-5pgr-37hm-gqpw/GHSA-5pgr-37hm-gqpw.json index ea16b814f2e..5bccb6a7a6d 100644 --- a/advisories/unreviewed/2023/03/GHSA-5pgr-37hm-gqpw/GHSA-5pgr-37hm-gqpw.json +++ b/advisories/unreviewed/2023/03/GHSA-5pgr-37hm-gqpw/GHSA-5pgr-37hm-gqpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pgr-37hm-gqpw", - "modified": "2023-03-17T15:30:25Z", + "modified": "2025-03-03T21:30:54Z", "published": "2023-03-13T12:30:17Z", "aliases": [ "CVE-2023-24033" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-7m4j-wfjv-chxw/GHSA-7m4j-wfjv-chxw.json b/advisories/unreviewed/2023/03/GHSA-7m4j-wfjv-chxw/GHSA-7m4j-wfjv-chxw.json index 0171aa659e3..55abd6437cc 100644 --- a/advisories/unreviewed/2023/03/GHSA-7m4j-wfjv-chxw/GHSA-7m4j-wfjv-chxw.json +++ b/advisories/unreviewed/2023/03/GHSA-7m4j-wfjv-chxw/GHSA-7m4j-wfjv-chxw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-8gcq-hc82-pqq2/GHSA-8gcq-hc82-pqq2.json b/advisories/unreviewed/2023/03/GHSA-8gcq-hc82-pqq2/GHSA-8gcq-hc82-pqq2.json index 0954f47c366..3970e994a21 100644 --- a/advisories/unreviewed/2023/03/GHSA-8gcq-hc82-pqq2/GHSA-8gcq-hc82-pqq2.json +++ b/advisories/unreviewed/2023/03/GHSA-8gcq-hc82-pqq2/GHSA-8gcq-hc82-pqq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gcq-hc82-pqq2", - "modified": "2023-03-17T06:30:35Z", + "modified": "2025-03-03T21:30:55Z", "published": "2023-03-13T15:30:19Z", "aliases": [ "CVE-2023-24762" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24762" }, + { + "type": "WEB", + "url": "https://hackmd.io/%40uuXne2y3RjOdpWM87fw6_A/HyPK04zho" + }, { "type": "WEB", "url": "https://hackmd.io/@uuXne2y3RjOdpWM87fw6_A/HyPK04zho" diff --git a/advisories/unreviewed/2023/03/GHSA-fj79-cqcm-7g2m/GHSA-fj79-cqcm-7g2m.json b/advisories/unreviewed/2023/03/GHSA-fj79-cqcm-7g2m/GHSA-fj79-cqcm-7g2m.json index 3949e78cce6..ae3f084a274 100644 --- a/advisories/unreviewed/2023/03/GHSA-fj79-cqcm-7g2m/GHSA-fj79-cqcm-7g2m.json +++ b/advisories/unreviewed/2023/03/GHSA-fj79-cqcm-7g2m/GHSA-fj79-cqcm-7g2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj79-cqcm-7g2m", - "modified": "2023-03-17T06:30:35Z", + "modified": "2025-03-03T21:30:54Z", "published": "2023-03-13T12:30:17Z", "aliases": [ "CVE-2023-26072" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html" }, + { + "type": "WEB", + "url": "https://project-zero.issues.chromium.org/issues/42451534" + }, { "type": "WEB", "url": "https://semiconductor.samsung.com/processor/mobile-processor" diff --git a/advisories/unreviewed/2023/03/GHSA-q978-xx62-9w9r/GHSA-q978-xx62-9w9r.json b/advisories/unreviewed/2023/03/GHSA-q978-xx62-9w9r/GHSA-q978-xx62-9w9r.json index 71bfcf06de1..9dc5a506647 100644 --- a/advisories/unreviewed/2023/03/GHSA-q978-xx62-9w9r/GHSA-q978-xx62-9w9r.json +++ b/advisories/unreviewed/2023/03/GHSA-q978-xx62-9w9r/GHSA-q978-xx62-9w9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q978-xx62-9w9r", - "modified": "2023-03-17T06:30:35Z", + "modified": "2025-03-03T21:30:55Z", "published": "2023-03-13T15:30:19Z", "aliases": [ "CVE-2023-26073" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html" }, + { + "type": "WEB", + "url": "https://project-zero.issues.chromium.org/issues/42451535" + }, { "type": "WEB", "url": "https://semiconductor.samsung.com/processor/mobile-processor" diff --git a/advisories/unreviewed/2023/03/GHSA-vgrw-gggp-4wx3/GHSA-vgrw-gggp-4wx3.json b/advisories/unreviewed/2023/03/GHSA-vgrw-gggp-4wx3/GHSA-vgrw-gggp-4wx3.json index ff35062c767..43c01da10fe 100644 --- a/advisories/unreviewed/2023/03/GHSA-vgrw-gggp-4wx3/GHSA-vgrw-gggp-4wx3.json +++ b/advisories/unreviewed/2023/03/GHSA-vgrw-gggp-4wx3/GHSA-vgrw-gggp-4wx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vgrw-gggp-4wx3", - "modified": "2023-03-17T06:30:35Z", + "modified": "2025-03-03T21:30:55Z", "published": "2023-03-13T21:30:39Z", "aliases": [ "CVE-2023-25279" diff --git a/advisories/unreviewed/2023/03/GHSA-x79p-xvfj-9wfq/GHSA-x79p-xvfj-9wfq.json b/advisories/unreviewed/2023/03/GHSA-x79p-xvfj-9wfq/GHSA-x79p-xvfj-9wfq.json index 19e74639fa8..a935a7bc054 100644 --- a/advisories/unreviewed/2023/03/GHSA-x79p-xvfj-9wfq/GHSA-x79p-xvfj-9wfq.json +++ b/advisories/unreviewed/2023/03/GHSA-x79p-xvfj-9wfq/GHSA-x79p-xvfj-9wfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x79p-xvfj-9wfq", - "modified": "2023-03-20T15:30:20Z", + "modified": "2025-03-03T21:30:54Z", "published": "2023-03-13T06:30:25Z", "aliases": [ "CVE-2022-2259" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-2p2q-7m86-j6ch/GHSA-2p2q-7m86-j6ch.json b/advisories/unreviewed/2025/02/GHSA-2p2q-7m86-j6ch/GHSA-2p2q-7m86-j6ch.json index 4001655353f..982ed56c9e1 100644 --- a/advisories/unreviewed/2025/02/GHSA-2p2q-7m86-j6ch/GHSA-2p2q-7m86-j6ch.json +++ b/advisories/unreviewed/2025/02/GHSA-2p2q-7m86-j6ch/GHSA-2p2q-7m86-j6ch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2p2q-7m86-j6ch", - "modified": "2025-02-21T18:31:15Z", + "modified": "2025-03-03T21:30:56Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2025-25766" ], "details": "An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T18:16:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json b/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json index 6a8d068be25..8450cd9680a 100644 --- a/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json +++ b/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4hwx-j6w8-9w2r", - "modified": "2025-02-21T21:32:08Z", + "modified": "2025-03-03T21:30:56Z", "published": "2025-02-21T21:32:08Z", "aliases": [ "CVE-2025-25767" ], "details": "A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T19:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json index 30c1560971f..709804c47b8 100644 --- a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json +++ b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gghq-qp34-gqg8", - "modified": "2025-03-03T18:31:25Z", + "modified": "2025-03-03T21:30:56Z", "published": "2025-02-12T15:32:02Z", "aliases": [ "CVE-2025-1244" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2022" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2130" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2157" diff --git a/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json b/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json index 8ecedb4207b..c5a224533f8 100644 --- a/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json +++ b/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h76r-mvr3-76xg", - "modified": "2025-02-21T21:32:08Z", + "modified": "2025-03-03T21:30:56Z", "published": "2025-02-21T21:32:08Z", "aliases": [ "CVE-2025-25768" ], "details": "MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \\servlet\\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T19:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-mw38-fx9m-f8jc/GHSA-mw38-fx9m-f8jc.json b/advisories/unreviewed/2025/02/GHSA-mw38-fx9m-f8jc/GHSA-mw38-fx9m-f8jc.json index 9328ed4b08e..abee5a7473b 100644 --- a/advisories/unreviewed/2025/02/GHSA-mw38-fx9m-f8jc/GHSA-mw38-fx9m-f8jc.json +++ b/advisories/unreviewed/2025/02/GHSA-mw38-fx9m-f8jc/GHSA-mw38-fx9m-f8jc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mw38-fx9m-f8jc", - "modified": "2025-02-21T18:31:15Z", + "modified": "2025-03-03T21:30:56Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2025-25765" ], "details": "MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T18:16:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2cj7-q7vw-gwx8/GHSA-2cj7-q7vw-gwx8.json b/advisories/unreviewed/2025/03/GHSA-2cj7-q7vw-gwx8/GHSA-2cj7-q7vw-gwx8.json new file mode 100644 index 00000000000..021b5f8163b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2cj7-q7vw-gwx8/GHSA-2cj7-q7vw-gwx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cj7-q7vw-gwx8", + "modified": "2025-03-03T21:31:01Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51966" + ], + "details": "There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51966" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json b/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json new file mode 100644 index 00000000000..673e3a467d3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qh6-98mm-p9vr", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51953" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51953" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2v56-g578-78g2/GHSA-2v56-g578-78g2.json b/advisories/unreviewed/2025/03/GHSA-2v56-g578-78g2/GHSA-2v56-g578-78g2.json new file mode 100644 index 00000000000..bfb45e529f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2v56-g578-78g2/GHSA-2v56-g578-78g2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v56-g578-78g2", + "modified": "2025-03-03T21:31:01Z", + "published": "2025-03-03T21:31:01Z", + "aliases": [ + "CVE-2025-1880" + ], + "details": "A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1880" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/i-Drive" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298194" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298194" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510951" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-42jw-v43h-79m9/GHSA-42jw-v43h-79m9.json b/advisories/unreviewed/2025/03/GHSA-42jw-v43h-79m9/GHSA-42jw-v43h-79m9.json new file mode 100644 index 00000000000..ce80af9e1ad --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-42jw-v43h-79m9/GHSA-42jw-v43h-79m9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42jw-v43h-79m9", + "modified": "2025-03-03T21:31:01Z", + "published": "2025-03-03T21:31:01Z", + "aliases": [ + "CVE-2025-1882" + ], + "details": "A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1882" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/i-Drive" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298196" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298196" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510955" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json b/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json index 92927de8d49..acb37131e02 100644 --- a/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json +++ b/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qxw-jwh4-2vjv", - "modified": "2025-03-02T06:33:26Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-02T06:33:26Z", "aliases": [ "CVE-2025-1809" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/yago3008/cves" }, + { + "type": "WEB", + "url": "https://github.com/yago3008/cves/tree/main/CVE-2025-1809" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.298067" diff --git a/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json b/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json new file mode 100644 index 00000000000..90d9fa5cf04 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9h-49hf-v7f8", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51956" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51956" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json b/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json new file mode 100644 index 00000000000..a1265ab7ef6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5783-252r-fxpm", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2024-10904" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10904" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json b/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json new file mode 100644 index 00000000000..0017b40e8e0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggx-8w3f-h4gf", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51957" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51957" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json b/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json new file mode 100644 index 00000000000..13fcea34c47 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6pg6-qhjj-4wcm/GHSA-6pg6-qhjj-4wcm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pg6-qhjj-4wcm", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2025-25967" + ], + "details": "Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25967" + }, + { + "type": "WEB", + "url": "https://github.com/padayali-JD/CVE-2025-25967" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json b/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json new file mode 100644 index 00000000000..9a41ec073d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w26-66hj-8g45", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51942" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51942" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json b/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json new file mode 100644 index 00000000000..1f78f2bb62b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7855-vcjh-5fv2", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51945" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51945" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7qvr-xp68-rqhm/GHSA-7qvr-xp68-rqhm.json b/advisories/unreviewed/2025/03/GHSA-7qvr-xp68-rqhm/GHSA-7qvr-xp68-rqhm.json new file mode 100644 index 00000000000..8a8bfdd00af --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7qvr-xp68-rqhm/GHSA-7qvr-xp68-rqhm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qvr-xp68-rqhm", + "modified": "2025-03-03T21:31:01Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2025-1879" + ], + "details": "A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the physical device. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1879" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/i-Drive" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298193" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298193" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510950" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json b/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json new file mode 100644 index 00000000000..7a933d32021 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m3r-jg6f-34jp", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-5888" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5888" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wv6-qwwq-j2gj/GHSA-8wv6-qwwq-j2gj.json b/advisories/unreviewed/2025/03/GHSA-8wv6-qwwq-j2gj/GHSA-8wv6-qwwq-j2gj.json new file mode 100644 index 00000000000..70992890c76 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wv6-qwwq-j2gj/GHSA-8wv6-qwwq-j2gj.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wv6-qwwq-j2gj", + "modified": "2025-03-03T21:30:57Z", + "published": "2025-03-03T21:30:57Z", + "aliases": [ + "CVE-2025-25792" + ], + "details": "SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25792" + }, + { + "type": "WEB", + "url": "https://github.com/Ka7arotto/Seacms/blob/main/seacmsv13.3-rce-1.md" + }, + { + "type": "WEB", + "url": "https://www.seacms.com" + }, + { + "type": "WEB", + "url": "http://seacms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-97rw-2xpm-j863/GHSA-97rw-2xpm-j863.json b/advisories/unreviewed/2025/03/GHSA-97rw-2xpm-j863/GHSA-97rw-2xpm-j863.json index 68525a18bd1..45fbf467554 100644 --- a/advisories/unreviewed/2025/03/GHSA-97rw-2xpm-j863/GHSA-97rw-2xpm-j863.json +++ b/advisories/unreviewed/2025/03/GHSA-97rw-2xpm-j863/GHSA-97rw-2xpm-j863.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97rw-2xpm-j863", - "modified": "2025-03-02T03:30:31Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-02T03:30:31Z", "aliases": [ "CVE-2025-1808" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/yago3008/cves" }, + { + "type": "WEB", + "url": "https://github.com/yago3008/cves/tree/main/CVE-2025-1808" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.298066" diff --git a/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json b/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json new file mode 100644 index 00000000000..cdb4f67bf81 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h9v-jch8-f29w", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51950" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51950" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json b/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json new file mode 100644 index 00000000000..4c585e8fa59 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg48-xw7q-cpc8", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51961" + ], + "details": "There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51961" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json b/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json new file mode 100644 index 00000000000..d94b2546860 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwhx-ww39-3h7h", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51958" + ], + "details": "There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory.  There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51958" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json b/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json new file mode 100644 index 00000000000..023a279778f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxm9-pc6x-88r5", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51954" + ], + "details": "There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated)\n\nArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51954" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json b/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json index c237362dacc..6fd16a27c29 100644 --- a/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json +++ b/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f56w-wc87-frcc", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20651" ], "details": "In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json b/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json index 6d043453b08..703d19bf569 100644 --- a/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json +++ b/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqr8-q3mh-59gh", - "modified": "2025-03-02T18:30:53Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-02T18:30:53Z", "aliases": [ "CVE-2025-1818" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://www.yuque.com/u123456789-6sobi/cdgcbq/bg2g3eit41o4cpd4" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/u123456789-6sobi/cdgcbq/bg2g3eit41o4cpd4#" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json b/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json new file mode 100644 index 00000000000..524fce27822 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2q-29x3-38rp", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51951" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51951" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json b/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json new file mode 100644 index 00000000000..6f9b1b58158 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxxp-38jc-7cfq", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51959" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51959" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json b/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json new file mode 100644 index 00000000000..cf631f2059a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g274-9873-jcxx", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51962" + ], + "details": "A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51962" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json b/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json new file mode 100644 index 00000000000..ccc8cee9fe9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g468-6jvw-w4j4/GHSA-g468-6jvw-w4j4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g468-6jvw-w4j4", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2025-25939" + ], + "details": "Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25939" + }, + { + "type": "WEB", + "url": "https://github.com/SamR2406/CVE-IDs/blob/main/Reprise%20License%20Manager%2014.2%20-%20Reflected%20Cross-Site%20Scripting%20%28CVE-2025-25939%29" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json b/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json new file mode 100644 index 00000000000..6be27b4f83a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr9w-6j99-f5q5", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51947" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51947" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json b/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json new file mode 100644 index 00000000000..7c5a9a91d98 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h49w-5mwr-frr5", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51949" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51949" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hgp5-33wm-qq74/GHSA-hgp5-33wm-qq74.json b/advisories/unreviewed/2025/03/GHSA-hgp5-33wm-qq74/GHSA-hgp5-33wm-qq74.json new file mode 100644 index 00000000000..621052e6e2e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hgp5-33wm-qq74/GHSA-hgp5-33wm-qq74.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgp5-33wm-qq74", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2025-1878" + ], + "details": "A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects unknown code of the component WiFi. The manipulation leads to use of default password. Access to the local network is required for this attack to succeed. The complexity of an attack is rather high. The exploitation appears to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1878" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/i-Drive" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298192" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298192" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510949" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1393" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json b/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json new file mode 100644 index 00000000000..38e5ce500f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr72-4f8w-mw62", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51944" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51944" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hw34-rqc5-h2gm/GHSA-hw34-rqc5-h2gm.json b/advisories/unreviewed/2025/03/GHSA-hw34-rqc5-h2gm/GHSA-hw34-rqc5-h2gm.json new file mode 100644 index 00000000000..6a929d5aff2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hw34-rqc5-h2gm/GHSA-hw34-rqc5-h2gm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw34-rqc5-h2gm", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2025-1889" + ], + "details": "picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle include a malicious pickle file with a non-standard file extension. Because the malicious pickle file inclusion is not considered as part of the scope of picklescan, the file would pass security checks and appear to be safe, when it could instead prove to be problematic.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-655q-fx9r-782v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1889" + }, + { + "type": "WEB", + "url": "https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-1889" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-807" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxjw-pv8x-v7w3/GHSA-jxjw-pv8x-v7w3.json b/advisories/unreviewed/2025/03/GHSA-jxjw-pv8x-v7w3/GHSA-jxjw-pv8x-v7w3.json new file mode 100644 index 00000000000..262092034e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxjw-pv8x-v7w3/GHSA-jxjw-pv8x-v7w3.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxjw-pv8x-v7w3", + "modified": "2025-03-03T21:31:01Z", + "published": "2025-03-03T21:31:01Z", + "aliases": [ + "CVE-2025-1881" + ], + "details": "A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Video Footage/Live Video Stream. The manipulation leads to improper access controls. The attack can be launched remotely. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1881" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/i-Drive" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298195" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298195" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.510952" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json b/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json new file mode 100644 index 00000000000..1ae7187f987 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4jp-jx56-47gq", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51960" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51960" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json b/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json new file mode 100644 index 00000000000..018b4b8da9c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrpg-q4r4-m4g9", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51952" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51952" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json b/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json index 7a82e2a8649..8d7e1f53903 100644 --- a/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json +++ b/advisories/unreviewed/2025/03/GHSA-pcj4-9fcj-56c8/GHSA-pcj4-9fcj-56c8.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-305", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json b/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json new file mode 100644 index 00000000000..3eb865b9bec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgw2-vj22-3w7g", + "modified": "2025-03-03T21:31:01Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51963" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51963" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json b/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json new file mode 100644 index 00000000000..2631c08eab5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r47p-3h3g-wvw7", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51948" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51948" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json b/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json new file mode 100644 index 00000000000..16d09dca119 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r7pc-h4wr-xggx/GHSA-r7pc-h4wr-xggx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7pc-h4wr-xggx", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2025-26206" + ], + "details": "Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26206" + }, + { + "type": "WEB", + "url": "https://github.com/selldone/storefront/blob/main/index.html" + }, + { + "type": "WEB", + "url": "https://github.com/xibhi/CVE-2025-26206" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rf73-69vr-qxgj/GHSA-rf73-69vr-qxgj.json b/advisories/unreviewed/2025/03/GHSA-rf73-69vr-qxgj/GHSA-rf73-69vr-qxgj.json new file mode 100644 index 00000000000..145002dd789 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rf73-69vr-qxgj/GHSA-rf73-69vr-qxgj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf73-69vr-qxgj", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2025-1877" + ], + "details": "A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. The manipulation of the argument a1 leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1877" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298191" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298191" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.506526" + }, + { + "type": "WEB", + "url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1562-pure_auth_check-Vulnerability-1a5b2f2a63618013a1fecb743f2d0667" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rf85-mcvw-mw7j/GHSA-rf85-mcvw-mw7j.json b/advisories/unreviewed/2025/03/GHSA-rf85-mcvw-mw7j/GHSA-rf85-mcvw-mw7j.json index b5fec0ba29e..ce6617b0af9 100644 --- a/advisories/unreviewed/2025/03/GHSA-rf85-mcvw-mw7j/GHSA-rf85-mcvw-mw7j.json +++ b/advisories/unreviewed/2025/03/GHSA-rf85-mcvw-mw7j/GHSA-rf85-mcvw-mw7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rf85-mcvw-mw7j", - "modified": "2025-03-03T18:31:29Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2025-0287" ], "details": "Paragon Partition Manager version 7.9.1 contains a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T17:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json b/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json index 4474a51e93b..ffe1d55edb0 100644 --- a/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json +++ b/advisories/unreviewed/2025/03/GHSA-rh3q-7g79-rp3x/GHSA-rh3q-7g79-rp3x.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-305", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json b/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json new file mode 100644 index 00000000000..6eda66e183b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rvh7-h8xh-g43v/GHSA-rvh7-h8xh-g43v.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvh7-h8xh-g43v", + "modified": "2025-03-03T21:30:59Z", + "published": "2025-03-03T21:30:59Z", + "aliases": [ + "CVE-2024-30154" + ], + "details": "HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30154" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119437" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T19:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w87r-fm8h-m3v8/GHSA-w87r-fm8h-m3v8.json b/advisories/unreviewed/2025/03/GHSA-w87r-fm8h-m3v8/GHSA-w87r-fm8h-m3v8.json index 88fb2417be3..23a8a27782b 100644 --- a/advisories/unreviewed/2025/03/GHSA-w87r-fm8h-m3v8/GHSA-w87r-fm8h-m3v8.json +++ b/advisories/unreviewed/2025/03/GHSA-w87r-fm8h-m3v8/GHSA-w87r-fm8h-m3v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w87r-fm8h-m3v8", - "modified": "2025-03-02T00:35:15Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-02T00:35:15Z", "aliases": [ "CVE-2025-1806" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1806" }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1WT5mJwL9NvKxBLIIj7TDbeAq6dchs5Gk/view" + }, { "type": "WEB", "url": "https://drive.google.com/file/d/1WT5mJwL9NvKxBLIIj7TDbeAq6dchs5Gk/view?usp=sharing" diff --git a/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json b/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json new file mode 100644 index 00000000000..2b4aa273dbe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8g5-2237-xmj2", + "modified": "2025-03-03T21:31:00Z", + "published": "2025-03-03T21:31:00Z", + "aliases": [ + "CVE-2024-51946" + ], + "details": "There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51946" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/arcgis-server-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wp9g-3wc9-grhr/GHSA-wp9g-3wc9-grhr.json b/advisories/unreviewed/2025/03/GHSA-wp9g-3wc9-grhr/GHSA-wp9g-3wc9-grhr.json index 373a6c69f33..dfdf1ebf6dd 100644 --- a/advisories/unreviewed/2025/03/GHSA-wp9g-3wc9-grhr/GHSA-wp9g-3wc9-grhr.json +++ b/advisories/unreviewed/2025/03/GHSA-wp9g-3wc9-grhr/GHSA-wp9g-3wc9-grhr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wp9g-3wc9-grhr", - "modified": "2025-03-02T09:30:31Z", + "modified": "2025-03-03T21:30:58Z", "published": "2025-03-02T09:30:31Z", "aliases": [ "CVE-2025-1811" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/yago3008/cves" }, + { + "type": "WEB", + "url": "https://github.com/yago3008/cves/tree/main/CVE-2025-1811" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.298069"