diff --git a/advisories/unreviewed/2023/06/GHSA-7c26-765q-28xr/GHSA-7c26-765q-28xr.json b/advisories/unreviewed/2023/06/GHSA-7c26-765q-28xr/GHSA-7c26-765q-28xr.json
index af1b3a42845..3573dc1da6b 100644
--- a/advisories/unreviewed/2023/06/GHSA-7c26-765q-28xr/GHSA-7c26-765q-28xr.json
+++ b/advisories/unreviewed/2023/06/GHSA-7c26-765q-28xr/GHSA-7c26-765q-28xr.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-404"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/06/GHSA-cf9g-jhqf-gm5j/GHSA-cf9g-jhqf-gm5j.json b/advisories/unreviewed/2023/06/GHSA-cf9g-jhqf-gm5j/GHSA-cf9g-jhqf-gm5j.json
index afd4a149ff2..77b457e012b 100644
--- a/advisories/unreviewed/2023/06/GHSA-cf9g-jhqf-gm5j/GHSA-cf9g-jhqf-gm5j.json
+++ b/advisories/unreviewed/2023/06/GHSA-cf9g-jhqf-gm5j/GHSA-cf9g-jhqf-gm5j.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-346"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/06/GHSA-h6fr-rh94-prmv/GHSA-h6fr-rh94-prmv.json b/advisories/unreviewed/2023/06/GHSA-h6fr-rh94-prmv/GHSA-h6fr-rh94-prmv.json
index 3c0f20a133e..bb966a4c8ef 100644
--- a/advisories/unreviewed/2023/06/GHSA-h6fr-rh94-prmv/GHSA-h6fr-rh94-prmv.json
+++ b/advisories/unreviewed/2023/06/GHSA-h6fr-rh94-prmv/GHSA-h6fr-rh94-prmv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6fr-rh94-prmv",
- "modified": "2023-11-25T12:30:22Z",
+ "modified": "2025-01-07T18:30:37Z",
"published": "2023-06-07T21:30:18Z",
"aliases": [
"CVE-2023-33865"
diff --git a/advisories/unreviewed/2023/06/GHSA-m7x4-fm9r-7wj8/GHSA-m7x4-fm9r-7wj8.json b/advisories/unreviewed/2023/06/GHSA-m7x4-fm9r-7wj8/GHSA-m7x4-fm9r-7wj8.json
index 734af627f3a..39ccecf5f76 100644
--- a/advisories/unreviewed/2023/06/GHSA-m7x4-fm9r-7wj8/GHSA-m7x4-fm9r-7wj8.json
+++ b/advisories/unreviewed/2023/06/GHSA-m7x4-fm9r-7wj8/GHSA-m7x4-fm9r-7wj8.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-276",
"CWE-284"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2023/06/GHSA-r63h-2v62-7gwc/GHSA-r63h-2v62-7gwc.json b/advisories/unreviewed/2023/06/GHSA-r63h-2v62-7gwc/GHSA-r63h-2v62-7gwc.json
index e8b5ed1d350..ee72edbb716 100644
--- a/advisories/unreviewed/2023/06/GHSA-r63h-2v62-7gwc/GHSA-r63h-2v62-7gwc.json
+++ b/advisories/unreviewed/2023/06/GHSA-r63h-2v62-7gwc/GHSA-r63h-2v62-7gwc.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-1021"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/06/GHSA-wg27-v6fh-mh3j/GHSA-wg27-v6fh-mh3j.json b/advisories/unreviewed/2023/06/GHSA-wg27-v6fh-mh3j/GHSA-wg27-v6fh-mh3j.json
index ff852bbe72b..66b09140b20 100644
--- a/advisories/unreviewed/2023/06/GHSA-wg27-v6fh-mh3j/GHSA-wg27-v6fh-mh3j.json
+++ b/advisories/unreviewed/2023/06/GHSA-wg27-v6fh-mh3j/GHSA-wg27-v6fh-mh3j.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-290"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/07/GHSA-jjr8-xqm6-pj73/GHSA-jjr8-xqm6-pj73.json b/advisories/unreviewed/2023/07/GHSA-jjr8-xqm6-pj73/GHSA-jjr8-xqm6-pj73.json
index aa953bf1ec3..a46e089bcac 100644
--- a/advisories/unreviewed/2023/07/GHSA-jjr8-xqm6-pj73/GHSA-jjr8-xqm6-pj73.json
+++ b/advisories/unreviewed/2023/07/GHSA-jjr8-xqm6-pj73/GHSA-jjr8-xqm6-pj73.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjr8-xqm6-pj73",
- "modified": "2024-04-04T05:49:18Z",
+ "modified": "2025-01-07T18:30:36Z",
"published": "2023-07-06T21:15:07Z",
"aliases": [
"CVE-2023-20889"
diff --git a/advisories/unreviewed/2023/07/GHSA-pv9w-3hhv-xhxr/GHSA-pv9w-3hhv-xhxr.json b/advisories/unreviewed/2023/07/GHSA-pv9w-3hhv-xhxr/GHSA-pv9w-3hhv-xhxr.json
index 43e98dc5b99..2f11fae3f37 100644
--- a/advisories/unreviewed/2023/07/GHSA-pv9w-3hhv-xhxr/GHSA-pv9w-3hhv-xhxr.json
+++ b/advisories/unreviewed/2023/07/GHSA-pv9w-3hhv-xhxr/GHSA-pv9w-3hhv-xhxr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv9w-3hhv-xhxr",
- "modified": "2024-04-04T05:49:13Z",
+ "modified": "2025-01-07T18:30:36Z",
"published": "2023-07-06T21:15:07Z",
"aliases": [
"CVE-2023-20888"
diff --git a/advisories/unreviewed/2024/03/GHSA-2p62-g69r-34gr/GHSA-2p62-g69r-34gr.json b/advisories/unreviewed/2024/03/GHSA-2p62-g69r-34gr/GHSA-2p62-g69r-34gr.json
index d8d7fcb44e2..706d5f08272 100644
--- a/advisories/unreviewed/2024/03/GHSA-2p62-g69r-34gr/GHSA-2p62-g69r-34gr.json
+++ b/advisories/unreviewed/2024/03/GHSA-2p62-g69r-34gr/GHSA-2p62-g69r-34gr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p62-g69r-34gr",
- "modified": "2024-03-07T06:30:31Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-07T06:30:31Z",
"aliases": [
"CVE-2024-1377"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-6297-42q7-j694/GHSA-6297-42q7-j694.json b/advisories/unreviewed/2024/03/GHSA-6297-42q7-j694/GHSA-6297-42q7-j694.json
index 3130f0ca3e4..ab4cbde8e44 100644
--- a/advisories/unreviewed/2024/03/GHSA-6297-42q7-j694/GHSA-6297-42q7-j694.json
+++ b/advisories/unreviewed/2024/03/GHSA-6297-42q7-j694/GHSA-6297-42q7-j694.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6297-42q7-j694",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47125"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch_htb: fix refcount leak in htb_parent_to_leaf_offload\n\nThe commit ae81feb7338c (\"sch_htb: fix null pointer dereference\non a null new_q\") fixes a NULL pointer dereference bug, but it\nis not correct.\n\nBecause htb_graft_helper properly handles the case when new_q\nis NULL, and after the previous patch by skipping this call\nwhich creates an inconsistency : dev_queue->qdisc will still\npoint to the old qdisc, but cl->parent->leaf.q will point to\nthe new one (which will be noop_qdisc, because new_q was NULL).\nThe code is based on an assumption that these two pointers are\nthe same, so it can lead to refcount leaks.\n\nThe correct fix is to add a NULL pointer check to protect\nqdisc_refcount_inc inside htb_parent_to_leaf_offload.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-759c-p77c-j97r/GHSA-759c-p77c-j97r.json b/advisories/unreviewed/2024/03/GHSA-759c-p77c-j97r/GHSA-759c-p77c-j97r.json
index 21adf7bb498..532e3890397 100644
--- a/advisories/unreviewed/2024/03/GHSA-759c-p77c-j97r/GHSA-759c-p77c-j97r.json
+++ b/advisories/unreviewed/2024/03/GHSA-759c-p77c-j97r/GHSA-759c-p77c-j97r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-759c-p77c-j97r",
- "modified": "2024-03-04T21:31:11Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-04T21:31:11Z",
"aliases": [
"CVE-2021-47104"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/qib: Fix memory leak in qib_user_sdma_queue_pkts()\n\nThe wrong goto label was used for the error case and missed cleanup of the\npkt allocation.\n\nAddresses-Coverity-ID: 1493352 (\"Resource leak\")",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T19:15:18Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-7r6r-wq8x-9959/GHSA-7r6r-wq8x-9959.json b/advisories/unreviewed/2024/03/GHSA-7r6r-wq8x-9959/GHSA-7r6r-wq8x-9959.json
index 387bf7a27bd..9c5e8bacb3b 100644
--- a/advisories/unreviewed/2024/03/GHSA-7r6r-wq8x-9959/GHSA-7r6r-wq8x-9959.json
+++ b/advisories/unreviewed/2024/03/GHSA-7r6r-wq8x-9959/GHSA-7r6r-wq8x-9959.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7r6r-wq8x-9959",
- "modified": "2024-03-07T21:30:21Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-07T21:30:21Z",
"aliases": [
"CVE-2024-1802"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-825x-jxfp-rh4x/GHSA-825x-jxfp-rh4x.json b/advisories/unreviewed/2024/03/GHSA-825x-jxfp-rh4x/GHSA-825x-jxfp-rh4x.json
index df30094b677..f6fe1d21192 100644
--- a/advisories/unreviewed/2024/03/GHSA-825x-jxfp-rh4x/GHSA-825x-jxfp-rh4x.json
+++ b/advisories/unreviewed/2024/03/GHSA-825x-jxfp-rh4x/GHSA-825x-jxfp-rh4x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-825x-jxfp-rh4x",
- "modified": "2024-03-02T12:30:23Z",
+ "modified": "2025-01-07T18:30:37Z",
"published": "2024-03-02T12:30:23Z",
"aliases": [
"CVE-2024-0611"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json b/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json
index cafd7a12a23..8a791d47341 100644
--- a/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json
+++ b/advisories/unreviewed/2024/03/GHSA-8pp8-jv8p-6mxh/GHSA-8pp8-jv8p-6mxh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8pp8-jv8p-6mxh",
- "modified": "2024-03-02T12:30:23Z",
+ "modified": "2025-01-07T18:30:37Z",
"published": "2024-03-02T12:30:23Z",
"aliases": [
"CVE-2024-1449"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-8v27-f4gj-22cx/GHSA-8v27-f4gj-22cx.json b/advisories/unreviewed/2024/03/GHSA-8v27-f4gj-22cx/GHSA-8v27-f4gj-22cx.json
index 1e458544bfd..25d36b68739 100644
--- a/advisories/unreviewed/2024/03/GHSA-8v27-f4gj-22cx/GHSA-8v27-f4gj-22cx.json
+++ b/advisories/unreviewed/2024/03/GHSA-8v27-f4gj-22cx/GHSA-8v27-f4gj-22cx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8v27-f4gj-22cx",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47120"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: fix NULL-deref on disconnect\n\nCommit 9d7b18668956 (\"HID: magicmouse: add support for Apple Magic\nTrackpad 2\") added a sanity check for an Apple trackpad but returned\nsuccess instead of -ENODEV when the check failed. This means that the\nremove callback will dereference the never-initialised driver data\npointer when the driver is later unbound (e.g. on USB disconnect).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-fmwv-86xp-6vwg/GHSA-fmwv-86xp-6vwg.json b/advisories/unreviewed/2024/03/GHSA-fmwv-86xp-6vwg/GHSA-fmwv-86xp-6vwg.json
index dda6599b000..c5891597e22 100644
--- a/advisories/unreviewed/2024/03/GHSA-fmwv-86xp-6vwg/GHSA-fmwv-86xp-6vwg.json
+++ b/advisories/unreviewed/2024/03/GHSA-fmwv-86xp-6vwg/GHSA-fmwv-86xp-6vwg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmwv-86xp-6vwg",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47121"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: caif: fix memory leak in cfusbl_device_notify\n\nIn case of caif_enroll_dev() fail, allocated\nlink_support won't be assigned to the corresponding\nstructure. So simply free allocated pointer in case\nof error.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-fvc5-x7w5-6983/GHSA-fvc5-x7w5-6983.json b/advisories/unreviewed/2024/03/GHSA-fvc5-x7w5-6983/GHSA-fvc5-x7w5-6983.json
index 056480da6df..0bb2f91a3da 100644
--- a/advisories/unreviewed/2024/03/GHSA-fvc5-x7w5-6983/GHSA-fvc5-x7w5-6983.json
+++ b/advisories/unreviewed/2024/03/GHSA-fvc5-x7w5-6983/GHSA-fvc5-x7w5-6983.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvc5-x7w5-6983",
- "modified": "2024-03-07T06:30:31Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-07T06:30:31Z",
"aliases": [
"CVE-2024-1366"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-g7pr-gf5r-fx64/GHSA-g7pr-gf5r-fx64.json b/advisories/unreviewed/2024/03/GHSA-g7pr-gf5r-fx64/GHSA-g7pr-gf5r-fx64.json
index 320c34db162..a198ce00f51 100644
--- a/advisories/unreviewed/2024/03/GHSA-g7pr-gf5r-fx64/GHSA-g7pr-gf5r-fx64.json
+++ b/advisories/unreviewed/2024/03/GHSA-g7pr-gf5r-fx64/GHSA-g7pr-gf5r-fx64.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g7pr-gf5r-fx64",
- "modified": "2024-05-01T18:30:35Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52564"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"tty: n_gsm: fix UAF in gsm_cleanup_mux\"\n\nThis reverts commit 9b9c8195f3f0d74a826077fc1c01b9ee74907239.\n\nThe commit above is reverted as it did not solve the original issue.\n\ngsm_cleanup_mux() tries to free up the virtual ttys by calling\ngsm_dlci_release() for each available DLCI. There, dlci_put() is called to\ndecrease the reference counter for the DLCI via tty_port_put() which\nfinally calls gsm_dlci_free(). This already clears the pointer which is\nbeing checked in gsm_cleanup_mux() before calling gsm_dlci_release().\nTherefore, it is not necessary to clear this pointer in gsm_cleanup_mux()\nas done in the reverted commit. The commit introduces a null pointer\ndereference:\n \n ? __die+0x1f/0x70\n ? page_fault_oops+0x156/0x420\n ? search_exception_tables+0x37/0x50\n ? fixup_exception+0x21/0x310\n ? exc_page_fault+0x69/0x150\n ? asm_exc_page_fault+0x26/0x30\n ? tty_port_put+0x19/0xa0\n gsmtty_cleanup+0x29/0x80 [n_gsm]\n release_one_tty+0x37/0xe0\n process_one_work+0x1e6/0x3e0\n worker_thread+0x4c/0x3d0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe1/0x110\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2f/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \n\nThe actual issue is that nothing guards dlci_put() from being called\nmultiple times while the tty driver was triggered but did not yet finished\ncalling gsm_dlci_free().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-g9m8-8v57-f35j/GHSA-g9m8-8v57-f35j.json b/advisories/unreviewed/2024/03/GHSA-g9m8-8v57-f35j/GHSA-g9m8-8v57-f35j.json
index 44f521ec58d..386bfbcede7 100644
--- a/advisories/unreviewed/2024/03/GHSA-g9m8-8v57-f35j/GHSA-g9m8-8v57-f35j.json
+++ b/advisories/unreviewed/2024/03/GHSA-g9m8-8v57-f35j/GHSA-g9m8-8v57-f35j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9m8-8v57-f35j",
- "modified": "2024-03-23T03:30:25Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-23T03:30:25Z",
"aliases": [
"CVE-2024-2688"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json b/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json
index 2989da05f4a..770f396e126 100644
--- a/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json
+++ b/advisories/unreviewed/2024/03/GHSA-j4qq-hcfp-m638/GHSA-j4qq-hcfp-m638.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j4qq-hcfp-m638",
- "modified": "2024-03-11T18:31:09Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-11T18:31:09Z",
"aliases": [
"CVE-2023-52490"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: migrate: fix getting incorrect page mapping during page migration\n\nWhen running stress-ng testing, we found below kernel crash after a few hours:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\npc : dentry_name+0xd8/0x224\nlr : pointer+0x22c/0x370\nsp : ffff800025f134c0\n......\nCall trace:\n dentry_name+0xd8/0x224\n pointer+0x22c/0x370\n vsnprintf+0x1ec/0x730\n vscnprintf+0x2c/0x60\n vprintk_store+0x70/0x234\n vprintk_emit+0xe0/0x24c\n vprintk_default+0x3c/0x44\n vprintk_func+0x84/0x2d0\n printk+0x64/0x88\n __dump_page+0x52c/0x530\n dump_page+0x14/0x20\n set_migratetype_isolate+0x110/0x224\n start_isolate_page_range+0xc4/0x20c\n offline_pages+0x124/0x474\n memory_block_offline+0x44/0xf4\n memory_subsys_offline+0x3c/0x70\n device_offline+0xf0/0x120\n ......\n\nAfter analyzing the vmcore, I found this issue is caused by page migration.\nThe scenario is that, one thread is doing page migration, and we will use the\ntarget page's ->mapping field to save 'anon_vma' pointer between page unmap and\npage move, and now the target page is locked and refcount is 1.\n\nCurrently, there is another stress-ng thread performing memory hotplug,\nattempting to offline the target page that is being migrated. It discovers that\nthe refcount of this target page is 1, preventing the offline operation, thus\nproceeding to dump the page. However, page_mapping() of the target page may\nreturn an incorrect file mapping to crash the system in dump_mapping(), since\nthe target page->mapping only saves 'anon_vma' pointer without setting\nPAGE_MAPPING_ANON flag.\n\nThere are seveval ways to fix this issue:\n(1) Setting the PAGE_MAPPING_ANON flag for target page's ->mapping when saving\n'anon_vma', but this can confuse PageAnon() for PFN walkers, since the target\npage has not built mappings yet.\n(2) Getting the page lock to call page_mapping() in __dump_page() to avoid crashing\nthe system, however, there are still some PFN walkers that call page_mapping()\nwithout holding the page lock, such as compaction.\n(3) Using target page->private field to save the 'anon_vma' pointer and 2 bits\npage state, just as page->mapping records an anonymous page, which can remove\nthe page_mapping() impact for PFN walkers and also seems a simple way.\n\nSo I choose option 3 to fix this issue, and this can also fix other potential\nissues for PFN walkers, such as compaction.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T18:15:16Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-jwrw-gr4p-2mx9/GHSA-jwrw-gr4p-2mx9.json b/advisories/unreviewed/2024/03/GHSA-jwrw-gr4p-2mx9/GHSA-jwrw-gr4p-2mx9.json
index 8ddf3d18a86..839deff003e 100644
--- a/advisories/unreviewed/2024/03/GHSA-jwrw-gr4p-2mx9/GHSA-jwrw-gr4p-2mx9.json
+++ b/advisories/unreviewed/2024/03/GHSA-jwrw-gr4p-2mx9/GHSA-jwrw-gr4p-2mx9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwrw-gr4p-2mx9",
- "modified": "2024-03-25T12:30:52Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47180"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: nci: fix memory leak in nci_allocate_device\n\nnfcmrvl_disconnect fails to free the hci_dev field in struct nci_dev.\nFix this by freeing hci_dev in nci_free_device.\n\nBUG: memory leak\nunreferenced object 0xffff888111ea6800 (size 1024):\n comm \"kworker/1:0\", pid 19, jiffies 4294942308 (age 13.580s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 60 fd 0c 81 88 ff ff .........`......\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<000000004bc25d43>] kmalloc include/linux/slab.h:552 [inline]\n [<000000004bc25d43>] kzalloc include/linux/slab.h:682 [inline]\n [<000000004bc25d43>] nci_hci_allocate+0x21/0xd0 net/nfc/nci/hci.c:784\n [<00000000c59cff92>] nci_allocate_device net/nfc/nci/core.c:1170 [inline]\n [<00000000c59cff92>] nci_allocate_device+0x10b/0x160 net/nfc/nci/core.c:1132\n [<00000000006e0a8e>] nfcmrvl_nci_register_dev+0x10a/0x1c0 drivers/nfc/nfcmrvl/main.c:153\n [<000000004da1b57e>] nfcmrvl_probe+0x223/0x290 drivers/nfc/nfcmrvl/usb.c:345\n [<00000000d506aed9>] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396\n [<00000000bc632c92>] really_probe+0x159/0x4a0 drivers/base/dd.c:554\n [<00000000f5009125>] driver_probe_device+0x84/0x100 drivers/base/dd.c:740\n [<000000000ce658ca>] __device_attach_driver+0xee/0x110 drivers/base/dd.c:846\n [<000000007067d05f>] bus_for_each_drv+0xb7/0x100 drivers/base/bus.c:431\n [<00000000f8e13372>] __device_attach+0x122/0x250 drivers/base/dd.c:914\n [<000000009cf68860>] bus_probe_device+0xc6/0xe0 drivers/base/bus.c:491\n [<00000000359c965a>] device_add+0x5be/0xc30 drivers/base/core.c:3109\n [<00000000086e4bd3>] usb_set_configuration+0x9d9/0xb90 drivers/usb/core/message.c:2164\n [<00000000ca036872>] usb_generic_driver_probe+0x8c/0xc0 drivers/usb/core/generic.c:238\n [<00000000d40d36f6>] usb_probe_device+0x5c/0x140 drivers/usb/core/driver.c:293\n [<00000000bc632c92>] really_probe+0x159/0x4a0 drivers/base/dd.c:554",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:09Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-p8wh-6xv6-4499/GHSA-p8wh-6xv6-4499.json b/advisories/unreviewed/2024/03/GHSA-p8wh-6xv6-4499/GHSA-p8wh-6xv6-4499.json
index c881cb58f67..c6b47aff13e 100644
--- a/advisories/unreviewed/2024/03/GHSA-p8wh-6xv6-4499/GHSA-p8wh-6xv6-4499.json
+++ b/advisories/unreviewed/2024/03/GHSA-p8wh-6xv6-4499/GHSA-p8wh-6xv6-4499.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8wh-6xv6-4499",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47122"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: caif: fix memory leak in caif_device_notify\n\nIn case of caif_enroll_dev() fail, allocated\nlink_support won't be assigned to the corresponding\nstructure. So simply free allocated pointer in case\nof error",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json b/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json
index cc6d3d5c5ba..230896ec27a 100644
--- a/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json
+++ b/advisories/unreviewed/2024/03/GHSA-pw43-2cfm-ff7r/GHSA-pw43-2cfm-ff7r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pw43-2cfm-ff7r",
- "modified": "2024-03-02T12:30:23Z",
+ "modified": "2025-01-07T18:30:37Z",
"published": "2024-03-02T12:30:23Z",
"aliases": [
"CVE-2023-6326"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-q5v6-wm64-95g6/GHSA-q5v6-wm64-95g6.json b/advisories/unreviewed/2024/03/GHSA-q5v6-wm64-95g6/GHSA-q5v6-wm64-95g6.json
index 3d21e7136b2..bfbfcb060d2 100644
--- a/advisories/unreviewed/2024/03/GHSA-q5v6-wm64-95g6/GHSA-q5v6-wm64-95g6.json
+++ b/advisories/unreviewed/2024/03/GHSA-q5v6-wm64-95g6/GHSA-q5v6-wm64-95g6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5v6-wm64-95g6",
- "modified": "2024-03-23T03:30:25Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-23T03:30:25Z",
"aliases": [
"CVE-2024-2468"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-q7g4-fr87-482c/GHSA-q7g4-fr87-482c.json b/advisories/unreviewed/2024/03/GHSA-q7g4-fr87-482c/GHSA-q7g4-fr87-482c.json
index a8c00dba163..89d8483df1d 100644
--- a/advisories/unreviewed/2024/03/GHSA-q7g4-fr87-482c/GHSA-q7g4-fr87-482c.json
+++ b/advisories/unreviewed/2024/03/GHSA-q7g4-fr87-482c/GHSA-q7g4-fr87-482c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q7g4-fr87-482c",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47116"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix memory leak in ext4_mb_init_backend on error path.\n\nFix a memory leak discovered by syzbot when a file system is corrupted\nwith an illegally large s_log_groups_per_flex.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:06Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-r42v-97m8-w3j8/GHSA-r42v-97m8-w3j8.json b/advisories/unreviewed/2024/03/GHSA-r42v-97m8-w3j8/GHSA-r42v-97m8-w3j8.json
index 093f9bf32ba..93ad151df49 100644
--- a/advisories/unreviewed/2024/03/GHSA-r42v-97m8-w3j8/GHSA-r42v-97m8-w3j8.json
+++ b/advisories/unreviewed/2024/03/GHSA-r42v-97m8-w3j8/GHSA-r42v-97m8-w3j8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r42v-97m8-w3j8",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47133"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: amd_sfh: Fix memory leak in amd_sfh_work\n\nKmemleak tool detected a memory leak in the amd_sfh driver.\n\n====================\nunreferenced object 0xffff88810228ada0 (size 32):\n comm \"insmod\", pid 3968, jiffies 4295056001 (age 775.792s)\n hex dump (first 32 bytes):\n 00 20 73 1f 81 88 ff ff 00 01 00 00 00 00 ad de . s.............\n 22 01 00 00 00 00 ad de 01 00 02 00 00 00 00 00 \"...............\n backtrace:\n [<000000007b4c8799>] kmem_cache_alloc_trace+0x163/0x4f0\n [<0000000005326893>] amd_sfh_get_report+0xa4/0x1d0 [amd_sfh]\n [<000000002a9e5ec4>] amdtp_hid_request+0x62/0x80 [amd_sfh]\n [<00000000b8a95807>] sensor_hub_get_feature+0x145/0x270 [hid_sensor_hub]\n [<00000000fda054ee>] hid_sensor_parse_common_attributes+0x215/0x460 [hid_sensor_iio_common]\n [<0000000021279ecf>] hid_accel_3d_probe+0xff/0x4a0 [hid_sensor_accel_3d]\n [<00000000915760ce>] platform_probe+0x6a/0xd0\n [<0000000060258a1f>] really_probe+0x192/0x620\n [<00000000fa812f2d>] driver_probe_device+0x14a/0x1d0\n [<000000005e79f7fd>] __device_attach_driver+0xbd/0x110\n [<0000000070d15018>] bus_for_each_drv+0xfd/0x160\n [<0000000013a3c312>] __device_attach+0x18b/0x220\n [<000000008c7b4afc>] device_initial_probe+0x13/0x20\n [<00000000e6e99665>] bus_probe_device+0xfe/0x120\n [<00000000833fa90b>] device_add+0x6a6/0xe00\n [<00000000fa901078>] platform_device_add+0x180/0x380\n====================\n\nThe fix is to freeing request_list entry once the processed entry is\nremoved from the request_list.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-wp5w-r3x6-pmqh/GHSA-wp5w-r3x6-pmqh.json b/advisories/unreviewed/2024/03/GHSA-wp5w-r3x6-pmqh/GHSA-wp5w-r3x6-pmqh.json
index be45b7efdfe..e7f4a655b86 100644
--- a/advisories/unreviewed/2024/03/GHSA-wp5w-r3x6-pmqh/GHSA-wp5w-r3x6-pmqh.json
+++ b/advisories/unreviewed/2024/03/GHSA-wp5w-r3x6-pmqh/GHSA-wp5w-r3x6-pmqh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wp5w-r3x6-pmqh",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47127"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: track AF_XDP ZC enabled queues in bitmap\n\nCommit c7a219048e45 (\"ice: Remove xsk_buff_pool from VSI structure\")\nsilently introduced a regression and broke the Tx side of AF_XDP in copy\nmode. xsk_pool on ice_ring is set only based on the existence of the XDP\nprog on the VSI which in turn picks ice_clean_tx_irq_zc to be executed.\nThat is not something that should happen for copy mode as it should use\nthe regular data path ice_clean_tx_irq.\n\nThis results in a following splat when xdpsock is run in txonly or l2fwd\nscenarios in copy mode:\n\n\n[ 106.050195] BUG: kernel NULL pointer dereference, address: 0000000000000030\n[ 106.057269] #PF: supervisor read access in kernel mode\n[ 106.062493] #PF: error_code(0x0000) - not-present page\n[ 106.067709] PGD 0 P4D 0\n[ 106.070293] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ 106.074721] CPU: 61 PID: 0 Comm: swapper/61 Not tainted 5.12.0-rc2+ #45\n[ 106.081436] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019\n[ 106.092027] RIP: 0010:xp_raw_get_dma+0x36/0x50\n[ 106.096551] Code: 74 14 48 b8 ff ff ff ff ff ff 00 00 48 21 f0 48 c1 ee 30 48 01 c6 48 8b 87 90 00 00 00 48 89 f2 81 e6 ff 0f 00 00 48 c1 ea 0c <48> 8b 04 d0 48 83 e0 fe 48 01 f0 c3 66 66 2e 0f 1f 84 00 00 00 00\n[ 106.115588] RSP: 0018:ffffc9000d694e50 EFLAGS: 00010206\n[ 106.120893] RAX: 0000000000000000 RBX: ffff88984b8c8a00 RCX: ffff889852581800\n[ 106.128137] RDX: 0000000000000006 RSI: 0000000000000000 RDI: ffff88984cd8b800\n[ 106.135383] RBP: ffff888123b50001 R08: ffff889896800000 R09: 0000000000000800\n[ 106.142628] R10: 0000000000000000 R11: ffffffff826060c0 R12: 00000000000000ff\n[ 106.149872] R13: 0000000000000000 R14: 0000000000000040 R15: ffff888123b50018\n[ 106.157117] FS: 0000000000000000(0000) GS:ffff8897e0f40000(0000) knlGS:0000000000000000\n[ 106.165332] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 106.171163] CR2: 0000000000000030 CR3: 000000000560a004 CR4: 00000000007706e0\n[ 106.178408] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 106.185653] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 106.192898] PKRU: 55555554\n[ 106.195653] Call Trace:\n[ 106.198143] \n[ 106.200196] ice_clean_tx_irq_zc+0x183/0x2a0 [ice]\n[ 106.205087] ice_napi_poll+0x3e/0x590 [ice]\n[ 106.209356] __napi_poll+0x2a/0x160\n[ 106.212911] net_rx_action+0xd6/0x200\n[ 106.216634] __do_softirq+0xbf/0x29b\n[ 106.220274] irq_exit_rcu+0x88/0xc0\n[ 106.223819] common_interrupt+0x7b/0xa0\n[ 106.227719] \n[ 106.229857] asm_common_interrupt+0x1e/0x40\n\n\nFix this by introducing the bitmap of queues that are zero-copy enabled,\nwhere each bit, corresponding to a queue id that xsk pool is being\nconfigured on, will be set/cleared within ice_xsk_pool_{en,dis}able and\nchecked within ice_xsk_pool(). The latter is a function used for\ndeciding which napi poll routine is executed.\nIdea is being taken from our other drivers such as i40e and ixgbe.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-wr4h-r7rr-g3h9/GHSA-wr4h-r7rr-g3h9.json b/advisories/unreviewed/2024/03/GHSA-wr4h-r7rr-g3h9/GHSA-wr4h-r7rr-g3h9.json
index 8bb2752a38a..ff3e526012c 100644
--- a/advisories/unreviewed/2024/03/GHSA-wr4h-r7rr-g3h9/GHSA-wr4h-r7rr-g3h9.json
+++ b/advisories/unreviewed/2024/03/GHSA-wr4h-r7rr-g3h9/GHSA-wr4h-r7rr-g3h9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wr4h-r7rr-g3h9",
- "modified": "2024-03-07T21:30:21Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-07T21:30:21Z",
"aliases": [
"CVE-2024-2128"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-xv6r-2m8v-f893/GHSA-xv6r-2m8v-f893.json b/advisories/unreviewed/2024/03/GHSA-xv6r-2m8v-f893/GHSA-xv6r-2m8v-f893.json
index 015d2d73abd..03cb1cc6d74 100644
--- a/advisories/unreviewed/2024/03/GHSA-xv6r-2m8v-f893/GHSA-xv6r-2m8v-f893.json
+++ b/advisories/unreviewed/2024/03/GHSA-xv6r-2m8v-f893/GHSA-xv6r-2m8v-f893.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv6r-2m8v-f893",
- "modified": "2024-03-15T21:30:44Z",
+ "modified": "2025-01-07T18:30:38Z",
"published": "2024-03-15T21:30:44Z",
"aliases": [
"CVE-2021-47119"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix memory leak in ext4_fill_super\n\nBuffer head references must be released before calling kill_bdev();\notherwise the buffer head (and its page referenced by b_data) will not\nbe freed by kill_bdev, and subsequently that bh will be leaked.\n\nIf blocksizes differ, sb_set_blocksize() will kill current buffers and\npage cache by using kill_bdev(). And then super block will be reread\nagain but using correct blocksize this time. sb_set_blocksize() didn't\nfully free superblock page and buffer head, and being busy, they were\nnot freed and instead leaked.\n\nThis can easily be reproduced by calling an infinite loop of:\n\n systemctl start .mount, and\n systemctl stop .mount\n\n... since systemd creates a cgroup for each slice which it mounts, and\nthe bh leak get amplified by a dying memory cgroup that also never\ngets freed, and memory consumption is much more easily noticed.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T21:15:07Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json b/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json
index 1d7bad3a895..df8ba70e836 100644
--- a/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json
+++ b/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mrh-g8f4-xvjv",
- "modified": "2024-06-26T00:31:36Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2024-26695"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Fix null pointer dereference in __sev_platform_shutdown_locked\n\nThe SEV platform device can be shutdown with a null psp_master,\ne.g., using DEBUG_TEST_DRIVER_REMOVE. Found using KASAN:\n\n[ 137.148210] ccp 0000:23:00.1: enabling device (0000 -> 0002)\n[ 137.162647] ccp 0000:23:00.1: no command queues available\n[ 137.170598] ccp 0000:23:00.1: sev enabled\n[ 137.174645] ccp 0000:23:00.1: psp enabled\n[ 137.178890] general protection fault, probably for non-canonical address 0xdffffc000000001e: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC KASAN NOPTI\n[ 137.182693] KASAN: null-ptr-deref in range [0x00000000000000f0-0x00000000000000f7]\n[ 137.182693] CPU: 93 PID: 1 Comm: swapper/0 Not tainted 6.8.0-rc1+ #311\n[ 137.182693] RIP: 0010:__sev_platform_shutdown_locked+0x51/0x180\n[ 137.182693] Code: 08 80 3c 08 00 0f 85 0e 01 00 00 48 8b 1d 67 b6 01 08 48 b8 00 00 00 00 00 fc ff df 48 8d bb f0 00 00 00 48 89 f9 48 c1 e9 03 <80> 3c 01 00 0f 85 fe 00 00 00 48 8b 9b f0 00 00 00 48 85 db 74 2c\n[ 137.182693] RSP: 0018:ffffc900000cf9b0 EFLAGS: 00010216\n[ 137.182693] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 000000000000001e\n[ 137.182693] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 00000000000000f0\n[ 137.182693] RBP: ffffc900000cf9c8 R08: 0000000000000000 R09: fffffbfff58f5a66\n[ 137.182693] R10: ffffc900000cf9c8 R11: ffffffffac7ad32f R12: ffff8881e5052c28\n[ 137.182693] R13: ffff8881e5052c28 R14: ffff8881758e43e8 R15: ffffffffac64abf8\n[ 137.182693] FS: 0000000000000000(0000) GS:ffff889de7000000(0000) knlGS:0000000000000000\n[ 137.182693] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 137.182693] CR2: 0000000000000000 CR3: 0000001cf7c7e000 CR4: 0000000000350ef0\n[ 137.182693] Call Trace:\n[ 137.182693] \n[ 137.182693] ? show_regs+0x6c/0x80\n[ 137.182693] ? __die_body+0x24/0x70\n[ 137.182693] ? die_addr+0x4b/0x80\n[ 137.182693] ? exc_general_protection+0x126/0x230\n[ 137.182693] ? asm_exc_general_protection+0x2b/0x30\n[ 137.182693] ? __sev_platform_shutdown_locked+0x51/0x180\n[ 137.182693] sev_firmware_shutdown.isra.0+0x1e/0x80\n[ 137.182693] sev_dev_destroy+0x49/0x100\n[ 137.182693] psp_dev_destroy+0x47/0xb0\n[ 137.182693] sp_destroy+0xbb/0x240\n[ 137.182693] sp_pci_remove+0x45/0x60\n[ 137.182693] pci_device_remove+0xaa/0x1d0\n[ 137.182693] device_remove+0xc7/0x170\n[ 137.182693] really_probe+0x374/0xbe0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] __driver_probe_device+0x199/0x460\n[ 137.182693] driver_probe_device+0x4e/0xd0\n[ 137.182693] __driver_attach+0x191/0x3d0\n[ 137.182693] ? __pfx___driver_attach+0x10/0x10\n[ 137.182693] bus_for_each_dev+0x100/0x190\n[ 137.182693] ? __pfx_bus_for_each_dev+0x10/0x10\n[ 137.182693] ? __kasan_check_read+0x15/0x20\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? _raw_spin_unlock+0x27/0x50\n[ 137.182693] driver_attach+0x41/0x60\n[ 137.182693] bus_add_driver+0x2a8/0x580\n[ 137.182693] driver_register+0x141/0x480\n[ 137.182693] __pci_register_driver+0x1d6/0x2a0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? esrt_sysfs_init+0x1cd/0x5d0\n[ 137.182693] ? __pfx_sp_mod_init+0x10/0x10\n[ 137.182693] sp_pci_init+0x22/0x30\n[ 137.182693] sp_mod_init+0x14/0x30\n[ 137.182693] ? __pfx_sp_mod_init+0x10/0x10\n[ 137.182693] do_one_initcall+0xd1/0x470\n[ 137.182693] ? __pfx_do_one_initcall+0x10/0x10\n[ 137.182693] ? parameq+0x80/0xf0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? __kmalloc+0x3b0/0x4e0\n[ 137.182693] ? kernel_init_freeable+0x92d/0x1050\n[ 137.182693] ? kasan_populate_vmalloc_pte+0x171/0x190\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] kernel_init_freeable+0xa64/0x1050\n[ 137.182693] ? __pfx_kernel_init+0x10/0x10\n[ 137.182693] kernel_init+0x24/0x160\n[ 137.182693] ? __switch_to_asm+0x3e/0x70\n[ 137.182693] ret_from_fork+0x40/0x80\n[ 137.182693] ? __pfx_kernel_init+0x1\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:52Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json b/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json
index 0e518759ee5..d7a9f047923 100644
--- a/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json
+++ b/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w67-3g2f-j7p2",
- "modified": "2024-06-26T00:31:36Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2023-52637"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: Fix UAF in j1939_sk_match_filter during setsockopt(SO_J1939_FILTER)\n\nLock jsk->sk to prevent UAF when setsockopt(..., SO_J1939_FILTER, ...)\nmodifies jsk->filters while receiving packets.\n\nFollowing trace was seen on affected system:\n ==================================================================\n BUG: KASAN: slab-use-after-free in j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n Read of size 4 at addr ffff888012144014 by task j1939/350\n\n CPU: 0 PID: 350 Comm: j1939 Tainted: G W OE 6.5.0-rc5 #1\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\n Call Trace:\n print_report+0xd3/0x620\n ? kasan_complete_mode_report_info+0x7d/0x200\n ? j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n kasan_report+0xc2/0x100\n ? j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n __asan_load4+0x84/0xb0\n j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n j1939_sk_recv+0x20b/0x320 [can_j1939]\n ? __kasan_check_write+0x18/0x20\n ? __pfx_j1939_sk_recv+0x10/0x10 [can_j1939]\n ? j1939_simple_recv+0x69/0x280 [can_j1939]\n ? j1939_ac_recv+0x5e/0x310 [can_j1939]\n j1939_can_recv+0x43f/0x580 [can_j1939]\n ? __pfx_j1939_can_recv+0x10/0x10 [can_j1939]\n ? raw_rcv+0x42/0x3c0 [can_raw]\n ? __pfx_j1939_can_recv+0x10/0x10 [can_j1939]\n can_rcv_filter+0x11f/0x350 [can]\n can_receive+0x12f/0x190 [can]\n ? __pfx_can_rcv+0x10/0x10 [can]\n can_rcv+0xdd/0x130 [can]\n ? __pfx_can_rcv+0x10/0x10 [can]\n __netif_receive_skb_one_core+0x13d/0x150\n ? __pfx___netif_receive_skb_one_core+0x10/0x10\n ? __kasan_check_write+0x18/0x20\n ? _raw_spin_lock_irq+0x8c/0xe0\n __netif_receive_skb+0x23/0xb0\n process_backlog+0x107/0x260\n __napi_poll+0x69/0x310\n net_rx_action+0x2a1/0x580\n ? __pfx_net_rx_action+0x10/0x10\n ? __pfx__raw_spin_lock+0x10/0x10\n ? handle_irq_event+0x7d/0xa0\n __do_softirq+0xf3/0x3f8\n do_softirq+0x53/0x80\n \n \n __local_bh_enable_ip+0x6e/0x70\n netif_rx+0x16b/0x180\n can_send+0x32b/0x520 [can]\n ? __pfx_can_send+0x10/0x10 [can]\n ? __check_object_size+0x299/0x410\n raw_sendmsg+0x572/0x6d0 [can_raw]\n ? __pfx_raw_sendmsg+0x10/0x10 [can_raw]\n ? apparmor_socket_sendmsg+0x2f/0x40\n ? __pfx_raw_sendmsg+0x10/0x10 [can_raw]\n sock_sendmsg+0xef/0x100\n sock_write_iter+0x162/0x220\n ? __pfx_sock_write_iter+0x10/0x10\n ? __rtnl_unlock+0x47/0x80\n ? security_file_permission+0x54/0x320\n vfs_write+0x6ba/0x750\n ? __pfx_vfs_write+0x10/0x10\n ? __fget_light+0x1ca/0x1f0\n ? __rcu_read_unlock+0x5b/0x280\n ksys_write+0x143/0x170\n ? __pfx_ksys_write+0x10/0x10\n ? __kasan_check_read+0x15/0x20\n ? fpregs_assert_state_consistent+0x62/0x70\n __x64_sys_write+0x47/0x60\n do_syscall_64+0x60/0x90\n ? do_syscall_64+0x6d/0x90\n ? irqentry_exit+0x3f/0x50\n ? exc_page_fault+0x79/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Allocated by task 348:\n kasan_save_stack+0x2a/0x50\n kasan_set_track+0x29/0x40\n kasan_save_alloc_info+0x1f/0x30\n __kasan_kmalloc+0xb5/0xc0\n __kmalloc_node_track_caller+0x67/0x160\n j1939_sk_setsockopt+0x284/0x450 [can_j1939]\n __sys_setsockopt+0x15c/0x2f0\n __x64_sys_setsockopt+0x6b/0x80\n do_syscall_64+0x60/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Freed by task 349:\n kasan_save_stack+0x2a/0x50\n kasan_set_track+0x29/0x40\n kasan_save_free_info+0x2f/0x50\n __kasan_slab_free+0x12e/0x1c0\n __kmem_cache_free+0x1b9/0x380\n kfree+0x7a/0x120\n j1939_sk_setsockopt+0x3b2/0x450 [can_j1939]\n __sys_setsockopt+0x15c/0x2f0\n __x64_sys_setsockopt+0x6b/0x80\n do_syscall_64+0x60/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:51Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-398v-cx4g-hhxc/GHSA-398v-cx4g-hhxc.json b/advisories/unreviewed/2024/04/GHSA-398v-cx4g-hhxc/GHSA-398v-cx4g-hhxc.json
index 44ce566cb3b..f17e9830d8d 100644
--- a/advisories/unreviewed/2024/04/GHSA-398v-cx4g-hhxc/GHSA-398v-cx4g-hhxc.json
+++ b/advisories/unreviewed/2024/04/GHSA-398v-cx4g-hhxc/GHSA-398v-cx4g-hhxc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-398v-cx4g-hhxc",
- "modified": "2024-04-17T12:32:05Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-17T12:32:05Z",
"aliases": [
"CVE-2024-26888"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: msft: Fix memory leak\n\nFix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T11:15:10Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-4jv7-xrm9-5fjr/GHSA-4jv7-xrm9-5fjr.json b/advisories/unreviewed/2024/04/GHSA-4jv7-xrm9-5fjr/GHSA-4jv7-xrm9-5fjr.json
index 75866cb935f..9ad5e275c10 100644
--- a/advisories/unreviewed/2024/04/GHSA-4jv7-xrm9-5fjr/GHSA-4jv7-xrm9-5fjr.json
+++ b/advisories/unreviewed/2024/04/GHSA-4jv7-xrm9-5fjr/GHSA-4jv7-xrm9-5fjr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4jv7-xrm9-5fjr",
- "modified": "2024-04-10T21:30:31Z",
+ "modified": "2025-01-07T18:30:41Z",
"published": "2024-04-10T21:30:31Z",
"aliases": [
"CVE-2021-47190"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf bpf: Avoid memory leak from perf_env__insert_btf()\n\nperf_env__insert_btf() doesn't insert if a duplicate BTF id is\nencountered and this causes a memory leak. Modify the function to return\na success/error value and then free the memory if insertion didn't\nhappen.\n\nv2. Adds a return -1 when the insertion error occurs in\n perf_env__fetch_btf. This doesn't affect anything as the result is\n never checked.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T19:15:47Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json b/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json
index 2f74aeb8b93..bfe85aca0cc 100644
--- a/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json
+++ b/advisories/unreviewed/2024/04/GHSA-55x4-qvh8-76c6/GHSA-55x4-qvh8-76c6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55x4-qvh8-76c6",
- "modified": "2024-04-09T21:32:00Z",
+ "modified": "2025-01-07T18:30:41Z",
"published": "2024-04-09T21:32:00Z",
"aliases": [
"CVE-2024-3244"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json b/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json
index 4c3e2eaedaa..d441ad75433 100644
--- a/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json
+++ b/advisories/unreviewed/2024/04/GHSA-6jqp-mm8h-jjgv/GHSA-6jqp-mm8h-jjgv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6jqp-mm8h-jjgv",
- "modified": "2024-06-26T00:31:36Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-04T09:30:35Z",
"aliases": [
"CVE-2024-26781"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix possible deadlock in subflow diag\n\nSyzbot and Eric reported a lockdep splat in the subflow diag:\n\n WARNING: possible circular locking dependency detected\n 6.8.0-rc4-syzkaller-00212-g40b9385dd8e6 #0 Not tainted\n\n syz-executor.2/24141 is trying to acquire lock:\n ffff888045870130 (k-sk_lock-AF_INET6){+.+.}-{0:0}, at:\n tcp_diag_put_ulp net/ipv4/tcp_diag.c:100 [inline]\n ffff888045870130 (k-sk_lock-AF_INET6){+.+.}-{0:0}, at:\n tcp_diag_get_aux+0x738/0x830 net/ipv4/tcp_diag.c:137\n\n but task is already holding lock:\n ffffc9000135e488 (&h->lhash2[i].lock){+.+.}-{2:2}, at: spin_lock\n include/linux/spinlock.h:351 [inline]\n ffffc9000135e488 (&h->lhash2[i].lock){+.+.}-{2:2}, at:\n inet_diag_dump_icsk+0x39f/0x1f80 net/ipv4/inet_diag.c:1038\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #1 (&h->lhash2[i].lock){+.+.}-{2:2}:\n lock_acquire+0x1e3/0x530 kernel/locking/lockdep.c:5754\n __raw_spin_lock include/linux/spinlock_api_smp.h:133 [inline]\n _raw_spin_lock+0x2e/0x40 kernel/locking/spinlock.c:154\n spin_lock include/linux/spinlock.h:351 [inline]\n __inet_hash+0x335/0xbe0 net/ipv4/inet_hashtables.c:743\n inet_csk_listen_start+0x23a/0x320 net/ipv4/inet_connection_sock.c:1261\n __inet_listen_sk+0x2a2/0x770 net/ipv4/af_inet.c:217\n inet_listen+0xa3/0x110 net/ipv4/af_inet.c:239\n rds_tcp_listen_init+0x3fd/0x5a0 net/rds/tcp_listen.c:316\n rds_tcp_init_net+0x141/0x320 net/rds/tcp.c:577\n ops_init+0x352/0x610 net/core/net_namespace.c:136\n __register_pernet_operations net/core/net_namespace.c:1214 [inline]\n register_pernet_operations+0x2cb/0x660 net/core/net_namespace.c:1283\n register_pernet_device+0x33/0x80 net/core/net_namespace.c:1370\n rds_tcp_init+0x62/0xd0 net/rds/tcp.c:735\n do_one_initcall+0x238/0x830 init/main.c:1236\n do_initcall_level+0x157/0x210 init/main.c:1298\n do_initcalls+0x3f/0x80 init/main.c:1314\n kernel_init_freeable+0x42f/0x5d0 init/main.c:1551\n kernel_init+0x1d/0x2a0 init/main.c:1441\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:242\n\n -> #0 (k-sk_lock-AF_INET6){+.+.}-{0:0}:\n check_prev_add kernel/locking/lockdep.c:3134 [inline]\n check_prevs_add kernel/locking/lockdep.c:3253 [inline]\n validate_chain+0x18ca/0x58e0 kernel/locking/lockdep.c:3869\n __lock_acquire+0x1345/0x1fd0 kernel/locking/lockdep.c:5137\n lock_acquire+0x1e3/0x530 kernel/locking/lockdep.c:5754\n lock_sock_fast include/net/sock.h:1723 [inline]\n subflow_get_info+0x166/0xd20 net/mptcp/diag.c:28\n tcp_diag_put_ulp net/ipv4/tcp_diag.c:100 [inline]\n tcp_diag_get_aux+0x738/0x830 net/ipv4/tcp_diag.c:137\n inet_sk_diag_fill+0x10ed/0x1e00 net/ipv4/inet_diag.c:345\n inet_diag_dump_icsk+0x55b/0x1f80 net/ipv4/inet_diag.c:1061\n __inet_diag_dump+0x211/0x3a0 net/ipv4/inet_diag.c:1263\n inet_diag_dump_compat+0x1c1/0x2d0 net/ipv4/inet_diag.c:1371\n netlink_dump+0x59b/0xc80 net/netlink/af_netlink.c:2264\n __netlink_dump_start+0x5df/0x790 net/netlink/af_netlink.c:2370\n netlink_dump_start include/linux/netlink.h:338 [inline]\n inet_diag_rcv_msg_compat+0x209/0x4c0 net/ipv4/inet_diag.c:1405\n sock_diag_rcv_msg+0xe7/0x410\n netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2543\n sock_diag_rcv+0x2a/0x40 net/core/sock_diag.c:280\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x7ea/0x980 net/netlink/af_netlink.c:1367\n netlink_sendmsg+0xa3b/0xd70 net/netlink/af_netlink.c:1908\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2584\n ___sys_sendmsg net/socket.c:2638 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2667\n do_syscall_64+0xf9/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\n\nAs noted by Eric we can break the lock dependency chain avoid\ndumping \n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-04T09:15:07Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json b/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json
index 15f21b356e5..3d322eb9d49 100644
--- a/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json
+++ b/advisories/unreviewed/2024/04/GHSA-8289-h44w-mrcv/GHSA-8289-h44w-mrcv.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-86m3-4q38-6prj/GHSA-86m3-4q38-6prj.json b/advisories/unreviewed/2024/04/GHSA-86m3-4q38-6prj/GHSA-86m3-4q38-6prj.json
index c2a935221a5..2cac6fc142b 100644
--- a/advisories/unreviewed/2024/04/GHSA-86m3-4q38-6prj/GHSA-86m3-4q38-6prj.json
+++ b/advisories/unreviewed/2024/04/GHSA-86m3-4q38-6prj/GHSA-86m3-4q38-6prj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86m3-4q38-6prj",
- "modified": "2024-04-03T18:30:43Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26775"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\naoe: avoid potential deadlock at set_capacity\n\nMove set_capacity() outside of the section procected by (&d->lock).\nTo avoid possible interrupt unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n[1] lock(&bdev->bd_size_lock);\n local_irq_disable();\n [2] lock(&d->lock);\n [3] lock(&bdev->bd_size_lock);\n \n[4] lock(&d->lock);\n\n *** DEADLOCK ***\n\nWhere [1](&bdev->bd_size_lock) hold by zram_add()->set_capacity().\n[2]lock(&d->lock) hold by aoeblk_gdalloc(). And aoeblk_gdalloc()\nis trying to acquire [3](&bdev->bd_size_lock) at set_capacity() call.\nIn this situation an attempt to acquire [4]lock(&d->lock) from\naoecmd_cfg_rsp() will lead to deadlock.\n\nSo the simplest solution is breaking lock dependency\n[2](&d->lock) -> [3](&bdev->bd_size_lock) by moving set_capacity()\noutside.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json b/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json
index 8ea3a5f8978..a5767ada5f6 100644
--- a/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json
+++ b/advisories/unreviewed/2024/04/GHSA-c96c-x4rr-r9qq/GHSA-c96c-x4rr-r9qq.json
@@ -45,7 +45,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json b/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json
index e15d8438c0b..a1785209ec9 100644
--- a/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json
+++ b/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr3q-v98q-fwq5",
- "modified": "2024-04-03T15:30:41Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-04-02T09:30:40Z",
"aliases": [
"CVE-2024-26657"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sched: fix null-ptr-deref in init entity\n\nThe bug can be triggered by sending an amdgpu_cs_wait_ioctl\nto the AMDGPU DRM driver on any ASICs with valid context.\nThe bug was reported by Joonkyo Jung .\nFor example the following code:\n\n static void Syzkaller2(int fd)\n {\n\tunion drm_amdgpu_ctx arg1;\n\tunion drm_amdgpu_wait_cs arg2;\n\n\targ1.in.op = AMDGPU_CTX_OP_ALLOC_CTX;\n\tret = drmIoctl(fd, 0x140106442 /* amdgpu_ctx_ioctl */, &arg1);\n\n\targ2.in.handle = 0x0;\n\targ2.in.timeout = 0x2000000000000;\n\targ2.in.ip_type = AMD_IP_VPE /* 0x9 */;\n\targ2->in.ip_instance = 0x0;\n\targ2.in.ring = 0x0;\n\targ2.in.ctx_id = arg1.out.alloc.ctx_id;\n\n\tdrmIoctl(fd, 0xc0206449 /* AMDGPU_WAIT_CS * /, &arg2);\n }\n\nThe ioctl AMDGPU_WAIT_CS without previously submitted job could be assumed that\nthe error should be returned, but the following commit 1decbf6bb0b4dc56c9da6c5e57b994ebfc2be3aa\nmodified the logic and allowed to have sched_rq equal to NULL.\n\nAs a result when there is no job the ioctl AMDGPU_WAIT_CS returns success.\nThe change fixes null-ptr-deref in init entity and the stack below demonstrates\nthe error condition:\n\n[ +0.000007] BUG: kernel NULL pointer dereference, address: 0000000000000028\n[ +0.007086] #PF: supervisor read access in kernel mode\n[ +0.005234] #PF: error_code(0x0000) - not-present page\n[ +0.005232] PGD 0 P4D 0\n[ +0.002501] Oops: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[ +0.005034] CPU: 10 PID: 9229 Comm: amd_basic Tainted: G B W L 6.7.0+ #4\n[ +0.007797] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020\n[ +0.009798] RIP: 0010:drm_sched_entity_init+0x2d3/0x420 [gpu_sched]\n[ +0.006426] Code: 80 00 00 00 00 00 00 00 e8 1a 81 82 e0 49 89 9c 24 c0 00 00 00 4c 89 ef e8 4a 80 82 e0 49 8b 5d 00 48 8d 7b 28 e8 3d 80 82 e0 <48> 83 7b 28 00 0f 84 28 01 00 00 4d 8d ac 24 98 00 00 00 49 8d 5c\n[ +0.019094] RSP: 0018:ffffc90014c1fa40 EFLAGS: 00010282\n[ +0.005237] RAX: 0000000000000001 RBX: 0000000000000000 RCX: ffffffff8113f3fa\n[ +0.007326] RDX: fffffbfff0a7889d RSI: 0000000000000008 RDI: ffffffff853c44e0\n[ +0.007264] RBP: ffffc90014c1fa80 R08: 0000000000000001 R09: fffffbfff0a7889c\n[ +0.007266] R10: ffffffff853c44e7 R11: 0000000000000001 R12: ffff8881a719b010\n[ +0.007263] R13: ffff88810d412748 R14: 0000000000000002 R15: 0000000000000000\n[ +0.007264] FS: 00007ffff7045540(0000) GS:ffff8883cc900000(0000) knlGS:0000000000000000\n[ +0.008236] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.005851] CR2: 0000000000000028 CR3: 000000011912e000 CR4: 0000000000350ef0\n[ +0.007175] Call Trace:\n[ +0.002561] \n[ +0.002141] ? show_regs+0x6a/0x80\n[ +0.003473] ? __die+0x25/0x70\n[ +0.003124] ? page_fault_oops+0x214/0x720\n[ +0.004179] ? preempt_count_sub+0x18/0xc0\n[ +0.004093] ? __pfx_page_fault_oops+0x10/0x10\n[ +0.004590] ? srso_return_thunk+0x5/0x5f\n[ +0.004000] ? vprintk_default+0x1d/0x30\n[ +0.004063] ? srso_return_thunk+0x5/0x5f\n[ +0.004087] ? vprintk+0x5c/0x90\n[ +0.003296] ? drm_sched_entity_init+0x2d3/0x420 [gpu_sched]\n[ +0.005807] ? srso_return_thunk+0x5/0x5f\n[ +0.004090] ? _printk+0xb3/0xe0\n[ +0.003293] ? __pfx__printk+0x10/0x10\n[ +0.003735] ? asm_sysvec_apic_timer_interrupt+0x1b/0x20\n[ +0.005482] ? do_user_addr_fault+0x345/0x770\n[ +0.004361] ? exc_page_fault+0x64/0xf0\n[ +0.003972] ? asm_exc_page_fault+0x27/0x30\n[ +0.004271] ? add_taint+0x2a/0xa0\n[ +0.003476] ? drm_sched_entity_init+0x2d3/0x420 [gpu_sched]\n[ +0.005812] amdgpu_ctx_get_entity+0x3f9/0x770 [amdgpu]\n[ +0.009530] ? finish_task_switch.isra.0+0x129/0x470\n[ +0.005068] ? __pfx_amdgpu_ctx_get_entity+0x10/0x10 [amdgpu]\n[ +0.010063] ? __kasan_check_write+0x14/0x20\n[ +0.004356] ? srso_return_thunk+0x5/0x5f\n[ +0.004001] ? mutex_unlock+0x81/0xd0\n[ +0.003802] ? srso_return_thunk+0x5/0x5f\n[ +0.004096] amdgpu_cs_wait_ioctl+0xf6/0x270 [amdgpu]\n[ +0.009355] ? __pfx_\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T07:15:42Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json b/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json
index f70a8450884..1a4ef5d4b52 100644
--- a/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json
+++ b/advisories/unreviewed/2024/04/GHSA-g638-g65r-64rm/GHSA-g638-g65r-64rm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g638-g65r-64rm",
- "modified": "2024-06-27T15:30:38Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-17T12:32:03Z",
"aliases": [
"CVE-2024-26840"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: fix memory leak in cachefiles_add_cache()\n\nThe following memory leak was reported after unbinding /dev/cachefiles:\n\n==================================================================\nunreferenced object 0xffff9b674176e3c0 (size 192):\n comm \"cachefilesd2\", pid 680, jiffies 4294881224\n hex dump (first 32 bytes):\n 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc ea38a44b):\n [] kmem_cache_alloc+0x2d5/0x370\n [] prepare_creds+0x26/0x2e0\n [] cachefiles_determine_cache_security+0x1f/0x120\n [] cachefiles_add_cache+0x13c/0x3a0\n [] cachefiles_daemon_write+0x146/0x1c0\n [] vfs_write+0xcb/0x520\n [] ksys_write+0x69/0xf0\n [] do_syscall_64+0x72/0x140\n [] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n==================================================================\n\nPut the reference count of cache_cred in cachefiles_daemon_unbind() to\nfix the problem. And also put cache_cred in cachefiles_add_cache() error\nbranch to avoid memory leaks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T10:15:09Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-gf6p-hmwh-gpc7/GHSA-gf6p-hmwh-gpc7.json b/advisories/unreviewed/2024/04/GHSA-gf6p-hmwh-gpc7/GHSA-gf6p-hmwh-gpc7.json
index c60ac5361db..e2a17363cf1 100644
--- a/advisories/unreviewed/2024/04/GHSA-gf6p-hmwh-gpc7/GHSA-gf6p-hmwh-gpc7.json
+++ b/advisories/unreviewed/2024/04/GHSA-gf6p-hmwh-gpc7/GHSA-gf6p-hmwh-gpc7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gf6p-hmwh-gpc7",
- "modified": "2024-04-10T21:30:31Z",
+ "modified": "2025-01-07T18:30:41Z",
"published": "2024-04-10T21:30:31Z",
"aliases": [
"CVE-2021-47200"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/prime: Fix use after free in mmap with drm_gem_ttm_mmap\n\ndrm_gem_ttm_mmap() drops a reference to the gem object on success. If\nthe gem object's refcount == 1 on entry to drm_gem_prime_mmap(), that\ndrop will free the gem object, and the subsequent drm_gem_object_get()\nwill be a UAF. Fix by grabbing a reference before calling the mmap\nhelper.\n\nThis issue was forseen when the reference dropping was adding in\ncommit 9786b65bc61ac (\"drm/ttm: fix mmap refcounting\"):\n \"For that to work properly the drm_gem_object_get() call in\n drm_gem_ttm_mmap() must be moved so it happens before calling\n obj->funcs->mmap(), otherwise the gem refcount would go down\n to zero.\"",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T19:15:48Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-h445-49j7-8jw7/GHSA-h445-49j7-8jw7.json b/advisories/unreviewed/2024/04/GHSA-h445-49j7-8jw7/GHSA-h445-49j7-8jw7.json
index cff0c4d7d78..396147d2629 100644
--- a/advisories/unreviewed/2024/04/GHSA-h445-49j7-8jw7/GHSA-h445-49j7-8jw7.json
+++ b/advisories/unreviewed/2024/04/GHSA-h445-49j7-8jw7/GHSA-h445-49j7-8jw7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h445-49j7-8jw7",
- "modified": "2024-04-28T15:30:29Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-28T15:30:29Z",
"aliases": [
"CVE-2022-48641"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: fix memory leak when blob is malformed\n\nThe bug fix was incomplete, it \"replaced\" crash with a memory leak.\nThe old code had an assignment to \"ret\" embedded into the conditional,\nrestore this.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-28T13:15:06Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-h5px-p7wm-gqpv/GHSA-h5px-p7wm-gqpv.json b/advisories/unreviewed/2024/04/GHSA-h5px-p7wm-gqpv/GHSA-h5px-p7wm-gqpv.json
index 0b9e908997c..3421c09f50f 100644
--- a/advisories/unreviewed/2024/04/GHSA-h5px-p7wm-gqpv/GHSA-h5px-p7wm-gqpv.json
+++ b/advisories/unreviewed/2024/04/GHSA-h5px-p7wm-gqpv/GHSA-h5px-p7wm-gqpv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5px-p7wm-gqpv",
- "modified": "2024-04-17T12:32:04Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-17T12:32:04Z",
"aliases": [
"CVE-2024-26860"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-integrity: fix a memory leak when rechecking the data\n\nMemory for the \"checksums\" pointer will leak if the data is rechecked\nafter checksum failure (because the associated kfree won't happen due\nto 'goto skip_io').\n\nFix this by freeing the checksums memory before recheck, and just use\nthe \"checksum_onstack\" memory for storing checksum during recheck.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T11:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json b/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json
index 190714099da..f3ef51daefb 100644
--- a/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json
+++ b/advisories/unreviewed/2024/04/GHSA-h88v-572r-gvxx/GHSA-h88v-572r-gvxx.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-j8fx-m4jh-f28m/GHSA-j8fx-m4jh-f28m.json b/advisories/unreviewed/2024/04/GHSA-j8fx-m4jh-f28m/GHSA-j8fx-m4jh-f28m.json
index aef26b3cfd8..20e108ab9e4 100644
--- a/advisories/unreviewed/2024/04/GHSA-j8fx-m4jh-f28m/GHSA-j8fx-m4jh-f28m.json
+++ b/advisories/unreviewed/2024/04/GHSA-j8fx-m4jh-f28m/GHSA-j8fx-m4jh-f28m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8fx-m4jh-f28m",
- "modified": "2024-04-28T15:30:29Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-28T15:30:29Z",
"aliases": [
"CVE-2022-48642"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix percpu memory leak at nf_tables_addchain()\n\nIt seems to me that percpu memory for chain stats started leaking since\ncommit 3bc158f8d0330f0a (\"netfilter: nf_tables: map basechain priority to\nhardware priority\") when nft_chain_offload_priority() returned an error.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-28T13:15:07Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json b/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json
index e9a4894e406..266102a4770 100644
--- a/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json
+++ b/advisories/unreviewed/2024/04/GHSA-jg3j-8qg2-gph3/GHSA-jg3j-8qg2-gph3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jg3j-8qg2-gph3",
- "modified": "2024-06-27T12:30:44Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-04-02T09:30:41Z",
"aliases": [
"CVE-2024-26663"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: Check the bearer type before calling tipc_udp_nl_bearer_add()\n\nsyzbot reported the following general protection fault [1]:\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000010: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087]\n...\nRIP: 0010:tipc_udp_is_known_peer+0x9c/0x250 net/tipc/udp_media.c:291\n...\nCall Trace:\n \n tipc_udp_nl_bearer_add+0x212/0x2f0 net/tipc/udp_media.c:646\n tipc_nl_bearer_add+0x21e/0x360 net/tipc/bearer.c:1089\n genl_family_rcv_msg_doit+0x1fc/0x2e0 net/netlink/genetlink.c:972\n genl_family_rcv_msg net/netlink/genetlink.c:1052 [inline]\n genl_rcv_msg+0x561/0x800 net/netlink/genetlink.c:1067\n netlink_rcv_skb+0x16b/0x440 net/netlink/af_netlink.c:2544\n genl_rcv+0x28/0x40 net/netlink/genetlink.c:1076\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x53b/0x810 net/netlink/af_netlink.c:1367\n netlink_sendmsg+0x8b7/0xd70 net/netlink/af_netlink.c:1909\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0xd5/0x180 net/socket.c:745\n ____sys_sendmsg+0x6ac/0x940 net/socket.c:2584\n ___sys_sendmsg+0x135/0x1d0 net/socket.c:2638\n __sys_sendmsg+0x117/0x1e0 net/socket.c:2667\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x40/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nThe cause of this issue is that when tipc_nl_bearer_add() is called with\nthe TIPC_NLA_BEARER_UDP_OPTS attribute, tipc_udp_nl_bearer_add() is called\neven if the bearer is not UDP.\n\ntipc_udp_is_known_peer() called by tipc_udp_nl_bearer_add() assumes that\nthe media_ptr field of the tipc_bearer has an udp_bearer type object, so\nthe function goes crazy for non-UDP bearers.\n\nThis patch fixes the issue by checking the bearer type before calling\ntipc_udp_nl_bearer_add() in tipc_nl_bearer_add().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T07:15:43Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-jgcm-2g93-rjcx/GHSA-jgcm-2g93-rjcx.json b/advisories/unreviewed/2024/04/GHSA-jgcm-2g93-rjcx/GHSA-jgcm-2g93-rjcx.json
index 1ecba65a5d1..b9841f8eed1 100644
--- a/advisories/unreviewed/2024/04/GHSA-jgcm-2g93-rjcx/GHSA-jgcm-2g93-rjcx.json
+++ b/advisories/unreviewed/2024/04/GHSA-jgcm-2g93-rjcx/GHSA-jgcm-2g93-rjcx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgcm-2g93-rjcx",
- "modified": "2024-04-17T12:32:05Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-17T12:32:05Z",
"aliases": [
"CVE-2024-26887"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: Fix memory leak\n\nThis checks if CONFIG_DEV_COREDUMP is enabled before attempting to clone\nthe skb and also make sure btmtk_process_coredump frees the skb passed\nfollowing the same logic.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T11:15:10Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json b/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json
index 9a56577220e..952d6b46957 100644
--- a/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json
+++ b/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgpw-6hf2-c2m5",
- "modified": "2024-04-03T15:30:43Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-03T15:30:43Z",
"aliases": [
"CVE-2024-26725"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpll: fix possible deadlock during netlink dump operation\n\nRecently, I've been hitting following deadlock warning during dpll pin\ndump:\n\n[52804.637962] ======================================================\n[52804.638536] WARNING: possible circular locking dependency detected\n[52804.639111] 6.8.0-rc2jiri+ #1 Not tainted\n[52804.639529] ------------------------------------------------------\n[52804.640104] python3/2984 is trying to acquire lock:\n[52804.640581] ffff88810e642678 (nlk_cb_mutex-GENERIC){+.+.}-{3:3}, at: netlink_dump+0xb3/0x780\n[52804.641417]\n but task is already holding lock:\n[52804.642010] ffffffff83bde4c8 (dpll_lock){+.+.}-{3:3}, at: dpll_lock_dumpit+0x13/0x20\n[52804.642747]\n which lock already depends on the new lock.\n\n[52804.643551]\n the existing dependency chain (in reverse order) is:\n[52804.644259]\n -> #1 (dpll_lock){+.+.}-{3:3}:\n[52804.644836] lock_acquire+0x174/0x3e0\n[52804.645271] __mutex_lock+0x119/0x1150\n[52804.645723] dpll_lock_dumpit+0x13/0x20\n[52804.646169] genl_start+0x266/0x320\n[52804.646578] __netlink_dump_start+0x321/0x450\n[52804.647056] genl_family_rcv_msg_dumpit+0x155/0x1e0\n[52804.647575] genl_rcv_msg+0x1ed/0x3b0\n[52804.648001] netlink_rcv_skb+0xdc/0x210\n[52804.648440] genl_rcv+0x24/0x40\n[52804.648831] netlink_unicast+0x2f1/0x490\n[52804.649290] netlink_sendmsg+0x36d/0x660\n[52804.649742] __sock_sendmsg+0x73/0xc0\n[52804.650165] __sys_sendto+0x184/0x210\n[52804.650597] __x64_sys_sendto+0x72/0x80\n[52804.651045] do_syscall_64+0x6f/0x140\n[52804.651474] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[52804.652001]\n -> #0 (nlk_cb_mutex-GENERIC){+.+.}-{3:3}:\n[52804.652650] check_prev_add+0x1ae/0x1280\n[52804.653107] __lock_acquire+0x1ed3/0x29a0\n[52804.653559] lock_acquire+0x174/0x3e0\n[52804.653984] __mutex_lock+0x119/0x1150\n[52804.654423] netlink_dump+0xb3/0x780\n[52804.654845] __netlink_dump_start+0x389/0x450\n[52804.655321] genl_family_rcv_msg_dumpit+0x155/0x1e0\n[52804.655842] genl_rcv_msg+0x1ed/0x3b0\n[52804.656272] netlink_rcv_skb+0xdc/0x210\n[52804.656721] genl_rcv+0x24/0x40\n[52804.657119] netlink_unicast+0x2f1/0x490\n[52804.657570] netlink_sendmsg+0x36d/0x660\n[52804.658022] __sock_sendmsg+0x73/0xc0\n[52804.658450] __sys_sendto+0x184/0x210\n[52804.658877] __x64_sys_sendto+0x72/0x80\n[52804.659322] do_syscall_64+0x6f/0x140\n[52804.659752] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[52804.660281]\n other info that might help us debug this:\n\n[52804.661077] Possible unsafe locking scenario:\n\n[52804.661671] CPU0 CPU1\n[52804.662129] ---- ----\n[52804.662577] lock(dpll_lock);\n[52804.662924] lock(nlk_cb_mutex-GENERIC);\n[52804.663538] lock(dpll_lock);\n[52804.664073] lock(nlk_cb_mutex-GENERIC);\n[52804.664490]\n\nThe issue as follows: __netlink_dump_start() calls control->start(cb)\nwith nlk->cb_mutex held. In control->start(cb) the dpll_lock is taken.\nThen nlk->cb_mutex is released and taken again in netlink_dump(), while\ndpll_lock still being held. That leads to ABBA deadlock when another\nCPU races with the same operation.\n\nFix this by moving dpll_lock taking into dumpit() callback which ensures\ncorrect lock taking order.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:54Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json b/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json
index 3c51dfa17d2..716c666acf3 100644
--- a/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json
+++ b/advisories/unreviewed/2024/04/GHSA-jv96-qfmj-26f9/GHSA-jv96-qfmj-26f9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jv96-qfmj-26f9",
- "modified": "2024-06-26T00:31:36Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-17T12:32:03Z",
"aliases": [
"CVE-2024-26833"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix memory leak in dm_sw_fini()\n\nAfter destroying dmub_srv, the memory associated with it is\nnot freed, causing a memory leak:\n\nunreferenced object 0xffff896302b45800 (size 1024):\n comm \"(udev-worker)\", pid 222, jiffies 4294894636\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 6265fd77):\n [] kmalloc_trace+0x29d/0x340\n [] dm_dmub_sw_init+0xb4/0x450 [amdgpu]\n [] dm_sw_init+0x15/0x2b0 [amdgpu]\n [] amdgpu_device_init+0x1417/0x24e0 [amdgpu]\n [] amdgpu_driver_load_kms+0x15/0x190 [amdgpu]\n [] amdgpu_pci_probe+0x187/0x4e0 [amdgpu]\n [] local_pci_probe+0x3e/0x90\n [] pci_device_probe+0xc3/0x230\n [] really_probe+0xe2/0x480\n [] __driver_probe_device+0x78/0x160\n [] driver_probe_device+0x1f/0x90\n [] __driver_attach+0xce/0x1c0\n [] bus_for_each_dev+0x70/0xc0\n [] bus_add_driver+0x112/0x210\n [] driver_register+0x55/0x100\n [] do_one_initcall+0x41/0x300\n\nFix this by freeing dmub_srv after destroying it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T10:15:09Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json b/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json
index 4d70b0e4588..5afb85994a2 100644
--- a/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json
+++ b/advisories/unreviewed/2024/04/GHSA-m6gg-639w-rh6m/GHSA-m6gg-639w-rh6m.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json b/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json
index 2b1feb25827..c22154cd150 100644
--- a/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json
+++ b/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p46w-8mq5-8mgj",
- "modified": "2024-06-27T15:30:38Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-03T15:30:43Z",
"aliases": [
"CVE-2024-26722"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: rt5645: Fix deadlock in rt5645_jack_detect_work()\n\nThere is a path in rt5645_jack_detect_work(), where rt5645->jd_mutex\nis left locked forever. That may lead to deadlock\nwhen rt5645_jack_detect_work() is called for the second time.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:54Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json b/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json
index 37eadcc07e0..25243b4bb3b 100644
--- a/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json
+++ b/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpw5-gvf2-cq42",
- "modified": "2024-04-03T15:30:41Z",
+ "modified": "2025-01-07T18:30:39Z",
"published": "2024-04-01T15:30:29Z",
"aliases": [
"CVE-2024-26655"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nFix memory leak in posix_clock_open()\n\nIf the clk ops.open() function returns an error, we don't release the\npccontext we allocated for this clock.\n\nRe-organize the code slightly to make it all more obvious.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-01T15:15:49Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json b/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json
index da72e7efee0..2ad463a5d1d 100644
--- a/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json
+++ b/advisories/unreviewed/2024/04/GHSA-rfh9-p2f9-5x7m/GHSA-rfh9-p2f9-5x7m.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-862"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-rh2w-xmhj-38cv/GHSA-rh2w-xmhj-38cv.json b/advisories/unreviewed/2024/04/GHSA-rh2w-xmhj-38cv/GHSA-rh2w-xmhj-38cv.json
index 87a4fc22569..b84f5f41fee 100644
--- a/advisories/unreviewed/2024/04/GHSA-rh2w-xmhj-38cv/GHSA-rh2w-xmhj-38cv.json
+++ b/advisories/unreviewed/2024/04/GHSA-rh2w-xmhj-38cv/GHSA-rh2w-xmhj-38cv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rh2w-xmhj-38cv",
- "modified": "2024-04-28T12:30:28Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-28T12:30:28Z",
"aliases": [
"CVE-2024-26928"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential UAF in cifs_debug_files_proc_show()\n\nSkip sessions that are being teared down (status == SES_EXITING) to\navoid UAF.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-28T12:15:21Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-rh38-52q8-4ffc/GHSA-rh38-52q8-4ffc.json b/advisories/unreviewed/2024/04/GHSA-rh38-52q8-4ffc/GHSA-rh38-52q8-4ffc.json
index b7255483064..ff93e9730c9 100644
--- a/advisories/unreviewed/2024/04/GHSA-rh38-52q8-4ffc/GHSA-rh38-52q8-4ffc.json
+++ b/advisories/unreviewed/2024/04/GHSA-rh38-52q8-4ffc/GHSA-rh38-52q8-4ffc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rh38-52q8-4ffc",
- "modified": "2024-04-10T21:30:31Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-10T21:30:31Z",
"aliases": [
"CVE-2021-47206"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: host: ohci-tmio: check return value after calling platform_get_resource()\n\nIt will cause null-ptr-deref if platform_get_resource() returns NULL,\nwe need check the return value.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-10T19:15:48Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json b/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json
index b5537768c13..cdaccd9dd17 100644
--- a/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json
+++ b/advisories/unreviewed/2024/04/GHSA-rqgg-9h2q-r225/GHSA-rqgg-9h2q-r225.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqgg-9h2q-r225",
- "modified": "2024-04-06T03:30:26Z",
+ "modified": "2025-01-07T18:30:41Z",
"published": "2024-04-06T03:30:26Z",
"aliases": [
"CVE-2024-3245"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-rwch-8cp4-7v7r/GHSA-rwch-8cp4-7v7r.json b/advisories/unreviewed/2024/04/GHSA-rwch-8cp4-7v7r/GHSA-rwch-8cp4-7v7r.json
index ffc24517be2..2ebbd1de368 100644
--- a/advisories/unreviewed/2024/04/GHSA-rwch-8cp4-7v7r/GHSA-rwch-8cp4-7v7r.json
+++ b/advisories/unreviewed/2024/04/GHSA-rwch-8cp4-7v7r/GHSA-rwch-8cp4-7v7r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwch-8cp4-7v7r",
- "modified": "2024-04-03T18:30:42Z",
+ "modified": "2025-01-07T18:30:40Z",
"published": "2024-04-03T18:30:42Z",
"aliases": [
"CVE-2024-26739"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_mirred: don't override retval if we already lost the skb\n\nIf we're redirecting the skb, and haven't called tcf_mirred_forward(),\nyet, we need to tell the core to drop the skb by setting the retcode\nto SHOT. If we have called tcf_mirred_forward(), however, the skb\nis out of our hands and returning SHOT will lead to UaF.\n\nMove the retval override to the error path which actually need it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:51Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-vp2f-c695-vxrg/GHSA-vp2f-c695-vxrg.json b/advisories/unreviewed/2024/04/GHSA-vp2f-c695-vxrg/GHSA-vp2f-c695-vxrg.json
index 4cf5bbd44c1..5740fe401dd 100644
--- a/advisories/unreviewed/2024/04/GHSA-vp2f-c695-vxrg/GHSA-vp2f-c695-vxrg.json
+++ b/advisories/unreviewed/2024/04/GHSA-vp2f-c695-vxrg/GHSA-vp2f-c695-vxrg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp2f-c695-vxrg",
- "modified": "2024-04-17T12:32:04Z",
+ "modified": "2025-01-07T18:30:42Z",
"published": "2024-04-17T12:32:04Z",
"aliases": [
"CVE-2024-26865"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrds: tcp: Fix use-after-free of net in reqsk_timer_handler().\n\nsyzkaller reported a warning of netns tracker [0] followed by KASAN\nsplat [1] and another ref tracker warning [1].\n\nsyzkaller could not find a repro, but in the log, the only suspicious\nsequence was as follows:\n\n 18:26:22 executing program 1:\n r0 = socket$inet6_mptcp(0xa, 0x1, 0x106)\n ...\n connect$inet6(r0, &(0x7f0000000080)={0xa, 0x4001, 0x0, @loopback}, 0x1c) (async)\n\nThe notable thing here is 0x4001 in connect(), which is RDS_TCP_PORT.\n\nSo, the scenario would be:\n\n 1. unshare(CLONE_NEWNET) creates a per netns tcp listener in\n rds_tcp_listen_init().\n 2. syz-executor connect()s to it and creates a reqsk.\n 3. syz-executor exit()s immediately.\n 4. netns is dismantled. [0]\n 5. reqsk timer is fired, and UAF happens while freeing reqsk. [1]\n 6. listener is freed after RCU grace period. [2]\n\nBasically, reqsk assumes that the listener guarantees netns safety\nuntil all reqsk timers are expired by holding the listener's refcount.\nHowever, this was not the case for kernel sockets.\n\nCommit 740ea3c4a0b2 (\"tcp: Clean up kernel listener's reqsk in\ninet_twsk_purge()\") fixed this issue only for per-netns ehash.\n\nLet's apply the same fix for the global ehash.\n\n[0]:\nref_tracker: net notrefcnt@0000000065449cc3 has 1/1 users at\n sk_alloc (./include/net/net_namespace.h:337 net/core/sock.c:2146)\n inet6_create (net/ipv6/af_inet6.c:192 net/ipv6/af_inet6.c:119)\n __sock_create (net/socket.c:1572)\n rds_tcp_listen_init (net/rds/tcp_listen.c:279)\n rds_tcp_init_net (net/rds/tcp.c:577)\n ops_init (net/core/net_namespace.c:137)\n setup_net (net/core/net_namespace.c:340)\n copy_net_ns (net/core/net_namespace.c:497)\n create_new_namespaces (kernel/nsproxy.c:110)\n unshare_nsproxy_namespaces (kernel/nsproxy.c:228 (discriminator 4))\n ksys_unshare (kernel/fork.c:3429)\n __x64_sys_unshare (kernel/fork.c:3496)\n do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129)\n...\nWARNING: CPU: 0 PID: 27 at lib/ref_tracker.c:179 ref_tracker_dir_exit (lib/ref_tracker.c:179)\n\n[1]:\nBUG: KASAN: slab-use-after-free in inet_csk_reqsk_queue_drop (./include/net/inet_hashtables.h:180 net/ipv4/inet_connection_sock.c:952 net/ipv4/inet_connection_sock.c:966)\nRead of size 8 at addr ffff88801b370400 by task swapper/0/0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nCall Trace:\n \n dump_stack_lvl (lib/dump_stack.c:107 (discriminator 1))\n print_report (mm/kasan/report.c:378 mm/kasan/report.c:488)\n kasan_report (mm/kasan/report.c:603)\n inet_csk_reqsk_queue_drop (./include/net/inet_hashtables.h:180 net/ipv4/inet_connection_sock.c:952 net/ipv4/inet_connection_sock.c:966)\n reqsk_timer_handler (net/ipv4/inet_connection_sock.c:979 net/ipv4/inet_connection_sock.c:1092)\n call_timer_fn (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/timer.h:127 kernel/time/timer.c:1701)\n __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038)\n run_timer_softirq (kernel/time/timer.c:2053)\n __do_softirq (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/irq.h:142 kernel/softirq.c:554)\n irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644)\n sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14))\n \n\nAllocated by task 258 on cpu 0 at 83.612050s:\n kasan_save_stack (mm/kasan/common.c:48)\n kasan_save_track (mm/kasan/common.c:68)\n __kasan_slab_alloc (mm/kasan/common.c:343)\n kmem_cache_alloc (mm/slub.c:3813 mm/slub.c:3860 mm/slub.c:3867)\n copy_net_ns (./include/linux/slab.h:701 net/core/net_namespace.c:421 net/core/net_namespace.c:480)\n create_new_namespaces (kernel/nsproxy.c:110)\n unshare_nsproxy_name\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-17T11:15:09Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json b/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json
index 6724fd0dd0a..7f16337b1a3 100644
--- a/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json
+++ b/advisories/unreviewed/2024/04/GHSA-vvm6-xgvv-w5gg/GHSA-vvm6-xgvv-w5gg.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json b/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json
index e5f27e28c9a..3ef4a308cbd 100644
--- a/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json
+++ b/advisories/unreviewed/2024/04/GHSA-xhvg-2jp2-9c4h/GHSA-xhvg-2jp2-9c4h.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-2w3m-74v7-48pp/GHSA-2w3m-74v7-48pp.json b/advisories/unreviewed/2024/05/GHSA-2w3m-74v7-48pp/GHSA-2w3m-74v7-48pp.json
index bf80debd7dd..3515b874568 100644
--- a/advisories/unreviewed/2024/05/GHSA-2w3m-74v7-48pp/GHSA-2w3m-74v7-48pp.json
+++ b/advisories/unreviewed/2024/05/GHSA-2w3m-74v7-48pp/GHSA-2w3m-74v7-48pp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w3m-74v7-48pp",
- "modified": "2024-06-03T18:55:30Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-23T15:30:39Z",
"aliases": [
"CVE-2024-1803"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-863"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-3mcq-j4r6-r645/GHSA-3mcq-j4r6-r645.json b/advisories/unreviewed/2024/05/GHSA-3mcq-j4r6-r645/GHSA-3mcq-j4r6-r645.json
index 24e753e6d11..4c8dea46426 100644
--- a/advisories/unreviewed/2024/05/GHSA-3mcq-j4r6-r645/GHSA-3mcq-j4r6-r645.json
+++ b/advisories/unreviewed/2024/05/GHSA-3mcq-j4r6-r645/GHSA-3mcq-j4r6-r645.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mcq-j4r6-r645",
- "modified": "2024-05-21T09:31:16Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-21T09:31:16Z",
"aliases": [
"CVE-2024-4470"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-4grf-x53v-r95x/GHSA-4grf-x53v-r95x.json b/advisories/unreviewed/2024/05/GHSA-4grf-x53v-r95x/GHSA-4grf-x53v-r95x.json
index 84b408f606c..884647a0547 100644
--- a/advisories/unreviewed/2024/05/GHSA-4grf-x53v-r95x/GHSA-4grf-x53v-r95x.json
+++ b/advisories/unreviewed/2024/05/GHSA-4grf-x53v-r95x/GHSA-4grf-x53v-r95x.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-203",
"CWE-204"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2024/05/GHSA-6hxm-cj8c-h8v9/GHSA-6hxm-cj8c-h8v9.json b/advisories/unreviewed/2024/05/GHSA-6hxm-cj8c-h8v9/GHSA-6hxm-cj8c-h8v9.json
index 7c48e43a585..aa1756bd306 100644
--- a/advisories/unreviewed/2024/05/GHSA-6hxm-cj8c-h8v9/GHSA-6hxm-cj8c-h8v9.json
+++ b/advisories/unreviewed/2024/05/GHSA-6hxm-cj8c-h8v9/GHSA-6hxm-cj8c-h8v9.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-782m-whhf-wc44/GHSA-782m-whhf-wc44.json b/advisories/unreviewed/2024/05/GHSA-782m-whhf-wc44/GHSA-782m-whhf-wc44.json
index 872b26d9c55..e75ddcb5f86 100644
--- a/advisories/unreviewed/2024/05/GHSA-782m-whhf-wc44/GHSA-782m-whhf-wc44.json
+++ b/advisories/unreviewed/2024/05/GHSA-782m-whhf-wc44/GHSA-782m-whhf-wc44.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-8vc8-45wf-73mv/GHSA-8vc8-45wf-73mv.json b/advisories/unreviewed/2024/05/GHSA-8vc8-45wf-73mv/GHSA-8vc8-45wf-73mv.json
index 91048b21a30..6ab731097dd 100644
--- a/advisories/unreviewed/2024/05/GHSA-8vc8-45wf-73mv/GHSA-8vc8-45wf-73mv.json
+++ b/advisories/unreviewed/2024/05/GHSA-8vc8-45wf-73mv/GHSA-8vc8-45wf-73mv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vc8-45wf-73mv",
- "modified": "2024-05-31T12:30:49Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-31T12:30:49Z",
"aliases": [
"CVE-2024-5041"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-c4v9-g4cm-vgvx/GHSA-c4v9-g4cm-vgvx.json b/advisories/unreviewed/2024/05/GHSA-c4v9-g4cm-vgvx/GHSA-c4v9-g4cm-vgvx.json
index 428421a6d58..5582b1f71f0 100644
--- a/advisories/unreviewed/2024/05/GHSA-c4v9-g4cm-vgvx/GHSA-c4v9-g4cm-vgvx.json
+++ b/advisories/unreviewed/2024/05/GHSA-c4v9-g4cm-vgvx/GHSA-c4v9-g4cm-vgvx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c4v9-g4cm-vgvx",
- "modified": "2024-05-19T09:34:46Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-19T09:34:46Z",
"aliases": [
"CVE-2024-35883"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mchp-pci1xxx: Fix a possible null pointer dereference in pci1xxx_spi_probe\n\nIn function pci1xxxx_spi_probe, there is a potential null pointer that\nmay be caused by a failed memory allocation by the function devm_kzalloc.\nHence, a null pointer check needs to be added to prevent null pointer\ndereferencing later in the code.\n\nTo fix this issue, spi_bus->spi_int[iter] should be checked. The memory\nallocated by devm_kzalloc will be automatically released, so just directly\nreturn -ENOMEM without worrying about memory leaks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T09:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-hgmh-h7vj-ppm6/GHSA-hgmh-h7vj-ppm6.json b/advisories/unreviewed/2024/05/GHSA-hgmh-h7vj-ppm6/GHSA-hgmh-h7vj-ppm6.json
index 57fa2a2b015..cff49ce8e9b 100644
--- a/advisories/unreviewed/2024/05/GHSA-hgmh-h7vj-ppm6/GHSA-hgmh-h7vj-ppm6.json
+++ b/advisories/unreviewed/2024/05/GHSA-hgmh-h7vj-ppm6/GHSA-hgmh-h7vj-ppm6.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json b/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json
index 3992727606b..1b0b13ed19e 100644
--- a/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json
+++ b/advisories/unreviewed/2024/05/GHSA-jw95-5cpm-5722/GHSA-jw95-5cpm-5722.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jw95-5cpm-5722",
- "modified": "2024-05-17T15:31:08Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-17T15:31:08Z",
"aliases": [
"CVE-2023-52663"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe()\n\nDriver uses kasprintf() to initialize fw_{code,data}_bin members of\nstruct acp_dev_data, but kfree() is never called to deallocate the\nmemory, which results in a memory leak.\n\nFix the issue by switching to devm_kasprintf(). Additionally, ensure the\nallocation was successful by checking the pointer validity.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-m28h-92r7-f7rw/GHSA-m28h-92r7-f7rw.json b/advisories/unreviewed/2024/05/GHSA-m28h-92r7-f7rw/GHSA-m28h-92r7-f7rw.json
index 9bebabcb104..e634c8a7ad5 100644
--- a/advisories/unreviewed/2024/05/GHSA-m28h-92r7-f7rw/GHSA-m28h-92r7-f7rw.json
+++ b/advisories/unreviewed/2024/05/GHSA-m28h-92r7-f7rw/GHSA-m28h-92r7-f7rw.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json b/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json
index 5db1fc0d03a..94e148c97f9 100644
--- a/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json
+++ b/advisories/unreviewed/2024/05/GHSA-p7h5-86fq-j7r3/GHSA-p7h5-86fq-j7r3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7h5-86fq-j7r3",
- "modified": "2024-05-17T15:31:08Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-17T15:31:08Z",
"aliases": [
"CVE-2023-52664"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: eliminate double free in error handling logic\n\nDriver has a logic leak in ring data allocation/free,\nwhere aq_ring_free could be called multiple times on same ring,\nif system is under stress and got memory allocation error.\n\nRing pointer was used as an indicator of failure, but this is\nnot correct since only ring data is allocated/deallocated.\nRing itself is an array member.\n\nChanging ring allocation functions to return error code directly.\nThis simplifies error handling and eliminates aq_ring_free\non higher layer.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-415"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T14:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qvqh-2867-5v26/GHSA-qvqh-2867-5v26.json b/advisories/unreviewed/2024/05/GHSA-qvqh-2867-5v26/GHSA-qvqh-2867-5v26.json
index b49f04849ea..ff0b67d00ab 100644
--- a/advisories/unreviewed/2024/05/GHSA-qvqh-2867-5v26/GHSA-qvqh-2867-5v26.json
+++ b/advisories/unreviewed/2024/05/GHSA-qvqh-2867-5v26/GHSA-qvqh-2867-5v26.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qvqh-2867-5v26",
- "modified": "2024-05-14T18:30:54Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-14T18:30:54Z",
"aliases": [
"CVE-2024-4316"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json b/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json
index c33bab909ed..5d698239f26 100644
--- a/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json
+++ b/advisories/unreviewed/2024/05/GHSA-rx9j-rfmx-2gc3/GHSA-rx9j-rfmx-2gc3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rx9j-rfmx-2gc3",
- "modified": "2024-05-18T03:30:37Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-18T03:30:37Z",
"aliases": [
"CVE-2024-4865"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-w5j7-cgfv-4whw/GHSA-w5j7-cgfv-4whw.json b/advisories/unreviewed/2024/05/GHSA-w5j7-cgfv-4whw/GHSA-w5j7-cgfv-4whw.json
index 44b1fa95484..8b8e4af15b5 100644
--- a/advisories/unreviewed/2024/05/GHSA-w5j7-cgfv-4whw/GHSA-w5j7-cgfv-4whw.json
+++ b/advisories/unreviewed/2024/05/GHSA-w5j7-cgfv-4whw/GHSA-w5j7-cgfv-4whw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w5j7-cgfv-4whw",
- "modified": "2024-05-18T12:30:32Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-05-18T12:30:32Z",
"aliases": [
"CVE-2024-5088"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-x662-x49c-chqx/GHSA-x662-x49c-chqx.json b/advisories/unreviewed/2024/05/GHSA-x662-x49c-chqx/GHSA-x662-x49c-chqx.json
index a50203a44e8..649d9894d61 100644
--- a/advisories/unreviewed/2024/05/GHSA-x662-x49c-chqx/GHSA-x662-x49c-chqx.json
+++ b/advisories/unreviewed/2024/05/GHSA-x662-x49c-chqx/GHSA-x662-x49c-chqx.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/06/GHSA-93rv-vrc5-7jx2/GHSA-93rv-vrc5-7jx2.json b/advisories/unreviewed/2024/06/GHSA-93rv-vrc5-7jx2/GHSA-93rv-vrc5-7jx2.json
index 2e314fbd337..87db6c67064 100644
--- a/advisories/unreviewed/2024/06/GHSA-93rv-vrc5-7jx2/GHSA-93rv-vrc5-7jx2.json
+++ b/advisories/unreviewed/2024/06/GHSA-93rv-vrc5-7jx2/GHSA-93rv-vrc5-7jx2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93rv-vrc5-7jx2",
- "modified": "2024-06-21T12:31:20Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-06-21T12:31:20Z",
"aliases": [
"CVE-2024-38625"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Check 'folio' pointer for NULL\n\nIt can be NULL if bmap is called.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T11:15:11Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-r4ph-ww7g-63x3/GHSA-r4ph-ww7g-63x3.json b/advisories/unreviewed/2024/06/GHSA-r4ph-ww7g-63x3/GHSA-r4ph-ww7g-63x3.json
index fd5bbdcfd34..70e660ba298 100644
--- a/advisories/unreviewed/2024/06/GHSA-r4ph-ww7g-63x3/GHSA-r4ph-ww7g-63x3.json
+++ b/advisories/unreviewed/2024/06/GHSA-r4ph-ww7g-63x3/GHSA-r4ph-ww7g-63x3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4ph-ww7g-63x3",
- "modified": "2024-06-01T06:30:49Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-06-01T06:30:49Z",
"aliases": [
"CVE-2023-6382"
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/06/GHSA-vgqm-wj47-2wp5/GHSA-vgqm-wj47-2wp5.json b/advisories/unreviewed/2024/06/GHSA-vgqm-wj47-2wp5/GHSA-vgqm-wj47-2wp5.json
index 4f046e6443d..af8b03f858c 100644
--- a/advisories/unreviewed/2024/06/GHSA-vgqm-wj47-2wp5/GHSA-vgqm-wj47-2wp5.json
+++ b/advisories/unreviewed/2024/06/GHSA-vgqm-wj47-2wp5/GHSA-vgqm-wj47-2wp5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgqm-wj47-2wp5",
- "modified": "2024-06-27T12:30:48Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-06-21T12:31:20Z",
"aliases": [
"CVE-2024-36286"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()\n\nsyzbot reported that nf_reinject() could be called without rcu_read_lock() :\n\nWARNING: suspicious RCU usage\n6.9.0-rc7-syzkaller-02060-g5c1672705a1a #0 Not tainted\n\nnet/netfilter/nfnetlink_queue.c:263 suspicious rcu_dereference_check() usage!\n\nother info that might help us debug this:\n\nrcu_scheduler_active = 2, debug_locks = 1\n2 locks held by syz-executor.4/13427:\n #0: ffffffff8e334f60 (rcu_callback){....}-{0:0}, at: rcu_lock_acquire include/linux/rcupdate.h:329 [inline]\n #0: ffffffff8e334f60 (rcu_callback){....}-{0:0}, at: rcu_do_batch kernel/rcu/tree.c:2190 [inline]\n #0: ffffffff8e334f60 (rcu_callback){....}-{0:0}, at: rcu_core+0xa86/0x1830 kernel/rcu/tree.c:2471\n #1: ffff88801ca92958 (&inst->lock){+.-.}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n #1: ffff88801ca92958 (&inst->lock){+.-.}-{2:2}, at: nfqnl_flush net/netfilter/nfnetlink_queue.c:405 [inline]\n #1: ffff88801ca92958 (&inst->lock){+.-.}-{2:2}, at: instance_destroy_rcu+0x30/0x220 net/netfilter/nfnetlink_queue.c:172\n\nstack backtrace:\nCPU: 0 PID: 13427 Comm: syz-executor.4 Not tainted 6.9.0-rc7-syzkaller-02060-g5c1672705a1a #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/02/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n lockdep_rcu_suspicious+0x221/0x340 kernel/locking/lockdep.c:6712\n nf_reinject net/netfilter/nfnetlink_queue.c:323 [inline]\n nfqnl_reinject+0x6ec/0x1120 net/netfilter/nfnetlink_queue.c:397\n nfqnl_flush net/netfilter/nfnetlink_queue.c:410 [inline]\n instance_destroy_rcu+0x1ae/0x220 net/netfilter/nfnetlink_queue.c:172\n rcu_do_batch kernel/rcu/tree.c:2196 [inline]\n rcu_core+0xafd/0x1830 kernel/rcu/tree.c:2471\n handle_softirqs+0x2d6/0x990 kernel/softirq.c:554\n __do_softirq kernel/softirq.c:588 [inline]\n invoke_softirq kernel/softirq.c:428 [inline]\n __irq_exit_rcu+0xf4/0x1c0 kernel/softirq.c:637\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:649\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1043 [inline]\n sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1043\n \n ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -53,7 +58,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-21T11:15:10Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-hx58-3fx6-hp8m/GHSA-hx58-3fx6-hp8m.json b/advisories/unreviewed/2024/07/GHSA-hx58-3fx6-hp8m/GHSA-hx58-3fx6-hp8m.json
index a8c27ddb44a..1e1af30f38e 100644
--- a/advisories/unreviewed/2024/07/GHSA-hx58-3fx6-hp8m/GHSA-hx58-3fx6-hp8m.json
+++ b/advisories/unreviewed/2024/07/GHSA-hx58-3fx6-hp8m/GHSA-hx58-3fx6-hp8m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hx58-3fx6-hp8m",
- "modified": "2024-07-12T15:31:28Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-07-12T15:31:28Z",
"aliases": [
"CVE-2024-40962"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: allocate dummy checksums for zoned NODATASUM writes\n\nShin'ichiro reported that when he's running fstests' test-case\nbtrfs/167 on emulated zoned devices, he's seeing the following NULL\npointer dereference in 'btrfs_zone_finish_endio()':\n\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000011: 0000 [#1] PREEMPT SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f]\n CPU: 4 PID: 2332440 Comm: kworker/u80:15 Tainted: G W 6.10.0-rc2-kts+ #4\n Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020\n Workqueue: btrfs-endio-write btrfs_work_helper [btrfs]\n RIP: 0010:btrfs_zone_finish_endio.part.0+0x34/0x160 [btrfs]\n\n RSP: 0018:ffff88867f107a90 EFLAGS: 00010206\n RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff893e5534\n RDX: 0000000000000011 RSI: 0000000000000004 RDI: 0000000000000088\n RBP: 0000000000000002 R08: 0000000000000001 R09: ffffed1081696028\n R10: ffff88840b4b0143 R11: ffff88834dfff600 R12: ffff88840b4b0000\n R13: 0000000000020000 R14: 0000000000000000 R15: ffff888530ad5210\n FS: 0000000000000000(0000) GS:ffff888e3f800000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f87223fff38 CR3: 00000007a7c6a002 CR4: 00000000007706f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die_body.cold+0x19/0x27\n ? die_addr+0x46/0x70\n ? exc_general_protection+0x14f/0x250\n ? asm_exc_general_protection+0x26/0x30\n ? do_raw_read_unlock+0x44/0x70\n ? btrfs_zone_finish_endio.part.0+0x34/0x160 [btrfs]\n btrfs_finish_one_ordered+0x5d9/0x19a0 [btrfs]\n ? __pfx_lock_release+0x10/0x10\n ? do_raw_write_lock+0x90/0x260\n ? __pfx_do_raw_write_lock+0x10/0x10\n ? __pfx_btrfs_finish_one_ordered+0x10/0x10 [btrfs]\n ? _raw_write_unlock+0x23/0x40\n ? btrfs_finish_ordered_zoned+0x5a9/0x850 [btrfs]\n ? lock_acquire+0x435/0x500\n btrfs_work_helper+0x1b1/0xa70 [btrfs]\n ? __schedule+0x10a8/0x60b0\n ? __pfx___might_resched+0x10/0x10\n process_one_work+0x862/0x1410\n ? __pfx_lock_acquire+0x10/0x10\n ? __pfx_process_one_work+0x10/0x10\n ? assign_work+0x16c/0x240\n worker_thread+0x5e6/0x1010\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x2c3/0x3a0\n ? trace_irq_enable.constprop.0+0xce/0x110\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\nEnabling CONFIG_BTRFS_ASSERT revealed the following assertion to\ntrigger:\n\n assertion failed: !list_empty(&ordered->list), in fs/btrfs/zoned.c:1815\n\nThis indicates, that we're missing the checksums list on the\nordered_extent. As btrfs/167 is doing a NOCOW write this is to be\nexpected.\n\nFurther analysis with drgn confirmed the assumption:\n\n >>> inode = prog.crashed_thread().stack_trace()[11]['ordered'].inode\n >>> btrfs_inode = drgn.container_of(inode, \"struct btrfs_inode\", \\\n \t\t\t\t\"vfs_inode\")\n >>> print(btrfs_inode.flags)\n (u32)1\n\nAs zoned emulation mode simulates conventional zones on regular devices,\nwe cannot use zone-append for writing. But we're only attaching dummy\nchecksums if we're doing a zone-append write.\n\nSo for NOCOW zoned data writes on conventional zones, also attach a\ndummy checksum.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-12T13:15:18Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json b/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json
index c5bf6e85448..b6f145608b7 100644
--- a/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json
+++ b/advisories/unreviewed/2024/11/GHSA-8w77-hpx9-8fm3/GHSA-8w77-hpx9-8fm3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w77-hpx9-8fm3",
- "modified": "2024-11-06T21:30:56Z",
+ "modified": "2025-01-07T18:30:43Z",
"published": "2024-11-06T21:30:56Z",
"aliases": [
"CVE-2024-10941"
],
"details": "A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-06T21:15:05Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-pr36-74pg-m583/GHSA-pr36-74pg-m583.json b/advisories/unreviewed/2024/11/GHSA-pr36-74pg-m583/GHSA-pr36-74pg-m583.json
index 50de9e6b504..925753466e1 100644
--- a/advisories/unreviewed/2024/11/GHSA-pr36-74pg-m583/GHSA-pr36-74pg-m583.json
+++ b/advisories/unreviewed/2024/11/GHSA-pr36-74pg-m583/GHSA-pr36-74pg-m583.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pr36-74pg-m583",
- "modified": "2024-11-19T03:31:08Z",
+ "modified": "2025-01-07T18:30:44Z",
"published": "2024-11-19T03:31:08Z",
"aliases": [
"CVE-2024-50292"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: stm32: spdifrx: fix dma channel release in stm32_spdifrx_remove\n\nIn case of error when requesting ctrl_chan DMA channel, ctrl_chan is not\nnull. So the release of the dma channel leads to the following issue:\n[ 4.879000] st,stm32-spdifrx 500d0000.audio-controller:\ndma_request_slave_channel error -19\n[ 4.888975] Unable to handle kernel NULL pointer dereference\nat virtual address 000000000000003d\n[...]\n[ 5.096577] Call trace:\n[ 5.099099] dma_release_channel+0x24/0x100\n[ 5.103235] stm32_spdifrx_remove+0x24/0x60 [snd_soc_stm32_spdifrx]\n[ 5.109494] stm32_spdifrx_probe+0x320/0x4c4 [snd_soc_stm32_spdifrx]\n\nTo avoid this issue, release channel only if the pointer is valid.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-19T02:16:31Z"
diff --git a/advisories/unreviewed/2024/11/GHSA-px2p-6fmh-crpv/GHSA-px2p-6fmh-crpv.json b/advisories/unreviewed/2024/11/GHSA-px2p-6fmh-crpv/GHSA-px2p-6fmh-crpv.json
index 100e9e0a420..653586e0e24 100644
--- a/advisories/unreviewed/2024/11/GHSA-px2p-6fmh-crpv/GHSA-px2p-6fmh-crpv.json
+++ b/advisories/unreviewed/2024/11/GHSA-px2p-6fmh-crpv/GHSA-px2p-6fmh-crpv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-px2p-6fmh-crpv",
- "modified": "2024-11-19T03:31:08Z",
+ "modified": "2025-01-07T18:30:44Z",
"published": "2024-11-19T03:31:08Z",
"aliases": [
"CVE-2024-50293"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: do not leave a dangling sk pointer in __smc_create()\n\nThanks to commit 4bbd360a5084 (\"socket: Print pf->create() when\nit does not clear sock->sk on failure.\"), syzbot found an issue with AF_SMC:\n\nsmc_create must clear sock->sk on failure, family: 43, type: 1, protocol: 0\n WARNING: CPU: 0 PID: 5827 at net/socket.c:1565 __sock_create+0x96f/0xa30 net/socket.c:1563\nModules linked in:\nCPU: 0 UID: 0 PID: 5827 Comm: syz-executor259 Not tainted 6.12.0-rc6-next-20241106-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n RIP: 0010:__sock_create+0x96f/0xa30 net/socket.c:1563\nCode: 03 00 74 08 4c 89 e7 e8 4f 3b 85 f8 49 8b 34 24 48 c7 c7 40 89 0c 8d 8b 54 24 04 8b 4c 24 0c 44 8b 44 24 08 e8 32 78 db f7 90 <0f> 0b 90 90 e9 d3 fd ff ff 89 e9 80 e1 07 fe c1 38 c1 0f 8c ee f7\nRSP: 0018:ffffc90003e4fda0 EFLAGS: 00010246\nRAX: 099c6f938c7f4700 RBX: 1ffffffff1a595fd RCX: ffff888034823c00\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: 00000000ffffffe9 R08: ffffffff81567052 R09: 1ffff920007c9f50\nR10: dffffc0000000000 R11: fffff520007c9f51 R12: ffffffff8d2cafe8\nR13: 1ffffffff1a595fe R14: ffffffff9a789c40 R15: ffff8880764298c0\nFS: 000055557b518380(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fa62ff43225 CR3: 0000000031628000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n sock_create net/socket.c:1616 [inline]\n __sys_socket_create net/socket.c:1653 [inline]\n __sys_socket+0x150/0x3c0 net/socket.c:1700\n __do_sys_socket net/socket.c:1714 [inline]\n __se_sys_socket net/socket.c:1712 [inline]\n\nFor reference, see commit 2d859aff775d (\"Merge branch\n'do-not-leave-dangling-sk-pointers-in-pf-create-functions'\")",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-19T02:16:31Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-2xhp-fvvw-3838/GHSA-2xhp-fvvw-3838.json b/advisories/unreviewed/2024/12/GHSA-2xhp-fvvw-3838/GHSA-2xhp-fvvw-3838.json
index aa15af4293e..2b51a6343f5 100644
--- a/advisories/unreviewed/2024/12/GHSA-2xhp-fvvw-3838/GHSA-2xhp-fvvw-3838.json
+++ b/advisories/unreviewed/2024/12/GHSA-2xhp-fvvw-3838/GHSA-2xhp-fvvw-3838.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xhp-fvvw-3838",
- "modified": "2024-12-19T00:37:35Z",
+ "modified": "2025-01-07T18:30:46Z",
"published": "2024-12-19T00:37:35Z",
"aliases": [
"CVE-2024-12692"
],
"details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-843"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-18T22:15:05Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json b/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json
index 63ff0645fff..ebbe3af557a 100644
--- a/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json
+++ b/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-125"
+ "CWE-125",
+ "CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-5652-4j93-xhg6/GHSA-5652-4j93-xhg6.json b/advisories/unreviewed/2024/12/GHSA-5652-4j93-xhg6/GHSA-5652-4j93-xhg6.json
index 03d1a892289..11d965fecde 100644
--- a/advisories/unreviewed/2024/12/GHSA-5652-4j93-xhg6/GHSA-5652-4j93-xhg6.json
+++ b/advisories/unreviewed/2024/12/GHSA-5652-4j93-xhg6/GHSA-5652-4j93-xhg6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5652-4j93-xhg6",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-01-07T18:30:47Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53154"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: clk-apple-nco: Add NULL check in applnco_probe\n\nAdd NULL check in applnco_probe, to handle kernel NULL pointer\ndereference error.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-5hfq-6gvm-pw8c/GHSA-5hfq-6gvm-pw8c.json b/advisories/unreviewed/2024/12/GHSA-5hfq-6gvm-pw8c/GHSA-5hfq-6gvm-pw8c.json
index cf50d4da1c1..0a09aa2168e 100644
--- a/advisories/unreviewed/2024/12/GHSA-5hfq-6gvm-pw8c/GHSA-5hfq-6gvm-pw8c.json
+++ b/advisories/unreviewed/2024/12/GHSA-5hfq-6gvm-pw8c/GHSA-5hfq-6gvm-pw8c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hfq-6gvm-pw8c",
- "modified": "2024-12-24T12:30:42Z",
+ "modified": "2025-01-07T18:30:46Z",
"published": "2024-12-24T12:30:42Z",
"aliases": [
"CVE-2024-53145"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\num: Fix potential integer overflow during physmem setup\n\nThis issue happens when the real map size is greater than LONG_MAX,\nwhich can be easily triggered on UML/i386.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-7vq8-4frp-4vcv/GHSA-7vq8-4frp-4vcv.json b/advisories/unreviewed/2024/12/GHSA-7vq8-4frp-4vcv/GHSA-7vq8-4frp-4vcv.json
index d65429a1fe3..7225dcb7369 100644
--- a/advisories/unreviewed/2024/12/GHSA-7vq8-4frp-4vcv/GHSA-7vq8-4frp-4vcv.json
+++ b/advisories/unreviewed/2024/12/GHSA-7vq8-4frp-4vcv/GHSA-7vq8-4frp-4vcv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vq8-4frp-4vcv",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-01-07T18:30:46Z",
"published": "2024-12-24T12:30:42Z",
"aliases": [
"CVE-2024-53150"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Fix out of bounds reads when finding clock sources\n\nThe current USB-audio driver code doesn't check bLength of each\ndescriptor at traversing for clock descriptors. That is, when a\ndevice provides a bogus descriptor with a shorter bLength, the driver\nmight hit out-of-bounds reads.\n\nFor addressing it, this patch adds sanity checks to the validator\nfunctions for the clock descriptor traversal. When the descriptor\nlength is shorter than expected, it's skipped in the loop.\n\nFor the clock source and clock multiplier descriptors, we can just\ncheck bLength against the sizeof() of each descriptor type.\nOTOH, the clock selector descriptor of UAC2 and UAC3 has an array\nof bNrInPins elements and two more fields at its tail, hence those\nhave to be checked in addition to the sizeof() check.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-85vx-hjhp-432v/GHSA-85vx-hjhp-432v.json b/advisories/unreviewed/2024/12/GHSA-85vx-hjhp-432v/GHSA-85vx-hjhp-432v.json
index b4990e7a8c7..8b369254480 100644
--- a/advisories/unreviewed/2024/12/GHSA-85vx-hjhp-432v/GHSA-85vx-hjhp-432v.json
+++ b/advisories/unreviewed/2024/12/GHSA-85vx-hjhp-432v/GHSA-85vx-hjhp-432v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85vx-hjhp-432v",
- "modified": "2024-12-13T09:31:13Z",
+ "modified": "2025-01-07T18:30:45Z",
"published": "2024-12-13T09:31:13Z",
"aliases": [
"CVE-2024-11832"
diff --git a/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json b/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json
index 74fbf03aa96..e13b802a9c0 100644
--- a/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json
+++ b/advisories/unreviewed/2024/12/GHSA-cvm4-cfc7-c54q/GHSA-cvm4-cfc7-c54q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvm4-cfc7-c54q",
- "modified": "2024-12-17T18:33:50Z",
+ "modified": "2025-01-07T18:30:45Z",
"published": "2024-12-17T18:33:50Z",
"aliases": [
"CVE-2024-49816"
diff --git a/advisories/unreviewed/2024/12/GHSA-fcx4-qhgw-9q8f/GHSA-fcx4-qhgw-9q8f.json b/advisories/unreviewed/2024/12/GHSA-fcx4-qhgw-9q8f/GHSA-fcx4-qhgw-9q8f.json
index 8ea9cd467d6..48ee43c5490 100644
--- a/advisories/unreviewed/2024/12/GHSA-fcx4-qhgw-9q8f/GHSA-fcx4-qhgw-9q8f.json
+++ b/advisories/unreviewed/2024/12/GHSA-fcx4-qhgw-9q8f/GHSA-fcx4-qhgw-9q8f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcx4-qhgw-9q8f",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-01-07T18:30:46Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53151"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Address an integer overflow\n\nDan Carpenter reports:\n> Commit 78147ca8b4a9 (\"svcrdma: Add a \"parsed chunk list\" data\n> structure\") from Jun 22, 2020 (linux-next), leads to the following\n> Smatch static checker warning:\n>\n>\tnet/sunrpc/xprtrdma/svc_rdma_recvfrom.c:498 xdr_check_write_chunk()\n>\twarn: potential user controlled sizeof overflow 'segcount * 4 * 4'\n>\n> net/sunrpc/xprtrdma/svc_rdma_recvfrom.c\n> 488 static bool xdr_check_write_chunk(struct svc_rdma_recv_ctxt *rctxt)\n> 489 {\n> 490 u32 segcount;\n> 491 __be32 *p;\n> 492\n> 493 if (xdr_stream_decode_u32(&rctxt->rc_stream, &segcount))\n> ^^^^^^^^\n>\n> 494 return false;\n> 495\n> 496 /* A bogus segcount causes this buffer overflow check to fail. */\n> 497 p = xdr_inline_decode(&rctxt->rc_stream,\n> --> 498 segcount * rpcrdma_segment_maxsz * sizeof(*p));\n>\n>\n> segcount is an untrusted u32. On 32bit systems anything >= SIZE_MAX / 16 will\n> have an integer overflow and some those values will be accepted by\n> xdr_inline_decode().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-h5xq-p424-h7cq/GHSA-h5xq-p424-h7cq.json b/advisories/unreviewed/2024/12/GHSA-h5xq-p424-h7cq/GHSA-h5xq-p424-h7cq.json
index e5e12dce8cf..676a44d4ce9 100644
--- a/advisories/unreviewed/2024/12/GHSA-h5xq-p424-h7cq/GHSA-h5xq-p424-h7cq.json
+++ b/advisories/unreviewed/2024/12/GHSA-h5xq-p424-h7cq/GHSA-h5xq-p424-h7cq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5xq-p424-h7cq",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-01-07T18:30:47Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53155"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix uninitialized value in ocfs2_file_read_iter()\n\nSyzbot has reported the following KMSAN splat:\n\nBUG: KMSAN: uninit-value in ocfs2_file_read_iter+0x9a4/0xf80\n ocfs2_file_read_iter+0x9a4/0xf80\n __io_read+0x8d4/0x20f0\n io_read+0x3e/0xf0\n io_issue_sqe+0x42b/0x22c0\n io_wq_submit_work+0xaf9/0xdc0\n io_worker_handle_work+0xd13/0x2110\n io_wq_worker+0x447/0x1410\n ret_from_fork+0x6f/0x90\n ret_from_fork_asm+0x1a/0x30\n\nUninit was created at:\n __alloc_pages_noprof+0x9a7/0xe00\n alloc_pages_mpol_noprof+0x299/0x990\n alloc_pages_noprof+0x1bf/0x1e0\n allocate_slab+0x33a/0x1250\n ___slab_alloc+0x12ef/0x35e0\n kmem_cache_alloc_bulk_noprof+0x486/0x1330\n __io_alloc_req_refill+0x84/0x560\n io_submit_sqes+0x172f/0x2f30\n __se_sys_io_uring_enter+0x406/0x41c0\n __x64_sys_io_uring_enter+0x11f/0x1a0\n x64_sys_call+0x2b54/0x3ba0\n do_syscall_64+0xcd/0x1e0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nSince an instance of 'struct kiocb' may be passed from the block layer\nwith 'private' field uninitialized, introduce 'ocfs2_iocb_init_rw_locked()'\nand use it from where 'ocfs2_dio_end_io()' might take care, i.e. in\n'ocfs2_file_read_iter()' and 'ocfs2_file_write_iter()'.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-m934-94j6-4844/GHSA-m934-94j6-4844.json b/advisories/unreviewed/2024/12/GHSA-m934-94j6-4844/GHSA-m934-94j6-4844.json
index a6249523207..8a6cc8026b1 100644
--- a/advisories/unreviewed/2024/12/GHSA-m934-94j6-4844/GHSA-m934-94j6-4844.json
+++ b/advisories/unreviewed/2024/12/GHSA-m934-94j6-4844/GHSA-m934-94j6-4844.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m934-94j6-4844",
- "modified": "2024-12-02T09:39:12Z",
+ "modified": "2025-01-07T18:30:44Z",
"published": "2024-12-02T09:39:12Z",
"aliases": [
"CVE-2024-53103"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer\n\nWhen hvs is released, there is a possibility that vsk->trans may not\nbe initialized to NULL, which could lead to a dangling pointer.\nThis issue is resolved by initializing vsk->trans to NULL.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-02T08:15:08Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-qfgm-256j-rghm/GHSA-qfgm-256j-rghm.json b/advisories/unreviewed/2024/12/GHSA-qfgm-256j-rghm/GHSA-qfgm-256j-rghm.json
index 2a615ca1051..f80bcf206ff 100644
--- a/advisories/unreviewed/2024/12/GHSA-qfgm-256j-rghm/GHSA-qfgm-256j-rghm.json
+++ b/advisories/unreviewed/2024/12/GHSA-qfgm-256j-rghm/GHSA-qfgm-256j-rghm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfgm-256j-rghm",
- "modified": "2024-12-24T12:30:42Z",
+ "modified": "2025-01-07T18:30:46Z",
"published": "2024-12-24T12:30:42Z",
"aliases": [
"CVE-2024-53149"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: glink: fix off-by-one in connector_status\n\nUCSI connector's indices start from 1 up to 3, PMIC_GLINK_MAX_PORTS.\nCorrect the condition in the pmic_glink_ucsi_connector_status()\ncallback, fixing Type-C orientation reporting for the third USB-C\nconnector.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-193"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-rf84-f276-hxmw/GHSA-rf84-f276-hxmw.json b/advisories/unreviewed/2024/12/GHSA-rf84-f276-hxmw/GHSA-rf84-f276-hxmw.json
index 43b5ea2f5aa..e2b5be19845 100644
--- a/advisories/unreviewed/2024/12/GHSA-rf84-f276-hxmw/GHSA-rf84-f276-hxmw.json
+++ b/advisories/unreviewed/2024/12/GHSA-rf84-f276-hxmw/GHSA-rf84-f276-hxmw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rf84-f276-hxmw",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-01-07T18:30:48Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53235"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix file-backed mounts over FUSE\n\nsyzbot reported a null-ptr-deref in fuse_read_args_fill:\n fuse_read_folio+0xb0/0x100 fs/fuse/file.c:905\n filemap_read_folio+0xc6/0x2a0 mm/filemap.c:2367\n do_read_cache_folio+0x263/0x5c0 mm/filemap.c:3825\n read_mapping_folio include/linux/pagemap.h:1011 [inline]\n erofs_bread+0x34d/0x7e0 fs/erofs/data.c:41\n erofs_read_superblock fs/erofs/super.c:281 [inline]\n erofs_fc_fill_super+0x2b9/0x2500 fs/erofs/super.c:625\n\nUnlike most filesystems, some network filesystems and FUSE need\nunavoidable valid `file` pointers for their read I/Os [1].\nAnyway, those use cases need to be supported too.\n\n[1] https://docs.kernel.org/filesystems/vfs.html",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:31Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-rw8v-g4fm-gw3v/GHSA-rw8v-g4fm-gw3v.json b/advisories/unreviewed/2024/12/GHSA-rw8v-g4fm-gw3v/GHSA-rw8v-g4fm-gw3v.json
index 3605e6524b5..7a772e7df57 100644
--- a/advisories/unreviewed/2024/12/GHSA-rw8v-g4fm-gw3v/GHSA-rw8v-g4fm-gw3v.json
+++ b/advisories/unreviewed/2024/12/GHSA-rw8v-g4fm-gw3v/GHSA-rw8v-g4fm-gw3v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rw8v-g4fm-gw3v",
- "modified": "2024-12-24T12:30:42Z",
+ "modified": "2025-01-07T18:30:46Z",
"published": "2024-12-24T12:30:42Z",
"aliases": [
"CVE-2024-53146"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent a potential integer overflow\n\nIf the tag length is >= U32_MAX - 3 then the \"length + 4\" addition\ncan result in an integer overflow. Address this by splitting the\ndecoding into several steps so that decode_cb_compound4res() does\nnot have to perform arithmetic on the unsafe length value.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-v5hm-gx5h-94jm/GHSA-v5hm-gx5h-94jm.json b/advisories/unreviewed/2024/12/GHSA-v5hm-gx5h-94jm/GHSA-v5hm-gx5h-94jm.json
index c56c0d0dea9..62a91f3e57e 100644
--- a/advisories/unreviewed/2024/12/GHSA-v5hm-gx5h-94jm/GHSA-v5hm-gx5h-94jm.json
+++ b/advisories/unreviewed/2024/12/GHSA-v5hm-gx5h-94jm/GHSA-v5hm-gx5h-94jm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5hm-gx5h-94jm",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-01-07T18:30:47Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53156"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()\n\nI found the following bug in my fuzzer:\n\n UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath9k/htc_hst.c:26:51\n index 255 is out of range for type 'htc_endpoint [22]'\n CPU: 0 UID: 0 PID: 8 Comm: kworker/0:0 Not tainted 6.11.0-rc6-dirty #14\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Workqueue: events request_firmware_work_func\n Call Trace:\n \n dump_stack_lvl+0x180/0x1b0\n __ubsan_handle_out_of_bounds+0xd4/0x130\n htc_issue_send.constprop.0+0x20c/0x230\n ? _raw_spin_unlock_irqrestore+0x3c/0x70\n ath9k_wmi_cmd+0x41d/0x610\n ? mark_held_locks+0x9f/0xe0\n ...\n\nSince this bug has been confirmed to be caused by insufficient verification\nof conn_rsp_epid, I think it would be appropriate to add a range check for\nconn_rsp_epid to htc_connect_service() to prevent the bug from occurring.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-w5gw-f5vp-r675/GHSA-w5gw-f5vp-r675.json b/advisories/unreviewed/2024/12/GHSA-w5gw-f5vp-r675/GHSA-w5gw-f5vp-r675.json
index c7db0fd8fcd..1f43f8f4b16 100644
--- a/advisories/unreviewed/2024/12/GHSA-w5gw-f5vp-r675/GHSA-w5gw-f5vp-r675.json
+++ b/advisories/unreviewed/2024/12/GHSA-w5gw-f5vp-r675/GHSA-w5gw-f5vp-r675.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w5gw-f5vp-r675",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-01-07T18:30:47Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53157"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scpi: Check the DVFS OPP count returned by the firmware\n\nFix a kernel crash with the below call trace when the SCPI firmware\nreturns OPP count of zero.\n\ndvfs_info.opp_count may be zero on some platforms during the reboot\ntest, and the kernel will crash after dereferencing the pointer to\nkcalloc(info->count, sizeof(*opp), GFP_KERNEL).\n\n | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000028\n | Mem abort info:\n | ESR = 0x96000004\n | Exception class = DABT (current EL), IL = 32 bits\n | SET = 0, FnV = 0\n | EA = 0, S1PTW = 0\n | Data abort info:\n | ISV = 0, ISS = 0x00000004\n | CM = 0, WnR = 0\n | user pgtable: 4k pages, 48-bit VAs, pgdp = 00000000faefa08c\n | [0000000000000028] pgd=0000000000000000\n | Internal error: Oops: 96000004 [#1] SMP\n | scpi-hwmon: probe of PHYT000D:00 failed with error -110\n | Process systemd-udevd (pid: 1701, stack limit = 0x00000000aaede86c)\n | CPU: 2 PID: 1701 Comm: systemd-udevd Not tainted 4.19.90+ #1\n | Hardware name: PHYTIUM LTD Phytium FT2000/4/Phytium FT2000/4, BIOS\n | pstate: 60000005 (nZCv daif -PAN -UAO)\n | pc : scpi_dvfs_recalc_rate+0x40/0x58 [clk_scpi]\n | lr : clk_register+0x438/0x720\n | Call trace:\n | scpi_dvfs_recalc_rate+0x40/0x58 [clk_scpi]\n | devm_clk_hw_register+0x50/0xa0\n | scpi_clk_ops_init.isra.2+0xa0/0x138 [clk_scpi]\n | scpi_clocks_probe+0x528/0x70c [clk_scpi]\n | platform_drv_probe+0x58/0xa8\n | really_probe+0x260/0x3d0\n | driver_probe_device+0x12c/0x148\n | device_driver_attach+0x74/0x98\n | __driver_attach+0xb4/0xe8\n | bus_for_each_dev+0x88/0xe0\n | driver_attach+0x30/0x40\n | bus_add_driver+0x178/0x2b0\n | driver_register+0x64/0x118\n | __platform_driver_register+0x54/0x60\n | scpi_clocks_driver_init+0x24/0x1000 [clk_scpi]\n | do_one_initcall+0x54/0x220\n | do_init_module+0x54/0x1c8\n | load_module+0x14a4/0x1668\n | __se_sys_finit_module+0xf8/0x110\n | __arm64_sys_finit_module+0x24/0x30\n | el0_svc_common+0x78/0x170\n | el0_svc_handler+0x38/0x78\n | el0_svc+0x8/0x340\n | Code: 937d7c00 a94153f3 a8c27bfd f9400421 (b8606820)\n | ---[ end trace 06feb22469d89fa8 ]---\n | Kernel panic - not syncing: Fatal exception\n | SMP: stopping secondary CPUs\n | Kernel Offset: disabled\n | CPU features: 0x10,a0002008\n | Memory Limit: none",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:23Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json b/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json
new file mode 100644
index 00000000000..ea2194e6eea
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-24v2-mrj2-4wpc",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0247"
+ ],
+ "details": "Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0247"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1835193%2C1910021%2C1919803%2C1931576%2C1931948%2C1932173"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-24w6-qrfx-xwhv/GHSA-24w6-qrfx-xwhv.json b/advisories/unreviewed/2025/01/GHSA-24w6-qrfx-xwhv/GHSA-24w6-qrfx-xwhv.json
new file mode 100644
index 00000000000..c011ccd6cda
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-24w6-qrfx-xwhv/GHSA-24w6-qrfx-xwhv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-24w6-qrfx-xwhv",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22534"
+ ],
+ "details": "Missing Authorization vulnerability in Ella van Durpe Slides & Presentations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slides & Presentations: from n/a through 0.0.39.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22534"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/slide/vulnerability/wordpress-slides-presentations-plugin-0-0-39-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2563-x4h3-pq75/GHSA-2563-x4h3-pq75.json b/advisories/unreviewed/2025/01/GHSA-2563-x4h3-pq75/GHSA-2563-x4h3-pq75.json
new file mode 100644
index 00000000000..d39916820a0
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-2563-x4h3-pq75/GHSA-2563-x4h3-pq75.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2563-x4h3-pq75",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22518"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22518"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/justified-image-gallery/vulnerability/wordpress-justified-image-gallery-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-25jp-mpcv-w3p8/GHSA-25jp-mpcv-w3p8.json b/advisories/unreviewed/2025/01/GHSA-25jp-mpcv-w3p8/GHSA-25jp-mpcv-w3p8.json
new file mode 100644
index 00000000000..379639376b1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-25jp-mpcv-w3p8/GHSA-25jp-mpcv-w3p8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-25jp-mpcv-w3p8",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22365"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 Alert Boxes allows Stored XSS.This issue affects EMC2 Alert Boxes: from n/a through 1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22365"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/emc2-alert-boxes/vulnerability/wordpress-emc2-alert-boxes-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-26rf-hqgr-2gm6/GHSA-26rf-hqgr-2gm6.json b/advisories/unreviewed/2025/01/GHSA-26rf-hqgr-2gm6/GHSA-26rf-hqgr-2gm6.json
new file mode 100644
index 00000000000..063653822c2
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-26rf-hqgr-2gm6/GHSA-26rf-hqgr-2gm6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-26rf-hqgr-2gm6",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22549"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pablo Cornehl WP Github allows Stored XSS.This issue affects WP Github: from n/a through 1.3.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22549"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-github/vulnerability/wordpress-wp-github-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json b/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json
new file mode 100644
index 00000000000..1c2667f14bb
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2776-h8x3-vrr7",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2025-0237"
+ ],
+ "details": "The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0237"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1915257"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-296q-vjcw-5f97/GHSA-296q-vjcw-5f97.json b/advisories/unreviewed/2025/01/GHSA-296q-vjcw-5f97/GHSA-296q-vjcw-5f97.json
new file mode 100644
index 00000000000..d8cb8d89af7
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-296q-vjcw-5f97/GHSA-296q-vjcw-5f97.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-296q-vjcw-5f97",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22519"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eDoc Intelligence LLC eDoc Easy Tables allows SQL Injection.This issue affects eDoc Easy Tables: from n/a through 1.29.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22519"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/edoc-easy-tables/vulnerability/wordpress-edoc-easy-tables-plugin-1-29-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2cjc-6xrh-7w5q/GHSA-2cjc-6xrh-7w5q.json b/advisories/unreviewed/2025/01/GHSA-2cjc-6xrh-7w5q/GHSA-2cjc-6xrh-7w5q.json
new file mode 100644
index 00000000000..c6637d855f7
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-2cjc-6xrh-7w5q/GHSA-2cjc-6xrh-7w5q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2cjc-6xrh-7w5q",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-56272"
+ ],
+ "details": "Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56272"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hide-category-by-user-role-for-woocommerce/vulnerability/wordpress-hide-category-by-user-role-for-woocommerce-plugin-2-1-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json b/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json
new file mode 100644
index 00000000000..42bce3b4c1c
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2g52-qw8q-wfr9",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0245"
+ ],
+ "details": "Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0245"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1895342"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2g9m-9qhc-m426/GHSA-2g9m-9qhc-m426.json b/advisories/unreviewed/2025/01/GHSA-2g9m-9qhc-m426/GHSA-2g9m-9qhc-m426.json
new file mode 100644
index 00000000000..9bcfd265007
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-2g9m-9qhc-m426/GHSA-2g9m-9qhc-m426.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2g9m-9qhc-m426",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-0301"
+ ],
+ "details": "A vulnerability, which was classified as problematic, has been found in code-projects Online Book Shop 1.0. Affected by this issue is some unknown functionality of the file /subcat.php. The manipulation of the argument catnm leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0301"
+ },
+ {
+ "type": "WEB",
+ "url": "https://code-projects.org"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/th4s1s/03262c6ce877137b61d745a2e4fe8a63"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290450"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290450"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.475287"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2j5j-53gg-96g7/GHSA-2j5j-53gg-96g7.json b/advisories/unreviewed/2025/01/GHSA-2j5j-53gg-96g7/GHSA-2j5j-53gg-96g7.json
new file mode 100644
index 00000000000..ec80765ccdb
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-2j5j-53gg-96g7/GHSA-2j5j-53gg-96g7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2j5j-53gg-96g7",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22592"
+ ],
+ "details": "Missing Authorization vulnerability in Lenderd 1003 Mortgage Application allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 1003 Mortgage Application: from n/a through 1.87.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22592"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/1003-mortgage-application/vulnerability/wordpress-1003-mortgage-application-plugin-1-87-broken-access-control-vulnerability-2?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json b/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json
index 93c7793925e..e7eb3d4206d 100644
--- a/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json
+++ b/advisories/unreviewed/2025/01/GHSA-2jv4-86qg-m23h/GHSA-2jv4-86qg-m23h.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jv4-86qg-m23h",
- "modified": "2025-01-07T06:32:16Z",
+ "modified": "2025-01-07T18:30:48Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-10102"
],
"details": "The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T06:15:13Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-2pj5-7838-wqrw/GHSA-2pj5-7838-wqrw.json b/advisories/unreviewed/2025/01/GHSA-2pj5-7838-wqrw/GHSA-2pj5-7838-wqrw.json
index 7d4f137d040..9268951cf29 100644
--- a/advisories/unreviewed/2025/01/GHSA-2pj5-7838-wqrw/GHSA-2pj5-7838-wqrw.json
+++ b/advisories/unreviewed/2025/01/GHSA-2pj5-7838-wqrw/GHSA-2pj5-7838-wqrw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2pj5-7838-wqrw",
- "modified": "2025-01-07T06:32:16Z",
+ "modified": "2025-01-07T18:30:49Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-11606"
],
"details": "The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T06:15:14Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-2wgj-4jrq-2g66/GHSA-2wgj-4jrq-2g66.json b/advisories/unreviewed/2025/01/GHSA-2wgj-4jrq-2g66/GHSA-2wgj-4jrq-2g66.json
index 49466cd378b..bb1ab85ac57 100644
--- a/advisories/unreviewed/2025/01/GHSA-2wgj-4jrq-2g66/GHSA-2wgj-4jrq-2g66.json
+++ b/advisories/unreviewed/2025/01/GHSA-2wgj-4jrq-2g66/GHSA-2wgj-4jrq-2g66.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wgj-4jrq-2g66",
- "modified": "2025-01-07T00:31:39Z",
+ "modified": "2025-01-07T18:30:48Z",
"published": "2025-01-07T00:31:39Z",
"aliases": [
"CVE-2024-48456"
],
"details": "An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the parameter password at the change admin password page at the router web interface.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T22:15:09Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-3573-fj59-f7gh/GHSA-3573-fj59-f7gh.json b/advisories/unreviewed/2025/01/GHSA-3573-fj59-f7gh/GHSA-3573-fj59-f7gh.json
new file mode 100644
index 00000000000..2320228c42d
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3573-fj59-f7gh/GHSA-3573-fj59-f7gh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3573-fj59-f7gh",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22334"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FilaThemes Education LMS allows Stored XSS.This issue affects Education LMS: from n/a through 0.0.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22334"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/theme/education-lms/vulnerability/wordpress-education-lms-theme-0-0-7-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json b/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json
new file mode 100644
index 00000000000..77e3ba0e396
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json
@@ -0,0 +1,34 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3695-47qv-rc3x",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-54007"
+ ],
+ "details": "Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54007"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04763en_us&docLocale=en_US"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json b/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json
new file mode 100644
index 00000000000..3a2a4dc4476
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-39fw-qmf8-vr6v",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-55555"
+ ],
+ "details": "Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client.php file can be accessed without authentication. The parameter {hash} is passed to the function decrypt that expects a Laravel ciphered value containing a serialized object. (Furthermore, Laravel contains several gadget chains usable to trigger remote command execution from arbitrary deserialization.) Therefore, an attacker in possession of the APP_KEY is able to fully control a string passed to an unserialize function.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55555"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/invoiceninja/invoiceninja/commit/d9302021472c3e7e23bac8c3d5fbec57a5f38f0c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.synacktiv.com/advisories/invoiceninja-unauthenticated-remote-command-execution-when-appkey-known"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-3ccf-rhcf-m4x2/GHSA-3ccf-rhcf-m4x2.json b/advisories/unreviewed/2025/01/GHSA-3ccf-rhcf-m4x2/GHSA-3ccf-rhcf-m4x2.json
new file mode 100644
index 00000000000..5568fa08e02
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3ccf-rhcf-m4x2/GHSA-3ccf-rhcf-m4x2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3ccf-rhcf-m4x2",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22581"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bytephp Arcade Ready allows Stored XSS.This issue affects Arcade Ready: from n/a through 1.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22581"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/arcadeready/vulnerability/wordpress-arcade-ready-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-3f85-g95j-3rp7/GHSA-3f85-g95j-3rp7.json b/advisories/unreviewed/2025/01/GHSA-3f85-g95j-3rp7/GHSA-3f85-g95j-3rp7.json
new file mode 100644
index 00000000000..38210bc3417
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3f85-g95j-3rp7/GHSA-3f85-g95j-3rp7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3f85-g95j-3rp7",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22547"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jay Krishnan G JK Html To Pdf allows Stored XSS.This issue affects JK Html To Pdf: from n/a through 1.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22547"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/jk-html-to-pdf/vulnerability/wordpress-jk-html-to-pdf-plugin-1-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json b/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json
new file mode 100644
index 00000000000..4009ffa6a71
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3g3j-w5cc-fqpr/GHSA-3g3j-w5cc-fqpr.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3g3j-w5cc-fqpr",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-0299"
+ ],
+ "details": "A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0299"
+ },
+ {
+ "type": "WEB",
+ "url": "https://code-projects.org"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/th4s1s/b30a06e83b98ddcbc69b9038c145d8cd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290448"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290448"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.475285"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json b/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json
new file mode 100644
index 00000000000..b18086ad832
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json
@@ -0,0 +1,34 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3wcp-pwj7-fwmf",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-54006"
+ ],
+ "details": "Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54006"
+ },
+ {
+ "type": "WEB",
+ "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04763en_us&docLocale=en_US"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-4233-qhc3-4437/GHSA-4233-qhc3-4437.json b/advisories/unreviewed/2025/01/GHSA-4233-qhc3-4437/GHSA-4233-qhc3-4437.json
new file mode 100644
index 00000000000..d140b9079da
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-4233-qhc3-4437/GHSA-4233-qhc3-4437.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4233-qhc3-4437",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22335"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Rajib Dewan Opencart Product in WP allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through 1.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22335"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/opencart-product-in-wp/vulnerability/wordpress-opencart-product-in-wp-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-47h7-p64f-fpwm/GHSA-47h7-p64f-fpwm.json b/advisories/unreviewed/2025/01/GHSA-47h7-p64f-fpwm/GHSA-47h7-p64f-fpwm.json
new file mode 100644
index 00000000000..299fbdae8a8
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-47h7-p64f-fpwm/GHSA-47h7-p64f-fpwm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-47h7-p64f-fpwm",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22578"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WP Cookie allows Stored XSS.This issue affects WP Cookie: from n/a through 1.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22578"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-cookie/vulnerability/wordpress-wp-cookie-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-4gf8-cwcf-3hph/GHSA-4gf8-cwcf-3hph.json b/advisories/unreviewed/2025/01/GHSA-4gf8-cwcf-3hph/GHSA-4gf8-cwcf-3hph.json
new file mode 100644
index 00000000000..9fd1051f8d5
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-4gf8-cwcf-3hph/GHSA-4gf8-cwcf-3hph.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4gf8-cwcf-3hph",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22574"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Motacek ICS Button allows Stored XSS.This issue affects ICS Button: from n/a through 0.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22574"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ics-button/vulnerability/wordpress-ics-button-plugin-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-4mrr-864p-5jxj/GHSA-4mrr-864p-5jxj.json b/advisories/unreviewed/2025/01/GHSA-4mrr-864p-5jxj/GHSA-4mrr-864p-5jxj.json
new file mode 100644
index 00000000000..6b9f1892d0e
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-4mrr-864p-5jxj/GHSA-4mrr-864p-5jxj.json
@@ -0,0 +1,57 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4mrr-864p-5jxj",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0297"
+ ],
+ "details": "A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0297"
+ },
+ {
+ "type": "WEB",
+ "url": "https://code-projects.org"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/th4s1s/782f2e19784f48bb80e4d658a49bd680"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290446"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290446"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.475138"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74",
+ "CWE-89"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-4mw2-5g8m-w232/GHSA-4mw2-5g8m-w232.json b/advisories/unreviewed/2025/01/GHSA-4mw2-5g8m-w232/GHSA-4mw2-5g8m-w232.json
new file mode 100644
index 00000000000..9236401b755
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-4mw2-5g8m-w232/GHSA-4mw2-5g8m-w232.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4mw2-5g8m-w232",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2021-20455"
+ ],
+ "details": "IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20455"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7179163"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-4p32-6gwg-j2q3/GHSA-4p32-6gwg-j2q3.json b/advisories/unreviewed/2025/01/GHSA-4p32-6gwg-j2q3/GHSA-4p32-6gwg-j2q3.json
new file mode 100644
index 00000000000..6b525f262b1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-4p32-6gwg-j2q3/GHSA-4p32-6gwg-j2q3.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4p32-6gwg-j2q3",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22552"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jason Keeley, Bryan Nielsen Affiliate Disclosure Statement allows Cross Site Request Forgery.This issue affects Affiliate Disclosure Statement: from n/a through 0.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22552"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/affiliate-disclosure-statement/vulnerability/wordpress-affiliate-disclosure-statement-plugin-0-3-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-53ff-6r7j-xcfm/GHSA-53ff-6r7j-xcfm.json b/advisories/unreviewed/2025/01/GHSA-53ff-6r7j-xcfm/GHSA-53ff-6r7j-xcfm.json
new file mode 100644
index 00000000000..bc7bff61b33
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-53ff-6r7j-xcfm/GHSA-53ff-6r7j-xcfm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-53ff-6r7j-xcfm",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22536"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hiren Patel WP Music Player allows SQL Injection.This issue affects WP Music Player: from n/a through 1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22536"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-music-player/vulnerability/wordpress-wp-music-player-plugin-1-3-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json b/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json
index 6547bdc1a69..55beeb77b3f 100644
--- a/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json
+++ b/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-79"
+ "CWE-79",
+ "CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-576p-hp46-4rxc/GHSA-576p-hp46-4rxc.json b/advisories/unreviewed/2025/01/GHSA-576p-hp46-4rxc/GHSA-576p-hp46-4rxc.json
new file mode 100644
index 00000000000..c6e7e570866
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-576p-hp46-4rxc/GHSA-576p-hp46-4rxc.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-576p-hp46-4rxc",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22548"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frank Koenen ldap_login_password_and_role_manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through 1.0.12.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22548"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ldap-login-password-and-role-manager/vulnerability/wordpress-ldap-login-password-and-role-manager-plugin-1-0-12-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json b/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json
new file mode 100644
index 00000000000..4dd97b479ee
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5grh-jq56-9254",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-55413"
+ ],
+ "details": "A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55413"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55413/CVE-2024-55413_snxppamd.sys_README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.sunix.com/tw"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-5px7-7rrc-gfm7/GHSA-5px7-7rrc-gfm7.json b/advisories/unreviewed/2025/01/GHSA-5px7-7rrc-gfm7/GHSA-5px7-7rrc-gfm7.json
new file mode 100644
index 00000000000..8919351b3ea
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-5px7-7rrc-gfm7/GHSA-5px7-7rrc-gfm7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5px7-7rrc-gfm7",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22563"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Faaiq Pretty Url allows Cross Site Request Forgery.This issue affects Pretty Url: from n/a through 1.5.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22563"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pretty-url/vulnerability/wordpress-pretty-urls-plugin-1-5-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-5wgg-4qx4-hmv8/GHSA-5wgg-4qx4-hmv8.json b/advisories/unreviewed/2025/01/GHSA-5wgg-4qx4-hmv8/GHSA-5wgg-4qx4-hmv8.json
new file mode 100644
index 00000000000..f1fb59ee79a
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-5wgg-4qx4-hmv8/GHSA-5wgg-4qx4-hmv8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5wgg-4qx4-hmv8",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22350"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: from n/a through 3.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22350"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/indeed-learning-pro/vulnerability/wordpress-indeed-ultimate-learning-pro-plugin-3-9-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json b/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json
new file mode 100644
index 00000000000..00543fc13b0
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json
@@ -0,0 +1,31 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5wmg-fqv9-w9qf",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2024-40748"
+ ],
+ "details": "Lack of output escaping in the id attribute of menu lists.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40748"
+ },
+ {
+ "type": "WEB",
+ "url": "https://developer.joomla.org/security-centre/955-20250102-core-xss-vector-in-the-id-attribute-of-menu-lists.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-5wx7-jr8m-c2f3/GHSA-5wx7-jr8m-c2f3.json b/advisories/unreviewed/2025/01/GHSA-5wx7-jr8m-c2f3/GHSA-5wx7-jr8m-c2f3.json
new file mode 100644
index 00000000000..1a5874a8024
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-5wx7-jr8m-c2f3/GHSA-5wx7-jr8m-c2f3.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5wx7-jr8m-c2f3",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22593"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Burria Laika Pedigree Tree allows Stored XSS.This issue affects Laika Pedigree Tree: from n/a through 1.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22593"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/laika-pedigree-tree/vulnerability/wordpress-laika-pedigree-tree-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-63vw-c7j3-fmf8/GHSA-63vw-c7j3-fmf8.json b/advisories/unreviewed/2025/01/GHSA-63vw-c7j3-fmf8/GHSA-63vw-c7j3-fmf8.json
new file mode 100644
index 00000000000..1ecde8ed09b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-63vw-c7j3-fmf8/GHSA-63vw-c7j3-fmf8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-63vw-c7j3-fmf8",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22529"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WORDPRESTEEM WE Blocks allows Stored XSS.This issue affects WE Blocks: from n/a through 1.3.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22529"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/we-blocks/vulnerability/wordpress-we-blocks-1-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-652f-cv9j-cgcg/GHSA-652f-cv9j-cgcg.json b/advisories/unreviewed/2025/01/GHSA-652f-cv9j-cgcg/GHSA-652f-cv9j-cgcg.json
new file mode 100644
index 00000000000..a969083954c
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-652f-cv9j-cgcg/GHSA-652f-cv9j-cgcg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-652f-cv9j-cgcg",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22515"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simon Chuang Show Google Analytics widget allows Stored XSS.This issue affects Show Google Analytics widget: from n/a through 1.5.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22515"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/show-google-analytics-widget/vulnerability/wordpress-show-google-analytics-widget-plugin-1-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json b/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json
new file mode 100644
index 00000000000..070c670bfd8
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-68r8-f4jc-vc2p",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0244"
+ ],
+ "details": "When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. \n*Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0244"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929584"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-695q-x62q-c8hg/GHSA-695q-x62q-c8hg.json b/advisories/unreviewed/2025/01/GHSA-695q-x62q-c8hg/GHSA-695q-x62q-c8hg.json
new file mode 100644
index 00000000000..133fa75e0ec
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-695q-x62q-c8hg/GHSA-695q-x62q-c8hg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-695q-x62q-c8hg",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22590"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Prayer Times Anywhere allows Stored XSS.This issue affects Prayer Times Anywhere: from n/a through 2.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22590"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/prayer-times-anywhere/vulnerability/wordpress-prayer-times-anywhere-plugin-2-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-6hqr-x7j2-4jmh/GHSA-6hqr-x7j2-4jmh.json b/advisories/unreviewed/2025/01/GHSA-6hqr-x7j2-4jmh/GHSA-6hqr-x7j2-4jmh.json
new file mode 100644
index 00000000000..96a596e6d67
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-6hqr-x7j2-4jmh/GHSA-6hqr-x7j2-4jmh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6hqr-x7j2-4jmh",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-28778"
+ ],
+ "details": "IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28778"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7179163"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-798"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-6p8q-94vc-wgp9/GHSA-6p8q-94vc-wgp9.json b/advisories/unreviewed/2025/01/GHSA-6p8q-94vc-wgp9/GHSA-6p8q-94vc-wgp9.json
index d6209a10cb8..79f3f672a75 100644
--- a/advisories/unreviewed/2025/01/GHSA-6p8q-94vc-wgp9/GHSA-6p8q-94vc-wgp9.json
+++ b/advisories/unreviewed/2025/01/GHSA-6p8q-94vc-wgp9/GHSA-6p8q-94vc-wgp9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p8q-94vc-wgp9",
- "modified": "2025-01-07T00:31:39Z",
+ "modified": "2025-01-07T18:30:48Z",
"published": "2025-01-07T00:31:39Z",
"aliases": [
"CVE-2021-27285"
],
"details": "An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-276"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T22:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json b/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json
new file mode 100644
index 00000000000..e8ac662983b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6prq-q63r-xqhp",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-55414"
+ ],
+ "details": "A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55414"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55414/CVE-2024-55414_SmSerl64.sys_README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://us.motorola.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-6vm3-2q2x-wf88/GHSA-6vm3-2q2x-wf88.json b/advisories/unreviewed/2025/01/GHSA-6vm3-2q2x-wf88/GHSA-6vm3-2q2x-wf88.json
new file mode 100644
index 00000000000..e4bf49b0609
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-6vm3-2q2x-wf88/GHSA-6vm3-2q2x-wf88.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6vm3-2q2x-wf88",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22294"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gravity Master Custom Field For WP Job Manager allows Reflected XSS.This issue affects Custom Field For WP Job Manager: from n/a through 1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22294"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/custom-field-for-wp-job-manager/vulnerability/wordpress-custom-field-for-wp-job-manager-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-6wwx-5hf8-j928/GHSA-6wwx-5hf8-j928.json b/advisories/unreviewed/2025/01/GHSA-6wwx-5hf8-j928/GHSA-6wwx-5hf8-j928.json
new file mode 100644
index 00000000000..5cb933be33e
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-6wwx-5hf8-j928/GHSA-6wwx-5hf8-j928.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6wwx-5hf8-j928",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22572"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brianmiyaji Legacy ePlayer allows Stored XSS.This issue affects Legacy ePlayer: from n/a through 0.9.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22572"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/sportspress-tv/vulnerability/wordpress-legacy-eplayer-plugin-0-9-9-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-72px-349m-cf9q/GHSA-72px-349m-cf9q.json b/advisories/unreviewed/2025/01/GHSA-72px-349m-cf9q/GHSA-72px-349m-cf9q.json
new file mode 100644
index 00000000000..ed0559c2258
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-72px-349m-cf9q/GHSA-72px-349m-cf9q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-72px-349m-cf9q",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22525"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bharatkambariya Donation Block For PayPal allows Stored XSS.This issue affects Donation Block For PayPal: from n/a through 2.2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22525"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/donations-block/vulnerability/wordpress-donation-block-for-paypal-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-7chg-phxp-f5fq/GHSA-7chg-phxp-f5fq.json b/advisories/unreviewed/2025/01/GHSA-7chg-phxp-f5fq/GHSA-7chg-phxp-f5fq.json
new file mode 100644
index 00000000000..9f805f566c2
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-7chg-phxp-f5fq/GHSA-7chg-phxp-f5fq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7chg-phxp-f5fq",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22550"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddFunc AddFunc Mobile Detect allows Stored XSS.This issue affects AddFunc Mobile Detect: from n/a through 3.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22550"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/addfunc-mobile-detect/vulnerability/wordpress-addfunc-mobile-detect-plugin-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-7hhv-g9g2-362f/GHSA-7hhv-g9g2-362f.json b/advisories/unreviewed/2025/01/GHSA-7hhv-g9g2-362f/GHSA-7hhv-g9g2-362f.json
new file mode 100644
index 00000000000..1dcead2493e
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-7hhv-g9g2-362f/GHSA-7hhv-g9g2-362f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7hhv-g9g2-362f",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22520"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through 1.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22520"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/tock-widget/vulnerability/wordpress-tock-widget-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json b/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json
index 0805ae51244..d5f3944941d 100644
--- a/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json
+++ b/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-7w5c-75w2-qh2f/GHSA-7w5c-75w2-qh2f.json b/advisories/unreviewed/2025/01/GHSA-7w5c-75w2-qh2f/GHSA-7w5c-75w2-qh2f.json
new file mode 100644
index 00000000000..ec97384631b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-7w5c-75w2-qh2f/GHSA-7w5c-75w2-qh2f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7w5c-75w2-qh2f",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22571"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Instabot Instabot allows Cross Site Request Forgery.This issue affects Instabot: from n/a through 1.10.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22571"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/instabot/vulnerability/wordpress-instabot-plugin-1-10-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json b/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json
new file mode 100644
index 00000000000..4da07f945b4
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7wr9-8g48-p7wg",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-46601"
+ ],
+ "details": "Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46601"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.elspec-ltd.com/support/security-advisories"
+ },
+ {
+ "type": "WEB",
+ "url": "http://elspec.com"
+ },
+ {
+ "type": "WEB",
+ "url": "http://g5.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:34Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-86xp-9w89-4h5q/GHSA-86xp-9w89-4h5q.json b/advisories/unreviewed/2025/01/GHSA-86xp-9w89-4h5q/GHSA-86xp-9w89-4h5q.json
new file mode 100644
index 00000000000..d069ec5c3c5
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-86xp-9w89-4h5q/GHSA-86xp-9w89-4h5q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-86xp-9w89-4h5q",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22585"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Ultimate Image Hover Effects allows DOM-Based XSS.This issue affects Ultimate Image Hover Effects: from n/a through 1.1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22585"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ultimate-image-hover-effects/vulnerability/wordpress-ultimate-image-hover-effects-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-8jw6-9g8m-4vc2/GHSA-8jw6-9g8m-4vc2.json b/advisories/unreviewed/2025/01/GHSA-8jw6-9g8m-4vc2/GHSA-8jw6-9g8m-4vc2.json
new file mode 100644
index 00000000000..e59df867bde
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8jw6-9g8m-4vc2/GHSA-8jw6-9g8m-4vc2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8jw6-9g8m-4vc2",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22546"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in One Plus Solution jQuery TwentyTwenty allows Stored XSS.This issue affects jQuery TwentyTwenty: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22546"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/js-twentytwenty/vulnerability/wordpress-jquery-twentytwenty-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json b/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json
index 6fec3f9a655..d7748ba64e2 100644
--- a/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json
+++ b/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q2f-m3g8-m8qm",
- "modified": "2025-01-06T21:30:51Z",
+ "modified": "2025-01-07T18:30:48Z",
"published": "2025-01-06T21:30:51Z",
"aliases": [
"CVE-2024-55407"
],
"details": "An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-1284"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T19:15:12Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json b/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json
new file mode 100644
index 00000000000..4f36f7992a1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8rg4-cvw3-v3c2",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-46242"
+ ],
+ "details": "An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as e-mail address during registration.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46242"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/salvatore-abello/4f01f3fa54672febc0a492a11a26592c"
+ },
+ {
+ "type": "WEB",
+ "url": "http://ctfd.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-8vff-w6j8-wg6c/GHSA-8vff-w6j8-wg6c.json b/advisories/unreviewed/2025/01/GHSA-8vff-w6j8-wg6c/GHSA-8vff-w6j8-wg6c.json
new file mode 100644
index 00000000000..13f03a594c2
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8vff-w6j8-wg6c/GHSA-8vff-w6j8-wg6c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8vff-w6j8-wg6c",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22555"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Noel Jarencio. Smoothness Slider Shortcode allows Cross Site Request Forgery.This issue affects Smoothness Slider Shortcode: from n/a through v1.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22555"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/smoothness-slider-shortcode/vulnerability/wordpress-smoothness-slider-shortcode-plugin-v1-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-8w32-3h9r-m2h5/GHSA-8w32-3h9r-m2h5.json b/advisories/unreviewed/2025/01/GHSA-8w32-3h9r-m2h5/GHSA-8w32-3h9r-m2h5.json
new file mode 100644
index 00000000000..37b97854a89
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8w32-3h9r-m2h5/GHSA-8w32-3h9r-m2h5.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8w32-3h9r-m2h5",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-53800"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through 4.15.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53800"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/rezgo/vulnerability/wordpress-rezgo-online-booking-plugin-4-15-local-file-inclusion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-829",
+ "CWE-98"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-8xgj-5pjf-7xmj/GHSA-8xgj-5pjf-7xmj.json b/advisories/unreviewed/2025/01/GHSA-8xgj-5pjf-7xmj/GHSA-8xgj-5pjf-7xmj.json
new file mode 100644
index 00000000000..431b6f1bf68
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8xgj-5pjf-7xmj/GHSA-8xgj-5pjf-7xmj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8xgj-5pjf-7xmj",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22363"
+ ],
+ "details": "Missing Authorization vulnerability in ORION Allada T-shirt Designer for Woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through 1.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22363"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/allada-tshirt-designer-for-woocommerce/vulnerability/wordpress-allada-t-shirt-designer-for-woocommerce-plugin-1-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json b/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json
new file mode 100644
index 00000000000..f345d5f12c1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-928f-3rxq-5jvp",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0243"
+ ],
+ "details": "Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0243"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1827142%2C1932783"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-92wx-ghpq-p2mr/GHSA-92wx-ghpq-p2mr.json b/advisories/unreviewed/2025/01/GHSA-92wx-ghpq-p2mr/GHSA-92wx-ghpq-p2mr.json
new file mode 100644
index 00000000000..2dfa1489e78
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-92wx-ghpq-p2mr/GHSA-92wx-ghpq-p2mr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-92wx-ghpq-p2mr",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22338"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lich_wang WP-tagMaker allows Reflected XSS.This issue affects WP-tagMaker: from n/a through 0.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22338"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/tagmaker/vulnerability/wordpress-wp-tagmaker-plugin-0-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json b/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json
new file mode 100644
index 00000000000..2aba6523fd5
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-948c-8jvf-p44x",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-55411"
+ ],
+ "details": "An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55411"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55411/CVE-2024-55411_snxpcamd.sys_README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.sunix.com/tw"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-97m6-7wj3-g2cm/GHSA-97m6-7wj3-g2cm.json b/advisories/unreviewed/2025/01/GHSA-97m6-7wj3-g2cm/GHSA-97m6-7wj3-g2cm.json
new file mode 100644
index 00000000000..14e1d8cb9ba
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-97m6-7wj3-g2cm/GHSA-97m6-7wj3-g2cm.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-97m6-7wj3-g2cm",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-12430"
+ ],
+ "details": "An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject arbitrary commands into a specifically crafted file, which then will be executed by root user.\nAll AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12430"
+ },
+ {
+ "type": "WEB",
+ "url": "https://search.abb.com/library/Download.aspx?DocumentID=3ADR011377&LanguageCode=en&DocumentPartId=&Action=Launch"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-280"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-97v9-h65g-h2pr/GHSA-97v9-h65g-h2pr.json b/advisories/unreviewed/2025/01/GHSA-97v9-h65g-h2pr/GHSA-97v9-h65g-h2pr.json
new file mode 100644
index 00000000000..995337f9f5c
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-97v9-h65g-h2pr/GHSA-97v9-h65g-h2pr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-97v9-h65g-h2pr",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22530"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SIOT 아임포트 결제버튼 생성 플러그인 allows Stored XSS.This issue affects 아임포트 결제버튼 생성 플러그인: from n/a through 1.1.19.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22530"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/iamport-payment/vulnerability/wordpress-plugin-1-1-19-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-97vc-c8gj-7xp7/GHSA-97vc-c8gj-7xp7.json b/advisories/unreviewed/2025/01/GHSA-97vc-c8gj-7xp7/GHSA-97vc-c8gj-7xp7.json
new file mode 100644
index 00000000000..be5b6fde95e
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-97vc-c8gj-7xp7/GHSA-97vc-c8gj-7xp7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-97vc-c8gj-7xp7",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22557"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPMagic News Publisher Autopilot allows Cross Site Request Forgery.This issue affects News Publisher Autopilot: from n/a through 2.1.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22557"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wpm-news-api/vulnerability/wordpress-news-publisher-autopilot-plugin-2-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-9q87-5v6f-82ph/GHSA-9q87-5v6f-82ph.json b/advisories/unreviewed/2025/01/GHSA-9q87-5v6f-82ph/GHSA-9q87-5v6f-82ph.json
new file mode 100644
index 00000000000..767eda78d60
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-9q87-5v6f-82ph/GHSA-9q87-5v6f-82ph.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9q87-5v6f-82ph",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-25037"
+ ],
+ "details": "IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25037"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7179163"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-9vpv-6r96-4p4x/GHSA-9vpv-6r96-4p4x.json b/advisories/unreviewed/2025/01/GHSA-9vpv-6r96-4p4x/GHSA-9vpv-6r96-4p4x.json
new file mode 100644
index 00000000000..8d4514d04af
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-9vpv-6r96-4p4x/GHSA-9vpv-6r96-4p4x.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9vpv-6r96-4p4x",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22591"
+ ],
+ "details": "Missing Authorization vulnerability in Lenderd 1003 Mortgage Application allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1003 Mortgage Application: from n/a through 1.87.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22591"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/1003-mortgage-application/vulnerability/wordpress-1003-mortgage-application-plugin-1-87-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json b/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json
new file mode 100644
index 00000000000..8ecc0b1bef7
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c2qq-pcr6-27vg",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-55410"
+ ],
+ "details": "An issue in the 690b33e1-0462-4e84-9bea-c7552b45432a.sys component of Asus GPU Tweak II Program Driver v1.0.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55410"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55410/CVE-2024-55410_690b33e1-0462-4e84-9bea-c7552b45432a.sys_README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "http://asus.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-c3p9-p32w-9r8m/GHSA-c3p9-p32w-9r8m.json b/advisories/unreviewed/2025/01/GHSA-c3p9-p32w-9r8m/GHSA-c3p9-p32w-9r8m.json
new file mode 100644
index 00000000000..4d1b480eb30
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-c3p9-p32w-9r8m/GHSA-c3p9-p32w-9r8m.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c3p9-p32w-9r8m",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2024-40747"
+ ],
+ "details": "Various module chromes didn't properly process inputs, leading to XSS vectors.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40747"
+ },
+ {
+ "type": "WEB",
+ "url": "https://developer.joomla.org/security-centre/954-20250101-core-xss-vectors-in-module-chromes.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-c48r-59xp-mrh4/GHSA-c48r-59xp-mrh4.json b/advisories/unreviewed/2025/01/GHSA-c48r-59xp-mrh4/GHSA-c48r-59xp-mrh4.json
new file mode 100644
index 00000000000..48d92e431af
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-c48r-59xp-mrh4/GHSA-c48r-59xp-mrh4.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c48r-59xp-mrh4",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22516"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Patel Metadata SEO allows Stored XSS.This issue affects Metadata SEO: from n/a through 2.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22516"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/metadata-seo/vulnerability/wordpress-metadata-seo-plugin-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-c6v7-j86r-5whm/GHSA-c6v7-j86r-5whm.json b/advisories/unreviewed/2025/01/GHSA-c6v7-j86r-5whm/GHSA-c6v7-j86r-5whm.json
new file mode 100644
index 00000000000..6aaec726775
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-c6v7-j86r-5whm/GHSA-c6v7-j86r-5whm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c6v7-j86r-5whm",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22500"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Ali Alpha Price Table For Elementor allows DOM-Based XSS.This issue affects Alpha Price Table For Elementor: from n/a through 1.0.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22500"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/alpha-price-table-for-elementor/vulnerability/wordpress-alpha-price-table-for-elementor-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-cch6-wcwh-5wcc/GHSA-cch6-wcwh-5wcc.json b/advisories/unreviewed/2025/01/GHSA-cch6-wcwh-5wcc/GHSA-cch6-wcwh-5wcc.json
new file mode 100644
index 00000000000..4a02bc88cc5
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-cch6-wcwh-5wcc/GHSA-cch6-wcwh-5wcc.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cch6-wcwh-5wcc",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22502"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mindvalley MindValley Super PageMash allows SQL Injection.This issue affects MindValley Super PageMash: from n/a through 1.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22502"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/mindvalley-pagemash/vulnerability/wordpress-mindvalley-super-pagemash-plugin-1-1-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-cgcq-25xm-c9xc/GHSA-cgcq-25xm-c9xc.json b/advisories/unreviewed/2025/01/GHSA-cgcq-25xm-c9xc/GHSA-cgcq-25xm-c9xc.json
new file mode 100644
index 00000000000..98871b0e5ad
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-cgcq-25xm-c9xc/GHSA-cgcq-25xm-c9xc.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cgcq-25xm-c9xc",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22584"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pluginspoint Timeline Pro allows DOM-Based XSS.This issue affects Timeline Pro: from n/a through 1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22584"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/timeline-pro/vulnerability/wordpress-timeline-pro-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-cjvm-fcvg-8qgq/GHSA-cjvm-fcvg-8qgq.json b/advisories/unreviewed/2025/01/GHSA-cjvm-fcvg-8qgq/GHSA-cjvm-fcvg-8qgq.json
new file mode 100644
index 00000000000..aedb101b02f
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-cjvm-fcvg-8qgq/GHSA-cjvm-fcvg-8qgq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cjvm-fcvg-8qgq",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22556"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Greg Whitehead Norse Rune Oracle Plugin allows Cross Site Request Forgery.This issue affects Norse Rune Oracle Plugin: from n/a through 1.4.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22556"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/norse-runes-oracle/vulnerability/wordpress-norse-rune-oracle-plugin-1-4-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-cvfv-3wpx-3qqf/GHSA-cvfv-3wpx-3qqf.json b/advisories/unreviewed/2025/01/GHSA-cvfv-3wpx-3qqf/GHSA-cvfv-3wpx-3qqf.json
new file mode 100644
index 00000000000..e5c4c8b3386
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-cvfv-3wpx-3qqf/GHSA-cvfv-3wpx-3qqf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cvfv-3wpx-3qqf",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22551"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Julien Crego Boot-Modal allows Stored XSS.This issue affects Boot-Modal: from n/a through 1.9.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22551"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/boot-modal/vulnerability/wordpress-boot-modal-plugin-1-9-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json b/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json
new file mode 100644
index 00000000000..d1dbba26e37
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-f2hp-vf26-j2rg/GHSA-f2hp-vf26-j2rg.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f2hp-vf26-j2rg",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0298"
+ ],
+ "details": "A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the file /process_login.php. The manipulation of the argument usernm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0298"
+ },
+ {
+ "type": "WEB",
+ "url": "https://code-projects.org"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/th4s1s/5435e605e6e9f14a5b76c313483eb58a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290447"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290447"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.475159"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json b/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json
new file mode 100644
index 00000000000..77d39af87cd
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f3xq-g93v-w8cv",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2025-0240"
+ ],
+ "details": "Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0240"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929623"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-f6h9-w2m8-48cp/GHSA-f6h9-w2m8-48cp.json b/advisories/unreviewed/2025/01/GHSA-f6h9-w2m8-48cp/GHSA-f6h9-w2m8-48cp.json
new file mode 100644
index 00000000000..1edadcbeff3
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-f6h9-w2m8-48cp/GHSA-f6h9-w2m8-48cp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f6h9-w2m8-48cp",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22354"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Themes Digi Store allows DOM-Based XSS.This issue affects Digi Store: from n/a through 1.1.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22354"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/theme/digi-store/vulnerability/wordpress-digi-store-theme-1-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json b/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json
new file mode 100644
index 00000000000..6cafbc0f027
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-f74m-5p64-49qj/GHSA-f74m-5p64-49qj.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f74m-5p64-49qj",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-0300"
+ ],
+ "details": "A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /subcat.php. The manipulation of the argument cat leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0300"
+ },
+ {
+ "type": "WEB",
+ "url": "https://code-projects.org"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/th4s1s/21abb650b4b70fe8392d8449445703f7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290449"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290449"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.475286"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-f8c3-q6gm-6v3x/GHSA-f8c3-q6gm-6v3x.json b/advisories/unreviewed/2025/01/GHSA-f8c3-q6gm-6v3x/GHSA-f8c3-q6gm-6v3x.json
index 6f720db913f..4c722f5c371 100644
--- a/advisories/unreviewed/2025/01/GHSA-f8c3-q6gm-6v3x/GHSA-f8c3-q6gm-6v3x.json
+++ b/advisories/unreviewed/2025/01/GHSA-f8c3-q6gm-6v3x/GHSA-f8c3-q6gm-6v3x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f8c3-q6gm-6v3x",
- "modified": "2025-01-07T06:32:16Z",
+ "modified": "2025-01-07T18:30:49Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-8857"
],
"details": "The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T06:15:18Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-fcrw-wj57-c335/GHSA-fcrw-wj57-c335.json b/advisories/unreviewed/2025/01/GHSA-fcrw-wj57-c335/GHSA-fcrw-wj57-c335.json
new file mode 100644
index 00000000000..509e97ab613
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-fcrw-wj57-c335/GHSA-fcrw-wj57-c335.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fcrw-wj57-c335",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22507"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Benjamin Santalucia (ben@woow-fr.com) WPMU Prefill Post allows SQL Injection.This issue affects WPMU Prefill Post: from n/a through 1.02.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22507"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wpmu-prefill-post/vulnerability/wordpress-wpmu-prefill-post-plugin-1-02-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-fmmw-r3g8-j32w/GHSA-fmmw-r3g8-j32w.json b/advisories/unreviewed/2025/01/GHSA-fmmw-r3g8-j32w/GHSA-fmmw-r3g8-j32w.json
index a1b9411baa8..a03170affe2 100644
--- a/advisories/unreviewed/2025/01/GHSA-fmmw-r3g8-j32w/GHSA-fmmw-r3g8-j32w.json
+++ b/advisories/unreviewed/2025/01/GHSA-fmmw-r3g8-j32w/GHSA-fmmw-r3g8-j32w.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmmw-r3g8-j32w",
- "modified": "2025-01-07T00:31:40Z",
+ "modified": "2025-01-07T18:30:49Z",
"published": "2025-01-07T00:31:40Z",
"aliases": [
"CVE-2024-54767"
],
"details": "An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-203"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T23:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-fp8p-7vgr-3gx5/GHSA-fp8p-7vgr-3gx5.json b/advisories/unreviewed/2025/01/GHSA-fp8p-7vgr-3gx5/GHSA-fp8p-7vgr-3gx5.json
new file mode 100644
index 00000000000..9af428feb80
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-fp8p-7vgr-3gx5/GHSA-fp8p-7vgr-3gx5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fp8p-7vgr-3gx5",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22577"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damion Armentrout Able Player allows DOM-Based XSS.This issue affects Able Player: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22577"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-able-player/vulnerability/wordpress-able-player-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json b/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json
new file mode 100644
index 00000000000..39a98226f4b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-frx6-qwhw-g358",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-46602"
+ ],
+ "details": "An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46602"
+ },
+ {
+ "type": "WEB",
+ "url": "http://elspec.com"
+ },
+ {
+ "type": "WEB",
+ "url": "http://g5.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:34Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-g3qr-v2p6-vv6r/GHSA-g3qr-v2p6-vv6r.json b/advisories/unreviewed/2025/01/GHSA-g3qr-v2p6-vv6r/GHSA-g3qr-v2p6-vv6r.json
index 0fa5d5543c4..ab63a0a9be0 100644
--- a/advisories/unreviewed/2025/01/GHSA-g3qr-v2p6-vv6r/GHSA-g3qr-v2p6-vv6r.json
+++ b/advisories/unreviewed/2025/01/GHSA-g3qr-v2p6-vv6r/GHSA-g3qr-v2p6-vv6r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3qr-v2p6-vv6r",
- "modified": "2025-01-07T00:31:39Z",
+ "modified": "2025-01-07T18:30:48Z",
"published": "2025-01-07T00:31:39Z",
"aliases": [
"CVE-2024-48457"
],
"details": "An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the endpoint /cgi-bin/skk_set.cgi and binary /bin/scripts/start_wifi.sh",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T22:15:09Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json b/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json
new file mode 100644
index 00000000000..e8fbfcf2cbc
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g968-64xh-hq2x",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-44450"
+ ],
+ "details": "Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44450"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/BottleOfScotch/85e4c6e1d90060ddebd80b8384d59346"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-ggcc-c643-mc63/GHSA-ggcc-c643-mc63.json b/advisories/unreviewed/2025/01/GHSA-ggcc-c643-mc63/GHSA-ggcc-c643-mc63.json
new file mode 100644
index 00000000000..c54b30ae8c1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-ggcc-c643-mc63/GHSA-ggcc-c643-mc63.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ggcc-c643-mc63",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22573"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in copist Icons Enricher allows Stored XSS.This issue affects Icons Enricher: from n/a through 1.0.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22573"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/icons-enricher/vulnerability/wordpress-icons-enricher-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-gp6v-qqpw-37gp/GHSA-gp6v-qqpw-37gp.json b/advisories/unreviewed/2025/01/GHSA-gp6v-qqpw-37gp/GHSA-gp6v-qqpw-37gp.json
new file mode 100644
index 00000000000..f762c1c1ba0
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-gp6v-qqpw-37gp/GHSA-gp6v-qqpw-37gp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gp6v-qqpw-37gp",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22517"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson List Pages at Depth allows Stored XSS.This issue affects List Pages at Depth: from n/a through 1.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22517"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/list-pages-at-depth/vulnerability/wordpress-list-pages-at-depth-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json b/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json
new file mode 100644
index 00000000000..34391e502c1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gxfw-pm97-x2qf",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-55556"
+ ],
+ "details": "A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies on an attacker obtaining Laravel's secret APP_KEY, which would allow them to decrypt and manipulate session cookies (laravel_session) containing serialized data. By altering this data and re-encrypting it with the APP_KEY, the attacker could trigger arbitrary deserialization on the server, potentially leading to remote command execution (RCE). The vulnerability is primarily exploited by accessing an exposed cookie and manipulating it using the secret key to gain malicious access to the server.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55556"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/crater-invoice/crater"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.synacktiv.com"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.synacktiv.com/advisories/crater-invoice-unauthenticated-remote-command-execution-when-appkey-known"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-h2jj-x3fh-mjf6/GHSA-h2jj-x3fh-mjf6.json b/advisories/unreviewed/2025/01/GHSA-h2jj-x3fh-mjf6/GHSA-h2jj-x3fh-mjf6.json
new file mode 100644
index 00000000000..531d313e599
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-h2jj-x3fh-mjf6/GHSA-h2jj-x3fh-mjf6.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h2jj-x3fh-mjf6",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2024-12429"
+ ],
+ "details": "An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 version mentioned. A successfully \nauthenticated attacker can use this vulnerability to read system wide files and configuration\n\n\nAll AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12429"
+ },
+ {
+ "type": "WEB",
+ "url": "https://search.abb.com/library/Download.aspx?DocumentID=3ADR011377&LanguageCode=en&DocumentPartId=&Action=Launch"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json b/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json
new file mode 100644
index 00000000000..78957f4eff9
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json
@@ -0,0 +1,31 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h6vm-3gjm-rw54",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-40749"
+ ],
+ "details": "Improper Access Controls allows access to protected views.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40749"
+ },
+ {
+ "type": "WEB",
+ "url": "https://developer.joomla.org/security-centre/956-20250103-core-read-acl-violation-in-multiple-core-views.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hcqc-cxvc-78q8/GHSA-hcqc-cxvc-78q8.json b/advisories/unreviewed/2025/01/GHSA-hcqc-cxvc-78q8/GHSA-hcqc-cxvc-78q8.json
new file mode 100644
index 00000000000..b6d919e8587
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hcqc-cxvc-78q8/GHSA-hcqc-cxvc-78q8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hcqc-cxvc-78q8",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22559"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mario Mansour and Geoff Peters TubePress.NET allows Cross Site Request Forgery.This issue affects TubePress.NET: from n/a through 4.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22559"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/tubepressnet/vulnerability/wordpress-tubepress-net-plugin-4-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json b/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json
new file mode 100644
index 00000000000..ebc859c0181
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hg4v-r4m7-xj5j",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-46603"
+ ],
+ "details": "An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46603"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.elspec-ltd.com/support/security-advisories"
+ },
+ {
+ "type": "WEB",
+ "url": "http://elspec.com"
+ },
+ {
+ "type": "WEB",
+ "url": "http://g5.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:34Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hg8c-64w7-cgq2/GHSA-hg8c-64w7-cgq2.json b/advisories/unreviewed/2025/01/GHSA-hg8c-64w7-cgq2/GHSA-hg8c-64w7-cgq2.json
new file mode 100644
index 00000000000..9f0a76a0427
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hg8c-64w7-cgq2/GHSA-hg8c-64w7-cgq2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hg8c-64w7-cgq2",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22533"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WOOEXIM.COM WOOEXIM allows SQL Injection.This issue affects WOOEXIM: from n/a through 5.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22533"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wooexim/vulnerability/wordpress-wooexim-plugin-5-0-0-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hh4j-jwjv-8726/GHSA-hh4j-jwjv-8726.json b/advisories/unreviewed/2025/01/GHSA-hh4j-jwjv-8726/GHSA-hh4j-jwjv-8726.json
new file mode 100644
index 00000000000..0999b672f37
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hh4j-jwjv-8726/GHSA-hh4j-jwjv-8726.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hh4j-jwjv-8726",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0241"
+ ],
+ "details": "When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0241"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1933023"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hwv8-cg7p-hpfc/GHSA-hwv8-cg7p-hpfc.json b/advisories/unreviewed/2025/01/GHSA-hwv8-cg7p-hpfc/GHSA-hwv8-cg7p-hpfc.json
new file mode 100644
index 00000000000..6a74d493862
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hwv8-cg7p-hpfc/GHSA-hwv8-cg7p-hpfc.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hwv8-cg7p-hpfc",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22560"
+ ],
+ "details": "Missing Authorization vulnerability in Saoshyant.1994 Saoshyant Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Saoshyant Page Builder: from n/a through 3.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22560"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/saoshyant-page-builder/vulnerability/wordpress-saoshyant-page-builder-plugin-3-8-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-j2c7-hmc5-6hrq/GHSA-j2c7-hmc5-6hrq.json b/advisories/unreviewed/2025/01/GHSA-j2c7-hmc5-6hrq/GHSA-j2c7-hmc5-6hrq.json
new file mode 100644
index 00000000000..8a4f5e0fe4e
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-j2c7-hmc5-6hrq/GHSA-j2c7-hmc5-6hrq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j2c7-hmc5-6hrq",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-56270"
+ ],
+ "details": "Missing Authorization vulnerability in SecureSubmit WP SecureSubmit.This issue affects WP SecureSubmit: from n/a through 1.5.16.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56270"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/securesubmit/vulnerability/wordpress-wp-securesubmit-plugin-1-5-16-sensitive-data-exposure-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json b/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json
new file mode 100644
index 00000000000..4605e2455b4
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jcv7-vfq5-hj4c",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-50659"
+ ],
+ "details": "Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50659"
+ },
+ {
+ "type": "WEB",
+ "url": "https://petercipolone.info/wp-content/uploads/2025/01/iPublishMedia_AdPortal3.0.39_CVEs.pdf"
+ },
+ {
+ "type": "WEB",
+ "url": "http://adportal.com"
+ },
+ {
+ "type": "WEB",
+ "url": "http://ipublish.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-jv4g-4fp2-cgjp/GHSA-jv4g-4fp2-cgjp.json b/advisories/unreviewed/2025/01/GHSA-jv4g-4fp2-cgjp/GHSA-jv4g-4fp2-cgjp.json
new file mode 100644
index 00000000000..dce1822c6ae
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-jv4g-4fp2-cgjp/GHSA-jv4g-4fp2-cgjp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jv4g-4fp2-cgjp",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22554"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Franklin Video Embed Optimizer allows Stored XSS.This issue affects Video Embed Optimizer: from n/a through 1.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22554"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/video-embed-optimizer/vulnerability/wordpress-video-embed-optimizer-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-jvxr-2wvm-8254/GHSA-jvxr-2wvm-8254.json b/advisories/unreviewed/2025/01/GHSA-jvxr-2wvm-8254/GHSA-jvxr-2wvm-8254.json
new file mode 100644
index 00000000000..7c008a0a17f
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-jvxr-2wvm-8254/GHSA-jvxr-2wvm-8254.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jvxr-2wvm-8254",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22545"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sw-galati.ro iframe to embed allows Stored XSS.This issue affects iframe to embed: from n/a through 1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22545"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/iframe-to-embed/vulnerability/wordpress-iframe-to-embed-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json b/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json
new file mode 100644
index 00000000000..0f2cde153c9
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jxq8-vf97-xqr3",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-55008"
+ ],
+ "details": "JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the attacker can trigger the account lockout mechanism on the account level, effectively locking the user out indefinitely. Since the lockout is applied to the user account and not based on the IP address, any attacker can trigger the lockout on any user account, regardless of their privileges.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55008"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hacking-notes.medium.com/cve-2024-51379-jatos-v3-9-4-account-lockout-denial-of-service-cc970f4ca58f"
+ },
+ {
+ "type": "WEB",
+ "url": "http://jatos.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-m2f9-c937-mc57/GHSA-m2f9-c937-mc57.json b/advisories/unreviewed/2025/01/GHSA-m2f9-c937-mc57/GHSA-m2f9-c937-mc57.json
new file mode 100644
index 00000000000..2d95bc22710
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-m2f9-c937-mc57/GHSA-m2f9-c937-mc57.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m2f9-c937-mc57",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22524"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in instaform.ir فرم ساز فرم افزار allows Stored XSS.This issue affects فرم ساز فرم افزار: from n/a through 2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22524"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/formafzar/vulnerability/wordpress-frm-s-z-frm-fz-r-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-m5j5-r43x-p3hr/GHSA-m5j5-r43x-p3hr.json b/advisories/unreviewed/2025/01/GHSA-m5j5-r43x-p3hr/GHSA-m5j5-r43x-p3hr.json
new file mode 100644
index 00000000000..262bbbd37f6
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-m5j5-r43x-p3hr/GHSA-m5j5-r43x-p3hr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m5j5-r43x-p3hr",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22528"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Huurkalender Huurkalender WP allows Stored XSS.This issue affects Huurkalender WP: from n/a through 1.5.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22528"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/huurkalender-wp/vulnerability/wordpress-huurkalender-wp-plugin-1-5-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-m639-x5gx-wfmv/GHSA-m639-x5gx-wfmv.json b/advisories/unreviewed/2025/01/GHSA-m639-x5gx-wfmv/GHSA-m639-x5gx-wfmv.json
new file mode 100644
index 00000000000..608453b265c
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-m639-x5gx-wfmv/GHSA-m639-x5gx-wfmv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m639-x5gx-wfmv",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22503"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Digital Zoom Studio Admin debug wordpress – enable debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through 1.0.13.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22503"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/dzs-enable-debug/vulnerability/wordpress-admin-debug-wordpress-enable-debug-plugin-1-0-13-cross-site-request-forgery-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-mf5x-3qw7-x5m8/GHSA-mf5x-3qw7-x5m8.json b/advisories/unreviewed/2025/01/GHSA-mf5x-3qw7-x5m8/GHSA-mf5x-3qw7-x5m8.json
new file mode 100644
index 00000000000..fabfb5c6542
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-mf5x-3qw7-x5m8/GHSA-mf5x-3qw7-x5m8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mf5x-3qw7-x5m8",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22296"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements.This issue affects Hash Elements: from n/a through 1.4.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22296"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hash-elements/vulnerability/wordpress-hash-elements-plugin-1-4-9-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-mhp7-xr6g-mvhv/GHSA-mhp7-xr6g-mvhv.json b/advisories/unreviewed/2025/01/GHSA-mhp7-xr6g-mvhv/GHSA-mhp7-xr6g-mvhv.json
new file mode 100644
index 00000000000..420f41b5dc0
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-mhp7-xr6g-mvhv/GHSA-mhp7-xr6g-mvhv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mhp7-xr6g-mvhv",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22589"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in bozdoz Quote Tweet allows Stored XSS.This issue affects Quote Tweet: from n/a through 0.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22589"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/quote-tweet/vulnerability/wordpress-quote-tweet-plugin-0-7-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-mm8p-h8qc-2w5r/GHSA-mm8p-h8qc-2w5r.json b/advisories/unreviewed/2025/01/GHSA-mm8p-h8qc-2w5r/GHSA-mm8p-h8qc-2w5r.json
new file mode 100644
index 00000000000..d5b6a9a4b54
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-mm8p-h8qc-2w5r/GHSA-mm8p-h8qc-2w5r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mm8p-h8qc-2w5r",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22512"
+ ],
+ "details": "Missing Authorization vulnerability in Sprout Apps Help Scout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Help Scout: from n/a through 6.5.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22512"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/help-scout/vulnerability/wordpress-help-scout-plugin-6-5-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-p3r2-35xm-8q7v/GHSA-p3r2-35xm-8q7v.json b/advisories/unreviewed/2025/01/GHSA-p3r2-35xm-8q7v/GHSA-p3r2-35xm-8q7v.json
new file mode 100644
index 00000000000..3e171e565b5
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-p3r2-35xm-8q7v/GHSA-p3r2-35xm-8q7v.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p3r2-35xm-8q7v",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-8361"
+ ],
+ "details": "In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS).\nIf a watchdog is implemented, device will restart after watch dog expires. If watchdog is not implemented, device can be recovered only after a hard reset",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8361"
+ },
+ {
+ "type": "WEB",
+ "url": "https://community.silabs.com/068Vm00000I7zqo"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-131"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json b/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json
new file mode 100644
index 00000000000..dbf08f45948
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p4q7-g7ff-823j",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2025-0239"
+ ],
+ "details": "When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0239"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1929156"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json b/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json
new file mode 100644
index 00000000000..f2afc72f1cb
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-phcc-6pmp-qw9v",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2025-0238"
+ ],
+ "details": "Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0238"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1915535"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-03"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json b/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json
new file mode 100644
index 00000000000..37461c40b93
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pj5p-wjjg-q3w5",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-50658"
+ ],
+ "details": "Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50658"
+ },
+ {
+ "type": "WEB",
+ "url": "https://petercipolone.info/wp-content/uploads/2025/01/iPublishMedia_AdPortal3.0.39_CVEs.pdf"
+ },
+ {
+ "type": "WEB",
+ "url": "http://adportal.com"
+ },
+ {
+ "type": "WEB",
+ "url": "http://ipublish.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-pmhj-4ch6-436j/GHSA-pmhj-4ch6-436j.json b/advisories/unreviewed/2025/01/GHSA-pmhj-4ch6-436j/GHSA-pmhj-4ch6-436j.json
new file mode 100644
index 00000000000..d3dacc42be4
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-pmhj-4ch6-436j/GHSA-pmhj-4ch6-436j.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pmhj-4ch6-436j",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22582"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Nellé Uptime Robot allows Stored XSS.This issue affects Uptime Robot: from n/a through 0.1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22582"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/uptime-robot/vulnerability/wordpress-uptime-robot-plugin-0-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json b/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json
index 8199b8f347d..f1c87ada4a0 100644
--- a/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json
+++ b/advisories/unreviewed/2025/01/GHSA-pwfr-93g9-4wj6/GHSA-pwfr-93g9-4wj6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pwfr-93g9-4wj6",
- "modified": "2025-01-07T06:32:16Z",
+ "modified": "2025-01-07T18:30:49Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-10562"
],
"details": "The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T06:15:14Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-q5mw-9gpp-3qc2/GHSA-q5mw-9gpp-3qc2.json b/advisories/unreviewed/2025/01/GHSA-q5mw-9gpp-3qc2/GHSA-q5mw-9gpp-3qc2.json
new file mode 100644
index 00000000000..4be8bf6b5b5
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-q5mw-9gpp-3qc2/GHSA-q5mw-9gpp-3qc2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q5mw-9gpp-3qc2",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2022-22363"
+ ],
+ "details": "IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22363"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7179163"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-qrfp-c3c5-pw2c/GHSA-qrfp-c3c5-pw2c.json b/advisories/unreviewed/2025/01/GHSA-qrfp-c3c5-pw2c/GHSA-qrfp-c3c5-pw2c.json
index d241d415165..7349a7a4ee3 100644
--- a/advisories/unreviewed/2025/01/GHSA-qrfp-c3c5-pw2c/GHSA-qrfp-c3c5-pw2c.json
+++ b/advisories/unreviewed/2025/01/GHSA-qrfp-c3c5-pw2c/GHSA-qrfp-c3c5-pw2c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qrfp-c3c5-pw2c",
- "modified": "2025-01-07T06:32:16Z",
+ "modified": "2025-01-07T18:30:49Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-8855"
],
"details": "The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T06:15:17Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json b/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json
new file mode 100644
index 00000000000..a72c02ce0de
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qw28-p6qx-vj78",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0242"
+ ],
+ "details": "Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0242"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1874523%2C1926454%2C1931873%2C1932169"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-02"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-03"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json b/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json
new file mode 100644
index 00000000000..3e68dc1f131
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r253-3wvv-8j5p",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-48245"
+ ],
+ "details": "Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include \"Booking ID\", \"Action Name\", and \"Payment Confirmation ID\", which are present in /newvehicle.php and /newdriver.php.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48245"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ShadowByte1/CVE-2024-48245"
+ },
+ {
+ "type": "WEB",
+ "url": "http://vehicle.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:34Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json b/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json
new file mode 100644
index 00000000000..bc24fa5c8cd
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r7gg-4xq2-48h9",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-55412"
+ ],
+ "details": "A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55412"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55412/CVE-2024-55412_snxpsamd.sys_README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.sunix.com/tw"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json b/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json
new file mode 100644
index 00000000000..8f67936a1c8
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-rg8w-4hqw-2p27/GHSA-rg8w-4hqw-2p27.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rg8w-4hqw-2p27",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22621"
+ ],
+ "details": "In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the “admin“ Splunk roles.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22621"
+ },
+ {
+ "type": "WEB",
+ "url": "https://advisory.splunk.com/advisories/SVD-2025-0101"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-269"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-rh59-vgh2-8m84/GHSA-rh59-vgh2-8m84.json b/advisories/unreviewed/2025/01/GHSA-rh59-vgh2-8m84/GHSA-rh59-vgh2-8m84.json
new file mode 100644
index 00000000000..e62eeb91ae7
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-rh59-vgh2-8m84/GHSA-rh59-vgh2-8m84.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rh59-vgh2-8m84",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22306"
+ ],
+ "details": "Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.7.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22306"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-7-7-sensitive-data-exposure-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-538"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json b/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json
new file mode 100644
index 00000000000..c87e431ffdc
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rpgv-42mm-c94j",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2024-50660"
+ ],
+ "details": "File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50660"
+ },
+ {
+ "type": "WEB",
+ "url": "https://petercipolone.info/wp-content/uploads/2025/01/iPublishMedia_AdPortal3.0.39_CVEs.pdf"
+ },
+ {
+ "type": "WEB",
+ "url": "http://adportal.com"
+ },
+ {
+ "type": "WEB",
+ "url": "http://ipublish.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T18:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json b/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json
index bd0b7d2437a..436ed080b56 100644
--- a/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json
+++ b/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rqp2-5j8f-59r3",
- "modified": "2025-01-06T18:31:04Z",
+ "modified": "2025-01-07T18:30:47Z",
"published": "2025-01-06T18:31:04Z",
"aliases": [
"CVE-2024-46622"
],
"details": "An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arbitrary file creation, modification and deletion.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-281"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-06T18:15:19Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-rw3m-wxjr-rg26/GHSA-rw3m-wxjr-rg26.json b/advisories/unreviewed/2025/01/GHSA-rw3m-wxjr-rg26/GHSA-rw3m-wxjr-rg26.json
new file mode 100644
index 00000000000..d8313626c60
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-rw3m-wxjr-rg26/GHSA-rw3m-wxjr-rg26.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rw3m-wxjr-rg26",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22579"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arefly WP Header Notification allows Stored XSS.This issue affects WP Header Notification: from n/a through 1.2.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22579"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-header-notification/vulnerability/wordpress-wp-header-notification-plugin-1-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-v2jq-3fw5-f7jf/GHSA-v2jq-3fw5-f7jf.json b/advisories/unreviewed/2025/01/GHSA-v2jq-3fw5-f7jf/GHSA-v2jq-3fw5-f7jf.json
new file mode 100644
index 00000000000..66c3f4aba8a
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-v2jq-3fw5-f7jf/GHSA-v2jq-3fw5-f7jf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v2jq-3fw5-f7jf",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22511"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ella van Durpe Slides & Presentations allows Stored XSS.This issue affects Slides & Presentations: from n/a through 0.0.39.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22511"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/slide/vulnerability/wordpress-slides-presentations-plugin-0-0-39-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-v2wj-3vg2-2w7h/GHSA-v2wj-3vg2-2w7h.json b/advisories/unreviewed/2025/01/GHSA-v2wj-3vg2-2w7h/GHSA-v2wj-3vg2-2w7h.json
new file mode 100644
index 00000000000..9dddcb1f00b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-v2wj-3vg2-2w7h/GHSA-v2wj-3vg2-2w7h.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v2wj-3vg2-2w7h",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22562"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jason Funk Title Experiments Free allows Cross Site Request Forgery.This issue affects Title Experiments Free: from n/a through 9.0.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22562"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-experiments-free/vulnerability/wordpress-title-experiments-free-plugin-9-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-vmhr-q3mv-rjgr/GHSA-vmhr-q3mv-rjgr.json b/advisories/unreviewed/2025/01/GHSA-vmhr-q3mv-rjgr/GHSA-vmhr-q3mv-rjgr.json
new file mode 100644
index 00000000000..57c56f0dcf0
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-vmhr-q3mv-rjgr/GHSA-vmhr-q3mv-rjgr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vmhr-q3mv-rjgr",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22522"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roya Khosravi SingSong allows Stored XSS.This issue affects SingSong: from n/a through 1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22522"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/singsong/vulnerability/wordpress-singsong-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-vmx9-cf98-29xx/GHSA-vmx9-cf98-29xx.json b/advisories/unreviewed/2025/01/GHSA-vmx9-cf98-29xx/GHSA-vmx9-cf98-29xx.json
new file mode 100644
index 00000000000..e6eab88bc5e
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-vmx9-cf98-29xx/GHSA-vmx9-cf98-29xx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vmx9-cf98-29xx",
+ "modified": "2025-01-07T18:30:52Z",
+ "published": "2025-01-07T18:30:52Z",
+ "aliases": [
+ "CVE-2025-22319"
+ ],
+ "details": "Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22319"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/mashsharer/vulnerability/wordpress-mashshare-plugin-4-0-47-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T17:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-vq6g-94cm-fpcw/GHSA-vq6g-94cm-fpcw.json b/advisories/unreviewed/2025/01/GHSA-vq6g-94cm-fpcw/GHSA-vq6g-94cm-fpcw.json
new file mode 100644
index 00000000000..efd784b1ef2
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-vq6g-94cm-fpcw/GHSA-vq6g-94cm-fpcw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vq6g-94cm-fpcw",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22580"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biltorvet A/S Biltorvet Dealer Tools allows Stored XSS.This issue affects Biltorvet Dealer Tools: from n/a through 1.0.22.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22580"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/biltorvet-dealer-tools/vulnerability/wordpress-biltorvet-dealer-tools-plugin-1-0-22-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json b/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json
new file mode 100644
index 00000000000..05d7dcf420d
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vrcp-29m9-49c3",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-53345"
+ ],
+ "details": "An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53345"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ShadowByte1/CVE-2024-53345"
+ },
+ {
+ "type": "WEB",
+ "url": "http://car.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-w573-j2v8-vx6p/GHSA-w573-j2v8-vx6p.json b/advisories/unreviewed/2025/01/GHSA-w573-j2v8-vx6p/GHSA-w573-j2v8-vx6p.json
index 558cad44336..c97d4210c64 100644
--- a/advisories/unreviewed/2025/01/GHSA-w573-j2v8-vx6p/GHSA-w573-j2v8-vx6p.json
+++ b/advisories/unreviewed/2025/01/GHSA-w573-j2v8-vx6p/GHSA-w573-j2v8-vx6p.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w573-j2v8-vx6p",
- "modified": "2025-01-07T06:32:16Z",
+ "modified": "2025-01-07T18:30:49Z",
"published": "2025-01-07T06:32:16Z",
"aliases": [
"CVE-2024-9638"
],
"details": "The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T06:15:18Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-w62h-vvvx-3vjw/GHSA-w62h-vvvx-3vjw.json b/advisories/unreviewed/2025/01/GHSA-w62h-vvvx-3vjw/GHSA-w62h-vvvx-3vjw.json
new file mode 100644
index 00000000000..68465e243ab
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-w62h-vvvx-3vjw/GHSA-w62h-vvvx-3vjw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w62h-vvvx-3vjw",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22543"
+ ],
+ "details": "Missing Authorization vulnerability in Beautiful Templates ST Gallery WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ST Gallery WP: from n/a through 1.0.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22543"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/st-gallery-wp/vulnerability/wordpress-st-gallery-wp-plugin-1-0-8-settings-change-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-w673-qgm7-cm6g/GHSA-w673-qgm7-cm6g.json b/advisories/unreviewed/2025/01/GHSA-w673-qgm7-cm6g/GHSA-w673-qgm7-cm6g.json
new file mode 100644
index 00000000000..4736a8fcbf1
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-w673-qgm7-cm6g/GHSA-w673-qgm7-cm6g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w673-qgm7-cm6g",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22544"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mind Doodle Mind Doodle Visual Sitemaps & Tasks allows Stored XSS.This issue affects Mind Doodle Visual Sitemaps & Tasks: from n/a through 1.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22544"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/mind-doodle-sitemap/vulnerability/wordpress-mind-doodle-visual-sitemaps-tasks-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-wq4v-vx3p-7825/GHSA-wq4v-vx3p-7825.json b/advisories/unreviewed/2025/01/GHSA-wq4v-vx3p-7825/GHSA-wq4v-vx3p-7825.json
new file mode 100644
index 00000000000..ad412d9d359
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-wq4v-vx3p-7825/GHSA-wq4v-vx3p-7825.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wq4v-vx3p-7825",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22541"
+ ],
+ "details": "Missing Authorization vulnerability in Etruel Developments LLC WP Delete Post Copies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delete Post Copies: from n/a through 5.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22541"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/etruel-del-post-copies/vulnerability/wordpress-wp-delete-post-copies-plugin-5-5-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-wq6h-3x69-r3wq/GHSA-wq6h-3x69-r3wq.json b/advisories/unreviewed/2025/01/GHSA-wq6h-3x69-r3wq/GHSA-wq6h-3x69-r3wq.json
new file mode 100644
index 00000000000..58e094b7021
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-wq6h-3x69-r3wq/GHSA-wq6h-3x69-r3wq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wq6h-3x69-r3wq",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-22538"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ofek Nakar Virtual Bot allows Stored XSS.This issue affects Virtual Bot: from n/a through 1.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22538"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/virtual-bot/vulnerability/wordpress-virtual-bot-plugin-1-0-0-csrf-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-x57h-9xpv-xxrx/GHSA-x57h-9xpv-xxrx.json b/advisories/unreviewed/2025/01/GHSA-x57h-9xpv-xxrx/GHSA-x57h-9xpv-xxrx.json
new file mode 100644
index 00000000000..49983d43475
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-x57h-9xpv-xxrx/GHSA-x57h-9xpv-xxrx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x57h-9xpv-xxrx",
+ "modified": "2025-01-07T18:30:51Z",
+ "published": "2025-01-07T18:30:51Z",
+ "aliases": [
+ "CVE-2025-22558"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus C. J. Hartmann mcjh button shortcode allows Stored XSS.This issue affects mcjh button shortcode: from n/a through 1.6.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22558"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/mcjh-button-shortcode/vulnerability/wordpress-mcjh-button-shortcode-plugin-1-6-4-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-xf84-f9vv-4vfx/GHSA-xf84-f9vv-4vfx.json b/advisories/unreviewed/2025/01/GHSA-xf84-f9vv-4vfx/GHSA-xf84-f9vv-4vfx.json
new file mode 100644
index 00000000000..28502e20216
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-xf84-f9vv-4vfx/GHSA-xf84-f9vv-4vfx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xf84-f9vv-4vfx",
+ "modified": "2025-01-07T18:30:49Z",
+ "published": "2025-01-07T18:30:49Z",
+ "aliases": [
+ "CVE-2024-40702"
+ ],
+ "details": "IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40702"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7179163"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-295"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:33Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json b/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json
new file mode 100644
index 00000000000..c3eb36fd90b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xwpw-pxrm-39pm",
+ "modified": "2025-01-07T18:30:50Z",
+ "published": "2025-01-07T18:30:50Z",
+ "aliases": [
+ "CVE-2025-0246"
+ ],
+ "details": "When using an invalid protocol scheme, an attacker could spoof the address bar. \n*Note: This issue only affected Android operating systems. Other operating systems are unaffected.*\n*Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0246"
+ },
+ {
+ "type": "WEB",
+ "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1912709"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.mozilla.org/security/advisories/mfsa2025-01"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-07T16:15:39Z"
+ }
+}
\ No newline at end of file