diff --git a/advisories/unreviewed/2023/05/GHSA-2x42-h92q-qcvm/GHSA-2x42-h92q-qcvm.json b/advisories/unreviewed/2023/05/GHSA-2x42-h92q-qcvm/GHSA-2x42-h92q-qcvm.json index 4eb3622a5d0..6c09e46014b 100644 --- a/advisories/unreviewed/2023/05/GHSA-2x42-h92q-qcvm/GHSA-2x42-h92q-qcvm.json +++ b/advisories/unreviewed/2023/05/GHSA-2x42-h92q-qcvm/GHSA-2x42-h92q-qcvm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-3r37-p8j6-6wp6/GHSA-3r37-p8j6-6wp6.json b/advisories/unreviewed/2023/05/GHSA-3r37-p8j6-6wp6/GHSA-3r37-p8j6-6wp6.json index 36f0ec1ec87..0074ffd173a 100644 --- a/advisories/unreviewed/2023/05/GHSA-3r37-p8j6-6wp6/GHSA-3r37-p8j6-6wp6.json +++ b/advisories/unreviewed/2023/05/GHSA-3r37-p8j6-6wp6/GHSA-3r37-p8j6-6wp6.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-57wg-rgp4-66qm/GHSA-57wg-rgp4-66qm.json b/advisories/unreviewed/2023/05/GHSA-57wg-rgp4-66qm/GHSA-57wg-rgp4-66qm.json index 4f7ee3c0dfb..6840921faab 100644 --- a/advisories/unreviewed/2023/05/GHSA-57wg-rgp4-66qm/GHSA-57wg-rgp4-66qm.json +++ b/advisories/unreviewed/2023/05/GHSA-57wg-rgp4-66qm/GHSA-57wg-rgp4-66qm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-76qj-23pr-3333/GHSA-76qj-23pr-3333.json b/advisories/unreviewed/2023/05/GHSA-76qj-23pr-3333/GHSA-76qj-23pr-3333.json index ffdc62db9af..7d35df1a0c6 100644 --- a/advisories/unreviewed/2023/05/GHSA-76qj-23pr-3333/GHSA-76qj-23pr-3333.json +++ b/advisories/unreviewed/2023/05/GHSA-76qj-23pr-3333/GHSA-76qj-23pr-3333.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-125" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-9q8p-c2mj-7c5v/GHSA-9q8p-c2mj-7c5v.json b/advisories/unreviewed/2023/05/GHSA-9q8p-c2mj-7c5v/GHSA-9q8p-c2mj-7c5v.json index 3b10daeb720..c5482860a20 100644 --- a/advisories/unreviewed/2023/05/GHSA-9q8p-c2mj-7c5v/GHSA-9q8p-c2mj-7c5v.json +++ b/advisories/unreviewed/2023/05/GHSA-9q8p-c2mj-7c5v/GHSA-9q8p-c2mj-7c5v.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-295" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-cf86-5cg9-6496/GHSA-cf86-5cg9-6496.json b/advisories/unreviewed/2023/05/GHSA-cf86-5cg9-6496/GHSA-cf86-5cg9-6496.json index 427f064645b..9d0c6f736bf 100644 --- a/advisories/unreviewed/2023/05/GHSA-cf86-5cg9-6496/GHSA-cf86-5cg9-6496.json +++ b/advisories/unreviewed/2023/05/GHSA-cf86-5cg9-6496/GHSA-cf86-5cg9-6496.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-pp59-h84v-cqmh/GHSA-pp59-h84v-cqmh.json b/advisories/unreviewed/2023/05/GHSA-pp59-h84v-cqmh/GHSA-pp59-h84v-cqmh.json index 87ff1029635..81501fffc07 100644 --- a/advisories/unreviewed/2023/05/GHSA-pp59-h84v-cqmh/GHSA-pp59-h84v-cqmh.json +++ b/advisories/unreviewed/2023/05/GHSA-pp59-h84v-cqmh/GHSA-pp59-h84v-cqmh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-x53p-mh39-7rgf/GHSA-x53p-mh39-7rgf.json b/advisories/unreviewed/2023/05/GHSA-x53p-mh39-7rgf/GHSA-x53p-mh39-7rgf.json index 6543ef02dfc..06a0276f49e 100644 --- a/advisories/unreviewed/2023/05/GHSA-x53p-mh39-7rgf/GHSA-x53p-mh39-7rgf.json +++ b/advisories/unreviewed/2023/05/GHSA-x53p-mh39-7rgf/GHSA-x53p-mh39-7rgf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json b/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json index 2c498560945..fdbc6d819cc 100644 --- a/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json +++ b/advisories/unreviewed/2024/03/GHSA-8wfm-cwf4-qvjj/GHSA-8wfm-cwf4-qvjj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json b/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json index 2c5ce7408e4..e8c1a1e3270 100644 --- a/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json +++ b/advisories/unreviewed/2024/03/GHSA-gwcc-j6r9-59p8/GHSA-gwcc-j6r9-59p8.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-643" + "CWE-643", + "CWE-91" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json b/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json index b8434811f09..6fb6d0ff731 100644 --- a/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json +++ b/advisories/unreviewed/2024/03/GHSA-q4g5-6262-6h9p/GHSA-q4g5-6262-6h9p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json b/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json index 31fe189d79b..3b7ec054540 100644 --- a/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json +++ b/advisories/unreviewed/2024/03/GHSA-r6x7-5742-mcv8/GHSA-r6x7-5742-mcv8.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-v8cq-w557-hfjg/GHSA-v8cq-w557-hfjg.json b/advisories/unreviewed/2024/03/GHSA-v8cq-w557-hfjg/GHSA-v8cq-w557-hfjg.json index 0f6d24afc3c..cdb9bf7f18e 100644 --- a/advisories/unreviewed/2024/03/GHSA-v8cq-w557-hfjg/GHSA-v8cq-w557-hfjg.json +++ b/advisories/unreviewed/2024/03/GHSA-v8cq-w557-hfjg/GHSA-v8cq-w557-hfjg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vj7r-f7rj-7598/GHSA-vj7r-f7rj-7598.json b/advisories/unreviewed/2024/03/GHSA-vj7r-f7rj-7598/GHSA-vj7r-f7rj-7598.json index a3f0caaf27c..bfd8f23870e 100644 --- a/advisories/unreviewed/2024/03/GHSA-vj7r-f7rj-7598/GHSA-vj7r-f7rj-7598.json +++ b/advisories/unreviewed/2024/03/GHSA-vj7r-f7rj-7598/GHSA-vj7r-f7rj-7598.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json b/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json index 9572763705d..dbff421b1d5 100644 --- a/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json +++ b/advisories/unreviewed/2024/04/GHSA-3xr5-7rvh-x3v2/GHSA-3xr5-7rvh-x3v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xr5-7rvh-x3v2", - "modified": "2024-10-08T18:33:07Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25705" diff --git a/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json b/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json index 1af7c275410..211a859a2c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json +++ b/advisories/unreviewed/2024/04/GHSA-r8f4-r8pc-7q4p/GHSA-r8f4-r8pc-7q4p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2p4r-h63c-pgmr/GHSA-2p4r-h63c-pgmr.json b/advisories/unreviewed/2024/05/GHSA-2p4r-h63c-pgmr/GHSA-2p4r-h63c-pgmr.json index aaa1288eed2..2705dbd2893 100644 --- a/advisories/unreviewed/2024/05/GHSA-2p4r-h63c-pgmr/GHSA-2p4r-h63c-pgmr.json +++ b/advisories/unreviewed/2024/05/GHSA-2p4r-h63c-pgmr/GHSA-2p4r-h63c-pgmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2p4r-h63c-pgmr", - "modified": "2024-05-16T12:30:23Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-05-16T12:30:23Z", "aliases": [ "CVE-2024-4580" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-74m3-5qc8-837r/GHSA-74m3-5qc8-837r.json b/advisories/unreviewed/2024/05/GHSA-74m3-5qc8-837r/GHSA-74m3-5qc8-837r.json index 570db3b4431..1282ec9a025 100644 --- a/advisories/unreviewed/2024/05/GHSA-74m3-5qc8-837r/GHSA-74m3-5qc8-837r.json +++ b/advisories/unreviewed/2024/05/GHSA-74m3-5qc8-837r/GHSA-74m3-5qc8-837r.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7mg7-h7gf-rq88/GHSA-7mg7-h7gf-rq88.json b/advisories/unreviewed/2024/05/GHSA-7mg7-h7gf-rq88/GHSA-7mg7-h7gf-rq88.json index 63cd23b1cfd..9c7e1414290 100644 --- a/advisories/unreviewed/2024/05/GHSA-7mg7-h7gf-rq88/GHSA-7mg7-h7gf-rq88.json +++ b/advisories/unreviewed/2024/05/GHSA-7mg7-h7gf-rq88/GHSA-7mg7-h7gf-rq88.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-899m-qj3x-m494/GHSA-899m-qj3x-m494.json b/advisories/unreviewed/2024/05/GHSA-899m-qj3x-m494/GHSA-899m-qj3x-m494.json index 4639dce7443..b1cce027f1a 100644 --- a/advisories/unreviewed/2024/05/GHSA-899m-qj3x-m494/GHSA-899m-qj3x-m494.json +++ b/advisories/unreviewed/2024/05/GHSA-899m-qj3x-m494/GHSA-899m-qj3x-m494.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-9m45-35mq-gcp6/GHSA-9m45-35mq-gcp6.json b/advisories/unreviewed/2024/05/GHSA-9m45-35mq-gcp6/GHSA-9m45-35mq-gcp6.json index a20b1e48efa..ef937bd0a0a 100644 --- a/advisories/unreviewed/2024/05/GHSA-9m45-35mq-gcp6/GHSA-9m45-35mq-gcp6.json +++ b/advisories/unreviewed/2024/05/GHSA-9m45-35mq-gcp6/GHSA-9m45-35mq-gcp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m45-35mq-gcp6", - "modified": "2024-05-18T06:30:32Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-05-18T06:30:32Z", "aliases": [ "CVE-2024-4891" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cv8w-w26r-wrx4/GHSA-cv8w-w26r-wrx4.json b/advisories/unreviewed/2024/05/GHSA-cv8w-w26r-wrx4/GHSA-cv8w-w26r-wrx4.json index 76a90b56c16..0ea0a5a149e 100644 --- a/advisories/unreviewed/2024/05/GHSA-cv8w-w26r-wrx4/GHSA-cv8w-w26r-wrx4.json +++ b/advisories/unreviewed/2024/05/GHSA-cv8w-w26r-wrx4/GHSA-cv8w-w26r-wrx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cv8w-w26r-wrx4", - "modified": "2024-05-16T12:30:22Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-05-16T12:30:22Z", "aliases": [ "CVE-2024-4634" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p557-3fgh-xgcq/GHSA-p557-3fgh-xgcq.json b/advisories/unreviewed/2024/05/GHSA-p557-3fgh-xgcq/GHSA-p557-3fgh-xgcq.json index 9833c18f593..751b1410597 100644 --- a/advisories/unreviewed/2024/05/GHSA-p557-3fgh-xgcq/GHSA-p557-3fgh-xgcq.json +++ b/advisories/unreviewed/2024/05/GHSA-p557-3fgh-xgcq/GHSA-p557-3fgh-xgcq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qwjm-p7qm-cgm9/GHSA-qwjm-p7qm-cgm9.json b/advisories/unreviewed/2024/05/GHSA-qwjm-p7qm-cgm9/GHSA-qwjm-p7qm-cgm9.json index e74d204716c..b23e24df7b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-qwjm-p7qm-cgm9/GHSA-qwjm-p7qm-cgm9.json +++ b/advisories/unreviewed/2024/05/GHSA-qwjm-p7qm-cgm9/GHSA-qwjm-p7qm-cgm9.json @@ -1,13 +1,22 @@ { "schema_version": "1.4.0", "id": "GHSA-qwjm-p7qm-cgm9", - "modified": "2024-05-16T18:30:32Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-05-16T18:30:32Z", "aliases": [ "CVE-2024-4609" ], "details": "A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], "affected": [], "references": [ { @@ -21,9 +30,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T16:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xc3x-fhc6-j363/GHSA-xc3x-fhc6-j363.json b/advisories/unreviewed/2024/05/GHSA-xc3x-fhc6-j363/GHSA-xc3x-fhc6-j363.json index f390c7f186c..bfe25a35d91 100644 --- a/advisories/unreviewed/2024/05/GHSA-xc3x-fhc6-j363/GHSA-xc3x-fhc6-j363.json +++ b/advisories/unreviewed/2024/05/GHSA-xc3x-fhc6-j363/GHSA-xc3x-fhc6-j363.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xc3x-fhc6-j363", - "modified": "2024-06-03T18:56:24Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-05-23T12:31:02Z", "aliases": [ "CVE-2024-4779" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xvxq-7q9x-g29m/GHSA-xvxq-7q9x-g29m.json b/advisories/unreviewed/2024/05/GHSA-xvxq-7q9x-g29m/GHSA-xvxq-7q9x-g29m.json index 1ee829d2321..d4965ce0325 100644 --- a/advisories/unreviewed/2024/05/GHSA-xvxq-7q9x-g29m/GHSA-xvxq-7q9x-g29m.json +++ b/advisories/unreviewed/2024/05/GHSA-xvxq-7q9x-g29m/GHSA-xvxq-7q9x-g29m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvxq-7q9x-g29m", - "modified": "2024-05-14T18:30:52Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-05-14T18:30:52Z", "aliases": [ "CVE-2024-3055" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-g5j9-wcw5-899j/GHSA-g5j9-wcw5-899j.json b/advisories/unreviewed/2024/10/GHSA-g5j9-wcw5-899j/GHSA-g5j9-wcw5-899j.json index c33d93dd1e9..3c4258b7534 100644 --- a/advisories/unreviewed/2024/10/GHSA-g5j9-wcw5-899j/GHSA-g5j9-wcw5-899j.json +++ b/advisories/unreviewed/2024/10/GHSA-g5j9-wcw5-899j/GHSA-g5j9-wcw5-899j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5j9-wcw5-899j", - "modified": "2024-10-04T18:31:11Z", + "modified": "2025-01-30T18:32:04Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-8149" diff --git a/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json b/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json index 90a8870459a..e3aaa839cac 100644 --- a/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json +++ b/advisories/unreviewed/2025/01/GHSA-23h2-xx79-4xwr/GHSA-23h2-xx79-4xwr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23h2-xx79-4xwr", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24145" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.3, iOS 18.3 and iPadOS 18.3. An app may be able to view a contact's phone number in system logs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-532" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json b/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json index 15bf3ea0e4b..eb762a7ca82 100644 --- a/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json +++ b/advisories/unreviewed/2025/01/GHSA-23h9-xj7q-3m7r/GHSA-23h9-xj7q-3m7r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23h9-xj7q-3m7r", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24143" ], "details": "The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2795-pjw4-5495/GHSA-2795-pjw4-5495.json b/advisories/unreviewed/2025/01/GHSA-2795-pjw4-5495/GHSA-2795-pjw4-5495.json new file mode 100644 index 00000000000..77be40b1d3c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2795-pjw4-5495/GHSA-2795-pjw4-5495.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2795-pjw4-5495", + "modified": "2025-01-30T18:32:08Z", + "published": "2025-01-30T18:32:08Z", + "aliases": [ + "CVE-2024-2658" + ], + "details": "A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2658" + }, + { + "type": "WEB", + "url": "https://community.flexera.com/s/article/cve-2024-2658-flexnet-publisher-potential-local-privilege-escalation-issue" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-359" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json b/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json index 15454a7ef49..418c3e4437b 100644 --- a/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json +++ b/advisories/unreviewed/2025/01/GHSA-2wm4-qgw2-r6ff/GHSA-2wm4-qgw2-r6ff.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wm4-qgw2-r6ff", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24096" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json b/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json index 2f8b9ca05de..266704109a9 100644 --- a/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json +++ b/advisories/unreviewed/2025/01/GHSA-2xvj-j4wx-pf4c/GHSA-2xvj-j4wx-pf4c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xvj-j4wx-pf4c", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54541" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json b/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json index e0347a014f7..408ce16d09e 100644 --- a/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json +++ b/advisories/unreviewed/2025/01/GHSA-3q6v-mwhw-45h2/GHSA-3q6v-mwhw-45h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q6v-mwhw-45h2", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24153" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3r6v-762w-v9rw/GHSA-3r6v-762w-v9rw.json b/advisories/unreviewed/2025/01/GHSA-3r6v-762w-v9rw/GHSA-3r6v-762w-v9rw.json new file mode 100644 index 00000000000..031d486d1f5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3r6v-762w-v9rw/GHSA-3r6v-762w-v9rw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r6v-762w-v9rw", + "modified": "2025-01-30T18:32:09Z", + "published": "2025-01-30T18:32:09Z", + "aliases": [ + "CVE-2025-24099" + ], + "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Ventura 13.7.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24099" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122068" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122069" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122070" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json b/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json index 646a4f3fe7a..dcb686eefa8 100644 --- a/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json +++ b/advisories/unreviewed/2025/01/GHSA-47j8-qfh2-377q/GHSA-47j8-qfh2-377q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-47j8-qfh2-377q", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24087" ], "details": "The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-49jj-m435-g94r/GHSA-49jj-m435-g94r.json b/advisories/unreviewed/2025/01/GHSA-49jj-m435-g94r/GHSA-49jj-m435-g94r.json new file mode 100644 index 00000000000..f762125f19c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-49jj-m435-g94r/GHSA-49jj-m435-g94r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49jj-m435-g94r", + "modified": "2025-01-30T18:32:09Z", + "published": "2025-01-30T18:32:09Z", + "aliases": [ + "CVE-2025-0477" + ], + "details": "An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0477" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1721.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json b/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json index 191dbd986f5..813e7870f4b 100644 --- a/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json +++ b/advisories/unreviewed/2025/01/GHSA-4qxg-mfmj-r355/GHSA-4qxg-mfmj-r355.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4qxg-mfmj-r355", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24152" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json b/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json index 780485d34f9..9158aa568f7 100644 --- a/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json +++ b/advisories/unreviewed/2025/01/GHSA-5gcp-9j5g-mj5x/GHSA-5gcp-9j5g-mj5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gcp-9j5g-mj5x", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54522" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json b/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json index 074376b8560..f2a878e7e3d 100644 --- a/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json +++ b/advisories/unreviewed/2025/01/GHSA-65f9-48qm-g2v2/GHSA-65f9-48qm-g2v2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65f9-48qm-g2v2", - "modified": "2025-01-30T06:30:49Z", + "modified": "2025-01-30T18:32:07Z", "published": "2025-01-30T06:30:49Z", "aliases": [ "CVE-2024-12163" ], "details": "The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T06:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json b/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json index 5ce115dc3d8..2b50ba24048 100644 --- a/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json +++ b/advisories/unreviewed/2025/01/GHSA-69r8-3jjv-g7rv/GHSA-69r8-3jjv-g7rv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69r8-3jjv-g7rv", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24131" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An attacker in a privileged position may be able to perform a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6cxx-5fj7-8mm3/GHSA-6cxx-5fj7-8mm3.json b/advisories/unreviewed/2025/01/GHSA-6cxx-5fj7-8mm3/GHSA-6cxx-5fj7-8mm3.json new file mode 100644 index 00000000000..1a1f7c96a7b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6cxx-5fj7-8mm3/GHSA-6cxx-5fj7-8mm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cxx-5fj7-8mm3", + "modified": "2025-01-30T18:32:09Z", + "published": "2025-01-30T18:32:09Z", + "aliases": [ + "CVE-2025-0497" + ], + "details": "A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0497" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1721.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json b/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json index b38b23cf80f..c79c255aaf7 100644 --- a/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json +++ b/advisories/unreviewed/2025/01/GHSA-6xj4-vchf-pfcc/GHSA-6xj4-vchf-pfcc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6xj4-vchf-pfcc", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54497" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing web content may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7xmr-c34w-p9w7/GHSA-7xmr-c34w-p9w7.json b/advisories/unreviewed/2025/01/GHSA-7xmr-c34w-p9w7/GHSA-7xmr-c34w-p9w7.json index bb2a692a356..2031d76f517 100644 --- a/advisories/unreviewed/2025/01/GHSA-7xmr-c34w-p9w7/GHSA-7xmr-c34w-p9w7.json +++ b/advisories/unreviewed/2025/01/GHSA-7xmr-c34w-p9w7/GHSA-7xmr-c34w-p9w7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xmr-c34w-p9w7", - "modified": "2025-01-30T00:31:04Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-30T00:31:03Z", "aliases": [ "CVE-2024-54851" ], "details": "Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-29T22:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json b/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json index 5039f29bc21..74ffdce196f 100644 --- a/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json +++ b/advisories/unreviewed/2025/01/GHSA-9cmh-qh3j-rrp8/GHSA-9cmh-qh3j-rrp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9cmh-qh3j-rrp8", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24161" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json b/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json new file mode 100644 index 00000000000..02f5d4b4f13 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9h7m-pf82-g666/GHSA-9h7m-pf82-g666.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h7m-pf82-g666", + "modified": "2025-01-30T18:32:07Z", + "published": "2025-01-30T18:32:07Z", + "aliases": [ + "CVE-2025-22222" + ], + "details": "VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22222" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json b/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json index f58994dd068..c3a66f8ebd5 100644 --- a/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json +++ b/advisories/unreviewed/2025/01/GHSA-9mj5-43v3-x7pj/GHSA-9mj5-43v3-x7pj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9mj5-43v3-x7pj", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54517" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9mvw-93v8-wr2v/GHSA-9mvw-93v8-wr2v.json b/advisories/unreviewed/2025/01/GHSA-9mvw-93v8-wr2v/GHSA-9mvw-93v8-wr2v.json new file mode 100644 index 00000000000..c826a187418 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mvw-93v8-wr2v/GHSA-9mvw-93v8-wr2v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mvw-93v8-wr2v", + "modified": "2025-01-30T18:32:10Z", + "published": "2025-01-30T18:32:10Z", + "aliases": [ + "CVE-2025-0874" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management 1.0. Affected by this issue is some unknown functionality of the file /admin/approve.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0874" + }, + { + "type": "WEB", + "url": "https://github.com/magic2353112890/cve/issues/8" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294068" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.488538" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json b/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json index d6257bc4cf6..c0d7facedb8 100644 --- a/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json +++ b/advisories/unreviewed/2025/01/GHSA-9mwc-354m-hg9c/GHSA-9mwc-354m-hg9c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9mwc-354m-hg9c", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24094" ], "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9pmh-gp9r-2wrj/GHSA-9pmh-gp9r-2wrj.json b/advisories/unreviewed/2025/01/GHSA-9pmh-gp9r-2wrj/GHSA-9pmh-gp9r-2wrj.json index c52b24d2c96..39ba1bdcf84 100644 --- a/advisories/unreviewed/2025/01/GHSA-9pmh-gp9r-2wrj/GHSA-9pmh-gp9r-2wrj.json +++ b/advisories/unreviewed/2025/01/GHSA-9pmh-gp9r-2wrj/GHSA-9pmh-gp9r-2wrj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pmh-gp9r-2wrj", - "modified": "2025-01-30T00:31:03Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-30T00:31:03Z", "aliases": [ "CVE-2024-51182" ], "details": "HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the \"erro\" parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-29T22:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json b/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json index 46fe9d95eaf..6ec44666799 100644 --- a/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json +++ b/advisories/unreviewed/2025/01/GHSA-crm9-rr9p-qwr6/GHSA-crm9-rr9p-qwr6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crm9-rr9p-qwr6", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54516" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to approve a launch daemon without user consent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fx7g-h676-75c4/GHSA-fx7g-h676-75c4.json b/advisories/unreviewed/2025/01/GHSA-fx7g-h676-75c4/GHSA-fx7g-h676-75c4.json index e07b89614c4..c7731632e3e 100644 --- a/advisories/unreviewed/2025/01/GHSA-fx7g-h676-75c4/GHSA-fx7g-h676-75c4.json +++ b/advisories/unreviewed/2025/01/GHSA-fx7g-h676-75c4/GHSA-fx7g-h676-75c4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fx7g-h676-75c4", - "modified": "2025-01-30T06:30:50Z", + "modified": "2025-01-30T18:32:07Z", "published": "2025-01-30T06:30:50Z", "aliases": [ "CVE-2024-12709" ], "details": "The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T06:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json b/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json index fa58de164eb..a18215f968d 100644 --- a/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json +++ b/advisories/unreviewed/2025/01/GHSA-gm6v-g6wg-rpvc/GHSA-gm6v-g6wg-rpvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gm6v-g6wg-rpvc", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54509" ], "details": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gxhg-qc42-w3x4/GHSA-gxhg-qc42-w3x4.json b/advisories/unreviewed/2025/01/GHSA-gxhg-qc42-w3x4/GHSA-gxhg-qc42-w3x4.json index e7a9f7a52a8..9140f250789 100644 --- a/advisories/unreviewed/2025/01/GHSA-gxhg-qc42-w3x4/GHSA-gxhg-qc42-w3x4.json +++ b/advisories/unreviewed/2025/01/GHSA-gxhg-qc42-w3x4/GHSA-gxhg-qc42-w3x4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxhg-qc42-w3x4", - "modified": "2025-01-30T06:30:50Z", + "modified": "2025-01-30T18:32:07Z", "published": "2025-01-30T06:30:50Z", "aliases": [ "CVE-2024-12638" ], "details": "The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T06:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json b/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json index 4b5cfae90ca..2040fed66ab 100644 --- a/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json +++ b/advisories/unreviewed/2025/01/GHSA-h2jv-m23f-7xfh/GHSA-h2jv-m23f-7xfh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h2jv-m23f-7xfh", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:04Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-44172" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3, macOS Sequoia 15. An app may be able to access contacts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json b/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json new file mode 100644 index 00000000000..55b38a8f4e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h384-cwqp-rc8x", + "modified": "2025-01-30T18:32:07Z", + "published": "2025-01-30T18:32:07Z", + "aliases": [ + "CVE-2025-0872" + ], + "details": "A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /addpayment.php. The manipulation of the argument id/amount/desc/inccat leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0872" + }, + { + "type": "WEB", + "url": "https://github.com/magic2353112890/cve/issues/3" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294066" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294066" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.487953" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json b/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json index 8b2eaeefb99..a79ff6ff3a0 100644 --- a/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json +++ b/advisories/unreviewed/2025/01/GHSA-h9j3-chpr-5rjg/GHSA-h9j3-chpr-5rjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9j3-chpr-5rjg", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24169" ], "details": "A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.3, Safari 18.3. A malicious app may be able to bypass browser extension authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json b/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json index 729cfe957e3..c55d32c76fd 100644 --- a/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json +++ b/advisories/unreviewed/2025/01/GHSA-hfq6-5gvf-hm89/GHSA-hfq6-5gvf-hm89.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hfq6-5gvf-hm89", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T00:32:15Z", "aliases": [ "CVE-2025-24177" ], "details": "A null pointer dereference was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, iOS 18.3 and iPadOS 18.3. A remote attacker may be able to cause a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json b/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json index c5905959b99..690dac26bb4 100644 --- a/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json +++ b/advisories/unreviewed/2025/01/GHSA-j23p-p7c9-5hm5/GHSA-j23p-p7c9-5hm5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j23p-p7c9-5hm5", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54543" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.2, tvOS 18.2, Safari 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing maliciously crafted web content may lead to memory corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json b/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json index 15896ec83e1..f4ae630c131 100644 --- a/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json +++ b/advisories/unreviewed/2025/01/GHSA-j3f4-fw9x-x9c7/GHSA-j3f4-fw9x-x9c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3f4-fw9x-x9c7", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54536" ], "details": "The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.2. An app may be able to edit NVRAM variables.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json b/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json new file mode 100644 index 00000000000..7630904f5fc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j5gv-mwmr-ppp5/GHSA-j5gv-mwmr-ppp5.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5gv-mwmr-ppp5", + "modified": "2025-01-30T18:32:07Z", + "published": "2025-01-30T18:32:07Z", + "aliases": [ + "CVE-2025-22219" + ], + "details": "VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22219" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jgh6-r92w-wgcf/GHSA-jgh6-r92w-wgcf.json b/advisories/unreviewed/2025/01/GHSA-jgh6-r92w-wgcf/GHSA-jgh6-r92w-wgcf.json new file mode 100644 index 00000000000..f04a63d34f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jgh6-r92w-wgcf/GHSA-jgh6-r92w-wgcf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgh6-r92w-wgcf", + "modified": "2025-01-30T18:32:09Z", + "published": "2025-01-30T18:32:09Z", + "aliases": [ + "CVE-2023-29080" + ], + "details": "Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29080" + }, + { + "type": "WEB", + "url": "https://community.revenera.com/s/article/cve-2023-29080-security-patch-for-the-possible-privileged-escalation-scenarios-identified-in-installshield-nbsp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json b/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json new file mode 100644 index 00000000000..93135e99872 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m777-hj92-cw6q", + "modified": "2025-01-30T18:32:07Z", + "published": "2025-01-30T18:32:07Z", + "aliases": [ + "CVE-2025-22220" + ], + "details": "VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22220" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m9wf-858v-4363/GHSA-m9wf-858v-4363.json b/advisories/unreviewed/2025/01/GHSA-m9wf-858v-4363/GHSA-m9wf-858v-4363.json new file mode 100644 index 00000000000..b95edfdb81d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m9wf-858v-4363/GHSA-m9wf-858v-4363.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9wf-858v-4363", + "modified": "2025-01-30T18:32:09Z", + "published": "2025-01-30T18:32:09Z", + "aliases": [ + "CVE-2025-0498" + ], + "details": "A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0498" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1721.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json b/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json index b4a1b447a71..7510f2fc79b 100644 --- a/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json +++ b/advisories/unreviewed/2025/01/GHSA-mc69-xrvc-fghx/GHSA-mc69-xrvc-fghx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mc69-xrvc-fghx", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2025-24086" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing an image may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json b/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json index d20d126da6a..375ebaf8f51 100644 --- a/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json +++ b/advisories/unreviewed/2025/01/GHSA-p3qx-xphh-h4vv/GHSA-p3qx-xphh-h4vv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p3qx-xphh-h4vv", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24100" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access information about a user's contacts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json b/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json index 98c742d3121..cb72cf03c51 100644 --- a/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json +++ b/advisories/unreviewed/2025/01/GHSA-pgq2-vhv9-8pr9/GHSA-pgq2-vhv9-8pr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pgq2-vhv9-8pr9", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54512" ], "details": "The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json b/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json index ad9116d92d7..979aa4e03e0 100644 --- a/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json +++ b/advisories/unreviewed/2025/01/GHSA-q7g4-2c4x-wxxq/GHSA-q7g4-2c4x-wxxq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7g4-2c4x-wxxq", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54488" ], "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sonoma 14.7.2, macOS Sequoia 15.2. Photos in the Hidden Photos Album may be viewed without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json b/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json index 05b25471acd..299b745c1b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json +++ b/advisories/unreviewed/2025/01/GHSA-q965-9jfq-2h9g/GHSA-q965-9jfq-2h9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q965-9jfq-2h9g", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54557" ], "details": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An attacker may gain access to protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qf78-r92f-64mc/GHSA-qf78-r92f-64mc.json b/advisories/unreviewed/2025/01/GHSA-qf78-r92f-64mc/GHSA-qf78-r92f-64mc.json index 03c4abdd457..a2ab25dcc78 100644 --- a/advisories/unreviewed/2025/01/GHSA-qf78-r92f-64mc/GHSA-qf78-r92f-64mc.json +++ b/advisories/unreviewed/2025/01/GHSA-qf78-r92f-64mc/GHSA-qf78-r92f-64mc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qf78-r92f-64mc", - "modified": "2025-01-28T09:32:34Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T09:32:34Z", "aliases": [ "CVE-2024-13527" diff --git a/advisories/unreviewed/2025/01/GHSA-qjjh-33hc-226r/GHSA-qjjh-33hc-226r.json b/advisories/unreviewed/2025/01/GHSA-qjjh-33hc-226r/GHSA-qjjh-33hc-226r.json index 18ea196beb4..14e062d020e 100644 --- a/advisories/unreviewed/2025/01/GHSA-qjjh-33hc-226r/GHSA-qjjh-33hc-226r.json +++ b/advisories/unreviewed/2025/01/GHSA-qjjh-33hc-226r/GHSA-qjjh-33hc-226r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qjjh-33hc-226r", - "modified": "2025-01-30T06:30:50Z", + "modified": "2025-01-30T18:32:07Z", "published": "2025-01-30T06:30:50Z", "aliases": [ "CVE-2024-12708" ], "details": "The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T06:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json b/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json index bf0bc668131..a0efaa3ed33 100644 --- a/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json +++ b/advisories/unreviewed/2025/01/GHSA-qmjg-q5x7-48p2/GHSA-qmjg-q5x7-48p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qmjg-q5x7-48p2", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24150" ], "details": "A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qqrp-rh67-96r2/GHSA-qqrp-rh67-96r2.json b/advisories/unreviewed/2025/01/GHSA-qqrp-rh67-96r2/GHSA-qqrp-rh67-96r2.json index a55f417a3f3..f4dae449631 100644 --- a/advisories/unreviewed/2025/01/GHSA-qqrp-rh67-96r2/GHSA-qqrp-rh67-96r2.json +++ b/advisories/unreviewed/2025/01/GHSA-qqrp-rh67-96r2/GHSA-qqrp-rh67-96r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqrp-rh67-96r2", - "modified": "2025-01-28T09:32:33Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T09:32:33Z", "aliases": [ "CVE-2024-13509" diff --git a/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json b/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json new file mode 100644 index 00000000000..1a2060b9a8c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qrcx-78jp-35gm/GHSA-qrcx-78jp-35gm.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrcx-78jp-35gm", + "modified": "2025-01-30T18:32:07Z", + "published": "2025-01-30T18:32:07Z", + "aliases": [ + "CVE-2025-22221" + ], + "details": "VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22221" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25329" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rxh2-ghcp-6j9j/GHSA-rxh2-ghcp-6j9j.json b/advisories/unreviewed/2025/01/GHSA-rxh2-ghcp-6j9j/GHSA-rxh2-ghcp-6j9j.json index 981e1b35087..8a3161535d1 100644 --- a/advisories/unreviewed/2025/01/GHSA-rxh2-ghcp-6j9j/GHSA-rxh2-ghcp-6j9j.json +++ b/advisories/unreviewed/2025/01/GHSA-rxh2-ghcp-6j9j/GHSA-rxh2-ghcp-6j9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rxh2-ghcp-6j9j", - "modified": "2025-01-30T06:30:49Z", + "modified": "2025-01-30T18:32:07Z", "published": "2025-01-30T06:30:49Z", "aliases": [ "CVE-2024-10309" ], "details": "The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T06:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json b/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json index 2a08d6eb7a5..62bb97fc52c 100644 --- a/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json +++ b/advisories/unreviewed/2025/01/GHSA-w5x6-r7f6-w3x6/GHSA-w5x6-r7f6-w3x6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5x6-r7f6-w3x6", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24140" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json b/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json index 54f3ba96acd..cc2608f0c3e 100644 --- a/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json +++ b/advisories/unreviewed/2025/01/GHSA-wc57-w9rc-p4g6/GHSA-wc57-w9rc-p4g6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wc57-w9rc-p4g6", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24136" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious app may be able to create symlinks to protected regions of the disk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json b/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json index db686643766..dc91b3754d1 100644 --- a/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json +++ b/advisories/unreviewed/2025/01/GHSA-wjg3-gwjx-xwj5/GHSA-wjg3-gwjx-xwj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjg3-gwjx-xwj5", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24104" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in iPadOS 17.7.4, iOS 18.3 and iPadOS 18.3. Restoring a maliciously crafted backup file may lead to modification of protected system files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x8qf-h4pp-w59j/GHSA-x8qf-h4pp-w59j.json b/advisories/unreviewed/2025/01/GHSA-x8qf-h4pp-w59j/GHSA-x8qf-h4pp-w59j.json index 840d6bee893..5d60d2ef141 100644 --- a/advisories/unreviewed/2025/01/GHSA-x8qf-h4pp-w59j/GHSA-x8qf-h4pp-w59j.json +++ b/advisories/unreviewed/2025/01/GHSA-x8qf-h4pp-w59j/GHSA-x8qf-h4pp-w59j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8qf-h4pp-w59j", - "modified": "2025-01-28T09:32:34Z", + "modified": "2025-01-30T18:32:06Z", "published": "2025-01-28T09:32:34Z", "aliases": [ "CVE-2025-0321" diff --git a/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json b/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json new file mode 100644 index 00000000000..fc56344f1ca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm5v-9fv3-x7gp", + "modified": "2025-01-30T18:32:09Z", + "published": "2025-01-30T18:32:09Z", + "aliases": [ + "CVE-2025-0873" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipulation of the argument id/address/fullname/phonenumber/email/city/comment leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0873" + }, + { + "type": "WEB", + "url": "https://github.com/magic2353112890/cve/issues/5" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.487984" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json b/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json index b45b0c22d0c..fd1f33c8cda 100644 --- a/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json +++ b/advisories/unreviewed/2025/01/GHSA-xmpx-2mhf-xq2j/GHSA-xmpx-2mhf-xq2j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmpx-2mhf-xq2j", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-30T18:32:05Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24141" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json b/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json index d9e0a727b36..a119fa3ec19 100644 --- a/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json +++ b/advisories/unreviewed/2025/01/GHSA-xr4j-2qp3-r4xc/GHSA-xr4j-2qp3-r4xc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xr4j-2qp3-r4xc", - "modified": "2025-01-30T06:30:49Z", + "modified": "2025-01-30T18:32:07Z", "published": "2025-01-30T06:30:49Z", "aliases": [ "CVE-2024-12400" ], "details": "The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T06:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xrrm-r8x3-wh4p/GHSA-xrrm-r8x3-wh4p.json b/advisories/unreviewed/2025/01/GHSA-xrrm-r8x3-wh4p/GHSA-xrrm-r8x3-wh4p.json new file mode 100644 index 00000000000..f6f10daccd8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xrrm-r8x3-wh4p/GHSA-xrrm-r8x3-wh4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrrm-r8x3-wh4p", + "modified": "2025-01-30T18:32:08Z", + "published": "2025-01-30T18:32:08Z", + "aliases": [ + "CVE-2025-0367" + ], + "details": "In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0367" + }, + { + "type": "WEB", + "url": "https://advisory.splunk.com/advisories/SVD-2025-0103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T17:15:18Z" + } +} \ No newline at end of file