From 8bb6449464b4ec7588be9834bfed08ee4633f011 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 21 Mar 2025 21:32:53 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-xpm5-2pgw-v7g9.json | 9 ++- .../GHSA-29xc-g6f6-8cf9.json | 2 +- .../GHSA-2rv8-rcwh-2x8r.json | 2 +- .../GHSA-5wrv-vvhx-3wgq.json | 2 +- .../GHSA-6mgf-w4q5-rwj9.json | 2 +- .../GHSA-7fhv-rp66-q6r9.json | 5 +- .../GHSA-8vxm-rjvx-9v3r.json | 2 +- .../GHSA-9mqm-5q47-gj7c.json | 4 +- .../GHSA-9p88-mf79-r844.json | 2 +- .../GHSA-9xvv-g7xh-f2qr.json | 2 +- .../GHSA-c729-m2g9-m3xv.json | 4 +- .../GHSA-cjrm-898p-cxjr.json | 2 +- .../GHSA-f8mh-8977-gx9m.json | 2 +- .../GHSA-g9vx-qcqw-wcpx.json | 2 +- .../GHSA-m222-cmhp-v9m7.json | 2 +- .../GHSA-q26g-j482-m359.json | 2 +- .../GHSA-q6h2-6w35-jh4w.json | 2 +- .../GHSA-q7q7-xc84-hcqj.json | 4 +- .../GHSA-rxvx-wrgw-qpv7.json | 2 +- .../GHSA-w4fh-mw73-5c5w.json | 4 +- .../GHSA-w8wp-rv4w-h5pp.json | 14 ++++- .../GHSA-wm4x-x4q5-34vq.json | 2 +- .../GHSA-xmcc-cx53-xxg3.json | 2 +- .../GHSA-hc89-xf9q-xh2p.json | 2 +- .../GHSA-3q36-645m-456x.json | 4 +- .../GHSA-cfwg-f58j-689r.json | 4 +- .../GHSA-pqhm-crg4-8x2v.json | 4 +- .../GHSA-pr9m-x2x5-mj6q.json | 4 +- .../GHSA-q9f9-jvjh-rmh2.json | 4 +- .../GHSA-j2hp-jqgm-85pf.json | 4 +- .../GHSA-r5wc-932c-2vmp.json | 15 +++-- .../GHSA-fmp7-q9w4-g4x8.json | 6 +- .../GHSA-ccvr-35jj-hp58.json | 4 +- .../GHSA-x7gr-mmjj-hx3h.json | 3 +- .../GHSA-536x-p3x6-xv85.json | 56 +++++++++++++++++++ .../GHSA-5hc5-9qwg-w899.json | 15 +++-- .../GHSA-5hqf-7qhr-wqc3.json | 44 +++++++++++++++ .../GHSA-5p7f-cf35-c9jf.json | 15 +++-- .../GHSA-694q-974v-33w7.json | 15 +++-- .../GHSA-6fm4-x4xg-v3xr.json | 56 +++++++++++++++++++ .../GHSA-6fxv-ffp4-g24h.json | 52 +++++++++++++++++ .../GHSA-cwhr-q9q3-q73r.json | 56 +++++++++++++++++++ .../GHSA-g57w-j5gj-29qx.json | 15 +++-- .../GHSA-j48m-433v-3q7r.json | 15 +++-- .../GHSA-mghv-5x2h-9q5v.json | 56 +++++++++++++++++++ .../GHSA-p2r4-qh4v-qvh7.json | 52 +++++++++++++++++ .../GHSA-p6r9-p725-g42c.json | 15 +++-- .../GHSA-pgpf-3pvh-h5g7.json | 15 +++-- .../GHSA-r375-j569-v9qr.json | 15 +++-- .../GHSA-r63r-pwwp-jvj8.json | 15 +++-- .../GHSA-v222-4cxf-9gp4.json | 15 +++-- .../GHSA-v6jq-9h5f-2qcm.json | 15 +++-- .../GHSA-whf8-w5vj-q4w6.json | 15 +++-- .../GHSA-xhqx-hw3w-p9q3.json | 56 +++++++++++++++++++ 54 files changed, 645 insertions(+), 93 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5hqf-7qhr-wqc3/GHSA-5hqf-7qhr-wqc3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6fm4-x4xg-v3xr/GHSA-6fm4-x4xg-v3xr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6fxv-ffp4-g24h/GHSA-6fxv-ffp4-g24h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cwhr-q9q3-q73r/GHSA-cwhr-q9q3-q73r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mghv-5x2h-9q5v/GHSA-mghv-5x2h-9q5v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json diff --git a/advisories/unreviewed/2022/02/GHSA-xpm5-2pgw-v7g9/GHSA-xpm5-2pgw-v7g9.json b/advisories/unreviewed/2022/02/GHSA-xpm5-2pgw-v7g9/GHSA-xpm5-2pgw-v7g9.json index db449f19de7..7e90f753236 100644 --- a/advisories/unreviewed/2022/02/GHSA-xpm5-2pgw-v7g9/GHSA-xpm5-2pgw-v7g9.json +++ b/advisories/unreviewed/2022/02/GHSA-xpm5-2pgw-v7g9/GHSA-xpm5-2pgw-v7g9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpm5-2pgw-v7g9", - "modified": "2022-03-01T00:00:43Z", + "modified": "2025-03-21T21:31:27Z", "published": "2022-02-22T00:00:27Z", "aliases": [ "CVE-2021-25069" ], "details": "The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json b/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json index 258e6263f18..e92d79af60b 100644 --- a/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json +++ b/advisories/unreviewed/2023/02/GHSA-29xc-g6f6-8cf9/GHSA-29xc-g6f6-8cf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-29xc-g6f6-8cf9", - "modified": "2023-02-15T18:30:20Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0801" diff --git a/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json b/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json index 144512ea3d7..ad2a8cc567a 100644 --- a/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json +++ b/advisories/unreviewed/2023/02/GHSA-2rv8-rcwh-2x8r/GHSA-2rv8-rcwh-2x8r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2rv8-rcwh-2x8r", - "modified": "2023-02-15T18:30:20Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0803" diff --git a/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json b/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json index b023681312f..ada4fea736e 100644 --- a/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json +++ b/advisories/unreviewed/2023/02/GHSA-5wrv-vvhx-3wgq/GHSA-5wrv-vvhx-3wgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wrv-vvhx-3wgq", - "modified": "2023-02-15T18:30:20Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0800" diff --git a/advisories/unreviewed/2023/02/GHSA-6mgf-w4q5-rwj9/GHSA-6mgf-w4q5-rwj9.json b/advisories/unreviewed/2023/02/GHSA-6mgf-w4q5-rwj9/GHSA-6mgf-w4q5-rwj9.json index 9e1a2812143..7602b2a3abc 100644 --- a/advisories/unreviewed/2023/02/GHSA-6mgf-w4q5-rwj9/GHSA-6mgf-w4q5-rwj9.json +++ b/advisories/unreviewed/2023/02/GHSA-6mgf-w4q5-rwj9/GHSA-6mgf-w4q5-rwj9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mgf-w4q5-rwj9", - "modified": "2023-02-27T18:32:03Z", + "modified": "2025-03-21T21:31:30Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2023-22353" diff --git a/advisories/unreviewed/2023/02/GHSA-7fhv-rp66-q6r9/GHSA-7fhv-rp66-q6r9.json b/advisories/unreviewed/2023/02/GHSA-7fhv-rp66-q6r9/GHSA-7fhv-rp66-q6r9.json index dcf61f7c199..be286fb5fea 100644 --- a/advisories/unreviewed/2023/02/GHSA-7fhv-rp66-q6r9/GHSA-7fhv-rp66-q6r9.json +++ b/advisories/unreviewed/2023/02/GHSA-7fhv-rp66-q6r9/GHSA-7fhv-rp66-q6r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fhv-rp66-q6r9", - "modified": "2023-02-24T18:30:28Z", + "modified": "2025-03-21T21:31:28Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2022-43460" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-326" + "CWE-326", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-8vxm-rjvx-9v3r/GHSA-8vxm-rjvx-9v3r.json b/advisories/unreviewed/2023/02/GHSA-8vxm-rjvx-9v3r/GHSA-8vxm-rjvx-9v3r.json index fef2f67262e..b2e46bfc18c 100644 --- a/advisories/unreviewed/2023/02/GHSA-8vxm-rjvx-9v3r/GHSA-8vxm-rjvx-9v3r.json +++ b/advisories/unreviewed/2023/02/GHSA-8vxm-rjvx-9v3r/GHSA-8vxm-rjvx-9v3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8vxm-rjvx-9v3r", - "modified": "2023-02-23T06:30:17Z", + "modified": "2025-03-21T21:31:31Z", "published": "2023-02-13T15:30:26Z", "aliases": [ "CVE-2022-40022" diff --git a/advisories/unreviewed/2023/02/GHSA-9mqm-5q47-gj7c/GHSA-9mqm-5q47-gj7c.json b/advisories/unreviewed/2023/02/GHSA-9mqm-5q47-gj7c/GHSA-9mqm-5q47-gj7c.json index 651850e2b6f..381c70104e7 100644 --- a/advisories/unreviewed/2023/02/GHSA-9mqm-5q47-gj7c/GHSA-9mqm-5q47-gj7c.json +++ b/advisories/unreviewed/2023/02/GHSA-9mqm-5q47-gj7c/GHSA-9mqm-5q47-gj7c.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-9p88-mf79-r844/GHSA-9p88-mf79-r844.json b/advisories/unreviewed/2023/02/GHSA-9p88-mf79-r844/GHSA-9p88-mf79-r844.json index a3bcfa1337b..8705d8af2c0 100644 --- a/advisories/unreviewed/2023/02/GHSA-9p88-mf79-r844/GHSA-9p88-mf79-r844.json +++ b/advisories/unreviewed/2023/02/GHSA-9p88-mf79-r844/GHSA-9p88-mf79-r844.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9p88-mf79-r844", - "modified": "2023-02-27T15:30:22Z", + "modified": "2025-03-21T21:31:29Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2023-22347" diff --git a/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json b/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json index afc939f79ae..e2dbf190da7 100644 --- a/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json +++ b/advisories/unreviewed/2023/02/GHSA-9xvv-g7xh-f2qr/GHSA-9xvv-g7xh-f2qr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xvv-g7xh-f2qr", - "modified": "2023-02-15T18:30:20Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0799" diff --git a/advisories/unreviewed/2023/02/GHSA-c729-m2g9-m3xv/GHSA-c729-m2g9-m3xv.json b/advisories/unreviewed/2023/02/GHSA-c729-m2g9-m3xv/GHSA-c729-m2g9-m3xv.json index f95efd1711e..e5a036a02c9 100644 --- a/advisories/unreviewed/2023/02/GHSA-c729-m2g9-m3xv/GHSA-c729-m2g9-m3xv.json +++ b/advisories/unreviewed/2023/02/GHSA-c729-m2g9-m3xv/GHSA-c729-m2g9-m3xv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json b/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json index 9422436fb5e..15759b46c37 100644 --- a/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json +++ b/advisories/unreviewed/2023/02/GHSA-cjrm-898p-cxjr/GHSA-cjrm-898p-cxjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjrm-898p-cxjr", - "modified": "2023-02-15T18:30:21Z", + "modified": "2025-03-21T21:31:32Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0795" diff --git a/advisories/unreviewed/2023/02/GHSA-f8mh-8977-gx9m/GHSA-f8mh-8977-gx9m.json b/advisories/unreviewed/2023/02/GHSA-f8mh-8977-gx9m/GHSA-f8mh-8977-gx9m.json index b0efea28221..661b6c12e49 100644 --- a/advisories/unreviewed/2023/02/GHSA-f8mh-8977-gx9m/GHSA-f8mh-8977-gx9m.json +++ b/advisories/unreviewed/2023/02/GHSA-f8mh-8977-gx9m/GHSA-f8mh-8977-gx9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8mh-8977-gx9m", - "modified": "2023-02-27T18:32:03Z", + "modified": "2025-03-21T21:31:30Z", "published": "2023-02-13T03:30:28Z", "aliases": [ "CVE-2023-22360" diff --git a/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json b/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json index 98c5670b86a..8c219729399 100644 --- a/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json +++ b/advisories/unreviewed/2023/02/GHSA-g9vx-qcqw-wcpx/GHSA-g9vx-qcqw-wcpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9vx-qcqw-wcpx", - "modified": "2023-02-24T06:30:15Z", + "modified": "2025-03-21T21:31:31Z", "published": "2023-02-13T03:30:28Z", "aliases": [ "CVE-2023-22367" diff --git a/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json b/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json index 28c7e92c4f4..587e66f3c7b 100644 --- a/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json +++ b/advisories/unreviewed/2023/02/GHSA-m222-cmhp-v9m7/GHSA-m222-cmhp-v9m7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m222-cmhp-v9m7", - "modified": "2023-02-15T18:30:20Z", + "modified": "2025-03-21T21:31:32Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0796" diff --git a/advisories/unreviewed/2023/02/GHSA-q26g-j482-m359/GHSA-q26g-j482-m359.json b/advisories/unreviewed/2023/02/GHSA-q26g-j482-m359/GHSA-q26g-j482-m359.json index 7d8a6707a0d..c202034aaf2 100644 --- a/advisories/unreviewed/2023/02/GHSA-q26g-j482-m359/GHSA-q26g-j482-m359.json +++ b/advisories/unreviewed/2023/02/GHSA-q26g-j482-m359/GHSA-q26g-j482-m359.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q26g-j482-m359", - "modified": "2023-02-27T18:32:03Z", + "modified": "2025-03-21T21:31:30Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2023-22350" diff --git a/advisories/unreviewed/2023/02/GHSA-q6h2-6w35-jh4w/GHSA-q6h2-6w35-jh4w.json b/advisories/unreviewed/2023/02/GHSA-q6h2-6w35-jh4w/GHSA-q6h2-6w35-jh4w.json index 94bee2767d3..c00c7e8ce14 100644 --- a/advisories/unreviewed/2023/02/GHSA-q6h2-6w35-jh4w/GHSA-q6h2-6w35-jh4w.json +++ b/advisories/unreviewed/2023/02/GHSA-q6h2-6w35-jh4w/GHSA-q6h2-6w35-jh4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q6h2-6w35-jh4w", - "modified": "2023-02-27T15:30:22Z", + "modified": "2025-03-21T21:31:28Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2023-22345" diff --git a/advisories/unreviewed/2023/02/GHSA-q7q7-xc84-hcqj/GHSA-q7q7-xc84-hcqj.json b/advisories/unreviewed/2023/02/GHSA-q7q7-xc84-hcqj/GHSA-q7q7-xc84-hcqj.json index d0a1267772d..c371961b847 100644 --- a/advisories/unreviewed/2023/02/GHSA-q7q7-xc84-hcqj/GHSA-q7q7-xc84-hcqj.json +++ b/advisories/unreviewed/2023/02/GHSA-q7q7-xc84-hcqj/GHSA-q7q7-xc84-hcqj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-839" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json b/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json index a27fbffbf9c..cc0aadd2a68 100644 --- a/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json +++ b/advisories/unreviewed/2023/02/GHSA-rxvx-wrgw-qpv7/GHSA-rxvx-wrgw-qpv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rxvx-wrgw-qpv7", - "modified": "2023-02-15T18:30:21Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0802" diff --git a/advisories/unreviewed/2023/02/GHSA-w4fh-mw73-5c5w/GHSA-w4fh-mw73-5c5w.json b/advisories/unreviewed/2023/02/GHSA-w4fh-mw73-5c5w/GHSA-w4fh-mw73-5c5w.json index d814ac58232..5a102bb4e3d 100644 --- a/advisories/unreviewed/2023/02/GHSA-w4fh-mw73-5c5w/GHSA-w4fh-mw73-5c5w.json +++ b/advisories/unreviewed/2023/02/GHSA-w4fh-mw73-5c5w/GHSA-w4fh-mw73-5c5w.json @@ -34,7 +34,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-1284", + "CWE-20", + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-w8wp-rv4w-h5pp/GHSA-w8wp-rv4w-h5pp.json b/advisories/unreviewed/2023/02/GHSA-w8wp-rv4w-h5pp/GHSA-w8wp-rv4w-h5pp.json index b55b209372d..992bc23d303 100644 --- a/advisories/unreviewed/2023/02/GHSA-w8wp-rv4w-h5pp/GHSA-w8wp-rv4w-h5pp.json +++ b/advisories/unreviewed/2023/02/GHSA-w8wp-rv4w-h5pp/GHSA-w8wp-rv4w-h5pp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8wp-rv4w-h5pp", - "modified": "2023-03-13T15:30:19Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-02-28T18:30:16Z", "aliases": [ "CVE-2023-27320" @@ -19,6 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27320" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLXMRAMXC3BYL4DNKVTK3V6JDMUXZ7B" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6VW24YGXJYI4NZ5HZPQCF4MCE7766AU" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/332KN4QI6QXB7NI7SWSJ2EQJKWIILFN6" diff --git a/advisories/unreviewed/2023/02/GHSA-wm4x-x4q5-34vq/GHSA-wm4x-x4q5-34vq.json b/advisories/unreviewed/2023/02/GHSA-wm4x-x4q5-34vq/GHSA-wm4x-x4q5-34vq.json index 701c361960f..b27ea6a79ba 100644 --- a/advisories/unreviewed/2023/02/GHSA-wm4x-x4q5-34vq/GHSA-wm4x-x4q5-34vq.json +++ b/advisories/unreviewed/2023/02/GHSA-wm4x-x4q5-34vq/GHSA-wm4x-x4q5-34vq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wm4x-x4q5-34vq", - "modified": "2023-02-27T15:30:22Z", + "modified": "2025-03-21T21:31:29Z", "published": "2023-02-13T03:30:29Z", "aliases": [ "CVE-2023-22346" diff --git a/advisories/unreviewed/2023/02/GHSA-xmcc-cx53-xxg3/GHSA-xmcc-cx53-xxg3.json b/advisories/unreviewed/2023/02/GHSA-xmcc-cx53-xxg3/GHSA-xmcc-cx53-xxg3.json index e1ec5cd63f9..d618271f6f7 100644 --- a/advisories/unreviewed/2023/02/GHSA-xmcc-cx53-xxg3/GHSA-xmcc-cx53-xxg3.json +++ b/advisories/unreviewed/2023/02/GHSA-xmcc-cx53-xxg3/GHSA-xmcc-cx53-xxg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmcc-cx53-xxg3", - "modified": "2023-02-15T18:30:21Z", + "modified": "2025-03-21T21:31:32Z", "published": "2023-02-14T00:30:20Z", "aliases": [ "CVE-2023-0798" diff --git a/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json b/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json index bc803a789f8..9fff48761d4 100644 --- a/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json +++ b/advisories/unreviewed/2023/07/GHSA-hc89-xf9q-xh2p/GHSA-hc89-xf9q-xh2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hc89-xf9q-xh2p", - "modified": "2024-04-04T05:33:38Z", + "modified": "2025-03-21T21:31:33Z", "published": "2023-07-06T19:24:10Z", "aliases": [ "CVE-2023-27293" diff --git a/advisories/unreviewed/2024/03/GHSA-3q36-645m-456x/GHSA-3q36-645m-456x.json b/advisories/unreviewed/2024/03/GHSA-3q36-645m-456x/GHSA-3q36-645m-456x.json index ac4bd6a5102..ff2db1b44a2 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q36-645m-456x/GHSA-3q36-645m-456x.json +++ b/advisories/unreviewed/2024/03/GHSA-3q36-645m-456x/GHSA-3q36-645m-456x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3q36-645m-456x", - "modified": "2024-03-31T21:30:35Z", + "modified": "2025-03-21T21:31:33Z", "published": "2024-03-31T21:30:35Z", "aliases": [ "CVE-2024-31120" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Stored XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Stored XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-cfwg-f58j-689r/GHSA-cfwg-f58j-689r.json b/advisories/unreviewed/2024/03/GHSA-cfwg-f58j-689r/GHSA-cfwg-f58j-689r.json index 9488758c6be..fb90f95f044 100644 --- a/advisories/unreviewed/2024/03/GHSA-cfwg-f58j-689r/GHSA-cfwg-f58j-689r.json +++ b/advisories/unreviewed/2024/03/GHSA-cfwg-f58j-689r/GHSA-cfwg-f58j-689r.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pqhm-crg4-8x2v/GHSA-pqhm-crg4-8x2v.json b/advisories/unreviewed/2024/03/GHSA-pqhm-crg4-8x2v/GHSA-pqhm-crg4-8x2v.json index 0bb42de69cc..33a4a5e4253 100644 --- a/advisories/unreviewed/2024/03/GHSA-pqhm-crg4-8x2v/GHSA-pqhm-crg4-8x2v.json +++ b/advisories/unreviewed/2024/03/GHSA-pqhm-crg4-8x2v/GHSA-pqhm-crg4-8x2v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pqhm-crg4-8x2v", - "modified": "2024-03-31T21:30:36Z", + "modified": "2025-03-21T21:31:33Z", "published": "2024-03-31T21:30:36Z", "aliases": [ "CVE-2024-30524" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedLettuce Plugins PDF Viewer for Elementor allows Stored XSS.This issue affects PDF Viewer for Elementor: from n/a through 2.9.3.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedLettuce Plugins PDF Viewer for Elementor allows Stored XSS.This issue affects PDF Viewer for Elementor: from n/a through 2.9.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-pr9m-x2x5-mj6q/GHSA-pr9m-x2x5-mj6q.json b/advisories/unreviewed/2024/03/GHSA-pr9m-x2x5-mj6q/GHSA-pr9m-x2x5-mj6q.json index 7ade52fd94d..290e27baf41 100644 --- a/advisories/unreviewed/2024/03/GHSA-pr9m-x2x5-mj6q/GHSA-pr9m-x2x5-mj6q.json +++ b/advisories/unreviewed/2024/03/GHSA-pr9m-x2x5-mj6q/GHSA-pr9m-x2x5-mj6q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pr9m-x2x5-mj6q", - "modified": "2024-03-31T21:30:35Z", + "modified": "2025-03-21T21:31:33Z", "published": "2024-03-31T21:30:35Z", "aliases": [ "CVE-2024-31108" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iFlyChat Team iFlyChat – WordPress Chat iflychat allows Stored XSS.This issue affects iFlyChat – WordPress Chat: from n/a through 4.7.2.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iFlyChat Team iFlyChat – WordPress Chat iflychat allows Stored XSS.This issue affects iFlyChat – WordPress Chat: from n/a through 4.7.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-q9f9-jvjh-rmh2/GHSA-q9f9-jvjh-rmh2.json b/advisories/unreviewed/2024/03/GHSA-q9f9-jvjh-rmh2/GHSA-q9f9-jvjh-rmh2.json index 4b7a5a66aff..e85f25a7879 100644 --- a/advisories/unreviewed/2024/03/GHSA-q9f9-jvjh-rmh2/GHSA-q9f9-jvjh-rmh2.json +++ b/advisories/unreviewed/2024/03/GHSA-q9f9-jvjh-rmh2/GHSA-q9f9-jvjh-rmh2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q9f9-jvjh-rmh2", - "modified": "2024-03-31T21:30:36Z", + "modified": "2025-03-21T21:31:33Z", "published": "2024-03-31T21:30:36Z", "aliases": [ "CVE-2024-30550" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json b/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json index 5d3bf7f90c8..5e0c9be2032 100644 --- a/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json +++ b/advisories/unreviewed/2024/04/GHSA-j2hp-jqgm-85pf/GHSA-j2hp-jqgm-85pf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j2hp-jqgm-85pf", - "modified": "2024-04-26T09:30:34Z", + "modified": "2025-03-21T21:31:34Z", "published": "2024-04-26T09:30:34Z", "aliases": [ "CVE-2024-33639" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-r5wc-932c-2vmp/GHSA-r5wc-932c-2vmp.json b/advisories/unreviewed/2024/04/GHSA-r5wc-932c-2vmp/GHSA-r5wc-932c-2vmp.json index 3a574aced0b..70795793afd 100644 --- a/advisories/unreviewed/2024/04/GHSA-r5wc-932c-2vmp/GHSA-r5wc-932c-2vmp.json +++ b/advisories/unreviewed/2024/04/GHSA-r5wc-932c-2vmp/GHSA-r5wc-932c-2vmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5wc-932c-2vmp", - "modified": "2024-04-17T15:30:42Z", + "modified": "2025-03-21T21:31:34Z", "published": "2024-04-17T15:30:42Z", "aliases": [ "CVE-2024-30952" ], "details": "A stored cross-site scripting (XSS) vulnerability in PESCMS-TEAM v2.3.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the domain input field under /youdoamin/?g=Team&m=Setting&a=action.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T13:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fmp7-q9w4-g4x8/GHSA-fmp7-q9w4-g4x8.json b/advisories/unreviewed/2024/05/GHSA-fmp7-q9w4-g4x8/GHSA-fmp7-q9w4-g4x8.json index 243e554b98a..eabe1ed849b 100644 --- a/advisories/unreviewed/2024/05/GHSA-fmp7-q9w4-g4x8/GHSA-fmp7-q9w4-g4x8.json +++ b/advisories/unreviewed/2024/05/GHSA-fmp7-q9w4-g4x8/GHSA-fmp7-q9w4-g4x8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmp7-q9w4-g4x8", - "modified": "2024-05-15T00:30:38Z", + "modified": "2025-03-21T21:31:34Z", "published": "2024-05-15T00:30:38Z", "aliases": [ "CVE-2024-4666" @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json b/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json index 7455f424c93..c31143fc87b 100644 --- a/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json +++ b/advisories/unreviewed/2024/07/GHSA-ccvr-35jj-hp58/GHSA-ccvr-35jj-hp58.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-x7gr-mmjj-hx3h/GHSA-x7gr-mmjj-hx3h.json b/advisories/unreviewed/2024/11/GHSA-x7gr-mmjj-hx3h/GHSA-x7gr-mmjj-hx3h.json index 9afc43af27e..8b51eb6dd0b 100644 --- a/advisories/unreviewed/2024/11/GHSA-x7gr-mmjj-hx3h/GHSA-x7gr-mmjj-hx3h.json +++ b/advisories/unreviewed/2024/11/GHSA-x7gr-mmjj-hx3h/GHSA-x7gr-mmjj-hx3h.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1336" + "CWE-1336", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json b/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json new file mode 100644 index 00000000000..08e2a07d011 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-536x-p3x6-xv85/GHSA-536x-p3x6-xv85.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-536x-p3x6-xv85", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-2604" + ], + "details": "A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_act.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2604" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/issues/14" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300588" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300588" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517965" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T21:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5hc5-9qwg-w899/GHSA-5hc5-9qwg-w899.json b/advisories/unreviewed/2025/03/GHSA-5hc5-9qwg-w899/GHSA-5hc5-9qwg-w899.json index 43f9d8869e7..40f0d86fc6a 100644 --- a/advisories/unreviewed/2025/03/GHSA-5hc5-9qwg-w899/GHSA-5hc5-9qwg-w899.json +++ b/advisories/unreviewed/2025/03/GHSA-5hc5-9qwg-w899/GHSA-5hc5-9qwg-w899.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5hc5-9qwg-w899", - "modified": "2025-03-11T18:32:13Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-11T18:32:13Z", "aliases": [ "CVE-2025-25680" ], "details": "LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T16:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5hqf-7qhr-wqc3/GHSA-5hqf-7qhr-wqc3.json b/advisories/unreviewed/2025/03/GHSA-5hqf-7qhr-wqc3/GHSA-5hqf-7qhr-wqc3.json new file mode 100644 index 00000000000..562a0f3eb63 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5hqf-7qhr-wqc3/GHSA-5hqf-7qhr-wqc3.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hqf-7qhr-wqc3", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-25036" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25036" + }, + { + "type": "WEB", + "url": "https://community.jalios.com/jcms/jc1_893720/en/security-alert-2025-02-19" + }, + { + "type": "WEB", + "url": "https://issues.jalios.com/browse/JCMS-11250" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/jalios-jplatform-xxe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json b/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json index fe304702208..146bb5d3f9f 100644 --- a/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json +++ b/advisories/unreviewed/2025/03/GHSA-5p7f-cf35-c9jf/GHSA-5p7f-cf35-c9jf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5p7f-cf35-c9jf", - "modified": "2025-03-20T15:30:36Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T15:30:36Z", "aliases": [ "CVE-2025-29412" ], "details": "A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T14:15:24Z" diff --git a/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json b/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json index 23c67d92028..d0412abe35a 100644 --- a/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json +++ b/advisories/unreviewed/2025/03/GHSA-694q-974v-33w7/GHSA-694q-974v-33w7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-694q-974v-33w7", - "modified": "2025-03-20T15:30:36Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T15:30:36Z", "aliases": [ "CVE-2025-29410" ], "details": "A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T14:15:24Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6fm4-x4xg-v3xr/GHSA-6fm4-x4xg-v3xr.json b/advisories/unreviewed/2025/03/GHSA-6fm4-x4xg-v3xr/GHSA-6fm4-x4xg-v3xr.json new file mode 100644 index 00000000000..d3af329bf63 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6fm4-x4xg-v3xr/GHSA-6fm4-x4xg-v3xr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fm4-x4xg-v3xr", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-2602" + ], + "details": "A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file deactivate_reg.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2602" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/issues/11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300586" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300586" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517960" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6fxv-ffp4-g24h/GHSA-6fxv-ffp4-g24h.json b/advisories/unreviewed/2025/03/GHSA-6fxv-ffp4-g24h/GHSA-6fxv-ffp4-g24h.json new file mode 100644 index 00000000000..84c3fcdfcb7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6fxv-ffp4-g24h/GHSA-6fxv-ffp4-g24h.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fxv-ffp4-g24h", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:38Z", + "aliases": [ + "CVE-2025-25035" + ], + "details": "Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform 10: before 10.0.8 (SP8), before 10.0.7 (SP7), before 10.0.6 (SP6) and Jalios Workplace 6.2, Jalios Workplace 6.1, Jalios Workplace 6.0, and Jalios Workplace 5.3 to 5.5", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25035" + }, + { + "type": "WEB", + "url": "https://community.jalios.com/jcms/jc1_893720/en/security-alert-2025-02-19" + }, + { + "type": "WEB", + "url": "https://issues.jalios.com/browse/JCMS-11246" + }, + { + "type": "WEB", + "url": "https://issues.jalios.com/browse/JCMS-11248" + }, + { + "type": "WEB", + "url": "https://issues.jalios.com/browse/JCMS-11259" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/jalios-jplatform-xss" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T19:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cwhr-q9q3-q73r/GHSA-cwhr-q9q3-q73r.json b/advisories/unreviewed/2025/03/GHSA-cwhr-q9q3-q73r/GHSA-cwhr-q9q3-q73r.json new file mode 100644 index 00000000000..29686c8b0d4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cwhr-q9q3-q73r/GHSA-cwhr-q9q3-q73r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwhr-q9q3-q73r", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-2603" + ], + "details": "A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file deactivate.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2603" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/issues/12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300587" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300587" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517963" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json b/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json index 2679d328e2b..46fb0271498 100644 --- a/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json +++ b/advisories/unreviewed/2025/03/GHSA-g57w-j5gj-29qx/GHSA-g57w-j5gj-29qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g57w-j5gj-29qx", - "modified": "2025-03-11T15:31:01Z", + "modified": "2025-03-21T21:31:37Z", "published": "2025-03-11T15:31:01Z", "aliases": [ "CVE-2024-51319" ], "details": "A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T15:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j48m-433v-3q7r/GHSA-j48m-433v-3q7r.json b/advisories/unreviewed/2025/03/GHSA-j48m-433v-3q7r/GHSA-j48m-433v-3q7r.json index f1c4f0e518a..49dd67dcb87 100644 --- a/advisories/unreviewed/2025/03/GHSA-j48m-433v-3q7r/GHSA-j48m-433v-3q7r.json +++ b/advisories/unreviewed/2025/03/GHSA-j48m-433v-3q7r/GHSA-j48m-433v-3q7r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j48m-433v-3q7r", - "modified": "2025-03-20T18:30:30Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T18:30:30Z", "aliases": [ "CVE-2024-57440" ], "details": "D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T17:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-mghv-5x2h-9q5v/GHSA-mghv-5x2h-9q5v.json b/advisories/unreviewed/2025/03/GHSA-mghv-5x2h-9q5v/GHSA-mghv-5x2h-9q5v.json new file mode 100644 index 00000000000..d32b82fe5aa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mghv-5x2h-9q5v/GHSA-mghv-5x2h-9q5v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mghv-5x2h-9q5v", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-2601" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file activate_reg.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2601" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300585" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300585" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517959" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T20:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json b/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json new file mode 100644 index 00000000000..9c9ad8ba7d2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p2r4-qh4v-qvh7/GHSA-p2r4-qh4v-qvh7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2r4-qh4v-qvh7", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-2607" + ], + "details": "A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/upload/upimage.html of the component HTTP POST Request Handler. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2607" + }, + { + "type": "WEB", + "url": "https://github.com/Jingyi-u/lzcms/tree/main" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300590" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300590" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.518021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T21:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p6r9-p725-g42c/GHSA-p6r9-p725-g42c.json b/advisories/unreviewed/2025/03/GHSA-p6r9-p725-g42c/GHSA-p6r9-p725-g42c.json index 37e9714d05f..e9b8ef5a840 100644 --- a/advisories/unreviewed/2025/03/GHSA-p6r9-p725-g42c/GHSA-p6r9-p725-g42c.json +++ b/advisories/unreviewed/2025/03/GHSA-p6r9-p725-g42c/GHSA-p6r9-p725-g42c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p6r9-p725-g42c", - "modified": "2025-03-11T18:32:19Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2021-37787" ], "details": "The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE module", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T18:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pgpf-3pvh-h5g7/GHSA-pgpf-3pvh-h5g7.json b/advisories/unreviewed/2025/03/GHSA-pgpf-3pvh-h5g7/GHSA-pgpf-3pvh-h5g7.json index e923741aa94..fa1b50fa70c 100644 --- a/advisories/unreviewed/2025/03/GHSA-pgpf-3pvh-h5g7/GHSA-pgpf-3pvh-h5g7.json +++ b/advisories/unreviewed/2025/03/GHSA-pgpf-3pvh-h5g7/GHSA-pgpf-3pvh-h5g7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pgpf-3pvh-h5g7", - "modified": "2025-03-20T18:30:30Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T18:30:30Z", "aliases": [ "CVE-2025-29149" ], "details": "Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T17:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r375-j569-v9qr/GHSA-r375-j569-v9qr.json b/advisories/unreviewed/2025/03/GHSA-r375-j569-v9qr/GHSA-r375-j569-v9qr.json index 40fc0882b7b..58e85482c54 100644 --- a/advisories/unreviewed/2025/03/GHSA-r375-j569-v9qr/GHSA-r375-j569-v9qr.json +++ b/advisories/unreviewed/2025/03/GHSA-r375-j569-v9qr/GHSA-r375-j569-v9qr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r375-j569-v9qr", - "modified": "2025-03-11T18:32:21Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-11T18:32:20Z", "aliases": [ "CVE-2025-25748" ], "details": "A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T18:15:32Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json b/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json index f6919f124b8..565e64c0301 100644 --- a/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json +++ b/advisories/unreviewed/2025/03/GHSA-r63r-pwwp-jvj8/GHSA-r63r-pwwp-jvj8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r63r-pwwp-jvj8", - "modified": "2025-03-11T15:31:02Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-11T15:31:02Z", "aliases": [ "CVE-2024-51321" ], "details": "In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T15:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v222-4cxf-9gp4/GHSA-v222-4cxf-9gp4.json b/advisories/unreviewed/2025/03/GHSA-v222-4cxf-9gp4/GHSA-v222-4cxf-9gp4.json index 206bae98c91..9e6f4378302 100644 --- a/advisories/unreviewed/2025/03/GHSA-v222-4cxf-9gp4/GHSA-v222-4cxf-9gp4.json +++ b/advisories/unreviewed/2025/03/GHSA-v222-4cxf-9gp4/GHSA-v222-4cxf-9gp4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v222-4cxf-9gp4", - "modified": "2025-03-20T18:30:30Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T18:30:30Z", "aliases": [ "CVE-2025-29214" ], "details": "Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T16:15:16Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v6jq-9h5f-2qcm/GHSA-v6jq-9h5f-2qcm.json b/advisories/unreviewed/2025/03/GHSA-v6jq-9h5f-2qcm/GHSA-v6jq-9h5f-2qcm.json index f6a904af47e..7a98fecacbc 100644 --- a/advisories/unreviewed/2025/03/GHSA-v6jq-9h5f-2qcm/GHSA-v6jq-9h5f-2qcm.json +++ b/advisories/unreviewed/2025/03/GHSA-v6jq-9h5f-2qcm/GHSA-v6jq-9h5f-2qcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v6jq-9h5f-2qcm", - "modified": "2025-03-20T18:30:30Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T18:30:30Z", "aliases": [ "CVE-2025-29121" ], "details": "A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T17:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json b/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json index 009a20600ea..bb233c5d915 100644 --- a/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json +++ b/advisories/unreviewed/2025/03/GHSA-whf8-w5vj-q4w6/GHSA-whf8-w5vj-q4w6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-whf8-w5vj-q4w6", - "modified": "2025-03-20T15:30:36Z", + "modified": "2025-03-21T21:31:38Z", "published": "2025-03-20T15:30:36Z", "aliases": [ "CVE-2024-48591" ], "details": "Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T15:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json b/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json new file mode 100644 index 00000000000..cb0588f77e1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xhqx-hw3w-p9q3/GHSA-xhqx-hw3w-p9q3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhqx-hw3w-p9q3", + "modified": "2025-03-21T21:31:39Z", + "published": "2025-03-21T21:31:39Z", + "aliases": [ + "CVE-2025-2606" + ], + "details": "A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/soulwinning_crud.php. The manipulation of the argument photo/photo1 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2606" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/issues/15" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300589" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300589" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517974" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-21T21:15:37Z" + } +} \ No newline at end of file