From 91e845e8d5f1a3fb166ba39904ca761e52538bfc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 18 Mar 2025 15:32:36 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-43f2-6v99-hw83.json | 2 +- .../GHSA-7xgx-9pjc-2mv2.json | 2 +- .../GHSA-cw64-pq7m-342r.json | 10 +++- .../GHSA-fw8v-fr5c-x5f2.json | 4 +- .../GHSA-pxm3-f86h-vqrh.json | 6 +- .../GHSA-2j4p-2hc9-62f4.json | 6 +- .../GHSA-7gc2-q47v-36w5.json | 2 +- .../GHSA-pw3p-p75r-9r3f.json | 2 +- .../GHSA-6968-c3wh-v3mp.json | 4 +- .../GHSA-f99v-cqxr-cqqw.json | 5 +- .../GHSA-jwgq-m238-m247.json | 4 +- .../GHSA-4qgr-49jh-j3vp.json | 11 +++- .../GHSA-9hp2-5m46-r478.json | 15 +++-- .../GHSA-pjmm-jqrg-3hmg.json | 4 +- .../GHSA-xrwr-3m4h-cqcx.json | 4 +- .../GHSA-4j27-qhm5-88w7.json | 15 +++-- .../GHSA-hw5v-77jj-prp8.json | 11 +++- .../GHSA-24q7-jrrv-9x9w.json | 4 +- .../GHSA-335g-4xxp-8f55.json | 4 +- .../GHSA-5pv6-mmq6-6w3p.json | 4 +- .../GHSA-g53m-h56g-8c6v.json | 4 +- .../GHSA-rqrc-553g-fmrv.json | 2 +- .../GHSA-9g9q-cf56-cfh9.json | 4 +- .../GHSA-fqcp-xv9m-hcq2.json | 4 +- .../GHSA-pg35-867h-jm8h.json | 4 +- .../GHSA-whhw-2v2c-qg98.json | 6 +- .../GHSA-6v4c-8jrj-xwqj.json | 2 +- .../GHSA-2gqx-rmcg-8rp8.json | 1 + .../GHSA-363m-f7wv-qpfm.json | 1 + .../GHSA-429g-77c6-6p2v.json | 1 + .../GHSA-5cvp-4pwp-rvg8.json | 1 + .../GHSA-6xh4-6995-ppc6.json | 3 +- .../GHSA-7jj7-mxgf-79rv.json | 4 +- .../GHSA-fq6x-64vf-73q4.json | 3 +- .../GHSA-gw84-4qc8-q6cv.json | 3 +- .../GHSA-jhf5-fj8j-2h29.json | 1 + .../GHSA-p2xw-hr6c-g7h5.json | 3 +- .../GHSA-qhv7-wrpv-c54g.json | 1 + .../GHSA-r498-8rcj-p67x.json | 1 + .../GHSA-r9mp-qr63-99pq.json | 1 + .../GHSA-v4mm-j7r5-wxq4.json | 3 +- .../GHSA-wjxf-6r8p-9pvp.json | 1 + .../GHSA-99fv-v434-wh6f.json | 3 +- .../GHSA-2fm6-qmmh-8rv2.json | 56 +++++++++++++++++++ .../GHSA-2x4h-j98j-x2mw.json | 33 +++++++++++ .../GHSA-52gf-54f2-3825.json | 36 ++++++++++++ .../GHSA-5rfm-vp96-44gv.json | 33 +++++++++++ .../GHSA-639q-6q9p-hmc8.json | 36 ++++++++++++ .../GHSA-6hc9-74fh-6p7m.json | 29 ++++++++++ .../GHSA-78wq-w58w-pxgj.json | 36 ++++++++++++ .../GHSA-7gmh-9cm3-f962.json | 33 +++++++++++ .../GHSA-7q6m-9v39-q68q.json | 33 +++++++++++ .../GHSA-82gg-jm8m-39w6.json | 33 +++++++++++ .../GHSA-82xf-2h8m-pmc5.json | 29 ++++++++++ .../GHSA-966q-fgpf-cj7x.json | 29 ++++++++++ .../GHSA-9j5w-qvpr-crjv.json | 36 ++++++++++++ .../GHSA-9v3j-xfw8-fgh8.json | 33 +++++++++++ .../GHSA-cg8r-jwg7-r2x4.json | 33 +++++++++++ .../GHSA-fch9-7g2p-f49f.json | 36 ++++++++++++ .../GHSA-fpq3-c96f-26mv.json | 33 +++++++++++ .../GHSA-fxh3-9v44-3m3r.json | 36 ++++++++++++ .../GHSA-g38j-p66c-6qhp.json | 33 +++++++++++ .../GHSA-gg2f-r4jh-vpmh.json | 33 +++++++++++ .../GHSA-j5w5-3c3j-vg23.json | 52 +++++++++++++++++ .../GHSA-jg9g-2m55-m7hp.json | 33 +++++++++++ .../GHSA-jxv5-hhvx-cmg6.json | 33 +++++++++++ .../GHSA-m569-r4hr-26cw.json | 33 +++++++++++ .../GHSA-qvq7-g7xm-xr5h.json | 33 +++++++++++ .../GHSA-w5h7-mw56-4v7x.json | 33 +++++++++++ .../GHSA-wqh3-vwc7-rhvg.json | 33 +++++++++++ 70 files changed, 1068 insertions(+), 47 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2fm6-qmmh-8rv2/GHSA-2fm6-qmmh-8rv2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2x4h-j98j-x2mw/GHSA-2x4h-j98j-x2mw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-52gf-54f2-3825/GHSA-52gf-54f2-3825.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-639q-6q9p-hmc8/GHSA-639q-6q9p-hmc8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-78wq-w58w-pxgj/GHSA-78wq-w58w-pxgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7gmh-9cm3-f962/GHSA-7gmh-9cm3-f962.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7q6m-9v39-q68q/GHSA-7q6m-9v39-q68q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9j5w-qvpr-crjv/GHSA-9j5w-qvpr-crjv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9v3j-xfw8-fgh8/GHSA-9v3j-xfw8-fgh8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cg8r-jwg7-r2x4/GHSA-cg8r-jwg7-r2x4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fch9-7g2p-f49f/GHSA-fch9-7g2p-f49f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fpq3-c96f-26mv/GHSA-fpq3-c96f-26mv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fxh3-9v44-3m3r/GHSA-fxh3-9v44-3m3r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j5w5-3c3j-vg23/GHSA-j5w5-3c3j-vg23.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jxv5-hhvx-cmg6/GHSA-jxv5-hhvx-cmg6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wqh3-vwc7-rhvg/GHSA-wqh3-vwc7-rhvg.json diff --git a/advisories/unreviewed/2022/05/GHSA-43f2-6v99-hw83/GHSA-43f2-6v99-hw83.json b/advisories/unreviewed/2022/05/GHSA-43f2-6v99-hw83/GHSA-43f2-6v99-hw83.json index d763ef0e862..f0c90975aa6 100644 --- a/advisories/unreviewed/2022/05/GHSA-43f2-6v99-hw83/GHSA-43f2-6v99-hw83.json +++ b/advisories/unreviewed/2022/05/GHSA-43f2-6v99-hw83/GHSA-43f2-6v99-hw83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43f2-6v99-hw83", - "modified": "2022-05-14T00:57:42Z", + "modified": "2025-03-18T15:30:35Z", "published": "2022-05-14T00:57:42Z", "aliases": [ "CVE-2012-5853" diff --git a/advisories/unreviewed/2023/02/GHSA-7xgx-9pjc-2mv2/GHSA-7xgx-9pjc-2mv2.json b/advisories/unreviewed/2023/02/GHSA-7xgx-9pjc-2mv2/GHSA-7xgx-9pjc-2mv2.json index b6377850bf9..1d3c964159c 100644 --- a/advisories/unreviewed/2023/02/GHSA-7xgx-9pjc-2mv2/GHSA-7xgx-9pjc-2mv2.json +++ b/advisories/unreviewed/2023/02/GHSA-7xgx-9pjc-2mv2/GHSA-7xgx-9pjc-2mv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xgx-9pjc-2mv2", - "modified": "2023-03-06T18:30:22Z", + "modified": "2025-03-18T15:30:36Z", "published": "2023-02-23T18:31:06Z", "aliases": [ "CVE-2023-24104" diff --git a/advisories/unreviewed/2023/02/GHSA-cw64-pq7m-342r/GHSA-cw64-pq7m-342r.json b/advisories/unreviewed/2023/02/GHSA-cw64-pq7m-342r/GHSA-cw64-pq7m-342r.json index c3d8adb330e..fd372861f62 100644 --- a/advisories/unreviewed/2023/02/GHSA-cw64-pq7m-342r/GHSA-cw64-pq7m-342r.json +++ b/advisories/unreviewed/2023/02/GHSA-cw64-pq7m-342r/GHSA-cw64-pq7m-342r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw64-pq7m-342r", - "modified": "2023-02-28T21:30:17Z", + "modified": "2025-03-18T15:30:35Z", "published": "2023-02-20T03:30:18Z", "aliases": [ "CVE-2023-26081" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00015.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFWUNG6E4ZT43EYNHKYXS7QVSO2VW2H2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SADQCSQKTJKTTIJMEPY7GII6IVQSKEKV" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFWUNG6E4ZT43EYNHKYXS7QVSO2VW2H2" diff --git a/advisories/unreviewed/2023/02/GHSA-fw8v-fr5c-x5f2/GHSA-fw8v-fr5c-x5f2.json b/advisories/unreviewed/2023/02/GHSA-fw8v-fr5c-x5f2/GHSA-fw8v-fr5c-x5f2.json index 0e10f67a9a6..dcac734a239 100644 --- a/advisories/unreviewed/2023/02/GHSA-fw8v-fr5c-x5f2/GHSA-fw8v-fr5c-x5f2.json +++ b/advisories/unreviewed/2023/02/GHSA-fw8v-fr5c-x5f2/GHSA-fw8v-fr5c-x5f2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-pxm3-f86h-vqrh/GHSA-pxm3-f86h-vqrh.json b/advisories/unreviewed/2023/02/GHSA-pxm3-f86h-vqrh/GHSA-pxm3-f86h-vqrh.json index 8ed4e8d155a..019cf22ca3f 100644 --- a/advisories/unreviewed/2023/02/GHSA-pxm3-f86h-vqrh/GHSA-pxm3-f86h-vqrh.json +++ b/advisories/unreviewed/2023/02/GHSA-pxm3-f86h-vqrh/GHSA-pxm3-f86h-vqrh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxm3-f86h-vqrh", - "modified": "2023-03-03T18:30:27Z", + "modified": "2025-03-18T15:30:35Z", "published": "2023-02-22T00:30:31Z", "aliases": [ "CVE-2023-24320" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-2j4p-2hc9-62f4/GHSA-2j4p-2hc9-62f4.json b/advisories/unreviewed/2023/03/GHSA-2j4p-2hc9-62f4/GHSA-2j4p-2hc9-62f4.json index 18590987a13..cfe27c836b5 100644 --- a/advisories/unreviewed/2023/03/GHSA-2j4p-2hc9-62f4/GHSA-2j4p-2hc9-62f4.json +++ b/advisories/unreviewed/2023/03/GHSA-2j4p-2hc9-62f4/GHSA-2j4p-2hc9-62f4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j4p-2hc9-62f4", - "modified": "2023-03-10T18:30:23Z", + "modified": "2025-03-18T15:30:36Z", "published": "2023-03-01T00:30:37Z", "aliases": [ "CVE-2022-23240" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-7gc2-q47v-36w5/GHSA-7gc2-q47v-36w5.json b/advisories/unreviewed/2023/03/GHSA-7gc2-q47v-36w5/GHSA-7gc2-q47v-36w5.json index caf12b00947..2f3e8d26756 100644 --- a/advisories/unreviewed/2023/03/GHSA-7gc2-q47v-36w5/GHSA-7gc2-q47v-36w5.json +++ b/advisories/unreviewed/2023/03/GHSA-7gc2-q47v-36w5/GHSA-7gc2-q47v-36w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7gc2-q47v-36w5", - "modified": "2023-03-06T15:30:42Z", + "modified": "2025-03-18T15:30:36Z", "published": "2023-03-01T00:30:37Z", "aliases": [ "CVE-2022-47075" diff --git a/advisories/unreviewed/2023/03/GHSA-pw3p-p75r-9r3f/GHSA-pw3p-p75r-9r3f.json b/advisories/unreviewed/2023/03/GHSA-pw3p-p75r-9r3f/GHSA-pw3p-p75r-9r3f.json index 3bed81abe25..0f1e3f9426c 100644 --- a/advisories/unreviewed/2023/03/GHSA-pw3p-p75r-9r3f/GHSA-pw3p-p75r-9r3f.json +++ b/advisories/unreviewed/2023/03/GHSA-pw3p-p75r-9r3f/GHSA-pw3p-p75r-9r3f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pw3p-p75r-9r3f", - "modified": "2023-03-06T15:30:42Z", + "modified": "2025-03-18T15:30:36Z", "published": "2023-03-01T00:30:36Z", "aliases": [ "CVE-2022-47076" diff --git a/advisories/unreviewed/2024/02/GHSA-6968-c3wh-v3mp/GHSA-6968-c3wh-v3mp.json b/advisories/unreviewed/2024/02/GHSA-6968-c3wh-v3mp/GHSA-6968-c3wh-v3mp.json index 7c5c31cba1a..93ab26435a0 100644 --- a/advisories/unreviewed/2024/02/GHSA-6968-c3wh-v3mp/GHSA-6968-c3wh-v3mp.json +++ b/advisories/unreviewed/2024/02/GHSA-6968-c3wh-v3mp/GHSA-6968-c3wh-v3mp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json b/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json index 78268aed6c4..58282e420aa 100644 --- a/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json +++ b/advisories/unreviewed/2024/02/GHSA-f99v-cqxr-cqqw/GHSA-f99v-cqxr-cqqw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f99v-cqxr-cqqw", - "modified": "2024-12-18T18:30:49Z", + "modified": "2025-03-18T15:30:36Z", "published": "2024-02-15T21:31:27Z", "aliases": [ "CVE-2023-6123" ], - "details": "Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack. \n\n\n", + "details": "Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.", "severity": [ { "type": "CVSS_V3", @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-707", "CWE-79" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-jwgq-m238-m247/GHSA-jwgq-m238-m247.json b/advisories/unreviewed/2024/02/GHSA-jwgq-m238-m247/GHSA-jwgq-m238-m247.json index 94d95b55851..04b5fb0ca13 100644 --- a/advisories/unreviewed/2024/02/GHSA-jwgq-m238-m247/GHSA-jwgq-m238-m247.json +++ b/advisories/unreviewed/2024/02/GHSA-jwgq-m238-m247/GHSA-jwgq-m238-m247.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4qgr-49jh-j3vp/GHSA-4qgr-49jh-j3vp.json b/advisories/unreviewed/2024/03/GHSA-4qgr-49jh-j3vp/GHSA-4qgr-49jh-j3vp.json index 1f6a0184fcf..d307b73bd74 100644 --- a/advisories/unreviewed/2024/03/GHSA-4qgr-49jh-j3vp/GHSA-4qgr-49jh-j3vp.json +++ b/advisories/unreviewed/2024/03/GHSA-4qgr-49jh-j3vp/GHSA-4qgr-49jh-j3vp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4qgr-49jh-j3vp", - "modified": "2024-03-16T06:30:28Z", + "modified": "2025-03-18T15:30:37Z", "published": "2024-03-16T06:30:28Z", "aliases": [ "CVE-2024-28069" ], "details": "A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-922" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-16T06:15:13Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json b/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json index 5a85a30c2e2..73388248491 100644 --- a/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json +++ b/advisories/unreviewed/2024/03/GHSA-9hp2-5m46-r478/GHSA-9hp2-5m46-r478.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9hp2-5m46-r478", - "modified": "2024-03-27T03:31:17Z", + "modified": "2025-03-18T15:30:37Z", "published": "2024-03-27T03:31:17Z", "aliases": [ "CVE-2024-25734" ], "details": "An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T03:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pjmm-jqrg-3hmg/GHSA-pjmm-jqrg-3hmg.json b/advisories/unreviewed/2024/04/GHSA-pjmm-jqrg-3hmg/GHSA-pjmm-jqrg-3hmg.json index 2bb1b74c513..f44f5cd214f 100644 --- a/advisories/unreviewed/2024/04/GHSA-pjmm-jqrg-3hmg/GHSA-pjmm-jqrg-3hmg.json +++ b/advisories/unreviewed/2024/04/GHSA-pjmm-jqrg-3hmg/GHSA-pjmm-jqrg-3hmg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-xrwr-3m4h-cqcx/GHSA-xrwr-3m4h-cqcx.json b/advisories/unreviewed/2024/04/GHSA-xrwr-3m4h-cqcx/GHSA-xrwr-3m4h-cqcx.json index bd39173e067..e6bcd0ffe4b 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrwr-3m4h-cqcx/GHSA-xrwr-3m4h-cqcx.json +++ b/advisories/unreviewed/2024/04/GHSA-xrwr-3m4h-cqcx/GHSA-xrwr-3m4h-cqcx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-4j27-qhm5-88w7/GHSA-4j27-qhm5-88w7.json b/advisories/unreviewed/2024/05/GHSA-4j27-qhm5-88w7/GHSA-4j27-qhm5-88w7.json index 62f64d6104b..8a8d3d7999d 100644 --- a/advisories/unreviewed/2024/05/GHSA-4j27-qhm5-88w7/GHSA-4j27-qhm5-88w7.json +++ b/advisories/unreviewed/2024/05/GHSA-4j27-qhm5-88w7/GHSA-4j27-qhm5-88w7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4j27-qhm5-88w7", - "modified": "2024-05-06T18:30:35Z", + "modified": "2025-03-18T15:30:38Z", "published": "2024-05-06T18:30:35Z", "aliases": [ "CVE-2024-34092" ], "details": "An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T16:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json b/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json index d12a63fd7bf..32d6e5b7d05 100644 --- a/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json +++ b/advisories/unreviewed/2024/05/GHSA-hw5v-77jj-prp8/GHSA-hw5v-77jj-prp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hw5v-77jj-prp8", - "modified": "2024-05-31T06:30:28Z", + "modified": "2025-03-18T15:30:38Z", "published": "2024-05-31T06:30:28Z", "aliases": [ "CVE-2024-4469" ], "details": "The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-31T06:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-24q7-jrrv-9x9w/GHSA-24q7-jrrv-9x9w.json b/advisories/unreviewed/2024/07/GHSA-24q7-jrrv-9x9w/GHSA-24q7-jrrv-9x9w.json index 6510e2b010c..86ccb41b169 100644 --- a/advisories/unreviewed/2024/07/GHSA-24q7-jrrv-9x9w/GHSA-24q7-jrrv-9x9w.json +++ b/advisories/unreviewed/2024/07/GHSA-24q7-jrrv-9x9w/GHSA-24q7-jrrv-9x9w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-335g-4xxp-8f55/GHSA-335g-4xxp-8f55.json b/advisories/unreviewed/2024/07/GHSA-335g-4xxp-8f55/GHSA-335g-4xxp-8f55.json index d2231f20318..b224339ee50 100644 --- a/advisories/unreviewed/2024/07/GHSA-335g-4xxp-8f55/GHSA-335g-4xxp-8f55.json +++ b/advisories/unreviewed/2024/07/GHSA-335g-4xxp-8f55/GHSA-335g-4xxp-8f55.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-98" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-5pv6-mmq6-6w3p/GHSA-5pv6-mmq6-6w3p.json b/advisories/unreviewed/2024/07/GHSA-5pv6-mmq6-6w3p/GHSA-5pv6-mmq6-6w3p.json index 79ddd694f36..77141fe4d26 100644 --- a/advisories/unreviewed/2024/07/GHSA-5pv6-mmq6-6w3p/GHSA-5pv6-mmq6-6w3p.json +++ b/advisories/unreviewed/2024/07/GHSA-5pv6-mmq6-6w3p/GHSA-5pv6-mmq6-6w3p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-g53m-h56g-8c6v/GHSA-g53m-h56g-8c6v.json b/advisories/unreviewed/2024/07/GHSA-g53m-h56g-8c6v/GHSA-g53m-h56g-8c6v.json index 9f6bd8bba3e..a7772472a6d 100644 --- a/advisories/unreviewed/2024/07/GHSA-g53m-h56g-8c6v/GHSA-g53m-h56g-8c6v.json +++ b/advisories/unreviewed/2024/07/GHSA-g53m-h56g-8c6v/GHSA-g53m-h56g-8c6v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-rqrc-553g-fmrv/GHSA-rqrc-553g-fmrv.json b/advisories/unreviewed/2024/08/GHSA-rqrc-553g-fmrv/GHSA-rqrc-553g-fmrv.json index 478a4436479..b75aeee70b2 100644 --- a/advisories/unreviewed/2024/08/GHSA-rqrc-553g-fmrv/GHSA-rqrc-553g-fmrv.json +++ b/advisories/unreviewed/2024/08/GHSA-rqrc-553g-fmrv/GHSA-rqrc-553g-fmrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rqrc-553g-fmrv", - "modified": "2024-08-18T21:31:07Z", + "modified": "2025-03-18T15:30:40Z", "published": "2024-08-18T21:31:07Z", "aliases": [ "CVE-2024-43304" diff --git a/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json b/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json index 200b4129287..ffcba9a597b 100644 --- a/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json +++ b/advisories/unreviewed/2024/09/GHSA-9g9q-cf56-cfh9/GHSA-9g9q-cf56-cfh9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json b/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json index 1b3205a4a9d..90edbde9dd7 100644 --- a/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json +++ b/advisories/unreviewed/2024/10/GHSA-fqcp-xv9m-hcq2/GHSA-fqcp-xv9m-hcq2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json b/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json index 6b9d269902c..a7f14d02a19 100644 --- a/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json +++ b/advisories/unreviewed/2024/11/GHSA-pg35-867h-jm8h/GHSA-pg35-867h-jm8h.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json b/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json index dcf183e4bff..5a1e5a9a813 100644 --- a/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json +++ b/advisories/unreviewed/2024/11/GHSA-whhw-2v2c-qg98/GHSA-whhw-2v2c-qg98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whhw-2v2c-qg98", - "modified": "2024-11-29T12:31:48Z", + "modified": "2025-03-18T15:30:42Z", "published": "2024-11-29T12:31:48Z", "aliases": [ "CVE-2024-11482" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11482" }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2817658" + }, { "type": "WEB", "url": "https://thrive.trellix.com/s/article/000014058#h2_0" diff --git a/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json b/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json index 7caf11ef168..a4b0c3fd45a 100644 --- a/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json +++ b/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6v4c-8jrj-xwqj", - "modified": "2024-12-13T15:30:41Z", + "modified": "2025-03-18T15:30:42Z", "published": "2024-12-13T15:30:41Z", "aliases": [ "CVE-2023-36681" diff --git a/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json b/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json index ff3f45abf67..7cbcf5ff41b 100644 --- a/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json +++ b/advisories/unreviewed/2025/01/GHSA-2gqx-rmcg-8rp8/GHSA-2gqx-rmcg-8rp8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json b/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json index f4c5b5ab715..3a7e7a98ca3 100644 --- a/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json +++ b/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json b/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json index 8edfcec6ab0..3eedba4144f 100644 --- a/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json +++ b/advisories/unreviewed/2025/01/GHSA-429g-77c6-6p2v/GHSA-429g-77c6-6p2v.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-276" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json b/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json index 1de44704848..010506a56c7 100644 --- a/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json +++ b/advisories/unreviewed/2025/01/GHSA-5cvp-4pwp-rvg8/GHSA-5cvp-4pwp-rvg8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json b/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json index fe5ba6ac7af..93fc80a7e57 100644 --- a/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json +++ b/advisories/unreviewed/2025/01/GHSA-6xh4-6995-ppc6/GHSA-6xh4-6995-ppc6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1021" + "CWE-1021", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json b/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json index e92e2052681..c3215657836 100644 --- a/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json +++ b/advisories/unreviewed/2025/01/GHSA-7jj7-mxgf-79rv/GHSA-7jj7-mxgf-79rv.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json b/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json index 00ff89405ee..809edff5a00 100644 --- a/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json +++ b/advisories/unreviewed/2025/01/GHSA-fq6x-64vf-73q4/GHSA-fq6x-64vf-73q4.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json b/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json index b13eec2fc85..26d053603cf 100644 --- a/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json +++ b/advisories/unreviewed/2025/01/GHSA-gw84-4qc8-q6cv/GHSA-gw84-4qc8-q6cv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-863" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json b/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json index 359412ef4d6..a870c958b5d 100644 --- a/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json +++ b/advisories/unreviewed/2025/01/GHSA-jhf5-fj8j-2h29/GHSA-jhf5-fj8j-2h29.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-922" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json b/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json index 2553dedaa41..ec0d3d41719 100644 --- a/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json +++ b/advisories/unreviewed/2025/01/GHSA-p2xw-hr6c-g7h5/GHSA-p2xw-hr6c-g7h5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json b/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json index 89a4e9c30a4..0668e7f5954 100644 --- a/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json +++ b/advisories/unreviewed/2025/01/GHSA-qhv7-wrpv-c54g/GHSA-qhv7-wrpv-c54g.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-798" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-r498-8rcj-p67x/GHSA-r498-8rcj-p67x.json b/advisories/unreviewed/2025/01/GHSA-r498-8rcj-p67x/GHSA-r498-8rcj-p67x.json index 568b81dfae6..8e4d5df8092 100644 --- a/advisories/unreviewed/2025/01/GHSA-r498-8rcj-p67x/GHSA-r498-8rcj-p67x.json +++ b/advisories/unreviewed/2025/01/GHSA-r498-8rcj-p67x/GHSA-r498-8rcj-p67x.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-r9mp-qr63-99pq/GHSA-r9mp-qr63-99pq.json b/advisories/unreviewed/2025/01/GHSA-r9mp-qr63-99pq/GHSA-r9mp-qr63-99pq.json index 1f1e9fa457b..d20a6fafd76 100644 --- a/advisories/unreviewed/2025/01/GHSA-r9mp-qr63-99pq/GHSA-r9mp-qr63-99pq.json +++ b/advisories/unreviewed/2025/01/GHSA-r9mp-qr63-99pq/GHSA-r9mp-qr63-99pq.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-732" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json b/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json index 0e8eb1bdad7..15cadd194ad 100644 --- a/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json +++ b/advisories/unreviewed/2025/01/GHSA-v4mm-j7r5-wxq4/GHSA-v4mm-j7r5-wxq4.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-787" + "CWE-787", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json b/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json index 1bd05a6e0d9..9679a0c10e0 100644 --- a/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json +++ b/advisories/unreviewed/2025/01/GHSA-wjxf-6r8p-9pvp/GHSA-wjxf-6r8p-9pvp.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-922" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json b/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json index 85e5bfb23eb..44871d573d5 100644 --- a/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json +++ b/advisories/unreviewed/2025/02/GHSA-99fv-v434-wh6f/GHSA-99fv-v434-wh6f.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2fm6-qmmh-8rv2/GHSA-2fm6-qmmh-8rv2.json b/advisories/unreviewed/2025/03/GHSA-2fm6-qmmh-8rv2/GHSA-2fm6-qmmh-8rv2.json new file mode 100644 index 00000000000..3990fc31720 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2fm6-qmmh-8rv2/GHSA-2fm6-qmmh-8rv2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fm6-qmmh-8rv2", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:48Z", + "aliases": [ + "CVE-2025-2490" + ], + "details": "A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upload. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2490" + }, + { + "type": "WEB", + "url": "https://github.com/dromara/ujcms/issues/12" + }, + { + "type": "WEB", + "url": "https://github.com/dromara/ujcms/issues/13" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299996" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299996" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517267" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2x4h-j98j-x2mw/GHSA-2x4h-j98j-x2mw.json b/advisories/unreviewed/2025/03/GHSA-2x4h-j98j-x2mw/GHSA-2x4h-j98j-x2mw.json new file mode 100644 index 00000000000..ff5d177f774 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2x4h-j98j-x2mw/GHSA-2x4h-j98j-x2mw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x4h-j98j-x2mw", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30110" + ], + "details": "On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC address verification, allowing an attacker to bypass authentication by spoofing an already-paired MAC address that can be captured via an ARP scan.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30110" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD-V" + }, + { + "type": "WEB", + "url": "https://iroad-dashcam.nl/iroad/iroad-x5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-52gf-54f2-3825/GHSA-52gf-54f2-3825.json b/advisories/unreviewed/2025/03/GHSA-52gf-54f2-3825/GHSA-52gf-54f2-3825.json new file mode 100644 index 00000000000..c2a4ce5ade4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-52gf-54f2-3825/GHSA-52gf-54f2-3825.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52gf-54f2-3825", + "modified": "2025-03-18T15:30:47Z", + "published": "2025-03-18T15:30:47Z", + "aliases": [ + "CVE-2023-47539" + ], + "details": "An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47539" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-439" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json b/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json new file mode 100644 index 00000000000..165c551e844 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5rfm-vp96-44gv/GHSA-5rfm-vp96-44gv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rfm-vp96-44gv", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30113" + ], + "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30113" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Hella" + }, + { + "type": "WEB", + "url": "https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-639q-6q9p-hmc8/GHSA-639q-6q9p-hmc8.json b/advisories/unreviewed/2025/03/GHSA-639q-6q9p-hmc8/GHSA-639q-6q9p-hmc8.json new file mode 100644 index 00000000000..a4c29fb926f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-639q-6q9p-hmc8/GHSA-639q-6q9p-hmc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-639q-6q9p-hmc8", + "modified": "2025-03-18T15:30:47Z", + "published": "2025-03-18T15:30:47Z", + "aliases": [ + "CVE-2024-8997" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection.This issue affects EVC04 Configuration Interface: through 18.03.2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8997" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json b/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json new file mode 100644 index 00000000000..e8b73c88acf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hc9-74fh-6p7m", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-25590" + ], + "details": "yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25590" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI7XH" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-78wq-w58w-pxgj/GHSA-78wq-w58w-pxgj.json b/advisories/unreviewed/2025/03/GHSA-78wq-w58w-pxgj/GHSA-78wq-w58w-pxgj.json new file mode 100644 index 00000000000..8dc21703932 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78wq-w58w-pxgj/GHSA-78wq-w58w-pxgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78wq-w58w-pxgj", + "modified": "2025-03-18T15:30:47Z", + "published": "2025-03-18T15:30:47Z", + "aliases": [ + "CVE-2025-2449" + ], + "details": "NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of URI files by the usiReg component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21805.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2449" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7gmh-9cm3-f962/GHSA-7gmh-9cm3-f962.json b/advisories/unreviewed/2025/03/GHSA-7gmh-9cm3-f962/GHSA-7gmh-9cm3-f962.json new file mode 100644 index 00000000000..08e9e2ac5a4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7gmh-9cm3-f962/GHSA-7gmh-9cm3-f962.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gmh-9cm3-f962", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:50Z", + "aliases": [ + "CVE-2025-30123" + ], + "details": "An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30123" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/RoadCam" + }, + { + "type": "WEB", + "url": "https://roadcam.my/pages/install-x3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7q6m-9v39-q68q/GHSA-7q6m-9v39-q68q.json b/advisories/unreviewed/2025/03/GHSA-7q6m-9v39-q68q/GHSA-7q6m-9v39-q68q.json new file mode 100644 index 00000000000..0102f416052 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7q6m-9v39-q68q/GHSA-7q6m-9v39-q68q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q6m-9v39-q68q", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30111" + ], + "details": "On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30111" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD-V" + }, + { + "type": "WEB", + "url": "https://iroad-dashcam.nl/iroad/iroad-x5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json b/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json new file mode 100644 index 00000000000..d36665f5ad9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-82gg-jm8m-39w6/GHSA-82gg-jm8m-39w6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82gg-jm8m-39w6", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:50Z", + "aliases": [ + "CVE-2025-30115" + ], + "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password (\"qwertyuiop\"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30115" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Hella" + }, + { + "type": "WEB", + "url": "https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json b/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json new file mode 100644 index 00000000000..32d31ee9c7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82xf-2h8m-pmc5", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-25585" + ], + "details": "Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25585" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI7PG" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json b/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json new file mode 100644 index 00000000000..5b4924287cc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-966q-fgpf-cj7x", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:48Z", + "aliases": [ + "CVE-2025-25580" + ], + "details": "yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25580" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI6XT" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9j5w-qvpr-crjv/GHSA-9j5w-qvpr-crjv.json b/advisories/unreviewed/2025/03/GHSA-9j5w-qvpr-crjv/GHSA-9j5w-qvpr-crjv.json new file mode 100644 index 00000000000..632f7b51e36 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9j5w-qvpr-crjv/GHSA-9j5w-qvpr-crjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j5w-qvpr-crjv", + "modified": "2025-03-18T15:30:47Z", + "published": "2025-03-18T15:30:47Z", + "aliases": [ + "CVE-2025-2450" + ], + "details": "NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the processing of VBAI files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22833.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2450" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-356" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9v3j-xfw8-fgh8/GHSA-9v3j-xfw8-fgh8.json b/advisories/unreviewed/2025/03/GHSA-9v3j-xfw8-fgh8/GHSA-9v3j-xfw8-fgh8.json new file mode 100644 index 00000000000..5824f8fb01a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9v3j-xfw8-fgh8/GHSA-9v3j-xfw8-fgh8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v3j-xfw8-fgh8", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30107" + ], + "details": "On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulnerability in the dashcam's configuration management allows unauthorized users to modify settings, disable critical functions, and turn off battery protection, potentially causing physical damage to the vehicle.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30107" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD-V" + }, + { + "type": "WEB", + "url": "https://iroad-dashcam.nl/iroad/iroad-x5/%27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cg8r-jwg7-r2x4/GHSA-cg8r-jwg7-r2x4.json b/advisories/unreviewed/2025/03/GHSA-cg8r-jwg7-r2x4/GHSA-cg8r-jwg7-r2x4.json new file mode 100644 index 00000000000..c3cdb970f27 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cg8r-jwg7-r2x4/GHSA-cg8r-jwg7-r2x4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg8r-jwg7-r2x4", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:47Z", + "aliases": [ + "CVE-2025-25500" + ], + "details": "An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the blockchain.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25500" + }, + { + "type": "WEB", + "url": "https://gist.github.com/H3T76/8096a6ff9410f3a6d9a25db1a68ae657#file-cve-2025-25500" + }, + { + "type": "WEB", + "url": "https://github.com/CVEProject/cveproject.github.io/blob/gh-pages/requester/reservation-guidelines.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fch9-7g2p-f49f/GHSA-fch9-7g2p-f49f.json b/advisories/unreviewed/2025/03/GHSA-fch9-7g2p-f49f/GHSA-fch9-7g2p-f49f.json new file mode 100644 index 00000000000..3ee09575b5f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fch9-7g2p-f49f/GHSA-fch9-7g2p-f49f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fch9-7g2p-f49f", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:48Z", + "aliases": [ + "CVE-2024-49822" + ], + "details": "IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49822" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7186424" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fpq3-c96f-26mv/GHSA-fpq3-c96f-26mv.json b/advisories/unreviewed/2025/03/GHSA-fpq3-c96f-26mv/GHSA-fpq3-c96f-26mv.json new file mode 100644 index 00000000000..e7a45ddf2d9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fpq3-c96f-26mv/GHSA-fpq3-c96f-26mv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpq3-c96f-26mv", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:50Z", + "aliases": [ + "CVE-2025-30114" + ], + "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30114" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Hella" + }, + { + "type": "WEB", + "url": "https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fxh3-9v44-3m3r/GHSA-fxh3-9v44-3m3r.json b/advisories/unreviewed/2025/03/GHSA-fxh3-9v44-3m3r/GHSA-fxh3-9v44-3m3r.json new file mode 100644 index 00000000000..a14638fd47c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fxh3-9v44-3m3r/GHSA-fxh3-9v44-3m3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxh3-9v44-3m3r", + "modified": "2025-03-18T15:30:47Z", + "published": "2025-03-18T15:30:47Z", + "aliases": [ + "CVE-2024-21760" + ], + "details": "An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21760" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-420" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json b/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json new file mode 100644 index 00000000000..5b25de5f29d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g38j-p66c-6qhp/GHSA-g38j-p66c-6qhp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g38j-p66c-6qhp", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:50Z", + "aliases": [ + "CVE-2025-30132" + ], + "details": "An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. During analysis, it was found that this domain was not owned by IROAD, allowing an attacker to register it and potentially intercept sensitive device traffic. If the dashcam or related services attempt to resolve this domain over the public Internet instead of locally, it could lead to data exfiltration or man-in-the-middle attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30132" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD-V" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD?tab=readme-ov-file#finding-6-public-domain-used-for-internal-domain-name" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json b/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json new file mode 100644 index 00000000000..baa928fdfbb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gg2f-r4jh-vpmh/GHSA-gg2f-r4jh-vpmh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg2f-r4jh-vpmh", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:48Z", + "aliases": [ + "CVE-2024-44313" + ], + "details": "TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44313" + }, + { + "type": "WEB", + "url": "https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php" + }, + { + "type": "WEB", + "url": "https://medium.com/@cnetsec/cve-2024-44313-incorrect-access-control-in-tastyigniter-3-7-6-01a73c548b74" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j5w5-3c3j-vg23/GHSA-j5w5-3c3j-vg23.json b/advisories/unreviewed/2025/03/GHSA-j5w5-3c3j-vg23/GHSA-j5w5-3c3j-vg23.json new file mode 100644 index 00000000000..f27422dfa53 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j5w5-3c3j-vg23/GHSA-j5w5-3c3j-vg23.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5w5-3c3j-vg23", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-2491" + ], + "details": "A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2491" + }, + { + "type": "WEB", + "url": "https://github.com/dromara/ujcms/issues/14" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299997" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517269" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json b/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json new file mode 100644 index 00000000000..ea8a4a0692e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jg9g-2m55-m7hp/GHSA-jg9g-2m55-m7hp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg9g-2m55-m7hp", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:50Z", + "aliases": [ + "CVE-2025-30122" + ], + "details": "An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30122" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/RoadCam" + }, + { + "type": "WEB", + "url": "https://roadcam.my/pages/install-x3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxv5-hhvx-cmg6/GHSA-jxv5-hhvx-cmg6.json b/advisories/unreviewed/2025/03/GHSA-jxv5-hhvx-cmg6/GHSA-jxv5-hhvx-cmg6.json new file mode 100644 index 00000000000..9a46ca4f5e1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxv5-hhvx-cmg6/GHSA-jxv5-hhvx-cmg6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxv5-hhvx-cmg6", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:48Z", + "aliases": [ + "CVE-2025-30106" + ], + "details": "On IROAD v9 devices, the dashcam has hardcoded default credentials (\"qwertyuiop\") that cannot be changed by the user. This allows an attacker within Wi-Fi range to connect to the device's network to perform sniffing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30106" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD-V" + }, + { + "type": "WEB", + "url": "https://iroad-dashcam.nl/iroad/iroad-x5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json b/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json new file mode 100644 index 00000000000..5b4c3df0170 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m569-r4hr-26cw/GHSA-m569-r4hr-26cw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m569-r4hr-26cw", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30116" + ], + "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It allows remote attackers to access and download recorded video footage from the SD card via port 9091. Additionally, attackers can connect to port 9092 to stream the live video feed by bypassing the challenge-response authentication mechanism. This exposes sensitive location and personal data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30116" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Hella" + }, + { + "type": "WEB", + "url": "https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json b/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json new file mode 100644 index 00000000000..cb143f50082 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvq7-g7xm-xr5h/GHSA-qvq7-g7xm-xr5h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvq7-g7xm-xr5h", + "modified": "2025-03-18T15:30:50Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30117" + ], + "details": "An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. After bypassing the device pairing, an attacker can obtain sensitive user and vehicle information through the settings interface. Remote attackers can modify power management settings, disable recording, delete stored footage, and turn off battery protection, leading to potential denial-of-service conditions and vehicle battery drainage.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30117" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Hella" + }, + { + "type": "WEB", + "url": "https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json b/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json new file mode 100644 index 00000000000..1230ac0e4bd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w5h7-mw56-4v7x/GHSA-w5h7-mw56-4v7x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5h7-mw56-4v7x", + "modified": "2025-03-18T15:30:48Z", + "published": "2025-03-18T15:30:48Z", + "aliases": [ + "CVE-2024-44314" + ], + "details": "TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44314" + }, + { + "type": "WEB", + "url": "https://github.com/tastyigniter/TastyIgniter/blob/3.x/app/admin/controllers/Orders.php" + }, + { + "type": "WEB", + "url": "https://medium.com/@cnetsec/cve-2024-44314-incorrect-access-control-in-function-updateorder-fc5f2b1b0467" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wqh3-vwc7-rhvg/GHSA-wqh3-vwc7-rhvg.json b/advisories/unreviewed/2025/03/GHSA-wqh3-vwc7-rhvg/GHSA-wqh3-vwc7-rhvg.json new file mode 100644 index 00000000000..92ce0a2cfea --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wqh3-vwc7-rhvg/GHSA-wqh3-vwc7-rhvg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqh3-vwc7-rhvg", + "modified": "2025-03-18T15:30:49Z", + "published": "2025-03-18T15:30:49Z", + "aliases": [ + "CVE-2025-30109" + ], + "details": "In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and retrieve sensitive device information, including live and recorded footage.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30109" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD-V" + }, + { + "type": "WEB", + "url": "https://iroad-dashcam.nl/iroad/iroad-x5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T15:16:02Z" + } +} \ No newline at end of file