diff --git a/advisories/unreviewed/2022/05/GHSA-3x77-qmhw-v3hg/GHSA-3x77-qmhw-v3hg.json b/advisories/unreviewed/2022/05/GHSA-3x77-qmhw-v3hg/GHSA-3x77-qmhw-v3hg.json index d2f8a496d5b..0d4fb68543b 100644 --- a/advisories/unreviewed/2022/05/GHSA-3x77-qmhw-v3hg/GHSA-3x77-qmhw-v3hg.json +++ b/advisories/unreviewed/2022/05/GHSA-3x77-qmhw-v3hg/GHSA-3x77-qmhw-v3hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3x77-qmhw-v3hg", - "modified": "2022-05-24T17:18:54Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-24T17:18:54Z", "aliases": [ "CVE-2019-20805" ], "details": "p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-4pmq-77vh-vh7v/GHSA-4pmq-77vh-vh7v.json b/advisories/unreviewed/2022/05/GHSA-4pmq-77vh-vh7v/GHSA-4pmq-77vh-vh7v.json index 5f3774dfb3d..6e3c89620f3 100644 --- a/advisories/unreviewed/2022/05/GHSA-4pmq-77vh-vh7v/GHSA-4pmq-77vh-vh7v.json +++ b/advisories/unreviewed/2022/05/GHSA-4pmq-77vh-vh7v/GHSA-4pmq-77vh-vh7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4pmq-77vh-vh7v", - "modified": "2023-01-20T18:30:23Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-24T17:05:12Z", "aliases": [ "CVE-2019-20051" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://github.com/upx/upx/issues/313" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO" diff --git a/advisories/unreviewed/2022/05/GHSA-5339-45c2-mh5v/GHSA-5339-45c2-mh5v.json b/advisories/unreviewed/2022/05/GHSA-5339-45c2-mh5v/GHSA-5339-45c2-mh5v.json index 4379b718617..97b6a87d652 100644 --- a/advisories/unreviewed/2022/05/GHSA-5339-45c2-mh5v/GHSA-5339-45c2-mh5v.json +++ b/advisories/unreviewed/2022/05/GHSA-5339-45c2-mh5v/GHSA-5339-45c2-mh5v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5339-45c2-mh5v", - "modified": "2022-05-24T19:03:32Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-24T19:03:32Z", "aliases": [ "CVE-2021-30500" ], "details": "Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-68mf-gv4w-rh82/GHSA-68mf-gv4w-rh82.json b/advisories/unreviewed/2022/05/GHSA-68mf-gv4w-rh82/GHSA-68mf-gv4w-rh82.json index 56f1b77ccf2..b09f94ef28f 100644 --- a/advisories/unreviewed/2022/05/GHSA-68mf-gv4w-rh82/GHSA-68mf-gv4w-rh82.json +++ b/advisories/unreviewed/2022/05/GHSA-68mf-gv4w-rh82/GHSA-68mf-gv4w-rh82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68mf-gv4w-rh82", - "modified": "2022-07-11T00:00:18Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-24T19:02:26Z", "aliases": [ "CVE-2020-24119" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://cwe.mitre.org/data/definitions/126.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSQRO7YC72PSYDQG4PQLQYXZTZE3B4YV" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX" diff --git a/advisories/unreviewed/2022/05/GHSA-97cx-745f-9p9g/GHSA-97cx-745f-9p9g.json b/advisories/unreviewed/2022/05/GHSA-97cx-745f-9p9g/GHSA-97cx-745f-9p9g.json index 02f436130bd..b9608555dc1 100644 --- a/advisories/unreviewed/2022/05/GHSA-97cx-745f-9p9g/GHSA-97cx-745f-9p9g.json +++ b/advisories/unreviewed/2022/05/GHSA-97cx-745f-9p9g/GHSA-97cx-745f-9p9g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97cx-745f-9p9g", - "modified": "2023-01-20T18:30:23Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-24T17:05:11Z", "aliases": [ "CVE-2019-20021" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://github.com/upx/upx/issues/315" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO" diff --git a/advisories/unreviewed/2022/05/GHSA-phmx-286h-jcc3/GHSA-phmx-286h-jcc3.json b/advisories/unreviewed/2022/05/GHSA-phmx-286h-jcc3/GHSA-phmx-286h-jcc3.json index 1e32ac39241..ccf987215e8 100644 --- a/advisories/unreviewed/2022/05/GHSA-phmx-286h-jcc3/GHSA-phmx-286h-jcc3.json +++ b/advisories/unreviewed/2022/05/GHSA-phmx-286h-jcc3/GHSA-phmx-286h-jcc3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phmx-286h-jcc3", - "modified": "2022-05-24T17:05:12Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-24T17:05:12Z", "aliases": [ "CVE-2019-20053" ], "details": "An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-xvcg-hv6h-729g/GHSA-xvcg-hv6h-729g.json b/advisories/unreviewed/2022/05/GHSA-xvcg-hv6h-729g/GHSA-xvcg-hv6h-729g.json index 6333083fdd0..ccc85e49225 100644 --- a/advisories/unreviewed/2022/05/GHSA-xvcg-hv6h-729g/GHSA-xvcg-hv6h-729g.json +++ b/advisories/unreviewed/2022/05/GHSA-xvcg-hv6h-729g/GHSA-xvcg-hv6h-729g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvcg-hv6h-729g", - "modified": "2022-05-13T01:28:42Z", + "modified": "2025-04-11T12:31:38Z", "published": "2022-05-13T01:28:42Z", "aliases": [ "CVE-2018-11243" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://github.com/upx/upx/blob/devel/NEWS" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO" diff --git a/advisories/unreviewed/2022/08/GHSA-242r-jf27-g6pp/GHSA-242r-jf27-g6pp.json b/advisories/unreviewed/2022/08/GHSA-242r-jf27-g6pp/GHSA-242r-jf27-g6pp.json index 339a6d757f3..dce7b952fde 100644 --- a/advisories/unreviewed/2022/08/GHSA-242r-jf27-g6pp/GHSA-242r-jf27-g6pp.json +++ b/advisories/unreviewed/2022/08/GHSA-242r-jf27-g6pp/GHSA-242r-jf27-g6pp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-125", "CWE-787" ], diff --git a/advisories/unreviewed/2022/08/GHSA-2hpg-6pp8-gx2m/GHSA-2hpg-6pp8-gx2m.json b/advisories/unreviewed/2022/08/GHSA-2hpg-6pp8-gx2m/GHSA-2hpg-6pp8-gx2m.json index 7af6d426b63..39e37201b59 100644 --- a/advisories/unreviewed/2022/08/GHSA-2hpg-6pp8-gx2m/GHSA-2hpg-6pp8-gx2m.json +++ b/advisories/unreviewed/2022/08/GHSA-2hpg-6pp8-gx2m/GHSA-2hpg-6pp8-gx2m.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-125" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-4rhf-85wr-9pxc/GHSA-4rhf-85wr-9pxc.json b/advisories/unreviewed/2022/08/GHSA-4rhf-85wr-9pxc/GHSA-4rhf-85wr-9pxc.json index ec31f83d3ef..245f081e72c 100644 --- a/advisories/unreviewed/2022/08/GHSA-4rhf-85wr-9pxc/GHSA-4rhf-85wr-9pxc.json +++ b/advisories/unreviewed/2022/08/GHSA-4rhf-85wr-9pxc/GHSA-4rhf-85wr-9pxc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/08/GHSA-gqpc-4qr8-j9g3/GHSA-gqpc-4qr8-j9g3.json b/advisories/unreviewed/2022/08/GHSA-gqpc-4qr8-j9g3/GHSA-gqpc-4qr8-j9g3.json index edffc512317..6911635263f 100644 --- a/advisories/unreviewed/2022/08/GHSA-gqpc-4qr8-j9g3/GHSA-gqpc-4qr8-j9g3.json +++ b/advisories/unreviewed/2022/08/GHSA-gqpc-4qr8-j9g3/GHSA-gqpc-4qr8-j9g3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-763" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/08/GHSA-hrvc-4vxq-q985/GHSA-hrvc-4vxq-q985.json b/advisories/unreviewed/2022/08/GHSA-hrvc-4vxq-q985/GHSA-hrvc-4vxq-q985.json index 2d6cc097a3e..676776964a2 100644 --- a/advisories/unreviewed/2022/08/GHSA-hrvc-4vxq-q985/GHSA-hrvc-4vxq-q985.json +++ b/advisories/unreviewed/2022/08/GHSA-hrvc-4vxq-q985/GHSA-hrvc-4vxq-q985.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-125" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-jx23-r23x-qc23/GHSA-jx23-r23x-qc23.json b/advisories/unreviewed/2022/08/GHSA-jx23-r23x-qc23/GHSA-jx23-r23x-qc23.json index be7adc0ed09..cef2a13a8e8 100644 --- a/advisories/unreviewed/2022/08/GHSA-jx23-r23x-qc23/GHSA-jx23-r23x-qc23.json +++ b/advisories/unreviewed/2022/08/GHSA-jx23-r23x-qc23/GHSA-jx23-r23x-qc23.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-369" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/08/GHSA-mj66-hgqf-6qqw/GHSA-mj66-hgqf-6qqw.json b/advisories/unreviewed/2022/08/GHSA-mj66-hgqf-6qqw/GHSA-mj66-hgqf-6qqw.json index 57716f35e88..41d8a72d9b8 100644 --- a/advisories/unreviewed/2022/08/GHSA-mj66-hgqf-6qqw/GHSA-mj66-hgqf-6qqw.json +++ b/advisories/unreviewed/2022/08/GHSA-mj66-hgqf-6qqw/GHSA-mj66-hgqf-6qqw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-125" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-x97v-6wf2-6ffp/GHSA-x97v-6wf2-6ffp.json b/advisories/unreviewed/2022/08/GHSA-x97v-6wf2-6ffp/GHSA-x97v-6wf2-6ffp.json index c650d24f7ec..a768a6f2372 100644 --- a/advisories/unreviewed/2022/08/GHSA-x97v-6wf2-6ffp/GHSA-x97v-6wf2-6ffp.json +++ b/advisories/unreviewed/2022/08/GHSA-x97v-6wf2-6ffp/GHSA-x97v-6wf2-6ffp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-763" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/03/GHSA-2586-p5rg-fxqv/GHSA-2586-p5rg-fxqv.json b/advisories/unreviewed/2023/03/GHSA-2586-p5rg-fxqv/GHSA-2586-p5rg-fxqv.json index b6f3e581aed..143667faf07 100644 --- a/advisories/unreviewed/2023/03/GHSA-2586-p5rg-fxqv/GHSA-2586-p5rg-fxqv.json +++ b/advisories/unreviewed/2023/03/GHSA-2586-p5rg-fxqv/GHSA-2586-p5rg-fxqv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-3rqj-h86c-2fpp/GHSA-3rqj-h86c-2fpp.json b/advisories/unreviewed/2023/03/GHSA-3rqj-h86c-2fpp/GHSA-3rqj-h86c-2fpp.json index 80c0a1d995f..ef5edaa7d3f 100644 --- a/advisories/unreviewed/2023/03/GHSA-3rqj-h86c-2fpp/GHSA-3rqj-h86c-2fpp.json +++ b/advisories/unreviewed/2023/03/GHSA-3rqj-h86c-2fpp/GHSA-3rqj-h86c-2fpp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-fg24-8xq8-v4pp/GHSA-fg24-8xq8-v4pp.json b/advisories/unreviewed/2023/03/GHSA-fg24-8xq8-v4pp/GHSA-fg24-8xq8-v4pp.json index a4e30f27b38..bbed96aabb9 100644 --- a/advisories/unreviewed/2023/03/GHSA-fg24-8xq8-v4pp/GHSA-fg24-8xq8-v4pp.json +++ b/advisories/unreviewed/2023/03/GHSA-fg24-8xq8-v4pp/GHSA-fg24-8xq8-v4pp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-j554-cfvx-c858/GHSA-j554-cfvx-c858.json b/advisories/unreviewed/2023/03/GHSA-j554-cfvx-c858/GHSA-j554-cfvx-c858.json index ed721bd8c40..14d532f9cf1 100644 --- a/advisories/unreviewed/2023/03/GHSA-j554-cfvx-c858/GHSA-j554-cfvx-c858.json +++ b/advisories/unreviewed/2023/03/GHSA-j554-cfvx-c858/GHSA-j554-cfvx-c858.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-p7p3-32mv-p6h3/GHSA-p7p3-32mv-p6h3.json b/advisories/unreviewed/2023/03/GHSA-p7p3-32mv-p6h3/GHSA-p7p3-32mv-p6h3.json index 0026f1b6bef..994b7a0c80d 100644 --- a/advisories/unreviewed/2023/03/GHSA-p7p3-32mv-p6h3/GHSA-p7p3-32mv-p6h3.json +++ b/advisories/unreviewed/2023/03/GHSA-p7p3-32mv-p6h3/GHSA-p7p3-32mv-p6h3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-pc9f-fr4v-3pc2/GHSA-pc9f-fr4v-3pc2.json b/advisories/unreviewed/2023/03/GHSA-pc9f-fr4v-3pc2/GHSA-pc9f-fr4v-3pc2.json index d7fca5391bb..043951e3d66 100644 --- a/advisories/unreviewed/2023/03/GHSA-pc9f-fr4v-3pc2/GHSA-pc9f-fr4v-3pc2.json +++ b/advisories/unreviewed/2023/03/GHSA-pc9f-fr4v-3pc2/GHSA-pc9f-fr4v-3pc2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-qw8f-cj3r-vr8p/GHSA-qw8f-cj3r-vr8p.json b/advisories/unreviewed/2023/03/GHSA-qw8f-cj3r-vr8p/GHSA-qw8f-cj3r-vr8p.json index f945878dae7..decc7cd7d2a 100644 --- a/advisories/unreviewed/2023/03/GHSA-qw8f-cj3r-vr8p/GHSA-qw8f-cj3r-vr8p.json +++ b/advisories/unreviewed/2023/03/GHSA-qw8f-cj3r-vr8p/GHSA-qw8f-cj3r-vr8p.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-2547-59jc-hhfr/GHSA-2547-59jc-hhfr.json b/advisories/unreviewed/2025/04/GHSA-2547-59jc-hhfr/GHSA-2547-59jc-hhfr.json new file mode 100644 index 00000000000..741da53b6fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2547-59jc-hhfr/GHSA-2547-59jc-hhfr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2547-59jc-hhfr", + "modified": "2025-04-11T12:31:39Z", + "published": "2025-04-11T12:31:39Z", + "aliases": [ + "CVE-2025-31932" + ], + "details": "Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console.\nThe vendor provides the workaround information and recommends to apply it to the deployment environment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31932" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN30641875" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/360029772271" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/39951710517145" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/39952052043289" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/39953373809305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-53mq-ph34-h4jf/GHSA-53mq-ph34-h4jf.json b/advisories/unreviewed/2025/04/GHSA-53mq-ph34-h4jf/GHSA-53mq-ph34-h4jf.json new file mode 100644 index 00000000000..25c2a514d2e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-53mq-ph34-h4jf/GHSA-53mq-ph34-h4jf.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53mq-ph34-h4jf", + "modified": "2025-04-11T12:31:39Z", + "published": "2025-04-11T12:31:39Z", + "aliases": [ + "CVE-2025-2128" + ], + "details": "The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter in all versions up to, and including, 3.2.67 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2128" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/cost-calculator-builder/trunk/includes/classes/models/Payments.php#L52" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3263770" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/cost-calculator-builder/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7a7157c0-8378-4aa0-bc47-635be4ba2f8f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59cg-5vx3-8c3g/GHSA-59cg-5vx3-8c3g.json b/advisories/unreviewed/2025/04/GHSA-59cg-5vx3-8c3g/GHSA-59cg-5vx3-8c3g.json new file mode 100644 index 00000000000..4910cca5742 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-59cg-5vx3-8c3g/GHSA-59cg-5vx3-8c3g.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59cg-5vx3-8c3g", + "modified": "2025-04-11T12:31:39Z", + "published": "2025-04-11T12:31:39Z", + "aliases": [ + "CVE-2025-31362" + ], + "details": "Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption key is available.\nThe vendor provides the workaround information and recommends to apply it to the deployment environment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31362" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN30641875" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/360029772271" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/39951710517145" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/39952052043289" + }, + { + "type": "WEB", + "url": "https://knowledge.bizrobo.com/hc/ja/articles/39953373809305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q4q8-xrj7-g425/GHSA-q4q8-xrj7-g425.json b/advisories/unreviewed/2025/04/GHSA-q4q8-xrj7-g425/GHSA-q4q8-xrj7-g425.json new file mode 100644 index 00000000000..518b60a34e2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q4q8-xrj7-g425/GHSA-q4q8-xrj7-g425.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4q8-xrj7-g425", + "modified": "2025-04-11T12:31:39Z", + "published": "2025-04-11T12:31:39Z", + "aliases": [ + "CVE-2025-2541" + ], + "details": "The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2541" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wedevs-project-manager/tags/2.6.20/core/WP/Frontend.php#L209" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3268509" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wedevs-project-manager/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dcc68b62-7dd1-47d4-bbc5-d0237b7c85e7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rpw4-mcr9-3fq7/GHSA-rpw4-mcr9-3fq7.json b/advisories/unreviewed/2025/04/GHSA-rpw4-mcr9-3fq7/GHSA-rpw4-mcr9-3fq7.json new file mode 100644 index 00000000000..1089b0bf7f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rpw4-mcr9-3fq7/GHSA-rpw4-mcr9-3fq7.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpw4-mcr9-3fq7", + "modified": "2025-04-11T12:31:39Z", + "published": "2025-04-11T12:31:39Z", + "aliases": [ + "CVE-2025-2575" + ], + "details": "The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. Note: This requires Royal Shop theme to be installed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2575" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/z-companion/trunk/import/importer/wxr-importer.php#L149" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/z-companion/trunk/import/importer/wxr-importer.php#L63" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/z-companion/trunk/import/inc/importer.php#L148" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/z-companion/trunk/import/inc/importer.php#L62" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3270130" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/z-companion/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e0f7bba4-76c3-4904-bd96-2074147b33f5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T12:15:15Z" + } +} \ No newline at end of file