From 9ea292ec718dd9789747d42d87ce0082f2f0ad20 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Mar 2025 15:33:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-ph3v-2hq5-5qfq.json | 19 ++++++-- .../GHSA-2g67-jw5m-244m.json | 2 +- .../GHSA-2h7q-7935-rv26.json | 4 +- .../GHSA-3353-p834-c8g2.json | 3 +- .../GHSA-65cf-47pp-gwrg.json | 5 ++- .../GHSA-66f3-5m77-hrqg.json | 1 + .../GHSA-6h64-3q22-9hpq.json | 5 ++- .../GHSA-6m3c-9c9q-f5w3.json | 1 + .../GHSA-6q2p-wm97-x79g.json | 5 ++- .../GHSA-78w3-m2fr-9r73.json | 10 ++++- .../GHSA-7phj-7jw4-pf3j.json | 1 + .../GHSA-7q96-25c7-r8m6.json | 4 +- .../GHSA-7v66-8jm8-8x7g.json | 3 +- .../GHSA-8gjg-hfm2-ffq6.json | 5 ++- .../GHSA-g5qh-f5rv-grcp.json | 14 +++++- .../GHSA-gm5r-35xq-qr9c.json | 4 +- .../GHSA-hq8f-55fx-pqv7.json | 4 +- .../GHSA-j75c-xqjg-h88v.json | 4 +- .../GHSA-jhxg-8fv9-xvgm.json | 6 ++- .../GHSA-m59c-782g-v69q.json | 1 + .../GHSA-mccq-xq7h-7q89.json | 4 +- .../GHSA-mq9x-cjpv-8jjh.json | 4 +- .../GHSA-q2cv-v83m-r24w.json | 4 +- .../GHSA-q682-3896-xh7g.json | 5 ++- .../GHSA-qj7h-w49c-56jm.json | 5 ++- .../GHSA-qprx-rfxr-x663.json | 3 +- .../GHSA-rhj6-7p83-68fm.json | 3 +- .../GHSA-vgjq-43qm-8f24.json | 3 +- .../GHSA-wgxw-vjvf-vr8h.json | 3 +- .../GHSA-xrvm-qcmp-42vc.json | 6 ++- .../GHSA-c949-3ppw-h395.json | 4 +- .../GHSA-gvrj-cx9v-hg3m.json | 4 +- .../GHSA-v28c-957v-55vg.json | 15 +++++-- .../GHSA-3m3m-q3hw-6qq6.json | 4 +- .../GHSA-3mhw-f79r-crmm.json | 15 +++++-- .../GHSA-rhq7-7m7h-w8m7.json | 11 +++-- .../GHSA-7j6g-455m-7jv4.json | 4 +- .../GHSA-g38h-vjf2-59hp.json | 4 +- .../GHSA-m2xw-6755-w968.json | 4 +- .../GHSA-mvx6-xfx7-r23g.json | 4 +- .../GHSA-256g-w77v-wxmx.json | 15 +++++-- .../GHSA-2fgp-4w27-wc8x.json | 36 +++++++++++++++ .../GHSA-2qhm-mh5c-2242.json | 36 +++++++++++++++ .../GHSA-2r2c-pw94-m93j.json | 36 +++++++++++++++ .../GHSA-3962-gjv5-4r4p.json | 36 +++++++++++++++ .../GHSA-3cf5-h6wh-qmg6.json | 36 +++++++++++++++ .../GHSA-3cm3-xc2x-9g73.json | 36 +++++++++++++++ .../GHSA-3cv2-9pff-v434.json | 36 +++++++++++++++ .../GHSA-3h45-5qrh-cg5g.json | 36 +++++++++++++++ .../GHSA-495w-c474-hvvj.json | 36 +++++++++++++++ .../GHSA-4f8w-7rrv-r75q.json | 36 +++++++++++++++ .../GHSA-4mp6-9qmf-p4qw.json | 36 +++++++++++++++ .../GHSA-4q6p-vw5p-724c.json | 15 +++++-- .../GHSA-4xvx-54qc-h5fx.json | 36 +++++++++++++++ .../GHSA-52fg-w63x-36xq.json | 15 +++++-- .../GHSA-558w-4jfg-vp65.json | 36 +++++++++++++++ .../GHSA-55gp-8c42-mxr3.json | 36 +++++++++++++++ .../GHSA-5fh9-9r47-g22w.json | 44 +++++++++++++++++++ .../GHSA-5fxv-x2j7-rmwm.json | 15 +++++-- .../GHSA-5mgc-fcm2-r52q.json | 36 +++++++++++++++ .../GHSA-5qj6-mg77-q89g.json | 36 +++++++++++++++ .../GHSA-5x83-mrj6-f6x7.json | 36 +++++++++++++++ .../GHSA-5xrx-96wf-wfgx.json | 36 +++++++++++++++ .../GHSA-62q7-445r-42wh.json | 15 +++++-- .../GHSA-62wq-f836-x445.json | 36 +++++++++++++++ .../GHSA-6384-w4fj-cvg5.json | 36 +++++++++++++++ .../GHSA-666m-w6mw-m583.json | 36 +++++++++++++++ .../GHSA-674w-jwj3-6mv7.json | 15 +++++-- .../GHSA-684f-3jwr-92rr.json | 36 +++++++++++++++ .../GHSA-687p-fc47-c8ph.json | 15 +++++-- .../GHSA-6cpx-55pw-9cxq.json | 15 +++++-- .../GHSA-6hj5-9j3r-gpmm.json | 36 +++++++++++++++ .../GHSA-6mxg-4m6j-9xh2.json | 15 +++++-- .../GHSA-6vfq-fmxw-qgx5.json | 36 +++++++++++++++ .../GHSA-7374-x3rm-h27g.json | 36 +++++++++++++++ .../GHSA-7f56-j9jp-755p.json | 36 +++++++++++++++ .../GHSA-7h6r-r8cm-jcwr.json | 36 +++++++++++++++ .../GHSA-7ppg-mv7x-5fvw.json | 36 +++++++++++++++ .../GHSA-7xxp-v6x4-h4rj.json | 36 +++++++++++++++ .../GHSA-8525-h9w3-hxg7.json | 36 +++++++++++++++ .../GHSA-897j-g3gr-c45r.json | 36 +++++++++++++++ .../GHSA-8r7g-cp82-7wj7.json | 36 +++++++++++++++ .../GHSA-93vr-r8wm-997h.json | 36 +++++++++++++++ .../GHSA-96p6-38w3-wjpv.json | 15 +++++-- .../GHSA-9mjp-p38w-xgfq.json | 36 +++++++++++++++ .../GHSA-9pcx-rmqr-hp8m.json | 36 +++++++++++++++ .../GHSA-9rjp-j2f3-hgr2.json | 3 +- .../GHSA-c37p-8677-9fjp.json | 36 +++++++++++++++ .../GHSA-ccxp-4v4f-798f.json | 36 +++++++++++++++ .../GHSA-cf7v-rvrx-hj59.json | 36 +++++++++++++++ .../GHSA-cm76-ccg3-wcc8.json | 36 +++++++++++++++ .../GHSA-cv66-crjx-w6c2.json | 15 +++++-- .../GHSA-f82j-r7r9-rwqc.json | 36 +++++++++++++++ .../GHSA-fjvg-cccj-287m.json | 36 +++++++++++++++ .../GHSA-g442-92pc-f29g.json | 3 +- .../GHSA-g93w-hmq8-rmfm.json | 36 +++++++++++++++ .../GHSA-gg32-8592-8mq5.json | 36 +++++++++++++++ .../GHSA-gg84-rh2v-pxc7.json | 36 +++++++++++++++ .../GHSA-gj36-hrrj-wvg8.json | 15 +++++-- .../GHSA-gj66-2xh5-rjrr.json | 15 +++++-- .../GHSA-gr4p-qg3r-wj73.json | 36 +++++++++++++++ .../GHSA-gr92-mxmc-wrw8.json | 36 +++++++++++++++ .../GHSA-h3jh-gvh6-j6x9.json | 36 +++++++++++++++ .../GHSA-h876-5qxv-hfv8.json | 3 +- .../GHSA-hp5w-82fv-gq5h.json | 15 +++++-- .../GHSA-hph8-p5j3-prh4.json | 36 +++++++++++++++ .../GHSA-hpv9-g7qg-3mx5.json | 36 +++++++++++++++ .../GHSA-hr5f-49h6-wqx8.json | 36 +++++++++++++++ .../GHSA-j2rq-95q8-x377.json | 36 +++++++++++++++ .../GHSA-j568-rwg2-2cjc.json | 36 +++++++++++++++ .../GHSA-j6w5-x2v9-vjvh.json | 36 +++++++++++++++ .../GHSA-jmwp-wj4g-2wx6.json | 36 +++++++++++++++ .../GHSA-jxwh-6552-jgf9.json | 36 +++++++++++++++ .../GHSA-mf5w-5crj-3f7j.json | 36 +++++++++++++++ .../GHSA-mxrj-wg4w-q89c.json | 36 +++++++++++++++ .../GHSA-p2xx-r693-hcg3.json | 15 +++++-- .../GHSA-p7qf-r7jf-7mf3.json | 15 +++++-- .../GHSA-pcjq-f5x3-32jw.json | 36 +++++++++++++++ .../GHSA-phrv-w9px-24x9.json | 15 +++++-- .../GHSA-q4gq-f754-g4cm.json | 36 +++++++++++++++ .../GHSA-q6hv-hgwg-f36q.json | 36 +++++++++++++++ .../GHSA-qcw6-3cfv-2mjg.json | 36 +++++++++++++++ .../GHSA-qrh8-xh8q-58h3.json | 36 +++++++++++++++ .../GHSA-qvp7-vxrx-fx9x.json | 36 +++++++++++++++ .../GHSA-r4r6-77v3-8vgh.json | 36 +++++++++++++++ .../GHSA-r5jj-c2fp-rwxc.json | 3 +- .../GHSA-r9c5-mh6w-wh5v.json | 36 +++++++++++++++ .../GHSA-rf6p-cgc2-j8vp.json | 36 +++++++++++++++ .../GHSA-rhgp-3mp4-4qhc.json | 36 +++++++++++++++ .../GHSA-rmm8-wf49-vvww.json | 15 +++++-- .../GHSA-rr6x-4q8f-283c.json | 36 +++++++++++++++ .../GHSA-rx7j-2crx-fpf9.json | 36 +++++++++++++++ .../GHSA-rx8g-9fwr-gfmw.json | 36 +++++++++++++++ .../GHSA-v35q-38fv-g69h.json | 36 +++++++++++++++ .../GHSA-v3x8-h6r4-68c2.json | 36 +++++++++++++++ .../GHSA-v767-x36h-4gv8.json | 15 +++++-- .../GHSA-v842-8rq8-6j89.json | 36 +++++++++++++++ .../GHSA-v9xw-vg74-98jg.json | 36 +++++++++++++++ .../GHSA-w2ph-8pcw-pr59.json | 36 +++++++++++++++ .../GHSA-w6h6-x333-v779.json | 36 +++++++++++++++ .../GHSA-w992-x2xp-7wxj.json | 3 +- .../GHSA-wph6-jwvx-f7w9.json | 36 +++++++++++++++ .../GHSA-wwh3-mf32-qwp8.json | 36 +++++++++++++++ .../GHSA-x447-66j7-93px.json | 15 +++++-- .../GHSA-x4cg-7qf4-6q2m.json | 3 +- .../GHSA-x65v-g96x-c6gw.json | 15 +++++-- .../GHSA-x74r-f89v-3jw9.json | 15 +++++-- .../GHSA-x7x9-ghgp-468h.json | 36 +++++++++++++++ .../GHSA-xf28-r428-32c6.json | 3 +- .../GHSA-xhwr-82m4-g88f.json | 36 +++++++++++++++ .../GHSA-xmx6-fp5q-5xrh.json | 36 +++++++++++++++ 151 files changed, 3376 insertions(+), 145 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2fgp-4w27-wc8x/GHSA-2fgp-4w27-wc8x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2qhm-mh5c-2242/GHSA-2qhm-mh5c-2242.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2r2c-pw94-m93j/GHSA-2r2c-pw94-m93j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3962-gjv5-4r4p/GHSA-3962-gjv5-4r4p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3cf5-h6wh-qmg6/GHSA-3cf5-h6wh-qmg6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3cm3-xc2x-9g73/GHSA-3cm3-xc2x-9g73.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3cv2-9pff-v434/GHSA-3cv2-9pff-v434.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3h45-5qrh-cg5g/GHSA-3h45-5qrh-cg5g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-495w-c474-hvvj/GHSA-495w-c474-hvvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4f8w-7rrv-r75q/GHSA-4f8w-7rrv-r75q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4mp6-9qmf-p4qw/GHSA-4mp6-9qmf-p4qw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4xvx-54qc-h5fx/GHSA-4xvx-54qc-h5fx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-558w-4jfg-vp65/GHSA-558w-4jfg-vp65.json create mode 100644 advisories/unreviewed/2025/03/GHSA-55gp-8c42-mxr3/GHSA-55gp-8c42-mxr3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5fh9-9r47-g22w/GHSA-5fh9-9r47-g22w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5mgc-fcm2-r52q/GHSA-5mgc-fcm2-r52q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5qj6-mg77-q89g/GHSA-5qj6-mg77-q89g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5x83-mrj6-f6x7/GHSA-5x83-mrj6-f6x7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5xrx-96wf-wfgx/GHSA-5xrx-96wf-wfgx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-62wq-f836-x445/GHSA-62wq-f836-x445.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6384-w4fj-cvg5/GHSA-6384-w4fj-cvg5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-666m-w6mw-m583/GHSA-666m-w6mw-m583.json create mode 100644 advisories/unreviewed/2025/03/GHSA-684f-3jwr-92rr/GHSA-684f-3jwr-92rr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hj5-9j3r-gpmm/GHSA-6hj5-9j3r-gpmm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6vfq-fmxw-qgx5/GHSA-6vfq-fmxw-qgx5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7374-x3rm-h27g/GHSA-7374-x3rm-h27g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7f56-j9jp-755p/GHSA-7f56-j9jp-755p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7h6r-r8cm-jcwr/GHSA-7h6r-r8cm-jcwr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7ppg-mv7x-5fvw/GHSA-7ppg-mv7x-5fvw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7xxp-v6x4-h4rj/GHSA-7xxp-v6x4-h4rj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8525-h9w3-hxg7/GHSA-8525-h9w3-hxg7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-897j-g3gr-c45r/GHSA-897j-g3gr-c45r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8r7g-cp82-7wj7/GHSA-8r7g-cp82-7wj7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-93vr-r8wm-997h/GHSA-93vr-r8wm-997h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9mjp-p38w-xgfq/GHSA-9mjp-p38w-xgfq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9pcx-rmqr-hp8m/GHSA-9pcx-rmqr-hp8m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c37p-8677-9fjp/GHSA-c37p-8677-9fjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ccxp-4v4f-798f/GHSA-ccxp-4v4f-798f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cf7v-rvrx-hj59/GHSA-cf7v-rvrx-hj59.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cm76-ccg3-wcc8/GHSA-cm76-ccg3-wcc8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f82j-r7r9-rwqc/GHSA-f82j-r7r9-rwqc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fjvg-cccj-287m/GHSA-fjvg-cccj-287m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g93w-hmq8-rmfm/GHSA-g93w-hmq8-rmfm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gg32-8592-8mq5/GHSA-gg32-8592-8mq5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gg84-rh2v-pxc7/GHSA-gg84-rh2v-pxc7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gr4p-qg3r-wj73/GHSA-gr4p-qg3r-wj73.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gr92-mxmc-wrw8/GHSA-gr92-mxmc-wrw8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h3jh-gvh6-j6x9/GHSA-h3jh-gvh6-j6x9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hph8-p5j3-prh4/GHSA-hph8-p5j3-prh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hpv9-g7qg-3mx5/GHSA-hpv9-g7qg-3mx5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hr5f-49h6-wqx8/GHSA-hr5f-49h6-wqx8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j2rq-95q8-x377/GHSA-j2rq-95q8-x377.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j568-rwg2-2cjc/GHSA-j568-rwg2-2cjc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j6w5-x2v9-vjvh/GHSA-j6w5-x2v9-vjvh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jmwp-wj4g-2wx6/GHSA-jmwp-wj4g-2wx6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jxwh-6552-jgf9/GHSA-jxwh-6552-jgf9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mf5w-5crj-3f7j/GHSA-mf5w-5crj-3f7j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mxrj-wg4w-q89c/GHSA-mxrj-wg4w-q89c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pcjq-f5x3-32jw/GHSA-pcjq-f5x3-32jw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q4gq-f754-g4cm/GHSA-q4gq-f754-g4cm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q6hv-hgwg-f36q/GHSA-q6hv-hgwg-f36q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qcw6-3cfv-2mjg/GHSA-qcw6-3cfv-2mjg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qrh8-xh8q-58h3/GHSA-qrh8-xh8q-58h3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qvp7-vxrx-fx9x/GHSA-qvp7-vxrx-fx9x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r4r6-77v3-8vgh/GHSA-r4r6-77v3-8vgh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r9c5-mh6w-wh5v/GHSA-r9c5-mh6w-wh5v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rf6p-cgc2-j8vp/GHSA-rf6p-cgc2-j8vp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rhgp-3mp4-4qhc/GHSA-rhgp-3mp4-4qhc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rr6x-4q8f-283c/GHSA-rr6x-4q8f-283c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rx7j-2crx-fpf9/GHSA-rx7j-2crx-fpf9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rx8g-9fwr-gfmw/GHSA-rx8g-9fwr-gfmw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v35q-38fv-g69h/GHSA-v35q-38fv-g69h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v3x8-h6r4-68c2/GHSA-v3x8-h6r4-68c2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v842-8rq8-6j89/GHSA-v842-8rq8-6j89.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v9xw-vg74-98jg/GHSA-v9xw-vg74-98jg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w2ph-8pcw-pr59/GHSA-w2ph-8pcw-pr59.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6h6-x333-v779/GHSA-w6h6-x333-v779.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wph6-jwvx-f7w9/GHSA-wph6-jwvx-f7w9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wwh3-mf32-qwp8/GHSA-wwh3-mf32-qwp8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x7x9-ghgp-468h/GHSA-x7x9-ghgp-468h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xhwr-82m4-g88f/GHSA-xhwr-82m4-g88f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xmx6-fp5q-5xrh/GHSA-xmx6-fp5q-5xrh.json diff --git a/advisories/github-reviewed/2022/03/GHSA-ph3v-2hq5-5qfq/GHSA-ph3v-2hq5-5qfq.json b/advisories/github-reviewed/2022/03/GHSA-ph3v-2hq5-5qfq/GHSA-ph3v-2hq5-5qfq.json index fd1461974d3..22aaf5df8aa 100644 --- a/advisories/github-reviewed/2022/03/GHSA-ph3v-2hq5-5qfq/GHSA-ph3v-2hq5-5qfq.json +++ b/advisories/github-reviewed/2022/03/GHSA-ph3v-2hq5-5qfq/GHSA-ph3v-2hq5-5qfq.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-ph3v-2hq5-5qfq", - "modified": "2022-03-11T20:30:20Z", + "modified": "2025-03-26T15:32:24Z", "published": "2022-03-07T00:00:41Z", "aliases": [ "CVE-2021-46703" ], "summary": "Code injection in RazorEngine", "details": "In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [ { "package": { @@ -38,11 +43,17 @@ { "type": "WEB", "url": "https://github.com/Antaris/RazorEngine/issues/585" + }, + { + "type": "PACKAGE", + "url": "https://github.com/Antaris/RazorEngine" } ], "database_specific": { - "cwe_ids": [], - "severity": "MODERATE", + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-03-11T20:30:20Z", "nvd_published_at": "2022-03-06T06:15:00Z" diff --git a/advisories/unreviewed/2023/02/GHSA-2g67-jw5m-244m/GHSA-2g67-jw5m-244m.json b/advisories/unreviewed/2023/02/GHSA-2g67-jw5m-244m/GHSA-2g67-jw5m-244m.json index 3bf4be51e7b..4b48a861877 100644 --- a/advisories/unreviewed/2023/02/GHSA-2g67-jw5m-244m/GHSA-2g67-jw5m-244m.json +++ b/advisories/unreviewed/2023/02/GHSA-2g67-jw5m-244m/GHSA-2g67-jw5m-244m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2g67-jw5m-244m", - "modified": "2023-02-10T03:30:19Z", + "modified": "2025-03-26T15:32:08Z", "published": "2023-02-03T06:30:23Z", "aliases": [ "CVE-2023-25139" diff --git a/advisories/unreviewed/2023/02/GHSA-2h7q-7935-rv26/GHSA-2h7q-7935-rv26.json b/advisories/unreviewed/2023/02/GHSA-2h7q-7935-rv26/GHSA-2h7q-7935-rv26.json index 9e37a4f9600..610d32fd3dd 100644 --- a/advisories/unreviewed/2023/02/GHSA-2h7q-7935-rv26/GHSA-2h7q-7935-rv26.json +++ b/advisories/unreviewed/2023/02/GHSA-2h7q-7935-rv26/GHSA-2h7q-7935-rv26.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-3353-p834-c8g2/GHSA-3353-p834-c8g2.json b/advisories/unreviewed/2023/02/GHSA-3353-p834-c8g2/GHSA-3353-p834-c8g2.json index 4a5600c8c3b..09ea8a6fab4 100644 --- a/advisories/unreviewed/2023/02/GHSA-3353-p834-c8g2/GHSA-3353-p834-c8g2.json +++ b/advisories/unreviewed/2023/02/GHSA-3353-p834-c8g2/GHSA-3353-p834-c8g2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-65cf-47pp-gwrg/GHSA-65cf-47pp-gwrg.json b/advisories/unreviewed/2023/02/GHSA-65cf-47pp-gwrg/GHSA-65cf-47pp-gwrg.json index 13ac27e1395..5c693cac9fb 100644 --- a/advisories/unreviewed/2023/02/GHSA-65cf-47pp-gwrg/GHSA-65cf-47pp-gwrg.json +++ b/advisories/unreviewed/2023/02/GHSA-65cf-47pp-gwrg/GHSA-65cf-47pp-gwrg.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-66f3-5m77-hrqg/GHSA-66f3-5m77-hrqg.json b/advisories/unreviewed/2023/02/GHSA-66f3-5m77-hrqg/GHSA-66f3-5m77-hrqg.json index 2d6d5598204..273d4d30821 100644 --- a/advisories/unreviewed/2023/02/GHSA-66f3-5m77-hrqg/GHSA-66f3-5m77-hrqg.json +++ b/advisories/unreviewed/2023/02/GHSA-66f3-5m77-hrqg/GHSA-66f3-5m77-hrqg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/02/GHSA-6h64-3q22-9hpq/GHSA-6h64-3q22-9hpq.json b/advisories/unreviewed/2023/02/GHSA-6h64-3q22-9hpq/GHSA-6h64-3q22-9hpq.json index ba096386e24..68ed92de379 100644 --- a/advisories/unreviewed/2023/02/GHSA-6h64-3q22-9hpq/GHSA-6h64-3q22-9hpq.json +++ b/advisories/unreviewed/2023/02/GHSA-6h64-3q22-9hpq/GHSA-6h64-3q22-9hpq.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-6m3c-9c9q-f5w3/GHSA-6m3c-9c9q-f5w3.json b/advisories/unreviewed/2023/02/GHSA-6m3c-9c9q-f5w3/GHSA-6m3c-9c9q-f5w3.json index 2ca956a9f96..31d58524444 100644 --- a/advisories/unreviewed/2023/02/GHSA-6m3c-9c9q-f5w3/GHSA-6m3c-9c9q-f5w3.json +++ b/advisories/unreviewed/2023/02/GHSA-6m3c-9c9q-f5w3/GHSA-6m3c-9c9q-f5w3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/02/GHSA-6q2p-wm97-x79g/GHSA-6q2p-wm97-x79g.json b/advisories/unreviewed/2023/02/GHSA-6q2p-wm97-x79g/GHSA-6q2p-wm97-x79g.json index 6a0fcc1a498..a7588f54445 100644 --- a/advisories/unreviewed/2023/02/GHSA-6q2p-wm97-x79g/GHSA-6q2p-wm97-x79g.json +++ b/advisories/unreviewed/2023/02/GHSA-6q2p-wm97-x79g/GHSA-6q2p-wm97-x79g.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-78w3-m2fr-9r73/GHSA-78w3-m2fr-9r73.json b/advisories/unreviewed/2023/02/GHSA-78w3-m2fr-9r73/GHSA-78w3-m2fr-9r73.json index 9b3e23385c9..28f6c6e39a1 100644 --- a/advisories/unreviewed/2023/02/GHSA-78w3-m2fr-9r73/GHSA-78w3-m2fr-9r73.json +++ b/advisories/unreviewed/2023/02/GHSA-78w3-m2fr-9r73/GHSA-78w3-m2fr-9r73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78w3-m2fr-9r73", - "modified": "2023-02-14T21:30:34Z", + "modified": "2025-03-26T15:32:17Z", "published": "2023-02-06T21:30:29Z", "aliases": [ "CVE-2022-44267" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZLLS37P67CMBRML6OCG42GPCKGRCJNV" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S" diff --git a/advisories/unreviewed/2023/02/GHSA-7phj-7jw4-pf3j/GHSA-7phj-7jw4-pf3j.json b/advisories/unreviewed/2023/02/GHSA-7phj-7jw4-pf3j/GHSA-7phj-7jw4-pf3j.json index a7a43eb614a..2a0cdb13be5 100644 --- a/advisories/unreviewed/2023/02/GHSA-7phj-7jw4-pf3j/GHSA-7phj-7jw4-pf3j.json +++ b/advisories/unreviewed/2023/02/GHSA-7phj-7jw4-pf3j/GHSA-7phj-7jw4-pf3j.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-789", "CWE-89" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/02/GHSA-7q96-25c7-r8m6/GHSA-7q96-25c7-r8m6.json b/advisories/unreviewed/2023/02/GHSA-7q96-25c7-r8m6/GHSA-7q96-25c7-r8m6.json index ad6dd6d2d6d..f0cb82ee9c6 100644 --- a/advisories/unreviewed/2023/02/GHSA-7q96-25c7-r8m6/GHSA-7q96-25c7-r8m6.json +++ b/advisories/unreviewed/2023/02/GHSA-7q96-25c7-r8m6/GHSA-7q96-25c7-r8m6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-7v66-8jm8-8x7g/GHSA-7v66-8jm8-8x7g.json b/advisories/unreviewed/2023/02/GHSA-7v66-8jm8-8x7g/GHSA-7v66-8jm8-8x7g.json index 162d5595592..6489baf9324 100644 --- a/advisories/unreviewed/2023/02/GHSA-7v66-8jm8-8x7g/GHSA-7v66-8jm8-8x7g.json +++ b/advisories/unreviewed/2023/02/GHSA-7v66-8jm8-8x7g/GHSA-7v66-8jm8-8x7g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-78" + "CWE-78", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-8gjg-hfm2-ffq6/GHSA-8gjg-hfm2-ffq6.json b/advisories/unreviewed/2023/02/GHSA-8gjg-hfm2-ffq6/GHSA-8gjg-hfm2-ffq6.json index aedc309ed52..406179d1567 100644 --- a/advisories/unreviewed/2023/02/GHSA-8gjg-hfm2-ffq6/GHSA-8gjg-hfm2-ffq6.json +++ b/advisories/unreviewed/2023/02/GHSA-8gjg-hfm2-ffq6/GHSA-8gjg-hfm2-ffq6.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-g5qh-f5rv-grcp/GHSA-g5qh-f5rv-grcp.json b/advisories/unreviewed/2023/02/GHSA-g5qh-f5rv-grcp/GHSA-g5qh-f5rv-grcp.json index 8f6b66214a6..0e6525b1d35 100644 --- a/advisories/unreviewed/2023/02/GHSA-g5qh-f5rv-grcp/GHSA-g5qh-f5rv-grcp.json +++ b/advisories/unreviewed/2023/02/GHSA-g5qh-f5rv-grcp/GHSA-g5qh-f5rv-grcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qh-f5rv-grcp", - "modified": "2023-02-14T21:30:33Z", + "modified": "2025-03-26T15:32:17Z", "published": "2023-02-06T21:30:29Z", "aliases": [ "CVE-2022-44268" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZLLS37P67CMBRML6OCG42GPCKGRCJNV" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S" @@ -49,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-gm5r-35xq-qr9c/GHSA-gm5r-35xq-qr9c.json b/advisories/unreviewed/2023/02/GHSA-gm5r-35xq-qr9c/GHSA-gm5r-35xq-qr9c.json index 0789429167c..cbaea4ee641 100644 --- a/advisories/unreviewed/2023/02/GHSA-gm5r-35xq-qr9c/GHSA-gm5r-35xq-qr9c.json +++ b/advisories/unreviewed/2023/02/GHSA-gm5r-35xq-qr9c/GHSA-gm5r-35xq-qr9c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-hq8f-55fx-pqv7/GHSA-hq8f-55fx-pqv7.json b/advisories/unreviewed/2023/02/GHSA-hq8f-55fx-pqv7/GHSA-hq8f-55fx-pqv7.json index f8b45320bc5..0061d2dfbd8 100644 --- a/advisories/unreviewed/2023/02/GHSA-hq8f-55fx-pqv7/GHSA-hq8f-55fx-pqv7.json +++ b/advisories/unreviewed/2023/02/GHSA-hq8f-55fx-pqv7/GHSA-hq8f-55fx-pqv7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-525" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-j75c-xqjg-h88v/GHSA-j75c-xqjg-h88v.json b/advisories/unreviewed/2023/02/GHSA-j75c-xqjg-h88v/GHSA-j75c-xqjg-h88v.json index 32d4139294b..fa8046981ff 100644 --- a/advisories/unreviewed/2023/02/GHSA-j75c-xqjg-h88v/GHSA-j75c-xqjg-h88v.json +++ b/advisories/unreviewed/2023/02/GHSA-j75c-xqjg-h88v/GHSA-j75c-xqjg-h88v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-jhxg-8fv9-xvgm/GHSA-jhxg-8fv9-xvgm.json b/advisories/unreviewed/2023/02/GHSA-jhxg-8fv9-xvgm/GHSA-jhxg-8fv9-xvgm.json index 246e34dcc30..f03c8628981 100644 --- a/advisories/unreviewed/2023/02/GHSA-jhxg-8fv9-xvgm/GHSA-jhxg-8fv9-xvgm.json +++ b/advisories/unreviewed/2023/02/GHSA-jhxg-8fv9-xvgm/GHSA-jhxg-8fv9-xvgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhxg-8fv9-xvgm", - "modified": "2023-02-15T15:30:41Z", + "modified": "2025-03-26T15:32:17Z", "published": "2023-02-06T21:30:29Z", "aliases": [ "CVE-2022-42951" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-m59c-782g-v69q/GHSA-m59c-782g-v69q.json b/advisories/unreviewed/2023/02/GHSA-m59c-782g-v69q/GHSA-m59c-782g-v69q.json index f74b16b1ed9..d3a9154631d 100644 --- a/advisories/unreviewed/2023/02/GHSA-m59c-782g-v69q/GHSA-m59c-782g-v69q.json +++ b/advisories/unreviewed/2023/02/GHSA-m59c-782g-v69q/GHSA-m59c-782g-v69q.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/02/GHSA-mccq-xq7h-7q89/GHSA-mccq-xq7h-7q89.json b/advisories/unreviewed/2023/02/GHSA-mccq-xq7h-7q89/GHSA-mccq-xq7h-7q89.json index a44fefbb64d..d736dbabaf8 100644 --- a/advisories/unreviewed/2023/02/GHSA-mccq-xq7h-7q89/GHSA-mccq-xq7h-7q89.json +++ b/advisories/unreviewed/2023/02/GHSA-mccq-xq7h-7q89/GHSA-mccq-xq7h-7q89.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-mq9x-cjpv-8jjh/GHSA-mq9x-cjpv-8jjh.json b/advisories/unreviewed/2023/02/GHSA-mq9x-cjpv-8jjh/GHSA-mq9x-cjpv-8jjh.json index d4cc35058b2..2fd172bbaf7 100644 --- a/advisories/unreviewed/2023/02/GHSA-mq9x-cjpv-8jjh/GHSA-mq9x-cjpv-8jjh.json +++ b/advisories/unreviewed/2023/02/GHSA-mq9x-cjpv-8jjh/GHSA-mq9x-cjpv-8jjh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-q2cv-v83m-r24w/GHSA-q2cv-v83m-r24w.json b/advisories/unreviewed/2023/02/GHSA-q2cv-v83m-r24w/GHSA-q2cv-v83m-r24w.json index 598e8490789..a01aacdcda5 100644 --- a/advisories/unreviewed/2023/02/GHSA-q2cv-v83m-r24w/GHSA-q2cv-v83m-r24w.json +++ b/advisories/unreviewed/2023/02/GHSA-q2cv-v83m-r24w/GHSA-q2cv-v83m-r24w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-q682-3896-xh7g/GHSA-q682-3896-xh7g.json b/advisories/unreviewed/2023/02/GHSA-q682-3896-xh7g/GHSA-q682-3896-xh7g.json index 9a8cd39d8ca..bde19ae33d7 100644 --- a/advisories/unreviewed/2023/02/GHSA-q682-3896-xh7g/GHSA-q682-3896-xh7g.json +++ b/advisories/unreviewed/2023/02/GHSA-q682-3896-xh7g/GHSA-q682-3896-xh7g.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-qj7h-w49c-56jm/GHSA-qj7h-w49c-56jm.json b/advisories/unreviewed/2023/02/GHSA-qj7h-w49c-56jm/GHSA-qj7h-w49c-56jm.json index 6119e504c84..541330f37d9 100644 --- a/advisories/unreviewed/2023/02/GHSA-qj7h-w49c-56jm/GHSA-qj7h-w49c-56jm.json +++ b/advisories/unreviewed/2023/02/GHSA-qj7h-w49c-56jm/GHSA-qj7h-w49c-56jm.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-qprx-rfxr-x663/GHSA-qprx-rfxr-x663.json b/advisories/unreviewed/2023/02/GHSA-qprx-rfxr-x663/GHSA-qprx-rfxr-x663.json index 2356fa96789..02483b06b70 100644 --- a/advisories/unreviewed/2023/02/GHSA-qprx-rfxr-x663/GHSA-qprx-rfxr-x663.json +++ b/advisories/unreviewed/2023/02/GHSA-qprx-rfxr-x663/GHSA-qprx-rfxr-x663.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-rhj6-7p83-68fm/GHSA-rhj6-7p83-68fm.json b/advisories/unreviewed/2023/02/GHSA-rhj6-7p83-68fm/GHSA-rhj6-7p83-68fm.json index 3970eab0f25..034a88bee1e 100644 --- a/advisories/unreviewed/2023/02/GHSA-rhj6-7p83-68fm/GHSA-rhj6-7p83-68fm.json +++ b/advisories/unreviewed/2023/02/GHSA-rhj6-7p83-68fm/GHSA-rhj6-7p83-68fm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-476" + "CWE-476", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-vgjq-43qm-8f24/GHSA-vgjq-43qm-8f24.json b/advisories/unreviewed/2023/02/GHSA-vgjq-43qm-8f24/GHSA-vgjq-43qm-8f24.json index e917c544a49..f370359523b 100644 --- a/advisories/unreviewed/2023/02/GHSA-vgjq-43qm-8f24/GHSA-vgjq-43qm-8f24.json +++ b/advisories/unreviewed/2023/02/GHSA-vgjq-43qm-8f24/GHSA-vgjq-43qm-8f24.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-476" + "CWE-476", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-wgxw-vjvf-vr8h/GHSA-wgxw-vjvf-vr8h.json b/advisories/unreviewed/2023/02/GHSA-wgxw-vjvf-vr8h/GHSA-wgxw-vjvf-vr8h.json index 7d7b15abcdb..502b0d5c634 100644 --- a/advisories/unreviewed/2023/02/GHSA-wgxw-vjvf-vr8h/GHSA-wgxw-vjvf-vr8h.json +++ b/advisories/unreviewed/2023/02/GHSA-wgxw-vjvf-vr8h/GHSA-wgxw-vjvf-vr8h.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-xrvm-qcmp-42vc/GHSA-xrvm-qcmp-42vc.json b/advisories/unreviewed/2023/02/GHSA-xrvm-qcmp-42vc/GHSA-xrvm-qcmp-42vc.json index 8c8be4d9654..50595b4b661 100644 --- a/advisories/unreviewed/2023/02/GHSA-xrvm-qcmp-42vc/GHSA-xrvm-qcmp-42vc.json +++ b/advisories/unreviewed/2023/02/GHSA-xrvm-qcmp-42vc/GHSA-xrvm-qcmp-42vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrvm-qcmp-42vc", - "modified": "2023-02-15T15:30:41Z", + "modified": "2025-03-26T15:32:16Z", "published": "2023-02-06T21:30:29Z", "aliases": [ "CVE-2022-42950" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c949-3ppw-h395/GHSA-c949-3ppw-h395.json b/advisories/unreviewed/2024/04/GHSA-c949-3ppw-h395/GHSA-c949-3ppw-h395.json index 9ed1a938cc8..e3760e5357e 100644 --- a/advisories/unreviewed/2024/04/GHSA-c949-3ppw-h395/GHSA-c949-3ppw-h395.json +++ b/advisories/unreviewed/2024/04/GHSA-c949-3ppw-h395/GHSA-c949-3ppw-h395.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gvrj-cx9v-hg3m/GHSA-gvrj-cx9v-hg3m.json b/advisories/unreviewed/2024/04/GHSA-gvrj-cx9v-hg3m/GHSA-gvrj-cx9v-hg3m.json index 3ccf69de7fc..d4cb0bd0947 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvrj-cx9v-hg3m/GHSA-gvrj-cx9v-hg3m.json +++ b/advisories/unreviewed/2024/04/GHSA-gvrj-cx9v-hg3m/GHSA-gvrj-cx9v-hg3m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v28c-957v-55vg/GHSA-v28c-957v-55vg.json b/advisories/unreviewed/2024/04/GHSA-v28c-957v-55vg/GHSA-v28c-957v-55vg.json index 4fe91a08617..d9c08de43b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-v28c-957v-55vg/GHSA-v28c-957v-55vg.json +++ b/advisories/unreviewed/2024/04/GHSA-v28c-957v-55vg/GHSA-v28c-957v-55vg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v28c-957v-55vg", - "modified": "2024-04-25T15:30:37Z", + "modified": "2025-03-26T15:32:29Z", "published": "2024-04-25T15:30:37Z", "aliases": [ "CVE-2024-33247" ], "details": "Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-25T13:15:51Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json b/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json index a4d3b49abf6..1df13675620 100644 --- a/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json +++ b/advisories/unreviewed/2024/05/GHSA-3m3m-q3hw-6qq6/GHSA-3m3m-q3hw-6qq6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-3mhw-f79r-crmm/GHSA-3mhw-f79r-crmm.json b/advisories/unreviewed/2024/05/GHSA-3mhw-f79r-crmm/GHSA-3mhw-f79r-crmm.json index 5d465cd9879..c10904dbba1 100644 --- a/advisories/unreviewed/2024/05/GHSA-3mhw-f79r-crmm/GHSA-3mhw-f79r-crmm.json +++ b/advisories/unreviewed/2024/05/GHSA-3mhw-f79r-crmm/GHSA-3mhw-f79r-crmm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3mhw-f79r-crmm", - "modified": "2024-05-08T18:30:49Z", + "modified": "2025-03-26T15:32:29Z", "published": "2024-05-08T18:30:49Z", "aliases": [ "CVE-2024-33382" ], "details": "An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-08T17:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json b/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json index 20795cb871c..0b049d41c2e 100644 --- a/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json +++ b/advisories/unreviewed/2024/05/GHSA-rhq7-7m7h-w8m7/GHSA-rhq7-7m7h-w8m7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rhq7-7m7h-w8m7", - "modified": "2024-05-02T15:30:34Z", + "modified": "2025-03-26T15:32:29Z", "published": "2024-05-02T15:30:34Z", "aliases": [ "CVE-2024-33305" ], "details": "SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via \"Middle Name\" parameter in Create User.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-02T14:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7j6g-455m-7jv4/GHSA-7j6g-455m-7jv4.json b/advisories/unreviewed/2024/07/GHSA-7j6g-455m-7jv4/GHSA-7j6g-455m-7jv4.json index 2d402158702..f12c813398e 100644 --- a/advisories/unreviewed/2024/07/GHSA-7j6g-455m-7jv4/GHSA-7j6g-455m-7jv4.json +++ b/advisories/unreviewed/2024/07/GHSA-7j6g-455m-7jv4/GHSA-7j6g-455m-7jv4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json b/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json index 658dcbfdef6..59a57e0a46a 100644 --- a/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json +++ b/advisories/unreviewed/2024/07/GHSA-g38h-vjf2-59hp/GHSA-g38h-vjf2-59hp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-m2xw-6755-w968/GHSA-m2xw-6755-w968.json b/advisories/unreviewed/2024/07/GHSA-m2xw-6755-w968/GHSA-m2xw-6755-w968.json index 40966a2ca93..04c061e5dc1 100644 --- a/advisories/unreviewed/2024/07/GHSA-m2xw-6755-w968/GHSA-m2xw-6755-w968.json +++ b/advisories/unreviewed/2024/07/GHSA-m2xw-6755-w968/GHSA-m2xw-6755-w968.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json b/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json index 22b3461d79c..c13d3358f72 100644 --- a/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json +++ b/advisories/unreviewed/2024/10/GHSA-mvx6-xfx7-r23g/GHSA-mvx6-xfx7-r23g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json b/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json index 850d6230cac..0102f7e1db9 100644 --- a/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json +++ b/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-256g-w77v-wxmx", - "modified": "2025-03-24T21:30:34Z", + "modified": "2025-03-26T15:32:36Z", "published": "2025-03-24T21:30:33Z", "aliases": [ "CVE-2025-29312" ], "details": "An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-670" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2fgp-4w27-wc8x/GHSA-2fgp-4w27-wc8x.json b/advisories/unreviewed/2025/03/GHSA-2fgp-4w27-wc8x/GHSA-2fgp-4w27-wc8x.json new file mode 100644 index 00000000000..3bf4bd10885 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2fgp-4w27-wc8x/GHSA-2fgp-4w27-wc8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fgp-4w27-wc8x", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-27015" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27015" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/hostiko/vulnerability/wordpress-hostiko-theme-30-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2qhm-mh5c-2242/GHSA-2qhm-mh5c-2242.json b/advisories/unreviewed/2025/03/GHSA-2qhm-mh5c-2242/GHSA-2qhm-mh5c-2242.json new file mode 100644 index 00000000000..5eed0c38548 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2qhm-mh5c-2242/GHSA-2qhm-mh5c-2242.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qhm-mh5c-2242", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28921" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound SpatialMatch IDX allows Reflected XSS. This issue affects SpatialMatch IDX: from n/a through 3.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28921" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spatialmatch-free-lifestyle-search/vulnerability/wordpress-spatialmatch-idx-plugin-3-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2r2c-pw94-m93j/GHSA-2r2c-pw94-m93j.json b/advisories/unreviewed/2025/03/GHSA-2r2c-pw94-m93j/GHSA-2r2c-pw94-m93j.json new file mode 100644 index 00000000000..e0a24bf4206 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2r2c-pw94-m93j/GHSA-2r2c-pw94-m93j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r2c-pw94-m93j", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26541" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce allows Reflected XSS. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26541" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-altcoin-payment-gateway/vulnerability/wordpress-bitcoin-altcoin-payment-gateway-for-woocommerce-plugin-1-7-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3962-gjv5-4r4p/GHSA-3962-gjv5-4r4p.json b/advisories/unreviewed/2025/03/GHSA-3962-gjv5-4r4p/GHSA-3962-gjv5-4r4p.json new file mode 100644 index 00000000000..a44ef62cd69 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3962-gjv5-4r4p/GHSA-3962-gjv5-4r4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3962-gjv5-4r4p", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28924" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ZenphotoPress allows Reflected XSS. This issue affects ZenphotoPress: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zenphotopress/vulnerability/wordpress-zenphotopress-plugin-1-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3cf5-h6wh-qmg6/GHSA-3cf5-h6wh-qmg6.json b/advisories/unreviewed/2025/03/GHSA-3cf5-h6wh-qmg6/GHSA-3cf5-h6wh-qmg6.json new file mode 100644 index 00000000000..3fbcb7c7c19 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3cf5-h6wh-qmg6/GHSA-3cf5-h6wh-qmg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cf5-h6wh-qmg6", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28885" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Fiverr.com Official Search Box allows Stored XSS. This issue affects Fiverr.com Official Search Box: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28885" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fiverr-official-search-box/vulnerability/wordpress-fiverr-com-official-search-box-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3cm3-xc2x-9g73/GHSA-3cm3-xc2x-9g73.json b/advisories/unreviewed/2025/03/GHSA-3cm3-xc2x-9g73/GHSA-3cm3-xc2x-9g73.json new file mode 100644 index 00000000000..88c97c60063 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3cm3-xc2x-9g73/GHSA-3cm3-xc2x-9g73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cm3-xc2x-9g73", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28893" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Visual Text Editor allows Remote Code Inclusion. This issue affects Visual Text Editor: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28893" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visual-text-editor/vulnerability/wordpress-visual-text-editor-plugin-1-2-1-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3cv2-9pff-v434/GHSA-3cv2-9pff-v434.json b/advisories/unreviewed/2025/03/GHSA-3cv2-9pff-v434/GHSA-3cv2-9pff-v434.json new file mode 100644 index 00000000000..5683aaf2838 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3cv2-9pff-v434/GHSA-3cv2-9pff-v434.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cv2-9pff-v434", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23952" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget allows PHP Local File Inclusion. This issue affects custom-field-list-widget: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23952" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-field-list-widget/vulnerability/wordpress-custom-field-list-widget-plugin-1-5-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3h45-5qrh-cg5g/GHSA-3h45-5qrh-cg5g.json b/advisories/unreviewed/2025/03/GHSA-3h45-5qrh-cg5g/GHSA-3h45-5qrh-cg5g.json new file mode 100644 index 00000000000..be6ff54071e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3h45-5qrh-cg5g/GHSA-3h45-5qrh-cg5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h45-5qrh-cg5g", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28903" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Driving Directions allows Reflected XSS. This issue affects Driving Directions: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28903" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ddirections/vulnerability/wordpress-driving-directions-plugin-1-4-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-495w-c474-hvvj/GHSA-495w-c474-hvvj.json b/advisories/unreviewed/2025/03/GHSA-495w-c474-hvvj/GHSA-495w-c474-hvvj.json new file mode 100644 index 00000000000..3f76733d818 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-495w-c474-hvvj/GHSA-495w-c474-hvvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-495w-c474-hvvj", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-2820" + ], + "details": "An authenticated attacker can compromise the availability of the device via the network", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2820" + }, + { + "type": "WEB", + "url": "https://www.bizerba.com/downloads/global/information-security/2025/bizerba-sa-2025-0002.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4f8w-7rrv-r75q/GHSA-4f8w-7rrv-r75q.json b/advisories/unreviewed/2025/03/GHSA-4f8w-7rrv-r75q/GHSA-4f8w-7rrv-r75q.json new file mode 100644 index 00000000000..4b20a8d2640 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4f8w-7rrv-r75q/GHSA-4f8w-7rrv-r75q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f8w-7rrv-r75q", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26536" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yendif Player Another Events Calendar allows Reflected XSS. This issue affects Another Events Calendar: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26536" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/another-events-calendar/vulnerability/wordpress-another-events-calendar-plugin-1-7-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4mp6-9qmf-p4qw/GHSA-4mp6-9qmf-p4qw.json b/advisories/unreviewed/2025/03/GHSA-4mp6-9qmf-p4qw/GHSA-4mp6-9qmf-p4qw.json new file mode 100644 index 00000000000..0c7752a18a5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4mp6-9qmf-p4qw/GHSA-4mp6-9qmf-p4qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mp6-9qmf-p4qw", + "modified": "2025-03-26T15:32:39Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2025-23460" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound RWS Enquiry And Lead Follow-up allows Reflected XSS. This issue affects RWS Enquiry And Lead Follow-up: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rws-enquiry/vulnerability/wordpress-rws-enquiry-and-lead-follow-up-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json b/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json index a5dbe8c8bc3..c7dc1a6f4c1 100644 --- a/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json +++ b/advisories/unreviewed/2025/03/GHSA-4q6p-vw5p-724c/GHSA-4q6p-vw5p-724c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4q6p-vw5p-724c", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27833" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4xvx-54qc-h5fx/GHSA-4xvx-54qc-h5fx.json b/advisories/unreviewed/2025/03/GHSA-4xvx-54qc-h5fx/GHSA-4xvx-54qc-h5fx.json new file mode 100644 index 00000000000..def9130b48d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4xvx-54qc-h5fx/GHSA-4xvx-54qc-h5fx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xvx-54qc-h5fx", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-26986" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Business allows PHP Local File Inclusion.This issue affects Pearl - Corporate Business: from n/a before 3.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/pearl/vulnerability/wordpress-pearl-theme-3-4-8-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json b/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json index f8765cb0210..06c5ad51e1a 100644 --- a/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json +++ b/advisories/unreviewed/2025/03/GHSA-52fg-w63x-36xq/GHSA-52fg-w63x-36xq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-52fg-w63x-36xq", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27832" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-558w-4jfg-vp65/GHSA-558w-4jfg-vp65.json b/advisories/unreviewed/2025/03/GHSA-558w-4jfg-vp65/GHSA-558w-4jfg-vp65.json new file mode 100644 index 00000000000..7c822761c43 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-558w-4jfg-vp65/GHSA-558w-4jfg-vp65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-558w-4jfg-vp65", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26579" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper MicroPayments allows Reflected XSS. This issue affects MicroPayments: from n/a through 3.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paid-membership/vulnerability/wordpress-micropayments-paid-membership-plugin-1-2-reflected-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-55gp-8c42-mxr3/GHSA-55gp-8c42-mxr3.json b/advisories/unreviewed/2025/03/GHSA-55gp-8c42-mxr3/GHSA-55gp-8c42-mxr3.json new file mode 100644 index 00000000000..abcad698f65 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-55gp-8c42-mxr3/GHSA-55gp-8c42-mxr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55gp-8c42-mxr3", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26537" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound GDPR Tools allows Stored XSS. This issue affects GDPR Tools: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26537" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdpr-tools/vulnerability/wordpress-gdpr-tools-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5fh9-9r47-g22w/GHSA-5fh9-9r47-g22w.json b/advisories/unreviewed/2025/03/GHSA-5fh9-9r47-g22w/GHSA-5fh9-9r47-g22w.json new file mode 100644 index 00000000000..198eb5466e3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5fh9-9r47-g22w/GHSA-5fh9-9r47-g22w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fh9-9r47-g22w", + "modified": "2025-03-26T15:32:39Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2025-2228" + ], + "details": "The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.8 the 'register_user' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including usernames and passwords of any users who register via the Edit Login | Registration Form widget, as long as that user opens the email notification for successful registration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2228" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/responsive-addons-for-elementor/trunk/includes/modules-manager/login-register/class-login-register.php#L369" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261241" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/659ef2e8-589c-4901-88ce-1d674c056ece?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json b/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json index c78ccee8492..c68e3c2d72f 100644 --- a/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json +++ b/advisories/unreviewed/2025/03/GHSA-5fxv-x2j7-rmwm/GHSA-5fxv-x2j7-rmwm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5fxv-x2j7-rmwm", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:38Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27830" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5mgc-fcm2-r52q/GHSA-5mgc-fcm2-r52q.json b/advisories/unreviewed/2025/03/GHSA-5mgc-fcm2-r52q/GHSA-5mgc-fcm2-r52q.json new file mode 100644 index 00000000000..6d8a99d5b7b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5mgc-fcm2-r52q/GHSA-5mgc-fcm2-r52q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mgc-fcm2-r52q", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28880" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Blue Captcha allows Reflected XSS. This issue affects Blue Captcha: from n/a through 1.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28880" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blue-captcha/vulnerability/wordpress-blue-captcha-plugin-1-7-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5qj6-mg77-q89g/GHSA-5qj6-mg77-q89g.json b/advisories/unreviewed/2025/03/GHSA-5qj6-mg77-q89g/GHSA-5qj6-mg77-q89g.json new file mode 100644 index 00000000000..600c640d52a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5qj6-mg77-q89g/GHSA-5qj6-mg77-q89g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qj6-mg77-q89g", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26559" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Secure Invites allows Reflected XSS. This issue affects Secure Invites: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26559" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-mu-secure-invites/vulnerability/wordpress-secure-invites-plugin-1-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5x83-mrj6-f6x7/GHSA-5x83-mrj6-f6x7.json b/advisories/unreviewed/2025/03/GHSA-5x83-mrj6-f6x7/GHSA-5x83-mrj6-f6x7.json new file mode 100644 index 00000000000..beeb9eca52f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5x83-mrj6-f6x7/GHSA-5x83-mrj6-f6x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x83-mrj6-f6x7", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23735" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cosmin Schiopu Infugrator allows Reflected XSS. This issue affects Infugrator: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23735" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/infugrator/vulnerability/wordpress-infugrator-plugin-1-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5xrx-96wf-wfgx/GHSA-5xrx-96wf-wfgx.json b/advisories/unreviewed/2025/03/GHSA-5xrx-96wf-wfgx/GHSA-5xrx-96wf-wfgx.json new file mode 100644 index 00000000000..eaa7c8dd371 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5xrx-96wf-wfgx/GHSA-5xrx-96wf-wfgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xrx-96wf-wfgx", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26581" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Picture Gallery allows Reflected XSS. This issue affects Picture Gallery: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26581" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/picture-gallery/vulnerability/wordpress-picture-gallery-plugin-1-5-23-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json b/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json index 9aec39d0022..87c255eb8d3 100644 --- a/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json +++ b/advisories/unreviewed/2025/03/GHSA-62q7-445r-42wh/GHSA-62q7-445r-42wh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62q7-445r-42wh", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27834" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-62wq-f836-x445/GHSA-62wq-f836-x445.json b/advisories/unreviewed/2025/03/GHSA-62wq-f836-x445/GHSA-62wq-f836-x445.json new file mode 100644 index 00000000000..b33aedcc1c5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-62wq-f836-x445/GHSA-62wq-f836-x445.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62wq-f836-x445", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28889" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom Product Stickers for Woocommerce allows Reflected XSS. This issue affects Custom Product Stickers for Woocommerce: from n/a through 1.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28889" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-product-stickers-for-woocommerce/vulnerability/wordpress-custom-product-stickers-for-woocommerce-plugin-1-9-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6384-w4fj-cvg5/GHSA-6384-w4fj-cvg5.json b/advisories/unreviewed/2025/03/GHSA-6384-w4fj-cvg5/GHSA-6384-w4fj-cvg5.json new file mode 100644 index 00000000000..73bee83e2b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6384-w4fj-cvg5/GHSA-6384-w4fj-cvg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6384-w4fj-cvg5", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26560" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Contact Form III allows Reflected XSS. This issue affects WP Contact Form III: from n/a through 1.6.2d.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26560" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-contact-form-iii/vulnerability/wordpress-wp-contact-form-iii-plugin-1-6-2d-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-666m-w6mw-m583/GHSA-666m-w6mw-m583.json b/advisories/unreviewed/2025/03/GHSA-666m-w6mw-m583/GHSA-666m-w6mw-m583.json new file mode 100644 index 00000000000..153c58ad918 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-666m-w6mw-m583/GHSA-666m-w6mw-m583.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-666m-w6mw-m583", + "modified": "2025-03-26T15:32:39Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2022-39163" + ], + "details": "IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39163" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7192746" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json b/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json index 0e9b5f25498..46d12af68d5 100644 --- a/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json +++ b/advisories/unreviewed/2025/03/GHSA-674w-jwj3-6mv7/GHSA-674w-jwj3-6mv7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-674w-jwj3-6mv7", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:38Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-25372" ], "details": "NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-684f-3jwr-92rr/GHSA-684f-3jwr-92rr.json b/advisories/unreviewed/2025/03/GHSA-684f-3jwr-92rr/GHSA-684f-3jwr-92rr.json new file mode 100644 index 00000000000..cfab123c422 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-684f-3jwr-92rr/GHSA-684f-3jwr-92rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-684f-3jwr-92rr", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26576" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in takumin WP Simple Slideshow allows Reflected XSS. This issue affects WP Simple Slideshow: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-simple-slideshow/vulnerability/wordpress-wp-simple-slideshow-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json b/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json index 0d00dfca959..c32676e58a6 100644 --- a/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json +++ b/advisories/unreviewed/2025/03/GHSA-687p-fc47-c8ph/GHSA-687p-fc47-c8ph.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-687p-fc47-c8ph", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:37Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2024-48818" ], "details": "An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T20:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json b/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json index 9d4e87105d0..82d09d4e415 100644 --- a/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json +++ b/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6cpx-55pw-9cxq", - "modified": "2025-03-24T21:30:33Z", + "modified": "2025-03-26T15:32:36Z", "published": "2025-03-24T21:30:33Z", "aliases": [ "CVE-2025-29311" ], "details": "Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-331" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6hj5-9j3r-gpmm/GHSA-6hj5-9j3r-gpmm.json b/advisories/unreviewed/2025/03/GHSA-6hj5-9j3r-gpmm/GHSA-6hj5-9j3r-gpmm.json new file mode 100644 index 00000000000..a727b6dcaf3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hj5-9j3r-gpmm/GHSA-6hj5-9j3r-gpmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hj5-9j3r-gpmm", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26929" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NOUS Ouvert Utile et Simple Accounting for WooCommerce allows Stored XSS.This issue affects Accounting for WooCommerce: from n/a through 1.6.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26929" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/accounting-for-woocommerce/vulnerability/wordpress-accounting-for-woocommerce-plugin-1-6-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json b/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json index 12b2c7b8b8c..dfe60144263 100644 --- a/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json +++ b/advisories/unreviewed/2025/03/GHSA-6mxg-4m6j-9xh2/GHSA-6mxg-4m6j-9xh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6mxg-4m6j-9xh2", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:38Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2025-25374" ], "details": "In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6vfq-fmxw-qgx5/GHSA-6vfq-fmxw-qgx5.json b/advisories/unreviewed/2025/03/GHSA-6vfq-fmxw-qgx5/GHSA-6vfq-fmxw-qgx5.json new file mode 100644 index 00000000000..fb7878b7d2d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6vfq-fmxw-qgx5/GHSA-6vfq-fmxw-qgx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vfq-fmxw-qgx5", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2025-23543" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FOMO Pay Chinese Payment Solution allows Reflected XSS. This issue affects FOMO Pay Chinese Payment Solution: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fomo-payment-gateway-for-woocommerce/vulnerability/wordpress-fomo-pay-chinese-payment-solution-plugin-2-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7374-x3rm-h27g/GHSA-7374-x3rm-h27g.json b/advisories/unreviewed/2025/03/GHSA-7374-x3rm-h27g/GHSA-7374-x3rm-h27g.json new file mode 100644 index 00000000000..d33aa197158 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7374-x3rm-h27g/GHSA-7374-x3rm-h27g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7374-x3rm-h27g", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26941" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin allows SQL Injection.This issue affects Church Admin: from n/a through 5.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26941" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/church-admin/vulnerability/wordpress-church-admin-plugin-5-0-18-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7f56-j9jp-755p/GHSA-7f56-j9jp-755p.json b/advisories/unreviewed/2025/03/GHSA-7f56-j9jp-755p/GHSA-7f56-j9jp-755p.json new file mode 100644 index 00000000000..1d68a2f07dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7f56-j9jp-755p/GHSA-7f56-j9jp-755p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f56-j9jp-755p", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28898" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WP Multistore Locator allows SQL Injection. This issue affects WP Multistore Locator: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28898" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-multi-store-locator/vulnerability/wordpress-wp-multistore-locator-plugin-2-5-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7h6r-r8cm-jcwr/GHSA-7h6r-r8cm-jcwr.json b/advisories/unreviewed/2025/03/GHSA-7h6r-r8cm-jcwr/GHSA-7h6r-r8cm-jcwr.json new file mode 100644 index 00000000000..8be4511efbe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7h6r-r8cm-jcwr/GHSA-7h6r-r8cm-jcwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h6r-r8cm-jcwr", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26573" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Rizzi Guestbook allows Reflected XSS. This issue affects Rizzi Guestbook: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26573" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rizzi-guestbook/vulnerability/wordpress-rizzi-guestbook-plugin-4-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7ppg-mv7x-5fvw/GHSA-7ppg-mv7x-5fvw.json b/advisories/unreviewed/2025/03/GHSA-7ppg-mv7x-5fvw/GHSA-7ppg-mv7x-5fvw.json new file mode 100644 index 00000000000..b9981327975 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7ppg-mv7x-5fvw/GHSA-7ppg-mv7x-5fvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ppg-mv7x-5fvw", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26566" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound In Stock Mailer for WooCommerce allows Reflected XSS. This issue affects In Stock Mailer for WooCommerce: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26566" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/in-stock-mailer-for-woocommerce/vulnerability/wordpress-in-stock-mailer-for-woocommerce-plugin-2-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7xxp-v6x4-h4rj/GHSA-7xxp-v6x4-h4rj.json b/advisories/unreviewed/2025/03/GHSA-7xxp-v6x4-h4rj/GHSA-7xxp-v6x4-h4rj.json new file mode 100644 index 00000000000..fad80083025 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7xxp-v6x4-h4rj/GHSA-7xxp-v6x4-h4rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xxp-v6x4-h4rj", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23666" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Management-screen-droptiles allows Reflected XSS. This issue affects Management-screen-droptiles: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23666" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cxc-sawa/vulnerability/wordpress-management-screen-droptiles-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8525-h9w3-hxg7/GHSA-8525-h9w3-hxg7.json b/advisories/unreviewed/2025/03/GHSA-8525-h9w3-hxg7/GHSA-8525-h9w3-hxg7.json new file mode 100644 index 00000000000..c6d4ea2a918 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8525-h9w3-hxg7/GHSA-8525-h9w3-hxg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8525-h9w3-hxg7", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23937" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound LinkedIn Lite allows PHP Local File Inclusion. This issue affects LinkedIn Lite: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/linkedin-lite/vulnerability/wordpress-linkedin-lite-plugin-1-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-897j-g3gr-c45r/GHSA-897j-g3gr-c45r.json b/advisories/unreviewed/2025/03/GHSA-897j-g3gr-c45r/GHSA-897j-g3gr-c45r.json new file mode 100644 index 00000000000..fd7af50a11e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-897j-g3gr-c45r/GHSA-897j-g3gr-c45r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-897j-g3gr-c45r", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28911" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gravity2pdf Gravity 2 PDF allows Reflected XSS. This issue affects Gravity 2 PDF: from n/a through 3.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28911" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gf2pdf/vulnerability/wordpress-gravity-2-pdf-plugin-3-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8r7g-cp82-7wj7/GHSA-8r7g-cp82-7wj7.json b/advisories/unreviewed/2025/03/GHSA-8r7g-cp82-7wj7/GHSA-8r7g-cp82-7wj7.json new file mode 100644 index 00000000000..662c8ab7469 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8r7g-cp82-7wj7/GHSA-8r7g-cp82-7wj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r7g-cp82-7wj7", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-23964" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Google Plus allows Reflected XSS. This issue affects Google Plus: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23964" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-plus-google/vulnerability/wordpress-google-plus-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-93vr-r8wm-997h/GHSA-93vr-r8wm-997h.json b/advisories/unreviewed/2025/03/GHSA-93vr-r8wm-997h/GHSA-93vr-r8wm-997h.json new file mode 100644 index 00000000000..41adff9bf00 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-93vr-r8wm-997h/GHSA-93vr-r8wm-997h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93vr-r8wm-997h", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23680" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Narnoo Operator allows Reflected XSS. This issue affects Narnoo Operator: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23680" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/narnoo-shortcodes/vulnerability/wordpress-narnoo-operator-plugin-2-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json b/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json index c0fdbf0f984..3f7ff49543e 100644 --- a/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json +++ b/advisories/unreviewed/2025/03/GHSA-96p6-38w3-wjpv/GHSA-96p6-38w3-wjpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96p6-38w3-wjpv", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27836" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9mjp-p38w-xgfq/GHSA-9mjp-p38w-xgfq.json b/advisories/unreviewed/2025/03/GHSA-9mjp-p38w-xgfq/GHSA-9mjp-p38w-xgfq.json new file mode 100644 index 00000000000..98d4b82dcb8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9mjp-p38w-xgfq/GHSA-9mjp-p38w-xgfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mjp-p38w-xgfq", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26584" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound TBTestimonials allows Reflected XSS. This issue affects TBTestimonials: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26584" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tb-testimonials/vulnerability/wordpress-tbtestimonials-plugin-1-7-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9pcx-rmqr-hp8m/GHSA-9pcx-rmqr-hp8m.json b/advisories/unreviewed/2025/03/GHSA-9pcx-rmqr-hp8m/GHSA-9pcx-rmqr-hp8m.json new file mode 100644 index 00000000000..0b9f24b9d24 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9pcx-rmqr-hp8m/GHSA-9pcx-rmqr-hp8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pcx-rmqr-hp8m", + "modified": "2025-03-26T15:32:39Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2025-22283" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riyaz GetSocial allows Reflected XSS. This issue affects GetSocial: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/getsocial/vulnerability/wordpress-getsocial-plugin-2-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json b/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json index 6b86bebb20b..3ac174acade 100644 --- a/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json +++ b/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-c37p-8677-9fjp/GHSA-c37p-8677-9fjp.json b/advisories/unreviewed/2025/03/GHSA-c37p-8677-9fjp/GHSA-c37p-8677-9fjp.json new file mode 100644 index 00000000000..6f0cc5a6eee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c37p-8677-9fjp/GHSA-c37p-8677-9fjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c37p-8677-9fjp", + "modified": "2025-03-26T15:32:39Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2024-45351" + ], + "details": "A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45351" + }, + { + "type": "WEB", + "url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=549" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ccxp-4v4f-798f/GHSA-ccxp-4v4f-798f.json b/advisories/unreviewed/2025/03/GHSA-ccxp-4v4f-798f/GHSA-ccxp-4v4f-798f.json new file mode 100644 index 00000000000..9eaecb95206 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ccxp-4v4f-798f/GHSA-ccxp-4v4f-798f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccxp-4v4f-798f", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26739" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction newseqo allows Stored XSS.This issue affects newseqo: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26739" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/newseqo/vulnerability/wordpress-newseqo-theme-2-1-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cf7v-rvrx-hj59/GHSA-cf7v-rvrx-hj59.json b/advisories/unreviewed/2025/03/GHSA-cf7v-rvrx-hj59/GHSA-cf7v-rvrx-hj59.json new file mode 100644 index 00000000000..9b5a1f91a30 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cf7v-rvrx-hj59/GHSA-cf7v-rvrx-hj59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf7v-rvrx-hj59", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23728" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AuMenu allows Reflected XSS. This issue affects AuMenu: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23728" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aumenu/vulnerability/wordpress-aumenu-plugin-1-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cm76-ccg3-wcc8/GHSA-cm76-ccg3-wcc8.json b/advisories/unreviewed/2025/03/GHSA-cm76-ccg3-wcc8/GHSA-cm76-ccg3-wcc8.json new file mode 100644 index 00000000000..bc4a4310072 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cm76-ccg3-wcc8/GHSA-cm76-ccg3-wcc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm76-ccg3-wcc8", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28869" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nextgen-gallery-voting/vulnerability/wordpress-nextgen-gallery-voting-plugin-2-7-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json b/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json index 21178ac5429..f799b4a92da 100644 --- a/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json +++ b/advisories/unreviewed/2025/03/GHSA-cv66-crjx-w6c2/GHSA-cv66-crjx-w6c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cv66-crjx-w6c2", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:37Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2025-30118" ], "details": "An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by occupying the only available connection. The SSID remains broadcast at all times, increasing exposure to potential attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T20:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f82j-r7r9-rwqc/GHSA-f82j-r7r9-rwqc.json b/advisories/unreviewed/2025/03/GHSA-f82j-r7r9-rwqc/GHSA-f82j-r7r9-rwqc.json new file mode 100644 index 00000000000..ce58cd76730 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f82j-r7r9-rwqc/GHSA-f82j-r7r9-rwqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f82j-r7r9-rwqc", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-24690" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allows PHP Local File Inclusion. This issue affects Formality: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24690" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/formality/vulnerability/wordpress-formality-plugin-1-5-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fjvg-cccj-287m/GHSA-fjvg-cccj-287m.json b/advisories/unreviewed/2025/03/GHSA-fjvg-cccj-287m/GHSA-fjvg-cccj-287m.json new file mode 100644 index 00000000000..4a379ad17e9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fjvg-cccj-287m/GHSA-fjvg-cccj-287m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjvg-cccj-287m", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28942" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCommerce allows SQL Injection. This issue affects Trust Payments Gateway for WooCommerce: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28942" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/trust-payments-hosted-payment-pages-integration/vulnerability/wordpress-trust-payments-gateway-for-woocommerce-plugin-1-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json b/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json index b4c73c2f353..c6a89dd60ea 100644 --- a/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json +++ b/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-g93w-hmq8-rmfm/GHSA-g93w-hmq8-rmfm.json b/advisories/unreviewed/2025/03/GHSA-g93w-hmq8-rmfm/GHSA-g93w-hmq8-rmfm.json new file mode 100644 index 00000000000..d7570c88508 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g93w-hmq8-rmfm/GHSA-g93w-hmq8-rmfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g93w-hmq8-rmfm", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28917" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom Smilies allows Stored XSS. This issue affects Custom Smilies: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28917" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-smilies-se/vulnerability/wordpress-custom-smilies-plugin-2-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gg32-8592-8mq5/GHSA-gg32-8592-8mq5.json b/advisories/unreviewed/2025/03/GHSA-gg32-8592-8mq5/GHSA-gg32-8592-8mq5.json new file mode 100644 index 00000000000..62a5b376890 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gg32-8592-8mq5/GHSA-gg32-8592-8mq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg32-8592-8mq5", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28890" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Lightview Plus allows Reflected XSS. This issue affects Lightview Plus: from n/a through 3.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28890" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lightview-plus/vulnerability/wordpress-lightview-plus-plugin-3-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gg84-rh2v-pxc7/GHSA-gg84-rh2v-pxc7.json b/advisories/unreviewed/2025/03/GHSA-gg84-rh2v-pxc7/GHSA-gg84-rh2v-pxc7.json new file mode 100644 index 00000000000..c0e026026c1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gg84-rh2v-pxc7/GHSA-gg84-rh2v-pxc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg84-rh2v-pxc7", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26869" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Build allows Stored XSS.This issue affects Build: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/build/vulnerability/wordpress-build-theme-1-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json b/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json index 894128fa2cf..d1f0622a225 100644 --- a/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json +++ b/advisories/unreviewed/2025/03/GHSA-gj36-hrrj-wvg8/GHSA-gj36-hrrj-wvg8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gj36-hrrj-wvg8", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27835" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json b/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json index cec34010970..38dae5080da 100644 --- a/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json +++ b/advisories/unreviewed/2025/03/GHSA-gj66-2xh5-rjrr/GHSA-gj66-2xh5-rjrr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gj66-2xh5-rjrr", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:38Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2025-25373" ], "details": "The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gr4p-qg3r-wj73/GHSA-gr4p-qg3r-wj73.json b/advisories/unreviewed/2025/03/GHSA-gr4p-qg3r-wj73/GHSA-gr4p-qg3r-wj73.json new file mode 100644 index 00000000000..b3ee0e0bd4b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gr4p-qg3r-wj73/GHSA-gr4p-qg3r-wj73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr4p-qg3r-wj73", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28858" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Maps allows Reflected XSS. This issue affects Arrow Maps: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28858" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ap-google-maps/vulnerability/wordpress-arrow-maps-plugin-1-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gr92-mxmc-wrw8/GHSA-gr92-mxmc-wrw8.json b/advisories/unreviewed/2025/03/GHSA-gr92-mxmc-wrw8/GHSA-gr92-mxmc-wrw8.json new file mode 100644 index 00000000000..1e2d8d4a75e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gr92-mxmc-wrw8/GHSA-gr92-mxmc-wrw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr92-mxmc-wrw8", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26542" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Zalo Live Chat allows Reflected XSS. This issue affects Zalo Live Chat: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zalo-live-chat/vulnerability/wordpress-zalo-live-chat-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h3jh-gvh6-j6x9/GHSA-h3jh-gvh6-j6x9.json b/advisories/unreviewed/2025/03/GHSA-h3jh-gvh6-j6x9/GHSA-h3jh-gvh6-j6x9.json new file mode 100644 index 00000000000..4f0c8909bb0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h3jh-gvh6-j6x9/GHSA-h3jh-gvh6-j6x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3jh-gvh6-j6x9", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23638" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Frontend Post Submission allows Reflected XSS. This issue affects Frontend Post Submission: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/frontend-post-submission/vulnerability/wordpress-frontend-post-submission-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h876-5qxv-hfv8/GHSA-h876-5qxv-hfv8.json b/advisories/unreviewed/2025/03/GHSA-h876-5qxv-hfv8/GHSA-h876-5qxv-hfv8.json index 41cab784f7a..949cd7faac0 100644 --- a/advisories/unreviewed/2025/03/GHSA-h876-5qxv-hfv8/GHSA-h876-5qxv-hfv8.json +++ b/advisories/unreviewed/2025/03/GHSA-h876-5qxv-hfv8/GHSA-h876-5qxv-hfv8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json b/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json index 93912b6be25..e28fe8aae76 100644 --- a/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json +++ b/advisories/unreviewed/2025/03/GHSA-hp5w-82fv-gq5h/GHSA-hp5w-82fv-gq5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hp5w-82fv-gq5h", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:38Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2025-25371" ], "details": "NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-hph8-p5j3-prh4/GHSA-hph8-p5j3-prh4.json b/advisories/unreviewed/2025/03/GHSA-hph8-p5j3-prh4/GHSA-hph8-p5j3-prh4.json new file mode 100644 index 00000000000..99c4a61834b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hph8-p5j3-prh4/GHSA-hph8-p5j3-prh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hph8-p5j3-prh4", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28873" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Shuffle allows Blind SQL Injection. This issue affects Shuffle: from n/a through 0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28873" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shuffle/vulnerability/wordpress-shuffle-plugin-0-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hpv9-g7qg-3mx5/GHSA-hpv9-g7qg-3mx5.json b/advisories/unreviewed/2025/03/GHSA-hpv9-g7qg-3mx5/GHSA-hpv9-g7qg-3mx5.json new file mode 100644 index 00000000000..132700290af --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hpv9-g7qg-3mx5/GHSA-hpv9-g7qg-3mx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpv9-g7qg-3mx5", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26922" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techthemes AuraMart allows Stored XSS.This issue affects AuraMart: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26922" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/auramart/vulnerability/wordpress-auramart-theme-2-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hr5f-49h6-wqx8/GHSA-hr5f-49h6-wqx8.json b/advisories/unreviewed/2025/03/GHSA-hr5f-49h6-wqx8/GHSA-hr5f-49h6-wqx8.json new file mode 100644 index 00000000000..99de0ab4ae7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hr5f-49h6-wqx8/GHSA-hr5f-49h6-wqx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr5f-49h6-wqx8", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26546" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cookies Pro allows Reflected XSS. This issue affects Cookies Pro: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cookies-pro/vulnerability/wordpress-cookies-pro-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j2rq-95q8-x377/GHSA-j2rq-95q8-x377.json b/advisories/unreviewed/2025/03/GHSA-j2rq-95q8-x377/GHSA-j2rq-95q8-x377.json new file mode 100644 index 00000000000..fe3aaaa9f16 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j2rq-95q8-x377/GHSA-j2rq-95q8-x377.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2rq-95q8-x377", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28934" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple Post Series allows Reflected XSS. This issue affects Simple Post Series: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28934" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-post-series/vulnerability/wordpress-simple-post-series-plugin-2-4-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j568-rwg2-2cjc/GHSA-j568-rwg2-2cjc.json b/advisories/unreviewed/2025/03/GHSA-j568-rwg2-2cjc/GHSA-j568-rwg2-2cjc.json new file mode 100644 index 00000000000..f3f79f4c9e7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j568-rwg2-2cjc/GHSA-j568-rwg2-2cjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j568-rwg2-2cjc", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26583" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Video Share VOD allows Reflected XSS. This issue affects Video Share VOD: from n/a through 2.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/video-share-vod/vulnerability/wordpress-video-share-vod-plugin-2-6-32-reflected-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j6w5-x2v9-vjvh/GHSA-j6w5-x2v9-vjvh.json b/advisories/unreviewed/2025/03/GHSA-j6w5-x2v9-vjvh/GHSA-j6w5-x2v9-vjvh.json new file mode 100644 index 00000000000..3675ae62534 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j6w5-x2v9-vjvh/GHSA-j6w5-x2v9-vjvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6w5-x2v9-vjvh", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-2819" + ], + "details": "There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2819" + }, + { + "type": "WEB", + "url": "https://www.bizerba.com/downloads/global/information-security/2025/bizerba-sa-2025-0001.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jmwp-wj4g-2wx6/GHSA-jmwp-wj4g-2wx6.json b/advisories/unreviewed/2025/03/GHSA-jmwp-wj4g-2wx6/GHSA-jmwp-wj4g-2wx6.json new file mode 100644 index 00000000000..555cf150f06 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jmwp-wj4g-2wx6/GHSA-jmwp-wj4g-2wx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmwp-wj4g-2wx6", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-30524" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog allows SQL Injection. This issue affects Product Catalog: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30524" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/displayproduct/vulnerability/wordpress-product-catalog-plugin-1-0-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxwh-6552-jgf9/GHSA-jxwh-6552-jgf9.json b/advisories/unreviewed/2025/03/GHSA-jxwh-6552-jgf9/GHSA-jxwh-6552-jgf9.json new file mode 100644 index 00000000000..f4ff45ca23c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxwh-6552-jgf9/GHSA-jxwh-6552-jgf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxwh-6552-jgf9", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28935" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus allows Reflected XSS. This issue affects Fancybox Plus: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fancybox-plus/vulnerability/wordpress-fancybox-plus-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mf5w-5crj-3f7j/GHSA-mf5w-5crj-3f7j.json b/advisories/unreviewed/2025/03/GHSA-mf5w-5crj-3f7j/GHSA-mf5w-5crj-3f7j.json new file mode 100644 index 00000000000..be46f7c18c6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mf5w-5crj-3f7j/GHSA-mf5w-5crj-3f7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf5w-5crj-3f7j", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23546" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound RDP inGroups+ allows Reflected XSS. This issue affects RDP inGroups+: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rdp-ingroups/vulnerability/wordpress-rdp-ingroups-plugin-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mxrj-wg4w-q89c/GHSA-mxrj-wg4w-q89c.json b/advisories/unreviewed/2025/03/GHSA-mxrj-wg4w-q89c/GHSA-mxrj-wg4w-q89c.json new file mode 100644 index 00000000000..df6745f9a87 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mxrj-wg4w-q89c/GHSA-mxrj-wg4w-q89c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxrj-wg4w-q89c", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28916" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Docpro allows PHP Local File Inclusion. This issue affects Docpro: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28916" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/docpro/vulnerability/wordpress-docpro-plugin-2-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json b/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json index fa188bfe108..7ff398e51ad 100644 --- a/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json +++ b/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2xx-r693-hcg3", - "modified": "2025-03-24T21:30:34Z", + "modified": "2025-03-26T15:32:35Z", "published": "2025-03-24T21:30:33Z", "aliases": [ "CVE-2025-29310" ], "details": "An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json b/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json index f31caf73f82..754c90ff199 100644 --- a/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json +++ b/advisories/unreviewed/2025/03/GHSA-p7qf-r7jf-7mf3/GHSA-p7qf-r7jf-7mf3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p7qf-r7jf-7mf3", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:37Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2024-55028" ], "details": "A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pcjq-f5x3-32jw/GHSA-pcjq-f5x3-32jw.json b/advisories/unreviewed/2025/03/GHSA-pcjq-f5x3-32jw/GHSA-pcjq-f5x3-32jw.json new file mode 100644 index 00000000000..4785c08faa5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pcjq-f5x3-32jw/GHSA-pcjq-f5x3-32jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcjq-f5x3-32jw", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23704" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reuven Karasik Your Lightbox allows Reflected XSS. This issue affects Your Lightbox: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23704" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/your-lightbox/vulnerability/wordpress-your-lightbox-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json b/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json index 82d547bb0ac..387c59ba5fa 100644 --- a/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json +++ b/advisories/unreviewed/2025/03/GHSA-phrv-w9px-24x9/GHSA-phrv-w9px-24x9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phrv-w9px-24x9", - "modified": "2025-03-25T21:31:33Z", + "modified": "2025-03-26T15:32:38Z", "published": "2025-03-25T21:31:33Z", "aliases": [ "CVE-2024-55030" ], "details": "A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-q4gq-f754-g4cm/GHSA-q4gq-f754-g4cm.json b/advisories/unreviewed/2025/03/GHSA-q4gq-f754-g4cm/GHSA-q4gq-f754-g4cm.json new file mode 100644 index 00000000000..afbce23983c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q4gq-f754-g4cm/GHSA-q4gq-f754-g4cm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4gq-f754-g4cm", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23612" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pixobe Cartography allows Reflected XSS. This issue affects Pixobe Cartography: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23612" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pixobe-cartography/vulnerability/wordpress-pixobe-cartography-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q6hv-hgwg-f36q/GHSA-q6hv-hgwg-f36q.json b/advisories/unreviewed/2025/03/GHSA-q6hv-hgwg-f36q/GHSA-q6hv-hgwg-f36q.json new file mode 100644 index 00000000000..29d3d3e5d7a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q6hv-hgwg-f36q/GHSA-q6hv-hgwg-f36q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6hv-hgwg-f36q", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-27014" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko allows Reflected XSS.This issue affects Hostiko: from n/a before 30.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27014" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/hostiko/vulnerability/wordpress-hostiko-theme-30-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qcw6-3cfv-2mjg/GHSA-qcw6-3cfv-2mjg.json b/advisories/unreviewed/2025/03/GHSA-qcw6-3cfv-2mjg/GHSA-qcw6-3cfv-2mjg.json new file mode 100644 index 00000000000..ea3fe3a366a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qcw6-3cfv-2mjg/GHSA-qcw6-3cfv-2mjg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcw6-3cfv-2mjg", + "modified": "2025-03-26T15:32:39Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2025-23459" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NS Simple Intro Loader allows Reflected XSS. This issue affects NS Simple Intro Loader: from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ns-simple-intro-loader/vulnerability/wordpress-ns-simple-intro-loader-plugin-2-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qrh8-xh8q-58h3/GHSA-qrh8-xh8q-58h3.json b/advisories/unreviewed/2025/03/GHSA-qrh8-xh8q-58h3/GHSA-qrh8-xh8q-58h3.json new file mode 100644 index 00000000000..01457b7298a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qrh8-xh8q-58h3/GHSA-qrh8-xh8q-58h3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrh8-xh8q-58h3", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28855" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Teleport allows Reflected XSS. This issue affects Teleport: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28855" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/teleport/vulnerability/wordpress-teleport-plugin-1-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qvp7-vxrx-fx9x/GHSA-qvp7-vxrx-fx9x.json b/advisories/unreviewed/2025/03/GHSA-qvp7-vxrx-fx9x/GHSA-qvp7-vxrx-fx9x.json new file mode 100644 index 00000000000..eb4df28376a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvp7-vxrx-fx9x/GHSA-qvp7-vxrx-fx9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvp7-vxrx-fx9x", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23466" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsiteeditor Site Editor Google Map allows Reflected XSS. This issue affects Site Editor Google Map: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23466" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-editor-google-map/vulnerability/wordpress-site-editor-google-map-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r4r6-77v3-8vgh/GHSA-r4r6-77v3-8vgh.json b/advisories/unreviewed/2025/03/GHSA-r4r6-77v3-8vgh/GHSA-r4r6-77v3-8vgh.json new file mode 100644 index 00000000000..37a91a43e21 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r4r6-77v3-8vgh/GHSA-r4r6-77v3-8vgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4r6-77v3-8vgh", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-26544" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UTM tags tracking for Contact Form 7 allows Reflected XSS. This issue affects UTM tags tracking for Contact Form 7: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-utm-tracking/vulnerability/wordpressutm-tags-landing-page-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json b/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json index 878b37a11ae..e5bf8a225fa 100644 --- a/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json +++ b/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-r9c5-mh6w-wh5v/GHSA-r9c5-mh6w-wh5v.json b/advisories/unreviewed/2025/03/GHSA-r9c5-mh6w-wh5v/GHSA-r9c5-mh6w-wh5v.json new file mode 100644 index 00000000000..c3d3d2f8d83 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r9c5-mh6w-wh5v/GHSA-r9c5-mh6w-wh5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9c5-mh6w-wh5v", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26923" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows Stored XSS.This issue affects Event post: from n/a through 5.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-post/vulnerability/wordpress-event-post-plugin-5-9-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rf6p-cgc2-j8vp/GHSA-rf6p-cgc2-j8vp.json b/advisories/unreviewed/2025/03/GHSA-rf6p-cgc2-j8vp/GHSA-rf6p-cgc2-j8vp.json new file mode 100644 index 00000000000..a48c9e1f251 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rf6p-cgc2-j8vp/GHSA-rf6p-cgc2-j8vp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf6p-cgc2-j8vp", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28939" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WP Google Calendar Manager allows Blind SQL Injection. This issue affects WP Google Calendar Manager: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28939" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-gcalendar/vulnerability/wordpress-wp-google-calendar-manager-plugin-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rhgp-3mp4-4qhc/GHSA-rhgp-3mp4-4qhc.json b/advisories/unreviewed/2025/03/GHSA-rhgp-3mp4-4qhc/GHSA-rhgp-3mp4-4qhc.json new file mode 100644 index 00000000000..23c0d544707 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rhgp-3mp4-4qhc/GHSA-rhgp-3mp4-4qhc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhgp-3mp4-4qhc", + "modified": "2025-03-26T15:32:41Z", + "published": "2025-03-26T15:32:41Z", + "aliases": [ + "CVE-2025-25134" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Theme Demo Bar allows Reflected XSS. This issue affects Theme Demo Bar: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25134" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-theme-demo-bar/vulnerability/wordpress-theme-demo-bar-plugin-1-6-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json b/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json index 2325255bafc..ec1b09a2dea 100644 --- a/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json +++ b/advisories/unreviewed/2025/03/GHSA-rmm8-wf49-vvww/GHSA-rmm8-wf49-vvww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rmm8-wf49-vvww", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27837" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rr6x-4q8f-283c/GHSA-rr6x-4q8f-283c.json b/advisories/unreviewed/2025/03/GHSA-rr6x-4q8f-283c/GHSA-rr6x-4q8f-283c.json new file mode 100644 index 00000000000..fc9493dccb3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rr6x-4q8f-283c/GHSA-rr6x-4q8f-283c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr6x-4q8f-283c", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26564" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kagla GNUCommerce allows Reflected XSS. This issue affects GNUCommerce: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gnucommerce/vulnerability/wordpress-gnucommerce-plugin-1-5-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rx7j-2crx-fpf9/GHSA-rx7j-2crx-fpf9.json b/advisories/unreviewed/2025/03/GHSA-rx7j-2crx-fpf9/GHSA-rx7j-2crx-fpf9.json new file mode 100644 index 00000000000..a76a5f3ca8a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rx7j-2crx-fpf9/GHSA-rx7j-2crx-fpf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx7j-2crx-fpf9", + "modified": "2025-03-26T15:32:43Z", + "published": "2025-03-26T15:32:43Z", + "aliases": [ + "CVE-2025-26747" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/rainbownews/vulnerability/wordpress-rainbownews-theme-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rx8g-9fwr-gfmw/GHSA-rx8g-9fwr-gfmw.json b/advisories/unreviewed/2025/03/GHSA-rx8g-9fwr-gfmw/GHSA-rx8g-9fwr-gfmw.json new file mode 100644 index 00000000000..96649079776 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rx8g-9fwr-gfmw/GHSA-rx8g-9fwr-gfmw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx8g-9fwr-gfmw", + "modified": "2025-03-26T15:32:46Z", + "published": "2025-03-26T15:32:46Z", + "aliases": [ + "CVE-2025-28928" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Are you robot google recaptcha for wordpress allows Reflected XSS. This issue affects Are you robot google recaptcha for wordpress: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/are-you-robot-recaptcha/vulnerability/wordpress-are-you-robot-google-recaptcha-for-wordpress-plugin-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v35q-38fv-g69h/GHSA-v35q-38fv-g69h.json b/advisories/unreviewed/2025/03/GHSA-v35q-38fv-g69h/GHSA-v35q-38fv-g69h.json new file mode 100644 index 00000000000..5dd6ab756d3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v35q-38fv-g69h/GHSA-v35q-38fv-g69h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v35q-38fv-g69h", + "modified": "2025-03-26T15:32:45Z", + "published": "2025-03-26T15:32:45Z", + "aliases": [ + "CVE-2025-28899" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Event Ticketing allows Reflected XSS. This issue affects WP Event Ticketing: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28899" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpeventticketing/vulnerability/wordpress-wp-event-ticketing-plugin-1-3-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v3x8-h6r4-68c2/GHSA-v3x8-h6r4-68c2.json b/advisories/unreviewed/2025/03/GHSA-v3x8-h6r4-68c2/GHSA-v3x8-h6r4-68c2.json new file mode 100644 index 00000000000..ebbdcb35f42 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v3x8-h6r4-68c2/GHSA-v3x8-h6r4-68c2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3x8-h6r4-68c2", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23633" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Database Audit allows Reflected XSS. This issue affects WP Database Audit: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/database-audit/vulnerability/wordpress-wp-database-audit-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json b/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json index 17c974638bf..6678dfdcbd6 100644 --- a/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json +++ b/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v767-x36h-4gv8", - "modified": "2025-03-24T21:30:33Z", + "modified": "2025-03-26T15:32:35Z", "published": "2025-03-24T21:30:33Z", "aliases": [ "CVE-2025-29135" ], "details": "A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v842-8rq8-6j89/GHSA-v842-8rq8-6j89.json b/advisories/unreviewed/2025/03/GHSA-v842-8rq8-6j89/GHSA-v842-8rq8-6j89.json new file mode 100644 index 00000000000..9e1ad6d6778 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v842-8rq8-6j89/GHSA-v842-8rq8-6j89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v842-8rq8-6j89", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28877" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Key4ce osTicket Bridge allows Reflected XSS. This issue affects Key4ce osTicket Bridge: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28877" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/key4ce-osticket-bridge/vulnerability/wordpress-key4ce-osticket-bridge-plugin-1-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v9xw-vg74-98jg/GHSA-v9xw-vg74-98jg.json b/advisories/unreviewed/2025/03/GHSA-v9xw-vg74-98jg/GHSA-v9xw-vg74-98jg.json new file mode 100644 index 00000000000..f5ab00516f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v9xw-vg74-98jg/GHSA-v9xw-vg74-98jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9xw-vg74-98jg", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23632" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button allows Reflected XSS. This issue affects CG Button: from n/a through 1.0.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/content-glass-button/vulnerability/wordpress-cg-button-plugin-1-0-5-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w2ph-8pcw-pr59/GHSA-w2ph-8pcw-pr59.json b/advisories/unreviewed/2025/03/GHSA-w2ph-8pcw-pr59/GHSA-w2ph-8pcw-pr59.json new file mode 100644 index 00000000000..e85714e8c14 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w2ph-8pcw-pr59/GHSA-w2ph-8pcw-pr59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2ph-8pcw-pr59", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26565" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kagla GNUPress allows Reflected XSS. This issue affects GNUPress: from n/a through 0.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26565" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gnupress/vulnerability/wordpress-gnupress-plugin-0-2-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w6h6-x333-v779/GHSA-w6h6-x333-v779.json b/advisories/unreviewed/2025/03/GHSA-w6h6-x333-v779/GHSA-w6h6-x333-v779.json new file mode 100644 index 00000000000..cc19e31bea4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w6h6-x333-v779/GHSA-w6h6-x333-v779.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6h6-x333-v779", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28865" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lionelroux WP Colorful Tag Cloud allows Reflected XSS. This issue affects WP Colorful Tag Cloud: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28865" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-colorful-tag-cloud/vulnerability/wordpress-wp-colorful-tag-cloud-plugin-2-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json b/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json index 3be69e932b9..b64213efc33 100644 --- a/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json +++ b/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-wph6-jwvx-f7w9/GHSA-wph6-jwvx-f7w9.json b/advisories/unreviewed/2025/03/GHSA-wph6-jwvx-f7w9/GHSA-wph6-jwvx-f7w9.json new file mode 100644 index 00000000000..8a4c7e4a2f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wph6-jwvx-f7w9/GHSA-wph6-jwvx-f7w9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wph6-jwvx-f7w9", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:39Z", + "aliases": [ + "CVE-2025-23542" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert D Payne RDP Linkedin Login allows Reflected XSS. This issue affects RDP Linkedin Login: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rdp-linkedin-login/vulnerability/wordpress-rdp-linkedin-login-plugin-1-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wwh3-mf32-qwp8/GHSA-wwh3-mf32-qwp8.json b/advisories/unreviewed/2025/03/GHSA-wwh3-mf32-qwp8/GHSA-wwh3-mf32-qwp8.json new file mode 100644 index 00000000000..21c98f5ccf8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wwh3-mf32-qwp8/GHSA-wwh3-mf32-qwp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwh3-mf32-qwp8", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-27267" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in srcoley Random Quotes allows Reflected XSS. This issue affects Random Quotes: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/random-quotes/vulnerability/wordpress-random-quotes-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json b/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json index cdcd14a5fbe..2dc4dde78d1 100644 --- a/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json +++ b/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x447-66j7-93px", - "modified": "2025-03-24T21:30:33Z", + "modified": "2025-03-26T15:32:35Z", "published": "2025-03-24T21:30:33Z", "aliases": [ "CVE-2025-29100" ], "details": "Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:17Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json b/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json index 89a2f9916bd..2c472c28a1a 100644 --- a/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json +++ b/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json b/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json index 7c5217b2b45..04f65cb1f45 100644 --- a/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json +++ b/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x65v-g96x-c6gw", - "modified": "2025-03-24T21:30:34Z", + "modified": "2025-03-26T15:32:37Z", "published": "2025-03-24T21:30:34Z", "aliases": [ "CVE-2025-29315" ], "details": "An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T21:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json b/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json index a2a5acd7c4f..f9344f95799 100644 --- a/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json +++ b/advisories/unreviewed/2025/03/GHSA-x74r-f89v-3jw9/GHSA-x74r-f89v-3jw9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x74r-f89v-3jw9", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T15:32:39Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-27831" ], "details": "An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-25T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x7x9-ghgp-468h/GHSA-x7x9-ghgp-468h.json b/advisories/unreviewed/2025/03/GHSA-x7x9-ghgp-468h/GHSA-x7x9-ghgp-468h.json new file mode 100644 index 00000000000..5365e376801 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x7x9-ghgp-468h/GHSA-x7x9-ghgp-468h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7x9-ghgp-468h", + "modified": "2025-03-26T15:32:42Z", + "published": "2025-03-26T15:32:42Z", + "aliases": [ + "CVE-2025-26575" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Maurer Display Post Meta allows Reflected XSS. This issue affects Display Post Meta: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/display-post-meta/vulnerability/wordpress-display-post-meta-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json b/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json index 0a4a098c2a2..4dcb3d04dee 100644 --- a/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json +++ b/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-xhwr-82m4-g88f/GHSA-xhwr-82m4-g88f.json b/advisories/unreviewed/2025/03/GHSA-xhwr-82m4-g88f/GHSA-xhwr-82m4-g88f.json new file mode 100644 index 00000000000..bfd41910f1a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xhwr-82m4-g88f/GHSA-xhwr-82m4-g88f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhwr-82m4-g88f", + "modified": "2025-03-26T15:32:40Z", + "published": "2025-03-26T15:32:40Z", + "aliases": [ + "CVE-2025-23714" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AppReview allows Reflected XSS. This issue affects AppReview: from n/a through 0.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23714" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appreview/vulnerability/wordpress-appreview-plugin-0-2-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xmx6-fp5q-5xrh/GHSA-xmx6-fp5q-5xrh.json b/advisories/unreviewed/2025/03/GHSA-xmx6-fp5q-5xrh/GHSA-xmx6-fp5q-5xrh.json new file mode 100644 index 00000000000..dfaa83633fe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xmx6-fp5q-5xrh/GHSA-xmx6-fp5q-5xrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmx6-fp5q-5xrh", + "modified": "2025-03-26T15:32:44Z", + "published": "2025-03-26T15:32:44Z", + "aliases": [ + "CVE-2025-28882" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omnify, Inc. Omnify allows Reflected XSS. This issue affects Omnify: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28882" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/omnify-widget/vulnerability/wordpress-omnify-plugin-2-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-26T15:16:15Z" + } +} \ No newline at end of file