From a8cd7327d3bbddb9a1d51a9a5c8cfc0a02017be4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Mar 2025 21:33:02 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3fw2-c83v-qv48.json | 3 +- .../GHSA-ch8r-8jgx-j3g6.json | 3 +- .../GHSA-cjh7-46ch-hp83.json | 4 +- .../GHSA-rg29-f6cq-5hp4.json | 3 +- .../GHSA-v47m-7f9r-q6v2.json | 4 +- .../GHSA-x5rv-46w7-9492.json | 3 +- .../GHSA-2995-qwmm-cm3p.json | 4 +- .../GHSA-3pjq-c8pr-33gx.json | 4 +- .../GHSA-6324-2p78-9j67.json | 4 +- .../GHSA-mpq2-r2jc-4wmr.json | 4 +- .../GHSA-qm38-g6p6-r6vr.json | 4 +- .../GHSA-3x3j-cw3j-2xvc.json | 2 +- .../GHSA-9p67-jm42-x3f6.json | 4 +- .../GHSA-9vm4-7h35-5g6c.json | 2 +- .../GHSA-h2p2-w857-329f.json | 18 ++++++- .../GHSA-w634-6x8m-jgvx.json | 4 +- .../GHSA-x8f4-mm5h-f849.json | 4 +- .../GHSA-j2r3-gxq6-3rp2.json | 2 +- .../GHSA-36mr-3fcp-m422.json | 6 ++- .../GHSA-rvmr-97cf-9f3m.json | 8 +-- .../GHSA-4ggp-9p27-vq7h.json | 4 +- .../GHSA-g759-3922-4v5f.json | 15 ++++-- .../GHSA-gq6r-j83x-w77v.json | 11 ++-- .../GHSA-mjq8-gg9x-87gr.json | 15 ++++-- .../GHSA-3gx6-pfq2-pf53.json | 11 ++-- .../GHSA-78fh-92p7-q975.json | 11 ++-- .../GHSA-hv4g-gwhx-j629.json | 11 ++-- .../GHSA-j23h-727c-9qvf.json | 11 ++-- .../GHSA-mxgq-9hhc-gf5w.json | 4 +- .../GHSA-265f-v3vf-6m77.json | 4 +- .../GHSA-36fq-6c6v-89gr.json | 4 +- .../GHSA-3j75-rq9m-pxrv.json | 11 ++-- .../GHSA-7x33-7jjx-2gmh.json | 11 ++-- .../GHSA-8hff-rh3f-34cf.json | 4 +- .../GHSA-cpr3-2wp6-xc3c.json | 6 ++- .../GHSA-fq2p-4p8g-3975.json | 4 +- .../GHSA-pjfh-ccg3-6463.json | 4 +- .../GHSA-rq46-9225-gj4f.json | 11 ++-- .../GHSA-7qxh-m238-859c.json | 3 +- .../GHSA-jwr6-46q6-xcr4.json | 4 +- .../GHSA-596r-xq28-523m.json | 4 +- .../GHSA-hqp7-v4pv-fg66.json | 4 +- .../GHSA-rg57-w2fr-7hgm.json | 4 +- .../GHSA-v4v9-v4wf-9c86.json | 1 + .../GHSA-9wpw-58rw-f8gm.json | 4 +- .../GHSA-86wc-gr98-6p59.json | 4 +- .../GHSA-v77g-99m4-2vmq.json | 4 +- .../GHSA-j6xc-hhqx-8w7p.json | 4 +- .../GHSA-2jvm-jgg9-h383.json | 36 +++++++++++++ .../GHSA-36w9-f92f-5ghj.json | 52 +++++++++++++++++++ .../GHSA-3j87-859p-q82m.json | 15 ++++-- .../GHSA-44vc-9wvw-r372.json | 11 ++-- .../GHSA-5jh9-vq9c-95gr.json | 11 ++-- .../GHSA-7w4w-ph42-vrfq.json | 11 ++-- .../GHSA-8hc3-wwgj-w8f5.json | 44 ++++++++++++++++ .../GHSA-8wwq-574q-q2j9.json | 38 ++++++++++++++ .../GHSA-9hr4-7h76-8f5h.json | 36 +++++++++++++ .../GHSA-ch85-v3jm-42jh.json | 11 ++-- .../GHSA-fpm3-qrmh-vx5x.json | 11 ++-- .../GHSA-p5g3-6w3j-v5qc.json | 33 ++++++++++++ .../GHSA-pph8-wh6p-w5m7.json | 11 ++-- .../GHSA-pxc8-qhvr-5954.json | 44 ++++++++++++++++ .../GHSA-qccg-v3f9-84pm.json | 11 ++-- .../GHSA-r56h-j38w-hrqq.json | 6 ++- .../GHSA-r6gw-8vw8-65gm.json | 40 ++++++++++++++ .../GHSA-rjgp-5vq3-q8c2.json | 37 +++++++++++++ .../GHSA-vff8-5vm8-wh67.json | 11 ++-- .../GHSA-xxvw-6qqh-qrjj.json | 37 +++++++++++++ 68 files changed, 678 insertions(+), 106 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2jvm-jgg9-h383/GHSA-2jvm-jgg9-h383.json create mode 100644 advisories/unreviewed/2025/03/GHSA-36w9-f92f-5ghj/GHSA-36w9-f92f-5ghj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8hc3-wwgj-w8f5/GHSA-8hc3-wwgj-w8f5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9hr4-7h76-8f5h/GHSA-9hr4-7h76-8f5h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p5g3-6w3j-v5qc/GHSA-p5g3-6w3j-v5qc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r6gw-8vw8-65gm/GHSA-r6gw-8vw8-65gm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rjgp-5vq3-q8c2/GHSA-rjgp-5vq3-q8c2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xxvw-6qqh-qrjj/GHSA-xxvw-6qqh-qrjj.json diff --git a/advisories/unreviewed/2022/05/GHSA-3fw2-c83v-qv48/GHSA-3fw2-c83v-qv48.json b/advisories/unreviewed/2022/05/GHSA-3fw2-c83v-qv48/GHSA-3fw2-c83v-qv48.json index 31d42e3896b..f90a2380c64 100644 --- a/advisories/unreviewed/2022/05/GHSA-3fw2-c83v-qv48/GHSA-3fw2-c83v-qv48.json +++ b/advisories/unreviewed/2022/05/GHSA-3fw2-c83v-qv48/GHSA-3fw2-c83v-qv48.json @@ -29,7 +29,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-ch8r-8jgx-j3g6/GHSA-ch8r-8jgx-j3g6.json b/advisories/unreviewed/2022/05/GHSA-ch8r-8jgx-j3g6/GHSA-ch8r-8jgx-j3g6.json index 2e499a09489..144ee4fef13 100644 --- a/advisories/unreviewed/2022/05/GHSA-ch8r-8jgx-j3g6/GHSA-ch8r-8jgx-j3g6.json +++ b/advisories/unreviewed/2022/05/GHSA-ch8r-8jgx-j3g6/GHSA-ch8r-8jgx-j3g6.json @@ -33,7 +33,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-cjh7-46ch-hp83/GHSA-cjh7-46ch-hp83.json b/advisories/unreviewed/2022/05/GHSA-cjh7-46ch-hp83/GHSA-cjh7-46ch-hp83.json index 5a257d8422c..c6371b5b1d2 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjh7-46ch-hp83/GHSA-cjh7-46ch-hp83.json +++ b/advisories/unreviewed/2022/05/GHSA-cjh7-46ch-hp83/GHSA-cjh7-46ch-hp83.json @@ -28,7 +28,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-rg29-f6cq-5hp4/GHSA-rg29-f6cq-5hp4.json b/advisories/unreviewed/2022/05/GHSA-rg29-f6cq-5hp4/GHSA-rg29-f6cq-5hp4.json index 3e27674d8b0..1c0b850a962 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg29-f6cq-5hp4/GHSA-rg29-f6cq-5hp4.json +++ b/advisories/unreviewed/2022/05/GHSA-rg29-f6cq-5hp4/GHSA-rg29-f6cq-5hp4.json @@ -29,7 +29,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-v47m-7f9r-q6v2/GHSA-v47m-7f9r-q6v2.json b/advisories/unreviewed/2022/05/GHSA-v47m-7f9r-q6v2/GHSA-v47m-7f9r-q6v2.json index bd5127c3fff..86284cfa12f 100644 --- a/advisories/unreviewed/2022/05/GHSA-v47m-7f9r-q6v2/GHSA-v47m-7f9r-q6v2.json +++ b/advisories/unreviewed/2022/05/GHSA-v47m-7f9r-q6v2/GHSA-v47m-7f9r-q6v2.json @@ -28,7 +28,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-190" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-x5rv-46w7-9492/GHSA-x5rv-46w7-9492.json b/advisories/unreviewed/2022/05/GHSA-x5rv-46w7-9492/GHSA-x5rv-46w7-9492.json index 45518045aa1..6d005f37d44 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5rv-46w7-9492/GHSA-x5rv-46w7-9492.json +++ b/advisories/unreviewed/2022/05/GHSA-x5rv-46w7-9492/GHSA-x5rv-46w7-9492.json @@ -29,7 +29,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-2995-qwmm-cm3p/GHSA-2995-qwmm-cm3p.json b/advisories/unreviewed/2023/01/GHSA-2995-qwmm-cm3p/GHSA-2995-qwmm-cm3p.json index f899b830411..9d6b7ea3bcc 100644 --- a/advisories/unreviewed/2023/01/GHSA-2995-qwmm-cm3p/GHSA-2995-qwmm-cm3p.json +++ b/advisories/unreviewed/2023/01/GHSA-2995-qwmm-cm3p/GHSA-2995-qwmm-cm3p.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-3pjq-c8pr-33gx/GHSA-3pjq-c8pr-33gx.json b/advisories/unreviewed/2023/01/GHSA-3pjq-c8pr-33gx/GHSA-3pjq-c8pr-33gx.json index 75e550fc533..2610a3ccb55 100644 --- a/advisories/unreviewed/2023/01/GHSA-3pjq-c8pr-33gx/GHSA-3pjq-c8pr-33gx.json +++ b/advisories/unreviewed/2023/01/GHSA-3pjq-c8pr-33gx/GHSA-3pjq-c8pr-33gx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-6324-2p78-9j67/GHSA-6324-2p78-9j67.json b/advisories/unreviewed/2023/01/GHSA-6324-2p78-9j67/GHSA-6324-2p78-9j67.json index 684d14796e5..5e481e40eab 100644 --- a/advisories/unreviewed/2023/01/GHSA-6324-2p78-9j67/GHSA-6324-2p78-9j67.json +++ b/advisories/unreviewed/2023/01/GHSA-6324-2p78-9j67/GHSA-6324-2p78-9j67.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-mpq2-r2jc-4wmr/GHSA-mpq2-r2jc-4wmr.json b/advisories/unreviewed/2023/01/GHSA-mpq2-r2jc-4wmr/GHSA-mpq2-r2jc-4wmr.json index 828efed36b0..8ef34ed0d83 100644 --- a/advisories/unreviewed/2023/01/GHSA-mpq2-r2jc-4wmr/GHSA-mpq2-r2jc-4wmr.json +++ b/advisories/unreviewed/2023/01/GHSA-mpq2-r2jc-4wmr/GHSA-mpq2-r2jc-4wmr.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-qm38-g6p6-r6vr/GHSA-qm38-g6p6-r6vr.json b/advisories/unreviewed/2023/01/GHSA-qm38-g6p6-r6vr/GHSA-qm38-g6p6-r6vr.json index b77a761064c..19e54c4265d 100644 --- a/advisories/unreviewed/2023/01/GHSA-qm38-g6p6-r6vr/GHSA-qm38-g6p6-r6vr.json +++ b/advisories/unreviewed/2023/01/GHSA-qm38-g6p6-r6vr/GHSA-qm38-g6p6-r6vr.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-3x3j-cw3j-2xvc/GHSA-3x3j-cw3j-2xvc.json b/advisories/unreviewed/2023/02/GHSA-3x3j-cw3j-2xvc/GHSA-3x3j-cw3j-2xvc.json index 33ceab79887..f9601722b62 100644 --- a/advisories/unreviewed/2023/02/GHSA-3x3j-cw3j-2xvc/GHSA-3x3j-cw3j-2xvc.json +++ b/advisories/unreviewed/2023/02/GHSA-3x3j-cw3j-2xvc/GHSA-3x3j-cw3j-2xvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x3j-cw3j-2xvc", - "modified": "2023-02-22T18:30:34Z", + "modified": "2025-03-20T21:31:37Z", "published": "2023-02-14T09:30:16Z", "aliases": [ "CVE-2023-25758" diff --git a/advisories/unreviewed/2023/02/GHSA-9p67-jm42-x3f6/GHSA-9p67-jm42-x3f6.json b/advisories/unreviewed/2023/02/GHSA-9p67-jm42-x3f6/GHSA-9p67-jm42-x3f6.json index ff521a48836..da96f6f0f4a 100644 --- a/advisories/unreviewed/2023/02/GHSA-9p67-jm42-x3f6/GHSA-9p67-jm42-x3f6.json +++ b/advisories/unreviewed/2023/02/GHSA-9p67-jm42-x3f6/GHSA-9p67-jm42-x3f6.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-602" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-9vm4-7h35-5g6c/GHSA-9vm4-7h35-5g6c.json b/advisories/unreviewed/2023/02/GHSA-9vm4-7h35-5g6c/GHSA-9vm4-7h35-5g6c.json index 19e6b6f8e39..d9cbbd7eca1 100644 --- a/advisories/unreviewed/2023/02/GHSA-9vm4-7h35-5g6c/GHSA-9vm4-7h35-5g6c.json +++ b/advisories/unreviewed/2023/02/GHSA-9vm4-7h35-5g6c/GHSA-9vm4-7h35-5g6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vm4-7h35-5g6c", - "modified": "2023-03-03T21:30:19Z", + "modified": "2025-03-20T21:31:38Z", "published": "2023-02-25T06:30:22Z", "aliases": [ "CVE-2023-26545" diff --git a/advisories/unreviewed/2023/02/GHSA-h2p2-w857-329f/GHSA-h2p2-w857-329f.json b/advisories/unreviewed/2023/02/GHSA-h2p2-w857-329f/GHSA-h2p2-w857-329f.json index 6047a1c16a5..3d2c6516425 100644 --- a/advisories/unreviewed/2023/02/GHSA-h2p2-w857-329f/GHSA-h2p2-w857-329f.json +++ b/advisories/unreviewed/2023/02/GHSA-h2p2-w857-329f/GHSA-h2p2-w857-329f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2p2-w857-329f", - "modified": "2023-02-23T15:33:07Z", + "modified": "2025-03-20T21:31:37Z", "published": "2023-02-14T21:30:28Z", "aliases": [ "CVE-2023-25725" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25725" }, + { + "type": "WEB", + "url": "https://git.haproxy.org/?p=haproxy-2.7.git%3Ba=commit%3Bh=a0e561ad7f29ed50c473f5a9da664267b60d1112" + }, { "type": "WEB", "url": "https://git.haproxy.org/?p=haproxy-2.7.git;a=commit;h=a0e561ad7f29ed50c473f5a9da664267b60d1112" @@ -27,6 +31,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00012.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPTJQHKUEU2PQ7RWFUYAFLAD4STEIKHU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JM5NCIBTHYDTLPY2UNC4HO2VAHHE6CJG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FPTJQHKUEU2PQ7RWFUYAFLAD4STEIKHU" @@ -45,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-444" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-w634-6x8m-jgvx/GHSA-w634-6x8m-jgvx.json b/advisories/unreviewed/2023/02/GHSA-w634-6x8m-jgvx/GHSA-w634-6x8m-jgvx.json index 4f768206ba6..e47c86491b9 100644 --- a/advisories/unreviewed/2023/02/GHSA-w634-6x8m-jgvx/GHSA-w634-6x8m-jgvx.json +++ b/advisories/unreviewed/2023/02/GHSA-w634-6x8m-jgvx/GHSA-w634-6x8m-jgvx.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-x8f4-mm5h-f849/GHSA-x8f4-mm5h-f849.json b/advisories/unreviewed/2023/02/GHSA-x8f4-mm5h-f849/GHSA-x8f4-mm5h-f849.json index f465ed1df98..6471b30a6b7 100644 --- a/advisories/unreviewed/2023/02/GHSA-x8f4-mm5h-f849/GHSA-x8f4-mm5h-f849.json +++ b/advisories/unreviewed/2023/02/GHSA-x8f4-mm5h-f849/GHSA-x8f4-mm5h-f849.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-522" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-j2r3-gxq6-3rp2/GHSA-j2r3-gxq6-3rp2.json b/advisories/unreviewed/2023/03/GHSA-j2r3-gxq6-3rp2/GHSA-j2r3-gxq6-3rp2.json index 2bb57bd3b88..69c70e30f49 100644 --- a/advisories/unreviewed/2023/03/GHSA-j2r3-gxq6-3rp2/GHSA-j2r3-gxq6-3rp2.json +++ b/advisories/unreviewed/2023/03/GHSA-j2r3-gxq6-3rp2/GHSA-j2r3-gxq6-3rp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2r3-gxq6-3rp2", - "modified": "2023-03-09T03:30:15Z", + "modified": "2025-03-20T21:31:38Z", "published": "2023-03-01T21:30:18Z", "aliases": [ "CVE-2023-23000" diff --git a/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json b/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json index acd81818039..5b7c5f186fa 100644 --- a/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json +++ b/advisories/unreviewed/2024/02/GHSA-36mr-3fcp-m422/GHSA-36mr-3fcp-m422.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-36mr-3fcp-m422", - "modified": "2024-02-21T06:30:32Z", + "modified": "2025-03-20T21:31:39Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-22235" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json b/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json index 704c1ce165c..3c310c51f48 100644 --- a/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json +++ b/advisories/unreviewed/2024/02/GHSA-rvmr-97cf-9f3m/GHSA-rvmr-97cf-9f3m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rvmr-97cf-9f3m", - "modified": "2024-10-24T15:31:06Z", + "modified": "2025-03-20T21:31:39Z", "published": "2024-02-13T21:30:30Z", "aliases": [ "CVE-2023-31346" ], - "details": "Failure to initialize\nmemory in SEV Firmware may allow a privileged attacker to access stale data\nfrom other guests.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n", + "details": "Failure to initialize\nmemory in SEV Firmware may allow a privileged attacker to access stale data\nfrom other guests.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json b/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json index 3b0651799b0..15f9b2c1901 100644 --- a/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json +++ b/advisories/unreviewed/2024/03/GHSA-4ggp-9p27-vq7h/GHSA-4ggp-9p27-vq7h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-g759-3922-4v5f/GHSA-g759-3922-4v5f.json b/advisories/unreviewed/2024/03/GHSA-g759-3922-4v5f/GHSA-g759-3922-4v5f.json index 750bb97ec24..de642f491c1 100644 --- a/advisories/unreviewed/2024/03/GHSA-g759-3922-4v5f/GHSA-g759-3922-4v5f.json +++ b/advisories/unreviewed/2024/03/GHSA-g759-3922-4v5f/GHSA-g759-3922-4v5f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g759-3922-4v5f", - "modified": "2024-03-16T06:30:29Z", + "modified": "2025-03-20T21:31:39Z", "published": "2024-03-16T06:30:29Z", "aliases": [ "CVE-2024-28070" ], "details": "A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit could allow an attacker to access sensitive information and gain unauthorized access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-16T06:15:14Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json b/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json index d6022687c95..b3c9b6e63ee 100644 --- a/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json +++ b/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gq6r-j83x-w77v", - "modified": "2024-03-11T18:31:09Z", + "modified": "2025-03-20T21:31:39Z", "published": "2024-03-11T18:31:09Z", "aliases": [ "CVE-2024-0559" ], "details": "The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T18:15:17Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mjq8-gg9x-87gr/GHSA-mjq8-gg9x-87gr.json b/advisories/unreviewed/2024/03/GHSA-mjq8-gg9x-87gr/GHSA-mjq8-gg9x-87gr.json index 359e2325cff..09bd0e626b6 100644 --- a/advisories/unreviewed/2024/03/GHSA-mjq8-gg9x-87gr/GHSA-mjq8-gg9x-87gr.json +++ b/advisories/unreviewed/2024/03/GHSA-mjq8-gg9x-87gr/GHSA-mjq8-gg9x-87gr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mjq8-gg9x-87gr", - "modified": "2024-03-18T09:30:31Z", + "modified": "2025-03-20T21:31:39Z", "published": "2024-03-18T09:30:31Z", "aliases": [ "CVE-2024-28128" ], "details": "Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json b/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json index 784707f0e80..23e072e77d7 100644 --- a/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json +++ b/advisories/unreviewed/2024/04/GHSA-3gx6-pfq2-pf53/GHSA-3gx6-pfq2-pf53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3gx6-pfq2-pf53", - "modified": "2024-04-15T06:30:35Z", + "modified": "2025-03-20T21:31:40Z", "published": "2024-04-15T06:30:35Z", "aliases": [ "CVE-2024-2739" ], "details": "The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-78fh-92p7-q975/GHSA-78fh-92p7-q975.json b/advisories/unreviewed/2024/04/GHSA-78fh-92p7-q975/GHSA-78fh-92p7-q975.json index 46236b3bb6e..583314557cd 100644 --- a/advisories/unreviewed/2024/04/GHSA-78fh-92p7-q975/GHSA-78fh-92p7-q975.json +++ b/advisories/unreviewed/2024/04/GHSA-78fh-92p7-q975/GHSA-78fh-92p7-q975.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78fh-92p7-q975", - "modified": "2024-04-30T21:30:32Z", + "modified": "2025-03-20T21:31:40Z", "published": "2024-04-30T21:30:32Z", "aliases": [ "CVE-2024-29466" ], "details": "Directory Traversal vulnerability in lsgwr spring boot online exam v.0.9 allows an attacker to execute arbitrary code via the FileTransUtil.java component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-26" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-30T21:15:45Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json b/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json index de0ec5a3614..a87d85dad35 100644 --- a/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json +++ b/advisories/unreviewed/2024/04/GHSA-hv4g-gwhx-j629/GHSA-hv4g-gwhx-j629.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hv4g-gwhx-j629", - "modified": "2024-04-01T06:30:31Z", + "modified": "2025-03-20T21:31:39Z", "published": "2024-04-01T06:30:31Z", "aliases": [ "CVE-2024-1526" ], "details": "The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T05:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-j23h-727c-9qvf/GHSA-j23h-727c-9qvf.json b/advisories/unreviewed/2024/04/GHSA-j23h-727c-9qvf/GHSA-j23h-727c-9qvf.json index 7dc9f5330d0..fd434ceb369 100644 --- a/advisories/unreviewed/2024/04/GHSA-j23h-727c-9qvf/GHSA-j23h-727c-9qvf.json +++ b/advisories/unreviewed/2024/04/GHSA-j23h-727c-9qvf/GHSA-j23h-727c-9qvf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j23h-727c-9qvf", - "modified": "2024-04-24T06:30:31Z", + "modified": "2025-03-20T21:31:40Z", "published": "2024-04-24T06:30:31Z", "aliases": [ "CVE-2024-1756" ], "details": "The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-24T05:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mxgq-9hhc-gf5w/GHSA-mxgq-9hhc-gf5w.json b/advisories/unreviewed/2024/04/GHSA-mxgq-9hhc-gf5w/GHSA-mxgq-9hhc-gf5w.json index 7730d4e9aaa..ff08cda7e8d 100644 --- a/advisories/unreviewed/2024/04/GHSA-mxgq-9hhc-gf5w/GHSA-mxgq-9hhc-gf5w.json +++ b/advisories/unreviewed/2024/04/GHSA-mxgq-9hhc-gf5w/GHSA-mxgq-9hhc-gf5w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json b/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json index 953252e2c46..d97a42408d9 100644 --- a/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json +++ b/advisories/unreviewed/2024/05/GHSA-265f-v3vf-6m77/GHSA-265f-v3vf-6m77.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-36fq-6c6v-89gr/GHSA-36fq-6c6v-89gr.json b/advisories/unreviewed/2024/05/GHSA-36fq-6c6v-89gr/GHSA-36fq-6c6v-89gr.json index c836e71f18a..e0365230a79 100644 --- a/advisories/unreviewed/2024/05/GHSA-36fq-6c6v-89gr/GHSA-36fq-6c6v-89gr.json +++ b/advisories/unreviewed/2024/05/GHSA-36fq-6c6v-89gr/GHSA-36fq-6c6v-89gr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-36fq-6c6v-89gr", - "modified": "2024-05-08T12:30:34Z", + "modified": "2025-03-20T21:31:41Z", "published": "2024-05-08T12:30:34Z", "aliases": [ "CVE-2024-34553" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json b/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json index 8c224df8c91..3a8e2e77dc4 100644 --- a/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json +++ b/advisories/unreviewed/2024/05/GHSA-3j75-rq9m-pxrv/GHSA-3j75-rq9m-pxrv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3j75-rq9m-pxrv", - "modified": "2024-05-06T03:30:47Z", + "modified": "2025-03-20T21:31:41Z", "published": "2024-05-06T03:30:47Z", "aliases": [ "CVE-2024-20060" ], "details": "In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1332" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T03:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json b/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json index 314fc8a334f..12aa5b063cf 100644 --- a/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json +++ b/advisories/unreviewed/2024/05/GHSA-7x33-7jjx-2gmh/GHSA-7x33-7jjx-2gmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7x33-7jjx-2gmh", - "modified": "2024-06-26T00:31:38Z", + "modified": "2025-03-20T21:31:40Z", "published": "2024-05-01T06:31:42Z", "aliases": [ "CVE-2024-26957" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: fix reference counting on zcrypt card objects\n\nTests with hot-plugging crytpo cards on KVM guests with debug\nkernel build revealed an use after free for the load field of\nthe struct zcrypt_card. The reason was an incorrect reference\nhandling of the zcrypt card object which could lead to a free\nof the zcrypt card object while it was still in use.\n\nThis is an example of the slab message:\n\n kernel: 0x00000000885a7512-0x00000000885a7513 @offset=1298. First byte 0x68 instead of 0x6b\n kernel: Allocated in zcrypt_card_alloc+0x36/0x70 [zcrypt] age=18046 cpu=3 pid=43\n kernel: kmalloc_trace+0x3f2/0x470\n kernel: zcrypt_card_alloc+0x36/0x70 [zcrypt]\n kernel: zcrypt_cex4_card_probe+0x26/0x380 [zcrypt_cex4]\n kernel: ap_device_probe+0x15c/0x290\n kernel: really_probe+0xd2/0x468\n kernel: driver_probe_device+0x40/0xf0\n kernel: __device_attach_driver+0xc0/0x140\n kernel: bus_for_each_drv+0x8c/0xd0\n kernel: __device_attach+0x114/0x198\n kernel: bus_probe_device+0xb4/0xc8\n kernel: device_add+0x4d2/0x6e0\n kernel: ap_scan_adapter+0x3d0/0x7c0\n kernel: ap_scan_bus+0x5a/0x3b0\n kernel: ap_scan_bus_wq_callback+0x40/0x60\n kernel: process_one_work+0x26e/0x620\n kernel: worker_thread+0x21c/0x440\n kernel: Freed in zcrypt_card_put+0x54/0x80 [zcrypt] age=9024 cpu=3 pid=43\n kernel: kfree+0x37e/0x418\n kernel: zcrypt_card_put+0x54/0x80 [zcrypt]\n kernel: ap_device_remove+0x4c/0xe0\n kernel: device_release_driver_internal+0x1c4/0x270\n kernel: bus_remove_device+0x100/0x188\n kernel: device_del+0x164/0x3c0\n kernel: device_unregister+0x30/0x90\n kernel: ap_scan_adapter+0xc8/0x7c0\n kernel: ap_scan_bus+0x5a/0x3b0\n kernel: ap_scan_bus_wq_callback+0x40/0x60\n kernel: process_one_work+0x26e/0x620\n kernel: worker_thread+0x21c/0x440\n kernel: kthread+0x150/0x168\n kernel: __ret_from_fork+0x3c/0x58\n kernel: ret_from_fork+0xa/0x30\n kernel: Slab 0x00000372022169c0 objects=20 used=18 fp=0x00000000885a7c88 flags=0x3ffff00000000a00(workingset|slab|node=0|zone=1|lastcpupid=0x1ffff)\n kernel: Object 0x00000000885a74b8 @offset=1208 fp=0x00000000885a7c88\n kernel: Redzone 00000000885a74b0: bb bb bb bb bb bb bb bb ........\n kernel: Object 00000000885a74b8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74c8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74d8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74e8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a74f8: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b kkkkkkkkkkkkkkkk\n kernel: Object 00000000885a7508: 6b 6b 6b 6b 6b 6b 6b 6b 6b 6b 68 4b 6b 6b 6b a5 kkkkkkkkkkhKkkk.\n kernel: Redzone 00000000885a7518: bb bb bb bb bb bb bb bb ........\n kernel: Padding 00000000885a756c: 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a ZZZZZZZZZZZZ\n kernel: CPU: 0 PID: 387 Comm: systemd-udevd Not tainted 6.8.0-HF #2\n kernel: Hardware name: IBM 3931 A01 704 (KVM/Linux)\n kernel: Call Trace:\n kernel: [<00000000ca5ab5b8>] dump_stack_lvl+0x90/0x120\n kernel: [<00000000c99d78bc>] check_bytes_and_report+0x114/0x140\n kernel: [<00000000c99d53cc>] check_object+0x334/0x3f8\n kernel: [<00000000c99d820c>] alloc_debug_processing+0xc4/0x1f8\n kernel: [<00000000c99d852e>] get_partial_node.part.0+0x1ee/0x3e0\n kernel: [<00000000c99d94ec>] ___slab_alloc+0xaf4/0x13c8\n kernel: [<00000000c99d9e38>] __slab_alloc.constprop.0+0x78/0xb8\n kernel: [<00000000c99dc8dc>] __kmalloc+0x434/0x590\n kernel: [<00000000c9b4c0ce>] ext4_htree_store_dirent+0x4e/0x1c0\n kernel: [<00000000c9b908a2>] htree_dirblock_to_tree+0x17a/0x3f0\n kernel: \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -59,7 +64,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8hff-rh3f-34cf/GHSA-8hff-rh3f-34cf.json b/advisories/unreviewed/2024/05/GHSA-8hff-rh3f-34cf/GHSA-8hff-rh3f-34cf.json index 3112e02ea5f..c9f0e1d1899 100644 --- a/advisories/unreviewed/2024/05/GHSA-8hff-rh3f-34cf/GHSA-8hff-rh3f-34cf.json +++ b/advisories/unreviewed/2024/05/GHSA-8hff-rh3f-34cf/GHSA-8hff-rh3f-34cf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8hff-rh3f-34cf", - "modified": "2024-05-08T12:30:34Z", + "modified": "2025-03-20T21:31:41Z", "published": "2024-05-08T12:30:34Z", "aliases": [ "CVE-2024-34558" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF allows Stored XSS.This issue affects WOLF: from n/a through 1.0.8.2.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF allows Stored XSS.This issue affects WOLF: from n/a through 1.0.8.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-cpr3-2wp6-xc3c/GHSA-cpr3-2wp6-xc3c.json b/advisories/unreviewed/2024/05/GHSA-cpr3-2wp6-xc3c/GHSA-cpr3-2wp6-xc3c.json index 3c984686830..da843e90f24 100644 --- a/advisories/unreviewed/2024/05/GHSA-cpr3-2wp6-xc3c/GHSA-cpr3-2wp6-xc3c.json +++ b/advisories/unreviewed/2024/05/GHSA-cpr3-2wp6-xc3c/GHSA-cpr3-2wp6-xc3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpr3-2wp6-xc3c", - "modified": "2024-05-16T12:30:22Z", + "modified": "2025-03-20T21:31:42Z", "published": "2024-05-16T12:30:22Z", "aliases": [ "CVE-2024-4400" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fq2p-4p8g-3975/GHSA-fq2p-4p8g-3975.json b/advisories/unreviewed/2024/05/GHSA-fq2p-4p8g-3975/GHSA-fq2p-4p8g-3975.json index d126d74a87f..934404da38b 100644 --- a/advisories/unreviewed/2024/05/GHSA-fq2p-4p8g-3975/GHSA-fq2p-4p8g-3975.json +++ b/advisories/unreviewed/2024/05/GHSA-fq2p-4p8g-3975/GHSA-fq2p-4p8g-3975.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fq2p-4p8g-3975", - "modified": "2024-05-14T18:30:51Z", + "modified": "2025-03-20T21:31:41Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34814" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.29.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.29.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json b/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json index 816ced9c166..18810a87b7a 100644 --- a/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json +++ b/advisories/unreviewed/2024/05/GHSA-pjfh-ccg3-6463/GHSA-pjfh-ccg3-6463.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-640" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json b/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json index 14187bb58c7..c4a74dd88e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json +++ b/advisories/unreviewed/2024/05/GHSA-rq46-9225-gj4f/GHSA-rq46-9225-gj4f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rq46-9225-gj4f", - "modified": "2024-05-23T06:30:45Z", + "modified": "2025-03-20T21:31:42Z", "published": "2024-05-23T06:30:45Z", "aliases": [ "CVE-2024-3594" ], "details": "The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json b/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json index a0c8fd98e58..5e99a107ba2 100644 --- a/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json +++ b/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json b/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json index ee8fce27314..0f31bba9ffb 100644 --- a/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json +++ b/advisories/unreviewed/2024/06/GHSA-jwr6-46q6-xcr4/GHSA-jwr6-46q6-xcr4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-596r-xq28-523m/GHSA-596r-xq28-523m.json b/advisories/unreviewed/2024/07/GHSA-596r-xq28-523m/GHSA-596r-xq28-523m.json index 9ba7499771f..eb7d2e7ebdd 100644 --- a/advisories/unreviewed/2024/07/GHSA-596r-xq28-523m/GHSA-596r-xq28-523m.json +++ b/advisories/unreviewed/2024/07/GHSA-596r-xq28-523m/GHSA-596r-xq28-523m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-378" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-hqp7-v4pv-fg66/GHSA-hqp7-v4pv-fg66.json b/advisories/unreviewed/2024/07/GHSA-hqp7-v4pv-fg66/GHSA-hqp7-v4pv-fg66.json index 118281944db..630ebcbe247 100644 --- a/advisories/unreviewed/2024/07/GHSA-hqp7-v4pv-fg66/GHSA-hqp7-v4pv-fg66.json +++ b/advisories/unreviewed/2024/07/GHSA-hqp7-v4pv-fg66/GHSA-hqp7-v4pv-fg66.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-rg57-w2fr-7hgm/GHSA-rg57-w2fr-7hgm.json b/advisories/unreviewed/2024/07/GHSA-rg57-w2fr-7hgm/GHSA-rg57-w2fr-7hgm.json index 24ecb90f5b8..596a39e9b2f 100644 --- a/advisories/unreviewed/2024/07/GHSA-rg57-w2fr-7hgm/GHSA-rg57-w2fr-7hgm.json +++ b/advisories/unreviewed/2024/07/GHSA-rg57-w2fr-7hgm/GHSA-rg57-w2fr-7hgm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v4v9-v4wf-9c86/GHSA-v4v9-v4wf-9c86.json b/advisories/unreviewed/2024/07/GHSA-v4v9-v4wf-9c86/GHSA-v4v9-v4wf-9c86.json index d9aa244239c..ef155a78295 100644 --- a/advisories/unreviewed/2024/07/GHSA-v4v9-v4wf-9c86/GHSA-v4v9-v4wf-9c86.json +++ b/advisories/unreviewed/2024/07/GHSA-v4v9-v4wf-9c86/GHSA-v4v9-v4wf-9c86.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json b/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json index af04305824b..0e03ac66578 100644 --- a/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json +++ b/advisories/unreviewed/2024/08/GHSA-9wpw-58rw-f8gm/GHSA-9wpw-58rw-f8gm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json b/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json index 9b6669b8e52..a85baacdecb 100644 --- a/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json +++ b/advisories/unreviewed/2024/09/GHSA-86wc-gr98-6p59/GHSA-86wc-gr98-6p59.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json b/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json index 604a2de99d1..8cae1d31864 100644 --- a/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json +++ b/advisories/unreviewed/2024/10/GHSA-v77g-99m4-2vmq/GHSA-v77g-99m4-2vmq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json b/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json index 7406cb66402..fbb07fa968b 100644 --- a/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json +++ b/advisories/unreviewed/2025/02/GHSA-j6xc-hhqx-8w7p/GHSA-j6xc-hhqx-8w7p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-248" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-2jvm-jgg9-h383/GHSA-2jvm-jgg9-h383.json b/advisories/unreviewed/2025/03/GHSA-2jvm-jgg9-h383/GHSA-2jvm-jgg9-h383.json new file mode 100644 index 00000000000..05ad66669f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2jvm-jgg9-h383/GHSA-2jvm-jgg9-h383.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jvm-jgg9-h383", + "modified": "2025-03-20T21:31:47Z", + "published": "2025-03-20T21:31:47Z", + "aliases": [ + "CVE-2025-2574" + ], + "details": "Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2574" + }, + { + "type": "WEB", + "url": "https://www.xpdfreader.com/security-bug/CVE-2025-2574.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-36w9-f92f-5ghj/GHSA-36w9-f92f-5ghj.json b/advisories/unreviewed/2025/03/GHSA-36w9-f92f-5ghj/GHSA-36w9-f92f-5ghj.json new file mode 100644 index 00000000000..1e97244ca6e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-36w9-f92f-5ghj/GHSA-36w9-f92f-5ghj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36w9-f92f-5ghj", + "modified": "2025-03-20T21:31:46Z", + "published": "2025-03-20T21:31:46Z", + "aliases": [ + "CVE-2025-2557" + ], + "details": "A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of the component Command API. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. Upgrading to version 2.89 and 2.90 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about these issues and acted very professional. Version 2.89 is fixing this issue for new customers and 2.90 is going to fix it for existing customers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2557" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Audi/blob/main/README.md#finding-4-execute-remote-commands" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300170" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300170" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.513393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3j87-859p-q82m/GHSA-3j87-859p-q82m.json b/advisories/unreviewed/2025/03/GHSA-3j87-859p-q82m/GHSA-3j87-859p-q82m.json index d036c827171..39abfaf50ee 100644 --- a/advisories/unreviewed/2025/03/GHSA-3j87-859p-q82m/GHSA-3j87-859p-q82m.json +++ b/advisories/unreviewed/2025/03/GHSA-3j87-859p-q82m/GHSA-3j87-859p-q82m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3j87-859p-q82m", - "modified": "2025-03-10T18:31:56Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-10T18:31:56Z", "aliases": [ "CVE-2025-25382" ], "details": "An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-472" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T16:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json b/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json index 201095a52f5..f263f1227ce 100644 --- a/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json +++ b/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-44vc-9wvw-r372", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-20T21:31:44Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20653" ], "details": "In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291064; Issue ID: MSV-2046.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:10Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json b/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json index c6295ace1b3..91cc36ab0a3 100644 --- a/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json +++ b/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5jh9-vq9c-95gr", - "modified": "2025-03-20T06:31:08Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-20T06:31:08Z", "aliases": [ "CVE-2024-13877" ], "details": "The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T06:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json b/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json index c78043800df..07af3a5d8aa 100644 --- a/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json +++ b/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7w4w-ph42-vrfq", - "modified": "2025-03-20T06:31:08Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-20T06:31:08Z", "aliases": [ "CVE-2024-13878" ], "details": "The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T06:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8hc3-wwgj-w8f5/GHSA-8hc3-wwgj-w8f5.json b/advisories/unreviewed/2025/03/GHSA-8hc3-wwgj-w8f5/GHSA-8hc3-wwgj-w8f5.json new file mode 100644 index 00000000000..79890269156 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8hc3-wwgj-w8f5/GHSA-8hc3-wwgj-w8f5.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hc3-wwgj-w8f5", + "modified": "2025-03-20T21:31:46Z", + "published": "2025-03-20T21:31:46Z", + "aliases": [ + "CVE-2025-29980" + ], + "details": "A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no longer supported, and users are recommended to migrate to the latest version of CentralSquare Community Development.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29980" + }, + { + "type": "WEB", + "url": "https://github.com/cisagov/CSAF/pull/182/files#diff-53861466371a59578b21f5e4b4b6be7b2a6267c5d0fe81eda2a849bf6915ed8d" + }, + { + "type": "WEB", + "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-079-01.json" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json b/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json new file mode 100644 index 00000000000..16cd444f1d2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wwq-574q-q2j9/GHSA-8wwq-574q-q2j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wwq-574q-q2j9", + "modified": "2025-03-20T21:31:46Z", + "published": "2025-03-20T21:31:46Z", + "aliases": [ + "CVE-2025-26852" + ], + "details": "DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26852" + }, + { + "type": "WEB", + "url": "https://www.descor.com/prodotti/infocad" + }, + { + "type": "WEB", + "url": "https://www.infocadfm.com/changelog/sql-injection" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9hr4-7h76-8f5h/GHSA-9hr4-7h76-8f5h.json b/advisories/unreviewed/2025/03/GHSA-9hr4-7h76-8f5h/GHSA-9hr4-7h76-8f5h.json new file mode 100644 index 00000000000..a6153618240 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9hr4-7h76-8f5h/GHSA-9hr4-7h76-8f5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hr4-7h76-8f5h", + "modified": "2025-03-20T21:31:47Z", + "published": "2025-03-20T21:31:47Z", + "aliases": [ + "CVE-2025-2538" + ], + "details": "A specific type of ArcGIS Enterprise deployment, is vulnerable to a Password Recovery Exploitation vulnerability in Portal, that could allow an attacker to reset the password on the built in admin account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2538" + }, + { + "type": "WEB", + "url": "https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2025-update-1-patch" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json b/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json index 7074dcf10dc..e0be8ea7b96 100644 --- a/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json +++ b/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ch85-v3jm-42jh", - "modified": "2025-03-19T21:30:52Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-19T21:30:52Z", "aliases": [ "CVE-2025-26816" ], "details": "A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-19T21:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json b/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json index 886c6c90551..96f69e806c8 100644 --- a/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json +++ b/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpm3-qrmh-vx5x", - "modified": "2025-03-20T06:31:08Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-20T06:31:08Z", "aliases": [ "CVE-2024-13880" ], "details": "The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T06:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p5g3-6w3j-v5qc/GHSA-p5g3-6w3j-v5qc.json b/advisories/unreviewed/2025/03/GHSA-p5g3-6w3j-v5qc/GHSA-p5g3-6w3j-v5qc.json new file mode 100644 index 00000000000..f017238955c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p5g3-6w3j-v5qc/GHSA-p5g3-6w3j-v5qc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5g3-6w3j-v5qc", + "modified": "2025-03-20T21:31:46Z", + "published": "2025-03-20T21:31:46Z", + "aliases": [ + "CVE-2025-29218" + ], + "details": "Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29218" + }, + { + "type": "WEB", + "url": "https://gist.github.com/isstabber/a03c9dc3e89d5cf3b9e46dbef1ee5bf1" + }, + { + "type": "WEB", + "url": "https://github.com/isstabber/my_VulnHub/blob/main/TendaW18eV2/poc_wifipwd_stack_overflow.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T19:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json b/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json index 9aa6ccac6c0..affcd6cabfb 100644 --- a/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json +++ b/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pph8-wh6p-w5m7", - "modified": "2025-03-20T06:31:08Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-20T06:31:08Z", "aliases": [ "CVE-2024-13875" ], "details": "The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T06:15:20Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json b/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json new file mode 100644 index 00000000000..a249d6e55b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pxc8-qhvr-5954/GHSA-pxc8-qhvr-5954.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxc8-qhvr-5954", + "modified": "2025-03-20T21:31:47Z", + "published": "2025-03-20T21:31:47Z", + "aliases": [ + "CVE-2025-30334" + ], + "details": "In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30334" + }, + { + "type": "WEB", + "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.5/common/015_wg.patch.sig" + }, + { + "type": "WEB", + "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/006_wg.patch.sig" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-131" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json b/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json index 8d7708dc37c..52217730be1 100644 --- a/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json +++ b/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qccg-v3f9-84pm", - "modified": "2025-03-20T06:31:08Z", + "modified": "2025-03-20T21:31:46Z", "published": "2025-03-20T06:31:08Z", "aliases": [ "CVE-2024-13881" ], "details": "The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T06:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r56h-j38w-hrqq/GHSA-r56h-j38w-hrqq.json b/advisories/unreviewed/2025/03/GHSA-r56h-j38w-hrqq/GHSA-r56h-j38w-hrqq.json index 0ff11f8e3ab..8cb16ff08e9 100644 --- a/advisories/unreviewed/2025/03/GHSA-r56h-j38w-hrqq/GHSA-r56h-j38w-hrqq.json +++ b/advisories/unreviewed/2025/03/GHSA-r56h-j38w-hrqq/GHSA-r56h-j38w-hrqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r56h-j38w-hrqq", - "modified": "2025-03-20T18:30:30Z", + "modified": "2025-03-20T21:31:46Z", "published": "2025-03-20T18:30:30Z", "aliases": [ "CVE-2024-7598" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://groups.google.com/g/kubernetes-security-announce/c/67D7UFqiPRc" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/20/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-r6gw-8vw8-65gm/GHSA-r6gw-8vw8-65gm.json b/advisories/unreviewed/2025/03/GHSA-r6gw-8vw8-65gm/GHSA-r6gw-8vw8-65gm.json new file mode 100644 index 00000000000..2fc23d6519d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r6gw-8vw8-65gm/GHSA-r6gw-8vw8-65gm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6gw-8vw8-65gm", + "modified": "2025-03-20T21:31:46Z", + "published": "2025-03-20T21:31:46Z", + "aliases": [ + "CVE-2025-26853" + ], + "details": "DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26853" + }, + { + "type": "WEB", + "url": "https://www.descor.com/prodotti/infocad" + }, + { + "type": "WEB", + "url": "https://www.infocadfm.com/changelog/broken-authorization-schema" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rjgp-5vq3-q8c2/GHSA-rjgp-5vq3-q8c2.json b/advisories/unreviewed/2025/03/GHSA-rjgp-5vq3-q8c2/GHSA-rjgp-5vq3-q8c2.json new file mode 100644 index 00000000000..37b02fa735f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rjgp-5vq3-q8c2/GHSA-rjgp-5vq3-q8c2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjgp-5vq3-q8c2", + "modified": "2025-03-20T21:31:47Z", + "published": "2025-03-20T21:31:47Z", + "aliases": [ + "CVE-2025-25758" + ], + "details": "An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup=\"true\" in the ANdroidManifest.xml", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-16835" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46918" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25758" + }, + { + "type": "WEB", + "url": "https://pastebin.com/0cb0KsGS" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json b/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json index a81a60ee80d..492d1ad07b6 100644 --- a/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json +++ b/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vff8-5vm8-wh67", - "modified": "2025-03-20T06:31:08Z", + "modified": "2025-03-20T21:31:45Z", "published": "2025-03-20T06:31:08Z", "aliases": [ "CVE-2024-13876" ], "details": "The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-20T06:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xxvw-6qqh-qrjj/GHSA-xxvw-6qqh-qrjj.json b/advisories/unreviewed/2025/03/GHSA-xxvw-6qqh-qrjj/GHSA-xxvw-6qqh-qrjj.json new file mode 100644 index 00000000000..eb61e4c2f51 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xxvw-6qqh-qrjj/GHSA-xxvw-6qqh-qrjj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxvw-6qqh-qrjj", + "modified": "2025-03-20T21:31:46Z", + "published": "2025-03-20T21:31:46Z", + "aliases": [ + "CVE-2025-29217" + ], + "details": "Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29217" + }, + { + "type": "WEB", + "url": "https://gist.github.com/isstabber/d170f68bd85ed97e66ff316e57634b99" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + }, + { + "type": "WEB", + "url": "http://w18e.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T19:15:37Z" + } +} \ No newline at end of file