From aa3d83b12fa92e6ef8675084d143b46bd981d36c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 28 Mar 2025 15:33:15 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-f82v-jwr5-mffw.json | 6 ++- .../GHSA-3xjv-m925-6jcj.json | 6 ++- .../GHSA-wc8w-gx27-xp92.json | 2 +- .../GHSA-wrj6-35fr-8xw5.json | 2 +- .../GHSA-3g23-95wx-3cc6.json | 3 +- .../GHSA-5jg2-4xpf-rvpc.json | 4 +- .../GHSA-76w4-2fg3-x9mc.json | 2 +- .../GHSA-fm73-7fg4-q5w8.json | 2 +- .../GHSA-w496-f5jm-w9c3.json | 2 +- .../GHSA-4w97-63h2-xcqx.json | 4 +- .../GHSA-rh83-2fx8-8x6x.json | 6 ++- .../GHSA-37xw-rpjg-xxfx.json | 6 ++- .../GHSA-cwpg-qgc6-jxvq.json | 6 ++- .../GHSA-hrpp-92f9-h887.json | 3 +- .../GHSA-m366-8h8r-6fqr.json | 6 ++- .../GHSA-2pvf-46qr-hp98.json | 2 +- .../GHSA-39q9-q8cr-48r9.json | 36 +++++++++++++++++ .../GHSA-3rpf-hx7x-258c.json | 36 +++++++++++++++++ .../GHSA-475h-5v9w-xfp6.json | 11 +++-- .../GHSA-4mr4-q2q7-hmgc.json | 5 ++- .../GHSA-57fm-4q7w-88cr.json | 33 +++++++++++++++ .../GHSA-5jx7-r789-wq9q.json | 2 +- .../GHSA-6vp2-xfpj-33p7.json | 36 +++++++++++++++++ .../GHSA-6x2j-qcg5-5j7v.json | 15 +++++-- .../GHSA-74w3-v342-q9gv.json | 36 +++++++++++++++++ .../GHSA-7crj-fp94-jm6j.json | 36 +++++++++++++++++ .../GHSA-7hhx-mfrf-57rx.json | 36 +++++++++++++++++ .../GHSA-7v32-cc9h-mhv6.json | 36 +++++++++++++++++ .../GHSA-7vwh-8p2g-h5hm.json | 36 +++++++++++++++++ .../GHSA-872j-44g4-7vfm.json | 36 +++++++++++++++++ .../GHSA-892m-ppf5-vm26.json | 15 +++++-- .../GHSA-8c63-c298-4546.json | 15 +++++-- .../GHSA-9hcv-xw76-m4h6.json | 6 ++- .../GHSA-9p48-8gpf-wwmc.json | 3 +- .../GHSA-9qmj-p674-g42j.json | 36 +++++++++++++++++ .../GHSA-cj7w-f46q-rmp6.json | 36 +++++++++++++++++ .../GHSA-cq9f-xr5j-3g97.json | 15 +++++-- .../GHSA-f45w-55jr-pvp2.json | 29 ++++++++++++++ .../GHSA-fffw-r3h2-v6wq.json | 6 ++- .../GHSA-fmgc-85r6-v6q3.json | 36 +++++++++++++++++ .../GHSA-fqg9-8xmx-9fgp.json | 29 ++++++++++++++ .../GHSA-g4rq-8hw9-mj8q.json | 40 +++++++++++++++++++ .../GHSA-gr89-4g8m-9f9g.json | 15 +++++-- .../GHSA-h7v6-4m6m-8gjj.json | 36 +++++++++++++++++ .../GHSA-hfvj-w63f-mc9j.json | 36 +++++++++++++++++ .../GHSA-hp88-hfjw-2hg4.json | 40 +++++++++++++++++++ .../GHSA-hprf-f9v4-9r3r.json | 36 +++++++++++++++++ .../GHSA-hqf3-3h38-frmh.json | 15 +++++-- .../GHSA-hrwg-r69j-hcrr.json | 36 +++++++++++++++++ .../GHSA-jc64-qjc6-h5vp.json | 36 +++++++++++++++++ .../GHSA-jfpc-5fff-j5r6.json | 40 +++++++++++++++++++ .../GHSA-mvjr-2pvh-8wqh.json | 15 +++++-- .../GHSA-p3q9-8vf2-3jfg.json | 36 +++++++++++++++++ .../GHSA-pcq5-5jmx-47cw.json | 36 +++++++++++++++++ .../GHSA-pq29-hpwp-p3wj.json | 36 +++++++++++++++++ .../GHSA-r299-g8pg-6xf2.json | 36 +++++++++++++++++ .../GHSA-rq3r-6rf7-m7m9.json | 29 ++++++++++++++ .../GHSA-v7cw-67xp-5685.json | 15 +++++-- .../GHSA-vc99-rg67-mm68.json | 15 +++++-- .../GHSA-vcgc-h73q-2m2p.json | 6 ++- .../GHSA-vg6w-rxwf-h2wq.json | 36 +++++++++++++++++ .../GHSA-wc34-fgpq-8hg7.json | 36 +++++++++++++++++ .../GHSA-wfxf-3935-5jgv.json | 40 +++++++++++++++++++ .../GHSA-x2v7-w9j6-rqmx.json | 11 +++-- .../GHSA-x542-2cq7-f2p3.json | 36 +++++++++++++++++ .../GHSA-x6xj-c9qw-4fjp.json | 36 +++++++++++++++++ 66 files changed, 1362 insertions(+), 65 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-39q9-q8cr-48r9/GHSA-39q9-q8cr-48r9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3rpf-hx7x-258c/GHSA-3rpf-hx7x-258c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6vp2-xfpj-33p7/GHSA-6vp2-xfpj-33p7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-74w3-v342-q9gv/GHSA-74w3-v342-q9gv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7crj-fp94-jm6j/GHSA-7crj-fp94-jm6j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7hhx-mfrf-57rx/GHSA-7hhx-mfrf-57rx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7v32-cc9h-mhv6/GHSA-7v32-cc9h-mhv6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7vwh-8p2g-h5hm/GHSA-7vwh-8p2g-h5hm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-872j-44g4-7vfm/GHSA-872j-44g4-7vfm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9qmj-p674-g42j/GHSA-9qmj-p674-g42j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cj7w-f46q-rmp6/GHSA-cj7w-f46q-rmp6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f45w-55jr-pvp2/GHSA-f45w-55jr-pvp2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fmgc-85r6-v6q3/GHSA-fmgc-85r6-v6q3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fqg9-8xmx-9fgp/GHSA-fqg9-8xmx-9fgp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g4rq-8hw9-mj8q/GHSA-g4rq-8hw9-mj8q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h7v6-4m6m-8gjj/GHSA-h7v6-4m6m-8gjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hfvj-w63f-mc9j/GHSA-hfvj-w63f-mc9j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hp88-hfjw-2hg4/GHSA-hp88-hfjw-2hg4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hprf-f9v4-9r3r/GHSA-hprf-f9v4-9r3r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hrwg-r69j-hcrr/GHSA-hrwg-r69j-hcrr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jc64-qjc6-h5vp/GHSA-jc64-qjc6-h5vp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jfpc-5fff-j5r6/GHSA-jfpc-5fff-j5r6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p3q9-8vf2-3jfg/GHSA-p3q9-8vf2-3jfg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pcq5-5jmx-47cw/GHSA-pcq5-5jmx-47cw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pq29-hpwp-p3wj/GHSA-pq29-hpwp-p3wj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r299-g8pg-6xf2/GHSA-r299-g8pg-6xf2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rq3r-6rf7-m7m9/GHSA-rq3r-6rf7-m7m9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vg6w-rxwf-h2wq/GHSA-vg6w-rxwf-h2wq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wc34-fgpq-8hg7/GHSA-wc34-fgpq-8hg7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wfxf-3935-5jgv/GHSA-wfxf-3935-5jgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x542-2cq7-f2p3/GHSA-x542-2cq7-f2p3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x6xj-c9qw-4fjp/GHSA-x6xj-c9qw-4fjp.json diff --git a/advisories/github-reviewed/2025/03/GHSA-f82v-jwr5-mffw/GHSA-f82v-jwr5-mffw.json b/advisories/github-reviewed/2025/03/GHSA-f82v-jwr5-mffw/GHSA-f82v-jwr5-mffw.json index 86b60ef7443..93e4413c8ff 100644 --- a/advisories/github-reviewed/2025/03/GHSA-f82v-jwr5-mffw/GHSA-f82v-jwr5-mffw.json +++ b/advisories/github-reviewed/2025/03/GHSA-f82v-jwr5-mffw/GHSA-f82v-jwr5-mffw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f82v-jwr5-mffw", - "modified": "2025-03-24T14:40:22Z", + "modified": "2025-03-28T15:31:53Z", "published": "2025-03-21T15:20:12Z", "aliases": [ "CVE-2025-29927" @@ -121,6 +121,10 @@ "type": "WEB", "url": "https://github.com/vercel/next.js/releases/tag/v13.5.9" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0002" + }, { "type": "WEB", "url": "https://vercel.com/changelog/vercel-firewall-proactively-protects-against-vulnerability-with-middleware" diff --git a/advisories/unreviewed/2022/02/GHSA-3xjv-m925-6jcj/GHSA-3xjv-m925-6jcj.json b/advisories/unreviewed/2022/02/GHSA-3xjv-m925-6jcj/GHSA-3xjv-m925-6jcj.json index 1cecfe4f516..7cf722bf2eb 100644 --- a/advisories/unreviewed/2022/02/GHSA-3xjv-m925-6jcj/GHSA-3xjv-m925-6jcj.json +++ b/advisories/unreviewed/2022/02/GHSA-3xjv-m925-6jcj/GHSA-3xjv-m925-6jcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xjv-m925-6jcj", - "modified": "2024-07-16T18:31:41Z", + "modified": "2025-03-28T15:31:42Z", "published": "2022-02-17T00:00:27Z", "aliases": [ "CVE-2021-3773" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://citizenlab.ca/2024/07/vulnerabilities-in-vpns-paper-presented-at-the-privacy-enhancing-technologies-symposium-2024" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2022.html" diff --git a/advisories/unreviewed/2022/05/GHSA-wc8w-gx27-xp92/GHSA-wc8w-gx27-xp92.json b/advisories/unreviewed/2022/05/GHSA-wc8w-gx27-xp92/GHSA-wc8w-gx27-xp92.json index ace5035e2da..57031dffe73 100644 --- a/advisories/unreviewed/2022/05/GHSA-wc8w-gx27-xp92/GHSA-wc8w-gx27-xp92.json +++ b/advisories/unreviewed/2022/05/GHSA-wc8w-gx27-xp92/GHSA-wc8w-gx27-xp92.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wc8w-gx27-xp92", - "modified": "2022-10-14T12:00:16Z", + "modified": "2025-03-28T15:31:42Z", "published": "2022-05-24T17:34:11Z", "aliases": [ "CVE-2020-8745" diff --git a/advisories/unreviewed/2022/05/GHSA-wrj6-35fr-8xw5/GHSA-wrj6-35fr-8xw5.json b/advisories/unreviewed/2022/05/GHSA-wrj6-35fr-8xw5/GHSA-wrj6-35fr-8xw5.json index b56b2d959e1..c73a69bc0d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrj6-35fr-8xw5/GHSA-wrj6-35fr-8xw5.json +++ b/advisories/unreviewed/2022/05/GHSA-wrj6-35fr-8xw5/GHSA-wrj6-35fr-8xw5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrj6-35fr-8xw5", - "modified": "2022-05-13T01:25:01Z", + "modified": "2025-03-28T15:31:43Z", "published": "2022-05-13T01:25:01Z", "aliases": [ "CVE-2016-9840" diff --git a/advisories/unreviewed/2023/01/GHSA-3g23-95wx-3cc6/GHSA-3g23-95wx-3cc6.json b/advisories/unreviewed/2023/01/GHSA-3g23-95wx-3cc6/GHSA-3g23-95wx-3cc6.json index a699a15245d..80047d0eea8 100644 --- a/advisories/unreviewed/2023/01/GHSA-3g23-95wx-3cc6/GHSA-3g23-95wx-3cc6.json +++ b/advisories/unreviewed/2023/01/GHSA-3g23-95wx-3cc6/GHSA-3g23-95wx-3cc6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-5jg2-4xpf-rvpc/GHSA-5jg2-4xpf-rvpc.json b/advisories/unreviewed/2023/01/GHSA-5jg2-4xpf-rvpc/GHSA-5jg2-4xpf-rvpc.json index 66d15206835..e55f7cd2daf 100644 --- a/advisories/unreviewed/2023/01/GHSA-5jg2-4xpf-rvpc/GHSA-5jg2-4xpf-rvpc.json +++ b/advisories/unreviewed/2023/01/GHSA-5jg2-4xpf-rvpc/GHSA-5jg2-4xpf-rvpc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-76w4-2fg3-x9mc/GHSA-76w4-2fg3-x9mc.json b/advisories/unreviewed/2023/01/GHSA-76w4-2fg3-x9mc/GHSA-76w4-2fg3-x9mc.json index 5030c6a8d03..83578c0e9ca 100644 --- a/advisories/unreviewed/2023/01/GHSA-76w4-2fg3-x9mc/GHSA-76w4-2fg3-x9mc.json +++ b/advisories/unreviewed/2023/01/GHSA-76w4-2fg3-x9mc/GHSA-76w4-2fg3-x9mc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76w4-2fg3-x9mc", - "modified": "2023-02-08T03:30:26Z", + "modified": "2025-03-28T15:31:44Z", "published": "2023-01-31T00:30:17Z", "aliases": [ "CVE-2022-48176" diff --git a/advisories/unreviewed/2023/01/GHSA-fm73-7fg4-q5w8/GHSA-fm73-7fg4-q5w8.json b/advisories/unreviewed/2023/01/GHSA-fm73-7fg4-q5w8/GHSA-fm73-7fg4-q5w8.json index 2d85702f9d4..7dea4f220ab 100644 --- a/advisories/unreviewed/2023/01/GHSA-fm73-7fg4-q5w8/GHSA-fm73-7fg4-q5w8.json +++ b/advisories/unreviewed/2023/01/GHSA-fm73-7fg4-q5w8/GHSA-fm73-7fg4-q5w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fm73-7fg4-q5w8", - "modified": "2023-02-06T21:30:33Z", + "modified": "2025-03-28T15:31:43Z", "published": "2023-01-30T09:30:40Z", "aliases": [ "CVE-2023-22324" diff --git a/advisories/unreviewed/2023/01/GHSA-w496-f5jm-w9c3/GHSA-w496-f5jm-w9c3.json b/advisories/unreviewed/2023/01/GHSA-w496-f5jm-w9c3/GHSA-w496-f5jm-w9c3.json index dd25c5feca5..f1f25c66803 100644 --- a/advisories/unreviewed/2023/01/GHSA-w496-f5jm-w9c3/GHSA-w496-f5jm-w9c3.json +++ b/advisories/unreviewed/2023/01/GHSA-w496-f5jm-w9c3/GHSA-w496-f5jm-w9c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w496-f5jm-w9c3", - "modified": "2023-02-06T21:30:33Z", + "modified": "2025-03-28T15:31:43Z", "published": "2023-01-30T09:30:40Z", "aliases": [ "CVE-2023-22332" diff --git a/advisories/unreviewed/2023/02/GHSA-4w97-63h2-xcqx/GHSA-4w97-63h2-xcqx.json b/advisories/unreviewed/2023/02/GHSA-4w97-63h2-xcqx/GHSA-4w97-63h2-xcqx.json index ae0cb5e4e67..4953e74aba6 100644 --- a/advisories/unreviewed/2023/02/GHSA-4w97-63h2-xcqx/GHSA-4w97-63h2-xcqx.json +++ b/advisories/unreviewed/2023/02/GHSA-4w97-63h2-xcqx/GHSA-4w97-63h2-xcqx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json b/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json index 3638f0777e0..ff7a1d446a5 100644 --- a/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json +++ b/advisories/unreviewed/2024/01/GHSA-rh83-2fx8-8x6x/GHSA-rh83-2fx8-8x6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rh83-2fx8-8x6x", - "modified": "2024-01-09T18:30:28Z", + "modified": "2025-03-28T15:31:44Z", "published": "2024-01-09T18:30:28Z", "aliases": [ "CVE-2024-20672" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20672" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0006" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-37xw-rpjg-xxfx/GHSA-37xw-rpjg-xxfx.json b/advisories/unreviewed/2024/05/GHSA-37xw-rpjg-xxfx/GHSA-37xw-rpjg-xxfx.json index 63c1bf9b992..1b31a7a1471 100644 --- a/advisories/unreviewed/2024/05/GHSA-37xw-rpjg-xxfx/GHSA-37xw-rpjg-xxfx.json +++ b/advisories/unreviewed/2024/05/GHSA-37xw-rpjg-xxfx/GHSA-37xw-rpjg-xxfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-37xw-rpjg-xxfx", - "modified": "2024-05-14T18:30:54Z", + "modified": "2025-03-28T15:31:50Z", "published": "2024-05-14T18:30:54Z", "aliases": [ "CVE-2024-4317" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4317" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0001" + }, { "type": "WEB", "url": "https://www.postgresql.org/support/security/CVE-2024-4317" diff --git a/advisories/unreviewed/2024/07/GHSA-cwpg-qgc6-jxvq/GHSA-cwpg-qgc6-jxvq.json b/advisories/unreviewed/2024/07/GHSA-cwpg-qgc6-jxvq/GHSA-cwpg-qgc6-jxvq.json index dd9475b96bb..3966b295f3e 100644 --- a/advisories/unreviewed/2024/07/GHSA-cwpg-qgc6-jxvq/GHSA-cwpg-qgc6-jxvq.json +++ b/advisories/unreviewed/2024/07/GHSA-cwpg-qgc6-jxvq/GHSA-cwpg-qgc6-jxvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cwpg-qgc6-jxvq", - "modified": "2024-08-21T15:30:49Z", + "modified": "2025-03-28T15:31:50Z", "published": "2024-07-02T21:32:16Z", "aliases": [ "CVE-2023-24531" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2962" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json b/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json index 462964b4d87..420831429f6 100644 --- a/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json +++ b/advisories/unreviewed/2025/02/GHSA-hrpp-92f9-h887/GHSA-hrpp-92f9-h887.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-862" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-m366-8h8r-6fqr/GHSA-m366-8h8r-6fqr.json b/advisories/unreviewed/2025/02/GHSA-m366-8h8r-6fqr/GHSA-m366-8h8r-6fqr.json index 09e9b8fa1ed..1f45d2c91da 100644 --- a/advisories/unreviewed/2025/02/GHSA-m366-8h8r-6fqr/GHSA-m366-8h8r-6fqr.json +++ b/advisories/unreviewed/2025/02/GHSA-m366-8h8r-6fqr/GHSA-m366-8h8r-6fqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m366-8h8r-6fqr", - "modified": "2025-02-19T00:31:16Z", + "modified": "2025-03-28T15:31:50Z", "published": "2025-02-19T00:31:16Z", "aliases": [ "CVE-2024-56171" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/828" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-2pvf-46qr-hp98/GHSA-2pvf-46qr-hp98.json b/advisories/unreviewed/2025/03/GHSA-2pvf-46qr-hp98/GHSA-2pvf-46qr-hp98.json index adce045e6f8..a0d4ae7cfdd 100644 --- a/advisories/unreviewed/2025/03/GHSA-2pvf-46qr-hp98/GHSA-2pvf-46qr-hp98.json +++ b/advisories/unreviewed/2025/03/GHSA-2pvf-46qr-hp98/GHSA-2pvf-46qr-hp98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pvf-46qr-hp98", - "modified": "2025-03-15T03:30:16Z", + "modified": "2025-03-28T15:31:50Z", "published": "2025-03-15T03:30:16Z", "aliases": [ "CVE-2025-1657" diff --git a/advisories/unreviewed/2025/03/GHSA-39q9-q8cr-48r9/GHSA-39q9-q8cr-48r9.json b/advisories/unreviewed/2025/03/GHSA-39q9-q8cr-48r9/GHSA-39q9-q8cr-48r9.json new file mode 100644 index 00000000000..a99ba8a8d35 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-39q9-q8cr-48r9/GHSA-39q9-q8cr-48r9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39q9-q8cr-48r9", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2861" + ], + "details": "SaTECH BCU in its firmware version 2.1.3 uses the HTTP protocol. The use of the HTTP protocol for web browsing has the problem that information is exchanged in unencrypted text. Since sensitive data such as credentials are exchanged, an attacker could obtain them and log in legitimately.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2861" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3rpf-hx7x-258c/GHSA-3rpf-hx7x-258c.json b/advisories/unreviewed/2025/03/GHSA-3rpf-hx7x-258c/GHSA-3rpf-hx7x-258c.json new file mode 100644 index 00000000000..61cf898d219 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3rpf-hx7x-258c/GHSA-3rpf-hx7x-258c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rpf-hx7x-258c", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2024-51624" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-Já Pagamentos for WooCommerce allows Reflected XSS. This issue affects Já-Já Pagamentos for WooCommerce: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51624" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-ja-ja-pagamentos-multicaixa-express/vulnerability/wordpress-ja-ja-pagamentos-for-woocommerce-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json b/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json index ee5ca293e10..223dae6e67b 100644 --- a/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json +++ b/advisories/unreviewed/2025/03/GHSA-475h-5v9w-xfp6/GHSA-475h-5v9w-xfp6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-475h-5v9w-xfp6", - "modified": "2025-03-28T06:30:27Z", + "modified": "2025-03-28T15:31:55Z", "published": "2025-03-28T06:30:27Z", "aliases": [ "CVE-2025-1762" ], "details": "The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T06:15:32Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4mr4-q2q7-hmgc/GHSA-4mr4-q2q7-hmgc.json b/advisories/unreviewed/2025/03/GHSA-4mr4-q2q7-hmgc/GHSA-4mr4-q2q7-hmgc.json index 38372b94840..8e5d6214572 100644 --- a/advisories/unreviewed/2025/03/GHSA-4mr4-q2q7-hmgc/GHSA-4mr4-q2q7-hmgc.json +++ b/advisories/unreviewed/2025/03/GHSA-4mr4-q2q7-hmgc/GHSA-4mr4-q2q7-hmgc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mr4-q2q7-hmgc", - "modified": "2025-03-15T06:30:32Z", + "modified": "2025-03-28T15:31:51Z", "published": "2025-03-15T06:30:32Z", "aliases": [ "CVE-2025-1667" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-639" + "CWE-639", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json b/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json new file mode 100644 index 00000000000..91d6111ddc0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57fm-4q7w-88cr", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2024-48615" + ], + "details": "Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48615" + }, + { + "type": "WEB", + "url": "https://github.com/88Sanghy88/crash-test" + }, + { + "type": "WEB", + "url": "https://github.com/libarchive/libarchive/releases/download/v3.7.6/libarchive-3.7.6.tar.gz" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5jx7-r789-wq9q/GHSA-5jx7-r789-wq9q.json b/advisories/unreviewed/2025/03/GHSA-5jx7-r789-wq9q/GHSA-5jx7-r789-wq9q.json index 77064673f12..52e27ba4746 100644 --- a/advisories/unreviewed/2025/03/GHSA-5jx7-r789-wq9q/GHSA-5jx7-r789-wq9q.json +++ b/advisories/unreviewed/2025/03/GHSA-5jx7-r789-wq9q/GHSA-5jx7-r789-wq9q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5jx7-r789-wq9q", - "modified": "2025-03-15T06:30:32Z", + "modified": "2025-03-28T15:31:50Z", "published": "2025-03-15T06:30:32Z", "aliases": [ "CVE-2024-12336" diff --git a/advisories/unreviewed/2025/03/GHSA-6vp2-xfpj-33p7/GHSA-6vp2-xfpj-33p7.json b/advisories/unreviewed/2025/03/GHSA-6vp2-xfpj-33p7/GHSA-6vp2-xfpj-33p7.json new file mode 100644 index 00000000000..bafdcd18cd0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6vp2-xfpj-33p7/GHSA-6vp2-xfpj-33p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vp2-xfpj-33p7", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22523" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Schedule allows Blind SQL Injection. This issue affects Schedule: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22523" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/schedule/vulnerability/wordpress-schedule-plugin-1-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json b/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json index a876709cd15..7def967773f 100644 --- a/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json +++ b/advisories/unreviewed/2025/03/GHSA-6x2j-qcg5-5j7v/GHSA-6x2j-qcg5-5j7v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6x2j-qcg5-5j7v", - "modified": "2025-03-27T15:31:13Z", + "modified": "2025-03-28T15:31:53Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29485" ], "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:15:59Z" diff --git a/advisories/unreviewed/2025/03/GHSA-74w3-v342-q9gv/GHSA-74w3-v342-q9gv.json b/advisories/unreviewed/2025/03/GHSA-74w3-v342-q9gv/GHSA-74w3-v342-q9gv.json new file mode 100644 index 00000000000..3e4940ba066 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-74w3-v342-q9gv/GHSA-74w3-v342-q9gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74w3-v342-q9gv", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2858" + ], + "details": "Privilege escalation vulnerability in the saTECH BCU firmware version 2.1.3. An attacker with access to the CLI of the device could make use of the nice command to bypass all restrictions and elevate privileges as a superuser.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2858" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7crj-fp94-jm6j/GHSA-7crj-fp94-jm6j.json b/advisories/unreviewed/2025/03/GHSA-7crj-fp94-jm6j/GHSA-7crj-fp94-jm6j.json new file mode 100644 index 00000000000..411f965bfd5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7crj-fp94-jm6j/GHSA-7crj-fp94-jm6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7crj-fp94-jm6j", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22566" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ULTIMATE VIDEO GALLERY allows Reflected XSS. This issue affects ULTIMATE VIDEO GALLERY: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22566" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-gallery/vulnerability/wordpress-ultimate-video-gallery-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7hhx-mfrf-57rx/GHSA-7hhx-mfrf-57rx.json b/advisories/unreviewed/2025/03/GHSA-7hhx-mfrf-57rx/GHSA-7hhx-mfrf-57rx.json new file mode 100644 index 00000000000..db8e8968268 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7hhx-mfrf-57rx/GHSA-7hhx-mfrf-57rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hhx-mfrf-57rx", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-22526" + ], + "details": "Deserialization of Untrusted Data vulnerability in NotFound PHP/MySQL CPU performance statistics allows Object Injection. This issue affects PHP/MySQL CPU performance statistics: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mywebtonet-performancestats/vulnerability/wordpress-php-mysql-cpu-performance-statistics-plugin-1-2-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7v32-cc9h-mhv6/GHSA-7v32-cc9h-mhv6.json b/advisories/unreviewed/2025/03/GHSA-7v32-cc9h-mhv6/GHSA-7v32-cc9h-mhv6.json new file mode 100644 index 00000000000..aca0eeb89d7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7v32-cc9h-mhv6/GHSA-7v32-cc9h-mhv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v32-cc9h-mhv6", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2865" + ], + "details": "SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2865" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-942" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7vwh-8p2g-h5hm/GHSA-7vwh-8p2g-h5hm.json b/advisories/unreviewed/2025/03/GHSA-7vwh-8p2g-h5hm/GHSA-7vwh-8p2g-h5hm.json new file mode 100644 index 00000000000..5adb43dbee5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7vwh-8p2g-h5hm/GHSA-7vwh-8p2g-h5hm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vwh-8p2g-h5hm", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2025-2908" + ], + "details": "The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2908" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-fermax-mobile-applications" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-872j-44g4-7vfm/GHSA-872j-44g4-7vfm.json b/advisories/unreviewed/2025/03/GHSA-872j-44g4-7vfm/GHSA-872j-44g4-7vfm.json new file mode 100644 index 00000000000..15b4f9398cf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-872j-44g4-7vfm/GHSA-872j-44g4-7vfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-872j-44g4-7vfm", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22575" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendyourweb SUPER RESPONSIVE SLIDER allows Reflected XSS. This issue affects SUPER RESPONSIVE SLIDER: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/super-slider/vulnerability/wordpress-super-responsive-slider-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json b/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json index 6d7d511ec62..0e96ee83fd0 100644 --- a/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json +++ b/advisories/unreviewed/2025/03/GHSA-892m-ppf5-vm26/GHSA-892m-ppf5-vm26.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-892m-ppf5-vm26", - "modified": "2025-03-27T15:31:14Z", + "modified": "2025-03-28T15:31:54Z", "published": "2025-03-27T15:31:14Z", "aliases": [ "CVE-2025-29492" ], "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json b/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json index c7b2da14ead..93266001761 100644 --- a/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json +++ b/advisories/unreviewed/2025/03/GHSA-8c63-c298-4546/GHSA-8c63-c298-4546.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8c63-c298-4546", - "modified": "2025-03-27T15:31:14Z", + "modified": "2025-03-28T15:31:54Z", "published": "2025-03-27T15:31:14Z", "aliases": [ "CVE-2025-29497" ], "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:16:01Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json index ef7619946b7..9de9c0dca46 100644 --- a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json +++ b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcv-xw76-m4h6", - "modified": "2025-03-17T18:31:52Z", + "modified": "2025-03-28T15:31:50Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2024-8176" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2024-8176" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0009" + }, { "type": "WEB", "url": "https://ubuntu.com/security/CVE-2024-8176" diff --git a/advisories/unreviewed/2025/03/GHSA-9p48-8gpf-wwmc/GHSA-9p48-8gpf-wwmc.json b/advisories/unreviewed/2025/03/GHSA-9p48-8gpf-wwmc/GHSA-9p48-8gpf-wwmc.json index 844052bab05..860eb5c132d 100644 --- a/advisories/unreviewed/2025/03/GHSA-9p48-8gpf-wwmc/GHSA-9p48-8gpf-wwmc.json +++ b/advisories/unreviewed/2025/03/GHSA-9p48-8gpf-wwmc/GHSA-9p48-8gpf-wwmc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9p48-8gpf-wwmc", - "modified": "2025-03-15T06:30:34Z", + "modified": "2025-03-28T15:31:51Z", "published": "2025-03-15T06:30:34Z", "aliases": [ "CVE-2024-13497" @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/03/GHSA-9qmj-p674-g42j/GHSA-9qmj-p674-g42j.json b/advisories/unreviewed/2025/03/GHSA-9qmj-p674-g42j/GHSA-9qmj-p674-g42j.json new file mode 100644 index 00000000000..c16e5b885f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9qmj-p674-g42j/GHSA-9qmj-p674-g42j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qmj-p674-g42j", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2025-0986" + ], + "details": "IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0986" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-409" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cj7w-f46q-rmp6/GHSA-cj7w-f46q-rmp6.json b/advisories/unreviewed/2025/03/GHSA-cj7w-f46q-rmp6/GHSA-cj7w-f46q-rmp6.json new file mode 100644 index 00000000000..4c5e56b611b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cj7w-f46q-rmp6/GHSA-cj7w-f46q-rmp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj7w-f46q-rmp6", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2911" + ], + "details": "Unauthorised access to the call forwarding service system in MeetMe products in versions prior to 2024-09 allows an attacker to identify multiple users and perform brute force attacks via extensions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2911" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-fermax-mobile-applications" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json b/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json index 5c1ece12e75..01d8e4a45e8 100644 --- a/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json +++ b/advisories/unreviewed/2025/03/GHSA-cq9f-xr5j-3g97/GHSA-cq9f-xr5j-3g97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cq9f-xr5j-3g97", - "modified": "2025-03-27T15:31:14Z", + "modified": "2025-03-28T15:31:54Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29490" ], "details": "libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f45w-55jr-pvp2/GHSA-f45w-55jr-pvp2.json b/advisories/unreviewed/2025/03/GHSA-f45w-55jr-pvp2/GHSA-f45w-55jr-pvp2.json new file mode 100644 index 00000000000..5c31a3c0633 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f45w-55jr-pvp2/GHSA-f45w-55jr-pvp2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f45w-55jr-pvp2", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-28219" + ], + "details": "Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter \"deviceName\" passed to the binary through a POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28219" + }, + { + "type": "WEB", + "url": "https://github.com/IdaJea/IOT_vuln_1/blob/master/DC112A_V1.0.0.64/sub_69600.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json b/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json index 87f06585508..41022b076ec 100644 --- a/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json +++ b/advisories/unreviewed/2025/03/GHSA-fffw-r3h2-v6wq/GHSA-fffw-r3h2-v6wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fffw-r3h2-v6wq", - "modified": "2025-03-27T15:31:14Z", + "modified": "2025-03-28T15:31:54Z", "published": "2025-03-27T15:31:14Z", "aliases": [ "CVE-2025-2854" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://github.com/Fizz-L/CVE/blob/main/sql-fizz.md" }, + { + "type": "WEB", + "url": "https://github.com/hak0neP/cve/blob/main/sql-fizz.md" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.301501" diff --git a/advisories/unreviewed/2025/03/GHSA-fmgc-85r6-v6q3/GHSA-fmgc-85r6-v6q3.json b/advisories/unreviewed/2025/03/GHSA-fmgc-85r6-v6q3/GHSA-fmgc-85r6-v6q3.json new file mode 100644 index 00000000000..24c49c73aa2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fmgc-85r6-v6q3/GHSA-fmgc-85r6-v6q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmgc-85r6-v6q3", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2024-54291" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound PluginPass allows Manipulating Web Input to File System Calls. This issue affects PluginPass: from n/a through 0.9.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pluginpass-pro-plugintheme-licensing/vulnerability/wordpress-pluginpass-plugin-0-9-10-arbitrary-file-download-delete-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fqg9-8xmx-9fgp/GHSA-fqg9-8xmx-9fgp.json b/advisories/unreviewed/2025/03/GHSA-fqg9-8xmx-9fgp/GHSA-fqg9-8xmx-9fgp.json new file mode 100644 index 00000000000..ac063d505f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fqg9-8xmx-9fgp/GHSA-fqg9-8xmx-9fgp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqg9-8xmx-9fgp", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2025-28220" + ], + "details": "Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28220" + }, + { + "type": "WEB", + "url": "https://github.com/IdaJea/IOT_vuln_1/blob/master/w6_s_v1.0.0.4/setcfm.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g4rq-8hw9-mj8q/GHSA-g4rq-8hw9-mj8q.json b/advisories/unreviewed/2025/03/GHSA-g4rq-8hw9-mj8q/GHSA-g4rq-8hw9-mj8q.json new file mode 100644 index 00000000000..0f78a847416 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g4rq-8hw9-mj8q/GHSA-g4rq-8hw9-mj8q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4rq-8hw9-mj8q", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2024-7407" + ], + "details": "Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how password are transformed. \nThis issue was fixed in 18.2.377 version of the software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7407" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/03/CVE-2024-7407" + }, + { + "type": "WEB", + "url": "https://www.streamsoft.pl/streamsoft-prestiz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-261" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json b/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json index 9b1403146e4..8d399c7fb4f 100644 --- a/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json +++ b/advisories/unreviewed/2025/03/GHSA-gr89-4g8m-9f9g/GHSA-gr89-4g8m-9f9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gr89-4g8m-9f9g", - "modified": "2025-03-27T15:31:13Z", + "modified": "2025-03-28T15:31:54Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29488" ], "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h7v6-4m6m-8gjj/GHSA-h7v6-4m6m-8gjj.json b/advisories/unreviewed/2025/03/GHSA-h7v6-4m6m-8gjj/GHSA-h7v6-4m6m-8gjj.json new file mode 100644 index 00000000000..18a3a0ece9a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h7v6-4m6m-8gjj/GHSA-h7v6-4m6m-8gjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7v6-4m6m-8gjj", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2862" + ], + "details": "SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2862" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-261" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hfvj-w63f-mc9j/GHSA-hfvj-w63f-mc9j.json b/advisories/unreviewed/2025/03/GHSA-hfvj-w63f-mc9j/GHSA-hfvj-w63f-mc9j.json new file mode 100644 index 00000000000..2cc43e60cfa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hfvj-w63f-mc9j/GHSA-hfvj-w63f-mc9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfvj-w63f-mc9j", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2025-2909" + ], + "details": "The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2909" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-fermax-mobile-applications" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hp88-hfjw-2hg4/GHSA-hp88-hfjw-2hg4.json b/advisories/unreviewed/2025/03/GHSA-hp88-hfjw-2hg4/GHSA-hp88-hfjw-2hg4.json new file mode 100644 index 00000000000..2ab27a1d560 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hp88-hfjw-2hg4/GHSA-hp88-hfjw-2hg4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp88-hfjw-2hg4", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2901" + ], + "details": "A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2901" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-2901" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355685" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hprf-f9v4-9r3r/GHSA-hprf-f9v4-9r3r.json b/advisories/unreviewed/2025/03/GHSA-hprf-f9v4-9r3r/GHSA-hprf-f9v4-9r3r.json new file mode 100644 index 00000000000..04c06502711 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hprf-f9v4-9r3r/GHSA-hprf-f9v4-9r3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hprf-f9v4-9r3r", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2863" + ], + "details": "Cross-site request forgery (CSRF) vulnerability in the web application of saTECH BCU firmware version 2.1.3, which could allow an unauthenticated local attacker to exploit active administrator sessions and perform malicious actions. The malicious actions that can be executed by the attacker depend on the logged-in user, and may include rebooting the device or modifying roles and permissions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2863" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json b/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json index c052d6bb703..5ea280ddf3e 100644 --- a/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json +++ b/advisories/unreviewed/2025/03/GHSA-hqf3-3h38-frmh/GHSA-hqf3-3h38-frmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hqf3-3h38-frmh", - "modified": "2025-03-27T15:31:13Z", + "modified": "2025-03-28T15:31:54Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29489" ], "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-hrwg-r69j-hcrr/GHSA-hrwg-r69j-hcrr.json b/advisories/unreviewed/2025/03/GHSA-hrwg-r69j-hcrr/GHSA-hrwg-r69j-hcrr.json new file mode 100644 index 00000000000..4f917936419 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hrwg-r69j-hcrr/GHSA-hrwg-r69j-hcrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrwg-r69j-hcrr", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22767" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in globalpayments GlobalPayments WooCommerce allows Reflected XSS. This issue affects GlobalPayments WooCommerce: from n/a through 1.13.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22767" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/global-payments-woocommerce/vulnerability/wordpress-globalpayments-woocommerce-plugin-1-12-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jc64-qjc6-h5vp/GHSA-jc64-qjc6-h5vp.json b/advisories/unreviewed/2025/03/GHSA-jc64-qjc6-h5vp/GHSA-jc64-qjc6-h5vp.json new file mode 100644 index 00000000000..1167baf1bdc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jc64-qjc6-h5vp/GHSA-jc64-qjc6-h5vp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc64-qjc6-h5vp", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2910" + ], + "details": "User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2910" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-fermax-mobile-applications" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jfpc-5fff-j5r6/GHSA-jfpc-5fff-j5r6.json b/advisories/unreviewed/2025/03/GHSA-jfpc-5fff-j5r6/GHSA-jfpc-5fff-j5r6.json new file mode 100644 index 00000000000..04ab7bb1d0d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jfpc-5fff-j5r6/GHSA-jfpc-5fff-j5r6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfpc-5fff-j5r6", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2024-11504" + ], + "details": "Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker. \nThis issue was fixed in 18.1.376.37 version of the software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11504" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/03/CVE-2024-7407" + }, + { + "type": "WEB", + "url": "https://www.streamsoft.pl/streamsoft-prestiz" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json b/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json index 830fc117537..b8e2a12a694 100644 --- a/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json +++ b/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mvjr-2pvh-8wqh", - "modified": "2025-03-27T18:31:23Z", + "modified": "2025-03-28T15:31:55Z", "published": "2025-03-27T18:31:23Z", "aliases": [ "CVE-2025-26265" ], "details": "A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T16:15:30Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p3q9-8vf2-3jfg/GHSA-p3q9-8vf2-3jfg.json b/advisories/unreviewed/2025/03/GHSA-p3q9-8vf2-3jfg/GHSA-p3q9-8vf2-3jfg.json new file mode 100644 index 00000000000..4646de6449b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p3q9-8vf2-3jfg/GHSA-p3q9-8vf2-3jfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3q9-8vf2-3jfg", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-31010" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX allows Cross Site Request Forgery. This issue affects SimplyRETS Real Estate IDX: from n/a through 3.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31010" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simply-rets/vulnerability/wordpress-simplyrets-real-estate-idx-plugin-3-0-3-csrf-to-multiple-admin-actions-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pcq5-5jmx-47cw/GHSA-pcq5-5jmx-47cw.json b/advisories/unreviewed/2025/03/GHSA-pcq5-5jmx-47cw/GHSA-pcq5-5jmx-47cw.json new file mode 100644 index 00000000000..b2fbcd52b55 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pcq5-5jmx-47cw/GHSA-pcq5-5jmx-47cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcq5-5jmx-47cw", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2024-54362" + ], + "details": "Path Traversal vulnerability in NotFound GetShop ecommerce allows Path Traversal. This issue affects GetShop ecommerce: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54362" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/getshop-ecommerce/vulnerability/wordpress-getshop-ecommerce-plugin-1-3-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pq29-hpwp-p3wj/GHSA-pq29-hpwp-p3wj.json b/advisories/unreviewed/2025/03/GHSA-pq29-hpwp-p3wj/GHSA-pq29-hpwp-p3wj.json new file mode 100644 index 00000000000..c8358c3e4ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pq29-hpwp-p3wj/GHSA-pq29-hpwp-p3wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq29-hpwp-p3wj", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22356" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stencies Stencies allows Reflected XSS. This issue affects Stencies: from n/a through 0.58.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22356" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stencies/vulnerability/wordpress-stencies-plugin-0-58-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r299-g8pg-6xf2/GHSA-r299-g8pg-6xf2.json b/advisories/unreviewed/2025/03/GHSA-r299-g8pg-6xf2/GHSA-r299-g8pg-6xf2.json new file mode 100644 index 00000000000..d2f07aed180 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r299-g8pg-6xf2/GHSA-r299-g8pg-6xf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r299-g8pg-6xf2", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22501" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Improve My City Improve My City allows Reflected XSS. This issue affects Improve My City: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22501" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/improve-my-city/vulnerability/wordpress-improve-my-city-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rq3r-6rf7-m7m9/GHSA-rq3r-6rf7-m7m9.json b/advisories/unreviewed/2025/03/GHSA-rq3r-6rf7-m7m9/GHSA-rq3r-6rf7-m7m9.json new file mode 100644 index 00000000000..bb5e1bf2d6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rq3r-6rf7-m7m9/GHSA-rq3r-6rf7-m7m9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq3r-6rf7-m7m9", + "modified": "2025-03-28T15:31:55Z", + "published": "2025-03-28T15:31:55Z", + "aliases": [ + "CVE-2025-28221" + ], + "details": "Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web server crash via parameter time passed to the binary through a POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28221" + }, + { + "type": "WEB", + "url": "https://github.com/IdaJea/IOT_vuln_1/blob/master/w6_s_v1.0.0.4/time.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json b/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json index 36d3f171ceb..187d6c303dc 100644 --- a/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json +++ b/advisories/unreviewed/2025/03/GHSA-v7cw-67xp-5685/GHSA-v7cw-67xp-5685.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7cw-67xp-5685", - "modified": "2025-03-27T15:31:13Z", + "modified": "2025-03-28T15:31:53Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29486" ], "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:15:59Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json b/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json index d268869a1f0..837282cdddd 100644 --- a/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json +++ b/advisories/unreviewed/2025/03/GHSA-vc99-rg67-mm68/GHSA-vc99-rg67-mm68.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vc99-rg67-mm68", - "modified": "2025-03-27T15:31:13Z", + "modified": "2025-03-28T15:31:53Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29487" ], "details": "An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json b/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json index 2280ebb0a27..b0b7d9c07b4 100644 --- a/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json +++ b/advisories/unreviewed/2025/03/GHSA-vcgc-h73q-2m2p/GHSA-vcgc-h73q-2m2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vcgc-h73q-2m2p", - "modified": "2025-03-11T15:31:00Z", + "modified": "2025-03-28T15:31:50Z", "published": "2025-03-11T15:31:00Z", "aliases": [ "CVE-2024-54085" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250328-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-vg6w-rxwf-h2wq/GHSA-vg6w-rxwf-h2wq.json b/advisories/unreviewed/2025/03/GHSA-vg6w-rxwf-h2wq/GHSA-vg6w-rxwf-h2wq.json new file mode 100644 index 00000000000..ce1cc45fbab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vg6w-rxwf-h2wq/GHSA-vg6w-rxwf-h2wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg6w-rxwf-h2wq", + "modified": "2025-03-28T15:31:57Z", + "published": "2025-03-28T15:31:57Z", + "aliases": [ + "CVE-2025-22360" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Azure offload allows Reflected XSS. This issue affects WP Azure offload: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22360" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-azure-offload/vulnerability/wordpress-wp-azure-offload-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wc34-fgpq-8hg7/GHSA-wc34-fgpq-8hg7.json b/advisories/unreviewed/2025/03/GHSA-wc34-fgpq-8hg7/GHSA-wc34-fgpq-8hg7.json new file mode 100644 index 00000000000..fb3c2b91a7f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wc34-fgpq-8hg7/GHSA-wc34-fgpq-8hg7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc34-fgpq-8hg7", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2864" + ], + "details": "SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2864" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wfxf-3935-5jgv/GHSA-wfxf-3935-5jgv.json b/advisories/unreviewed/2025/03/GHSA-wfxf-3935-5jgv/GHSA-wfxf-3935-5jgv.json new file mode 100644 index 00000000000..ddd95acb080 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wfxf-3935-5jgv/GHSA-wfxf-3935-5jgv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfxf-3935-5jgv", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2877" + ], + "details": "A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to \"debug\", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any \"debug\" action in a rulebook and also affects Event Streams.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2877" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-2877" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355540" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json b/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json index 4cb4b8353e0..f5316026aa5 100644 --- a/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json +++ b/advisories/unreviewed/2025/03/GHSA-x2v7-w9j6-rqmx/GHSA-x2v7-w9j6-rqmx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x2v7-w9j6-rqmx", - "modified": "2025-03-28T03:30:24Z", + "modified": "2025-03-28T15:31:55Z", "published": "2025-03-28T03:30:24Z", "aliases": [ "CVE-2024-13939" ], "details": "String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string.\n\nAs stated in the documentation: \"If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents).\"\n\nThis is similar to CVE-2020-36829", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-208" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T03:15:15Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x542-2cq7-f2p3/GHSA-x542-2cq7-f2p3.json b/advisories/unreviewed/2025/03/GHSA-x542-2cq7-f2p3/GHSA-x542-2cq7-f2p3.json new file mode 100644 index 00000000000..625066456c5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x542-2cq7-f2p3/GHSA-x542-2cq7-f2p3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x542-2cq7-f2p3", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2860" + ], + "details": "SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials that users have within the web (.xml file). In order to exploit this vulnerability, the attacker must know the path, regardless of the user's privileges on the website.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2860" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x6xj-c9qw-4fjp/GHSA-x6xj-c9qw-4fjp.json b/advisories/unreviewed/2025/03/GHSA-x6xj-c9qw-4fjp/GHSA-x6xj-c9qw-4fjp.json new file mode 100644 index 00000000000..f252d8cc98b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x6xj-c9qw-4fjp/GHSA-x6xj-c9qw-4fjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6xj-c9qw-4fjp", + "modified": "2025-03-28T15:31:56Z", + "published": "2025-03-28T15:31:56Z", + "aliases": [ + "CVE-2025-2859" + ], + "details": "An attacker with access to the network where the vulnerable device is located could capture traffic and obtain cookies from the user, allowing them to steal a user's active session and make changes to the device via the web, depending on the privileges obtained by the user.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2859" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-arteches-satech-bcu" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T14:15:20Z" + } +} \ No newline at end of file