diff --git a/advisories/unreviewed/2024/03/GHSA-3jc7-rm6x-qj46/GHSA-3jc7-rm6x-qj46.json b/advisories/unreviewed/2024/03/GHSA-3jc7-rm6x-qj46/GHSA-3jc7-rm6x-qj46.json index ea21dd637a2..1cf586ad7c9 100644 --- a/advisories/unreviewed/2024/03/GHSA-3jc7-rm6x-qj46/GHSA-3jc7-rm6x-qj46.json +++ b/advisories/unreviewed/2024/03/GHSA-3jc7-rm6x-qj46/GHSA-3jc7-rm6x-qj46.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json b/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json index b7af95ac9ed..881311dcc65 100644 --- a/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json +++ b/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json b/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json index 9721e027d67..d6f10deb811 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json +++ b/advisories/unreviewed/2024/03/GHSA-mfw5-pp35-j4h8/GHSA-mfw5-pp35-j4h8.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json b/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json index 80ded34deba..2fbb9173ff1 100644 --- a/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json +++ b/advisories/unreviewed/2024/04/GHSA-44wr-9xpq-76v2/GHSA-44wr-9xpq-76v2.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json b/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json index c55f8a23a89..e4b0c9375d1 100644 --- a/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json +++ b/advisories/unreviewed/2024/04/GHSA-4q8v-gqw7-8xpx/GHSA-4q8v-gqw7-8xpx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json b/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json index 25e32ecd822..7b5c28de34f 100644 --- a/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json +++ b/advisories/unreviewed/2024/04/GHSA-7g5r-fqfh-59j6/GHSA-7g5r-fqfh-59j6.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-824" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8x8h-8p2w-8g4f/GHSA-8x8h-8p2w-8g4f.json b/advisories/unreviewed/2024/04/GHSA-8x8h-8p2w-8g4f/GHSA-8x8h-8p2w-8g4f.json index af0b0d716b7..a85b0df2866 100644 --- a/advisories/unreviewed/2024/04/GHSA-8x8h-8p2w-8g4f/GHSA-8x8h-8p2w-8g4f.json +++ b/advisories/unreviewed/2024/04/GHSA-8x8h-8p2w-8g4f/GHSA-8x8h-8p2w-8g4f.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f2c7-w7wj-2qjw/GHSA-f2c7-w7wj-2qjw.json b/advisories/unreviewed/2024/04/GHSA-f2c7-w7wj-2qjw/GHSA-f2c7-w7wj-2qjw.json index 04dd3f1ebcc..a63f64688ef 100644 --- a/advisories/unreviewed/2024/04/GHSA-f2c7-w7wj-2qjw/GHSA-f2c7-w7wj-2qjw.json +++ b/advisories/unreviewed/2024/04/GHSA-f2c7-w7wj-2qjw/GHSA-f2c7-w7wj-2qjw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-129" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json b/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json index 3e7389c5a11..ac860aae438 100644 --- a/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json +++ b/advisories/unreviewed/2024/04/GHSA-w9qr-vr3p-gqmx/GHSA-w9qr-vr3p-gqmx.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json b/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json index aa841a30c24..1c02fb0d750 100644 --- a/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json +++ b/advisories/unreviewed/2024/05/GHSA-29pq-gr25-8674/GHSA-29pq-gr25-8674.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json b/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json index da495080c29..ad73b6d1b7d 100644 --- a/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json +++ b/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-7qvv-hm32-963p/GHSA-7qvv-hm32-963p.json b/advisories/unreviewed/2024/05/GHSA-7qvv-hm32-963p/GHSA-7qvv-hm32-963p.json index 69ec2997470..99d5d282cdf 100644 --- a/advisories/unreviewed/2024/05/GHSA-7qvv-hm32-963p/GHSA-7qvv-hm32-963p.json +++ b/advisories/unreviewed/2024/05/GHSA-7qvv-hm32-963p/GHSA-7qvv-hm32-963p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8xgr-fvrm-f9g3/GHSA-8xgr-fvrm-f9g3.json b/advisories/unreviewed/2024/05/GHSA-8xgr-fvrm-f9g3/GHSA-8xgr-fvrm-f9g3.json index c1199a4001e..6d19c7616ca 100644 --- a/advisories/unreviewed/2024/05/GHSA-8xgr-fvrm-f9g3/GHSA-8xgr-fvrm-f9g3.json +++ b/advisories/unreviewed/2024/05/GHSA-8xgr-fvrm-f9g3/GHSA-8xgr-fvrm-f9g3.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cqgv-cq5q-68pf/GHSA-cqgv-cq5q-68pf.json b/advisories/unreviewed/2024/05/GHSA-cqgv-cq5q-68pf/GHSA-cqgv-cq5q-68pf.json index a8df3d1ce64..e1d551b60c9 100644 --- a/advisories/unreviewed/2024/05/GHSA-cqgv-cq5q-68pf/GHSA-cqgv-cq5q-68pf.json +++ b/advisories/unreviewed/2024/05/GHSA-cqgv-cq5q-68pf/GHSA-cqgv-cq5q-68pf.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fqv6-crjx-gm34/GHSA-fqv6-crjx-gm34.json b/advisories/unreviewed/2024/05/GHSA-fqv6-crjx-gm34/GHSA-fqv6-crjx-gm34.json index 3aad17bb9a8..4bacf60000f 100644 --- a/advisories/unreviewed/2024/05/GHSA-fqv6-crjx-gm34/GHSA-fqv6-crjx-gm34.json +++ b/advisories/unreviewed/2024/05/GHSA-fqv6-crjx-gm34/GHSA-fqv6-crjx-gm34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqv6-crjx-gm34", - "modified": "2024-05-14T18:30:56Z", + "modified": "2025-04-04T15:30:53Z", "published": "2024-05-14T18:30:56Z", "aliases": [ "CVE-2024-4790" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-grfr-gx46-j682/GHSA-grfr-gx46-j682.json b/advisories/unreviewed/2024/05/GHSA-grfr-gx46-j682/GHSA-grfr-gx46-j682.json index 8383e036d31..feb065996e9 100644 --- a/advisories/unreviewed/2024/05/GHSA-grfr-gx46-j682/GHSA-grfr-gx46-j682.json +++ b/advisories/unreviewed/2024/05/GHSA-grfr-gx46-j682/GHSA-grfr-gx46-j682.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hv5r-r2vq-gcrh/GHSA-hv5r-r2vq-gcrh.json b/advisories/unreviewed/2024/05/GHSA-hv5r-r2vq-gcrh/GHSA-hv5r-r2vq-gcrh.json index f53b8ce9124..511d711963e 100644 --- a/advisories/unreviewed/2024/05/GHSA-hv5r-r2vq-gcrh/GHSA-hv5r-r2vq-gcrh.json +++ b/advisories/unreviewed/2024/05/GHSA-hv5r-r2vq-gcrh/GHSA-hv5r-r2vq-gcrh.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-908" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-jfx8-wc49-mg5c/GHSA-jfx8-wc49-mg5c.json b/advisories/unreviewed/2024/05/GHSA-jfx8-wc49-mg5c/GHSA-jfx8-wc49-mg5c.json index 8564cc89e45..c37d24f2d9a 100644 --- a/advisories/unreviewed/2024/05/GHSA-jfx8-wc49-mg5c/GHSA-jfx8-wc49-mg5c.json +++ b/advisories/unreviewed/2024/05/GHSA-jfx8-wc49-mg5c/GHSA-jfx8-wc49-mg5c.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json b/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json index 7077c60f469..eb31263e210 100644 --- a/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json +++ b/advisories/unreviewed/2024/05/GHSA-mpm3-wjp6-8g7x/GHSA-mpm3-wjp6-8g7x.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json b/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json index 05e933fc2ca..a7b2d4ef418 100644 --- a/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json +++ b/advisories/unreviewed/2024/05/GHSA-p47x-q59q-2mpw/GHSA-p47x-q59q-2mpw.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p8xf-2w27-6wqx/GHSA-p8xf-2w27-6wqx.json b/advisories/unreviewed/2024/05/GHSA-p8xf-2w27-6wqx/GHSA-p8xf-2w27-6wqx.json index 030270558bf..7f389bf1015 100644 --- a/advisories/unreviewed/2024/05/GHSA-p8xf-2w27-6wqx/GHSA-p8xf-2w27-6wqx.json +++ b/advisories/unreviewed/2024/05/GHSA-p8xf-2w27-6wqx/GHSA-p8xf-2w27-6wqx.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v8pp-r8hm-gfqw/GHSA-v8pp-r8hm-gfqw.json b/advisories/unreviewed/2024/05/GHSA-v8pp-r8hm-gfqw/GHSA-v8pp-r8hm-gfqw.json index 9ab45286bee..0b592bee0da 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8pp-r8hm-gfqw/GHSA-v8pp-r8hm-gfqw.json +++ b/advisories/unreviewed/2024/05/GHSA-v8pp-r8hm-gfqw/GHSA-v8pp-r8hm-gfqw.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json b/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json index 57bdf08aeb4..49d9e11dba8 100644 --- a/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json +++ b/advisories/unreviewed/2024/05/GHSA-wf38-7v3f-5mjp/GHSA-wf38-7v3f-5mjp.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x4rw-prfw-9mq5/GHSA-x4rw-prfw-9mq5.json b/advisories/unreviewed/2024/05/GHSA-x4rw-prfw-9mq5/GHSA-x4rw-prfw-9mq5.json index 215c9726c05..a08d7685370 100644 --- a/advisories/unreviewed/2024/05/GHSA-x4rw-prfw-9mq5/GHSA-x4rw-prfw-9mq5.json +++ b/advisories/unreviewed/2024/05/GHSA-x4rw-prfw-9mq5/GHSA-x4rw-prfw-9mq5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x4rw-prfw-9mq5", - "modified": "2024-05-14T18:30:50Z", + "modified": "2025-04-04T15:30:51Z", "published": "2024-05-14T18:30:50Z", "aliases": [ "CVE-2024-34440" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-6w85-2w93-mrpr/GHSA-6w85-2w93-mrpr.json b/advisories/unreviewed/2024/06/GHSA-6w85-2w93-mrpr/GHSA-6w85-2w93-mrpr.json index c4550a49492..5bd4b9ad5a2 100644 --- a/advisories/unreviewed/2024/06/GHSA-6w85-2w93-mrpr/GHSA-6w85-2w93-mrpr.json +++ b/advisories/unreviewed/2024/06/GHSA-6w85-2w93-mrpr/GHSA-6w85-2w93-mrpr.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-129" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-22g3-53pr-g6hg/GHSA-22g3-53pr-g6hg.json b/advisories/unreviewed/2025/04/GHSA-22g3-53pr-g6hg/GHSA-22g3-53pr-g6hg.json new file mode 100644 index 00000000000..30b7b15cce5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-22g3-53pr-g6hg/GHSA-22g3-53pr-g6hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22g3-53pr-g6hg", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2024-51800" + ], + "details": "Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51800" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/homey/vulnerability/wordpress-homey-theme-2-4-1-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-27w9-h9rx-p7c5/GHSA-27w9-h9rx-p7c5.json b/advisories/unreviewed/2025/04/GHSA-27w9-h9rx-p7c5/GHSA-27w9-h9rx-p7c5.json new file mode 100644 index 00000000000..563cf4ed5c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-27w9-h9rx-p7c5/GHSA-27w9-h9rx-p7c5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27w9-h9rx-p7c5", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-31403" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31403" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-calendar-and-notification/vulnerability/wordpress-booking-calendar-and-notification-plugin-4-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-28gr-56hr-prp6/GHSA-28gr-56hr-prp6.json b/advisories/unreviewed/2025/04/GHSA-28gr-56hr-prp6/GHSA-28gr-56hr-prp6.json index 8a282b8b167..6db4f1fc3b2 100644 --- a/advisories/unreviewed/2025/04/GHSA-28gr-56hr-prp6/GHSA-28gr-56hr-prp6.json +++ b/advisories/unreviewed/2025/04/GHSA-28gr-56hr-prp6/GHSA-28gr-56hr-prp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28gr-56hr-prp6", - "modified": "2025-04-02T15:31:36Z", + "modified": "2025-04-04T15:31:15Z", "published": "2025-04-02T15:31:36Z", "aliases": [ "CVE-2025-2786" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2786" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3607" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-2786" diff --git a/advisories/unreviewed/2025/04/GHSA-28j8-w7xj-m9x2/GHSA-28j8-w7xj-m9x2.json b/advisories/unreviewed/2025/04/GHSA-28j8-w7xj-m9x2/GHSA-28j8-w7xj-m9x2.json new file mode 100644 index 00000000000..15ef8751f5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-28j8-w7xj-m9x2/GHSA-28j8-w7xj-m9x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28j8-w7xj-m9x2", + "modified": "2025-04-04T15:31:18Z", + "published": "2025-04-04T15:31:18Z", + "aliases": [ + "CVE-2025-31407" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31407" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/tiger/vulnerability/wordpress-tiger-theme-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2fhw-h5f5-45gf/GHSA-2fhw-h5f5-45gf.json b/advisories/unreviewed/2025/04/GHSA-2fhw-h5f5-45gf/GHSA-2fhw-h5f5-45gf.json new file mode 100644 index 00000000000..f52bf3d036a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2fhw-h5f5-45gf/GHSA-2fhw-h5f5-45gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fhw-h5f5-45gf", + "modified": "2025-04-04T15:31:18Z", + "published": "2025-04-04T15:31:18Z", + "aliases": [ + "CVE-2025-31418" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noonnoo Gravel allows Reflected XSS.This issue affects Gravel: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31418" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/gravel/vulnerability/wordpress-gravel-theme-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-36cx-c3wx-4c25/GHSA-36cx-c3wx-4c25.json b/advisories/unreviewed/2025/04/GHSA-36cx-c3wx-4c25/GHSA-36cx-c3wx-4c25.json new file mode 100644 index 00000000000..52e96e674bb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-36cx-c3wx-4c25/GHSA-36cx-c3wx-4c25.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36cx-c3wx-4c25", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-2798" + ], + "details": "The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2798" + }, + { + "type": "WEB", + "url": "https://hub.woffice.io/woffice/changelog#april-1st-2025-version-5422" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6dd6169b-bc94-4642-8975-2e96bc01576f?source=cve" + }, + { + "type": "WEB", + "url": "http://localhost/wp-content/themes/woffice/inc/classes/Woffice_Register.php#L405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-37hr-3fmf-v449/GHSA-37hr-3fmf-v449.json b/advisories/unreviewed/2025/04/GHSA-37hr-3fmf-v449/GHSA-37hr-3fmf-v449.json new file mode 100644 index 00000000000..601b5a02d4f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37hr-3fmf-v449/GHSA-37hr-3fmf-v449.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37hr-3fmf-v449", + "modified": "2025-04-04T15:31:18Z", + "published": "2025-04-04T15:31:18Z", + "aliases": [ + "CVE-2025-3249" + ], + "details": "A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3249" + }, + { + "type": "WEB", + "url": "https://github.com/fjl1113/cve/blob/main/totolink.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303319" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303319" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.543214" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-43vx-c2h5-w85c/GHSA-43vx-c2h5-w85c.json b/advisories/unreviewed/2025/04/GHSA-43vx-c2h5-w85c/GHSA-43vx-c2h5-w85c.json new file mode 100644 index 00000000000..875d2357da6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43vx-c2h5-w85c/GHSA-43vx-c2h5-w85c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43vx-c2h5-w85c", + "modified": "2025-04-04T15:31:18Z", + "published": "2025-04-04T15:31:18Z", + "aliases": [ + "CVE-2025-31416" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwesomeTOGI Awesome Event Booking allows Reflected XSS.This issue affects Awesome Event Booking: from n/a through 2.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-event-booking/vulnerability/wordpress-awesome-event-booking-plugin-2-8-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-54m9-c6rr-42rm/GHSA-54m9-c6rr-42rm.json b/advisories/unreviewed/2025/04/GHSA-54m9-c6rr-42rm/GHSA-54m9-c6rr-42rm.json new file mode 100644 index 00000000000..68fdc5a4cc6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-54m9-c6rr-42rm/GHSA-54m9-c6rr-42rm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54m9-c6rr-42rm", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-31384" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows Reflected XSS.This issue affects Videos: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31384" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/videos/vulnerability/wordpress-videos-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5wgw-4vg2-8hxp/GHSA-5wgw-4vg2-8hxp.json b/advisories/unreviewed/2025/04/GHSA-5wgw-4vg2-8hxp/GHSA-5wgw-4vg2-8hxp.json new file mode 100644 index 00000000000..a79eecccbed --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5wgw-4vg2-8hxp/GHSA-5wgw-4vg2-8hxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wgw-4vg2-8hxp", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-31421" + ], + "details": "Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Oblak Studio Srbtranslatin allows Retrieve Embedded Sensitive Data.This issue affects Srbtranslatin: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/srbtranslatin/vulnerability/wordpress-srbtranslatin-plugin-3-2-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xf3-gmx4-529v/GHSA-5xf3-gmx4-529v.json b/advisories/unreviewed/2025/04/GHSA-5xf3-gmx4-529v/GHSA-5xf3-gmx4-529v.json index 0b86b4d1111..4efe86f8a30 100644 --- a/advisories/unreviewed/2025/04/GHSA-5xf3-gmx4-529v/GHSA-5xf3-gmx4-529v.json +++ b/advisories/unreviewed/2025/04/GHSA-5xf3-gmx4-529v/GHSA-5xf3-gmx4-529v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xf3-gmx4-529v", - "modified": "2025-04-02T15:31:36Z", + "modified": "2025-04-04T15:31:15Z", "published": "2025-04-02T15:31:36Z", "aliases": [ "CVE-2025-2842" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2842" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3607" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-2842" diff --git a/advisories/unreviewed/2025/04/GHSA-752q-gmq4-ghfx/GHSA-752q-gmq4-ghfx.json b/advisories/unreviewed/2025/04/GHSA-752q-gmq4-ghfx/GHSA-752q-gmq4-ghfx.json new file mode 100644 index 00000000000..b3429e650ca --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-752q-gmq4-ghfx/GHSA-752q-gmq4-ghfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-752q-gmq4-ghfx", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-31405" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami WooCommerce Compare allows PHP Local File Inclusion.This issue affects Fami WooCommerce Compare: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31405" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fami-woocommerce-compare/vulnerability/wordpress-fami-woocommerce-compare-plugin-1-0-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79h6-vv5m-43w2/GHSA-79h6-vv5m-43w2.json b/advisories/unreviewed/2025/04/GHSA-79h6-vv5m-43w2/GHSA-79h6-vv5m-43w2.json new file mode 100644 index 00000000000..3387d9c4f16 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79h6-vv5m-43w2/GHSA-79h6-vv5m-43w2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79h6-vv5m-43w2", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-22281" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joshix Simplish allows Stored XSS.This issue affects Simplish: from n/a through 2.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22281" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/simplish/vulnerability/wordpress-simplish-theme-2-6-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rf4-33cq-hww8/GHSA-7rf4-33cq-hww8.json b/advisories/unreviewed/2025/04/GHSA-7rf4-33cq-hww8/GHSA-7rf4-33cq-hww8.json new file mode 100644 index 00000000000..8d49cf3dd07 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rf4-33cq-hww8/GHSA-7rf4-33cq-hww8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rf4-33cq-hww8", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-3189" + ], + "details": "Stored Cross-Site Scripting (XSS) in DoWISP in versions prior to 1.16.2.50, which consists of an stored XSS through the upload of a profile picture in SVG format with malicious Javascript code in it.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3189" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-dowisp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json b/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json index 8c0f0ab9b0f..996bbc29808 100644 --- a/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json +++ b/advisories/unreviewed/2025/04/GHSA-c26r-vw7p-2m7h/GHSA-c26r-vw7p-2m7h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c26r-vw7p-2m7h", - "modified": "2025-04-03T18:30:58Z", + "modified": "2025-04-04T15:31:15Z", "published": "2025-04-03T18:30:58Z", "aliases": [ "CVE-2024-4877" ], "details": "OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-268" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T16:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f653-w82j-53xf/GHSA-f653-w82j-53xf.json b/advisories/unreviewed/2025/04/GHSA-f653-w82j-53xf/GHSA-f653-w82j-53xf.json new file mode 100644 index 00000000000..bc4e7201afe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f653-w82j-53xf/GHSA-f653-w82j-53xf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f653-w82j-53xf", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-31381" + ], + "details": "Missing Authorization vulnerability in shiptrack Booking Calendar and Notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31381" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-calendar-and-notification/vulnerability/wordpress-booking-calendar-and-notification-plugin-4-0-3-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json b/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json new file mode 100644 index 00000000000..34e03d8e941 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc2p-qppw-qq2v", + "modified": "2025-04-04T15:31:18Z", + "published": "2025-04-04T15:31:18Z", + "aliases": [ + "CVE-2025-3250" + ], + "details": "A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3250" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303320" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303320" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.546132" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/u520611/giuhru/vfvchim8sphv2y1g?singleDoc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json b/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json index 966eb45b9bc..c357841e551 100644 --- a/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json +++ b/advisories/unreviewed/2025/04/GHSA-fv89-7wfw-xmjg/GHSA-fv89-7wfw-xmjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fv89-7wfw-xmjg", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-04T15:31:15Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-47213" ], "details": "An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gwr7-g7gq-m3v3/GHSA-gwr7-g7gq-m3v3.json b/advisories/unreviewed/2025/04/GHSA-gwr7-g7gq-m3v3/GHSA-gwr7-g7gq-m3v3.json new file mode 100644 index 00000000000..9ab037d3e13 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwr7-g7gq-m3v3/GHSA-gwr7-g7gq-m3v3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwr7-g7gq-m3v3", + "modified": "2025-04-04T15:31:16Z", + "published": "2025-04-04T15:31:16Z", + "aliases": [ + "CVE-2025-31420" + ], + "details": "Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31420" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpforo/vulnerability/wordpress-wpforo-forum-plugin-2-4-2-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hppg-795j-v3gj/GHSA-hppg-795j-v3gj.json b/advisories/unreviewed/2025/04/GHSA-hppg-795j-v3gj/GHSA-hppg-795j-v3gj.json new file mode 100644 index 00000000000..57065fd39ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hppg-795j-v3gj/GHSA-hppg-795j-v3gj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hppg-795j-v3gj", + "modified": "2025-04-04T15:31:18Z", + "published": "2025-04-04T15:31:18Z", + "aliases": [ + "CVE-2025-3251" + ], + "details": "A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation of the argument motto leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3251" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/XSS1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303321" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303321" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.548971" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jx2j-r7xv-7cv9/GHSA-jx2j-r7xv-7cv9.json b/advisories/unreviewed/2025/04/GHSA-jx2j-r7xv-7cv9/GHSA-jx2j-r7xv-7cv9.json new file mode 100644 index 00000000000..208391de66d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jx2j-r7xv-7cv9/GHSA-jx2j-r7xv-7cv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx2j-r7xv-7cv9", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-31389" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sequel.Io Sequel allows Reflected XSS.This issue affects Sequel: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31389" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sequel/vulnerability/wordpress-sequel-plugin-1-0-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json b/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json index eefbcad5aef..df7b01471af 100644 --- a/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json +++ b/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pg7p-xxvc-73xx", - "modified": "2025-04-04T06:34:24Z", + "modified": "2025-04-04T15:31:16Z", "published": "2025-04-04T06:34:24Z", "aliases": [ "CVE-2025-2279" ], "details": "The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-04T06:15:40Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json b/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json new file mode 100644 index 00000000000..a6b448086e2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7wx-4c6m-pm7w/GHSA-q7wx-4c6m-pm7w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7wx-4c6m-pm7w", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-28146" + ], + "details": "Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28146" + }, + { + "type": "WEB", + "url": "https://github.com/regainer27/edimax-br-6478ac_v3-br-6478ac_v3_1.0.15/tree/main/3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xvv8-rrjg-xrq4/GHSA-xvv8-rrjg-xrq4.json b/advisories/unreviewed/2025/04/GHSA-xvv8-rrjg-xrq4/GHSA-xvv8-rrjg-xrq4.json new file mode 100644 index 00000000000..7ff115753b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xvv8-rrjg-xrq4/GHSA-xvv8-rrjg-xrq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvv8-rrjg-xrq4", + "modified": "2025-04-04T15:31:17Z", + "published": "2025-04-04T15:31:17Z", + "aliases": [ + "CVE-2025-22285" + ], + "details": "Missing Authorization vulnerability in Eniture Technology Pallet Packaging for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pallet Packaging for WooCommerce: from n/a through 1.1.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pallet-packaging-for-woocommerce/vulnerability/wordpress-pallet-packaging-for-woocommerce-plugin-1-1-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T14:15:21Z" + } +} \ No newline at end of file