diff --git a/advisories/unreviewed/2023/06/GHSA-phqx-gjxc-wrp9/GHSA-phqx-gjxc-wrp9.json b/advisories/unreviewed/2023/06/GHSA-phqx-gjxc-wrp9/GHSA-phqx-gjxc-wrp9.json index 0b64b0b723d..39c653c6db8 100644 --- a/advisories/unreviewed/2023/06/GHSA-phqx-gjxc-wrp9/GHSA-phqx-gjxc-wrp9.json +++ b/advisories/unreviewed/2023/06/GHSA-phqx-gjxc-wrp9/GHSA-phqx-gjxc-wrp9.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/06/GHSA-w4w8-q6pw-hgxq/GHSA-w4w8-q6pw-hgxq.json b/advisories/unreviewed/2023/06/GHSA-w4w8-q6pw-hgxq/GHSA-w4w8-q6pw-hgxq.json index 65003742dd2..3abbd85d66b 100644 --- a/advisories/unreviewed/2023/06/GHSA-w4w8-q6pw-hgxq/GHSA-w4w8-q6pw-hgxq.json +++ b/advisories/unreviewed/2023/06/GHSA-w4w8-q6pw-hgxq/GHSA-w4w8-q6pw-hgxq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4w8-q6pw-hgxq", - "modified": "2024-04-04T04:47:34Z", + "modified": "2025-01-03T21:30:38Z", "published": "2023-06-13T18:30:39Z", "aliases": [ "CVE-2023-31541" diff --git a/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json b/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json index 63abb916b93..f60e62aeb11 100644 --- a/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json +++ b/advisories/unreviewed/2025/01/GHSA-2mf6-q75m-3xr8/GHSA-2mf6-q75m-3xr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2mf6-q75m-3xr8", - "modified": "2025-01-03T15:30:38Z", + "modified": "2025-01-03T21:30:40Z", "published": "2025-01-03T15:30:38Z", "aliases": [ "CVE-2024-48814" ], "details": "SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-03T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json b/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json index f2e8ff6fdc0..98896147953 100644 --- a/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json +++ b/advisories/unreviewed/2025/01/GHSA-63xr-9hmx-v966/GHSA-63xr-9hmx-v966.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-63xr-9hmx-v966", - "modified": "2025-01-03T18:30:34Z", + "modified": "2025-01-03T21:30:40Z", "published": "2025-01-03T18:30:34Z", "aliases": [ "CVE-2024-35365" ], "details": "FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-03T18:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json b/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json new file mode 100644 index 00000000000..9d916552f87 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mf2-fq9m-xrff", + "modified": "2025-01-03T21:30:40Z", + "published": "2025-01-03T21:30:40Z", + "aliases": [ + "CVE-2025-0196" + ], + "details": "A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0196" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Masamuneee/13b0a6384f0c07e8db462df9cb18fd47" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json b/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json new file mode 100644 index 00000000000..576f10a8180 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82j5-p9gh-m4p2", + "modified": "2025-01-03T21:30:40Z", + "published": "2025-01-03T21:30:40Z", + "aliases": [ + "CVE-2025-0197" + ], + "details": "A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0197" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Masamuneee/07a787e5a4599954c178baf90eeb553c" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290134" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290134" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json b/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json new file mode 100644 index 00000000000..e58d4cbfde7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mgr-c64f-w923", + "modified": "2025-01-03T21:30:40Z", + "published": "2025-01-03T21:30:40Z", + "aliases": [ + "CVE-2025-0198" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/search_result.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0198" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Masamuneee/86580188bf42580c0ae70ae4d247e6df" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290135" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290135" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json b/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json index cc483ffafca..99bd2fbcbaa 100644 --- a/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json +++ b/advisories/unreviewed/2025/01/GHSA-h735-q6rm-hjcj/GHSA-h735-q6rm-hjcj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h735-q6rm-hjcj", - "modified": "2025-01-03T18:30:34Z", + "modified": "2025-01-03T21:30:40Z", "published": "2025-01-03T18:30:34Z", "aliases": [ "CVE-2024-55507" ], "details": "An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-03T16:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json b/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json index 0dbf841de6f..d59f04ae56a 100644 --- a/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json +++ b/advisories/unreviewed/2025/01/GHSA-xjpv-4c4j-wwp8/GHSA-xjpv-4c4j-wwp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjpv-4c4j-wwp8", - "modified": "2025-01-03T15:30:38Z", + "modified": "2025-01-03T21:30:40Z", "published": "2025-01-03T15:30:38Z", "aliases": [ "CVE-2024-55078" ], "details": "An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-03T15:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json b/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json index b51baa79f67..5f225c88237 100644 --- a/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json +++ b/advisories/unreviewed/2025/01/GHSA-xqm8-c3rv-5vpf/GHSA-xqm8-c3rv-5vpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xqm8-c3rv-5vpf", - "modified": "2025-01-03T18:30:34Z", + "modified": "2025-01-03T21:30:40Z", "published": "2025-01-03T18:30:34Z", "aliases": [ "CVE-2024-36613" ], "details": "FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-03T18:15:15Z"