diff --git a/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json b/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json index bf991537fd4..aa9fe4a4c28 100644 --- a/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json +++ b/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-754f-8gm6-c4r2", - "modified": "2025-03-13T21:43:02Z", + "modified": "2025-03-14T12:32:01Z", "published": "2025-03-12T20:54:42Z", "aliases": [ "CVE-2025-25292" @@ -98,6 +98,10 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25292.yml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0009" } ], "database_specific": { diff --git a/advisories/github-reviewed/2025/03/GHSA-92rq-c8cf-prrq/GHSA-92rq-c8cf-prrq.json b/advisories/github-reviewed/2025/03/GHSA-92rq-c8cf-prrq/GHSA-92rq-c8cf-prrq.json index eef3f865cfc..c40ddccfc4d 100644 --- a/advisories/github-reviewed/2025/03/GHSA-92rq-c8cf-prrq/GHSA-92rq-c8cf-prrq.json +++ b/advisories/github-reviewed/2025/03/GHSA-92rq-c8cf-prrq/GHSA-92rq-c8cf-prrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92rq-c8cf-prrq", - "modified": "2025-03-13T21:42:28Z", + "modified": "2025-03-14T12:32:01Z", "published": "2025-03-12T20:16:50Z", "aliases": [ "CVE-2025-25293" @@ -98,6 +98,10 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25293.yml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-27c6-7gh5-wmvg/GHSA-27c6-7gh5-wmvg.json b/advisories/unreviewed/2024/08/GHSA-27c6-7gh5-wmvg/GHSA-27c6-7gh5-wmvg.json index e0ad1bd5ae4..d4475fd3a1e 100644 --- a/advisories/unreviewed/2024/08/GHSA-27c6-7gh5-wmvg/GHSA-27c6-7gh5-wmvg.json +++ b/advisories/unreviewed/2024/08/GHSA-27c6-7gh5-wmvg/GHSA-27c6-7gh5-wmvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27c6-7gh5-wmvg", - "modified": "2024-08-14T15:31:13Z", + "modified": "2025-03-14T12:31:58Z", "published": "2024-08-14T15:31:13Z", "aliases": [ "CVE-2023-49141" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49141" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0003" + }, { "type": "WEB", "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01046.html" diff --git a/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json b/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json index 0b13b0d18eb..0b2a3718498 100644 --- a/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json +++ b/advisories/unreviewed/2024/12/GHSA-6hcg-vqw2-35jw/GHSA-6hcg-vqw2-35jw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hcg-vqw2-35jw", - "modified": "2024-12-11T18:30:40Z", + "modified": "2025-03-14T12:31:58Z", "published": "2024-12-05T21:31:52Z", "aliases": [ "CVE-2024-53589" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0006" + }, { "type": "WEB", "url": "https://www.gnu.org/software/binutils" diff --git a/advisories/unreviewed/2025/01/GHSA-5qjr-cj9f-phrx/GHSA-5qjr-cj9f-phrx.json b/advisories/unreviewed/2025/01/GHSA-5qjr-cj9f-phrx/GHSA-5qjr-cj9f-phrx.json index 6b6027e02a0..8543c2a588c 100644 --- a/advisories/unreviewed/2025/01/GHSA-5qjr-cj9f-phrx/GHSA-5qjr-cj9f-phrx.json +++ b/advisories/unreviewed/2025/01/GHSA-5qjr-cj9f-phrx/GHSA-5qjr-cj9f-phrx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qjr-cj9f-phrx", - "modified": "2025-02-28T21:32:14Z", + "modified": "2025-03-14T12:31:59Z", "published": "2025-01-31T18:31:08Z", "aliases": [ "CVE-2025-0938" @@ -54,6 +54,10 @@ { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json b/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json index 797e3a921c5..c2c7370468f 100644 --- a/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json +++ b/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74p9-4v44-wwx5", - "modified": "2025-02-14T21:31:04Z", + "modified": "2025-03-14T12:31:59Z", "published": "2025-02-14T18:30:51Z", "aliases": [ "CVE-2024-3220" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/CDXW34ND2LSAOYAR5N6UNONP4ZBX4D6R" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0001" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/02/14/8" diff --git a/advisories/unreviewed/2025/03/GHSA-4678-x95m-c2hf/GHSA-4678-x95m-c2hf.json b/advisories/unreviewed/2025/03/GHSA-4678-x95m-c2hf/GHSA-4678-x95m-c2hf.json new file mode 100644 index 00000000000..954d3f52365 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4678-x95m-c2hf/GHSA-4678-x95m-c2hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4678-x95m-c2hf", + "modified": "2025-03-14T12:32:01Z", + "published": "2025-03-14T12:32:01Z", + "aliases": [ + "CVE-2024-26006" + ], + "details": "An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26006" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-485" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-14T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-98c3-q46g-62qh/GHSA-98c3-q46g-62qh.json b/advisories/unreviewed/2025/03/GHSA-98c3-q46g-62qh/GHSA-98c3-q46g-62qh.json new file mode 100644 index 00000000000..3c7522e9dc2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-98c3-q46g-62qh/GHSA-98c3-q46g-62qh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98c3-q46g-62qh", + "modified": "2025-03-14T12:32:01Z", + "published": "2025-03-14T12:32:01Z", + "aliases": [ + "CVE-2024-13771" + ], + "details": "The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13771" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5ab2c74d-b83b-40ea-951c-83aeb76a7515?source=cve" + }, + { + "type": "WEB", + "url": "http://localhost:1337/wp-content/themes/civi/includes/class-ajax.php#L715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-14T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cghv-p6j4-5ch6/GHSA-cghv-p6j4-5ch6.json b/advisories/unreviewed/2025/03/GHSA-cghv-p6j4-5ch6/GHSA-cghv-p6j4-5ch6.json new file mode 100644 index 00000000000..17d728139cb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cghv-p6j4-5ch6/GHSA-cghv-p6j4-5ch6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cghv-p6j4-5ch6", + "modified": "2025-03-14T12:32:02Z", + "published": "2025-03-14T12:32:02Z", + "aliases": [ + "CVE-2025-2232" + ], + "details": "The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up to, and including, 1.2.8. This is due to insufficient role restrictions in the 'do_register_user' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2232" + }, + { + "type": "WEB", + "url": "https://docs.purethemes.net/findeo/knowledge-base/changelog-findeo" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/abe73ecd-1325-4d6d-8545-d27f6116ca43?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-14T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jrw2-pv6m-v2w5/GHSA-jrw2-pv6m-v2w5.json b/advisories/unreviewed/2025/03/GHSA-jrw2-pv6m-v2w5/GHSA-jrw2-pv6m-v2w5.json new file mode 100644 index 00000000000..dc7e02609c6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jrw2-pv6m-v2w5/GHSA-jrw2-pv6m-v2w5.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrw2-pv6m-v2w5", + "modified": "2025-03-14T12:32:01Z", + "published": "2025-03-14T12:32:01Z", + "aliases": [ + "CVE-2024-13772" + ], + "details": "The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13772" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bf04f458-7900-4dd3-84fb-169b74db97ab?source=cve" + }, + { + "type": "WEB", + "url": "http://localhost:1337/wp-content/themes/civi/includes/class-ajax.php#L567" + }, + { + "type": "WEB", + "url": "http://localhost:1337/wp-content/themes/civi/includes/class-ajax.php#L739" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-14T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m727-97qg-jrmp/GHSA-m727-97qg-jrmp.json b/advisories/unreviewed/2025/03/GHSA-m727-97qg-jrmp/GHSA-m727-97qg-jrmp.json new file mode 100644 index 00000000000..250972e754e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m727-97qg-jrmp/GHSA-m727-97qg-jrmp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m727-97qg-jrmp", + "modified": "2025-03-14T12:32:02Z", + "published": "2025-03-14T12:32:02Z", + "aliases": [ + "CVE-2024-13773" + ], + "details": "The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13773" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e3499182-7501-4fec-a7c6-b66ae47533cd?source=cve" + }, + { + "type": "WEB", + "url": "http://localhost:1337/wp-content/themes/civi/includes/class-init.php#L36" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-14T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p844-gjc4-j9h6/GHSA-p844-gjc4-j9h6.json b/advisories/unreviewed/2025/03/GHSA-p844-gjc4-j9h6/GHSA-p844-gjc4-j9h6.json new file mode 100644 index 00000000000..be10cd295c6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p844-gjc4-j9h6/GHSA-p844-gjc4-j9h6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p844-gjc4-j9h6", + "modified": "2025-03-14T12:32:01Z", + "published": "2025-03-14T12:32:01Z", + "aliases": [ + "CVE-2024-12810" + ], + "details": "The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 7.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files, generate backups, restore backups, update theme options, and reset theme options to default settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12810" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/jobcareer-job-board-responsive-wordpress-theme/14221636" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/24889552-0db6-44e6-9b12-f31b5e92a42e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-14T12:15:13Z" + } +} \ No newline at end of file