diff --git a/advisories/github-reviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json b/advisories/github-reviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json index 1fe7fca5c7b..9d90cb041bd 100644 --- a/advisories/github-reviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json +++ b/advisories/github-reviewed/2025/03/GHSA-p3fp-8748-vqfq/GHSA-p3fp-8748-vqfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p3fp-8748-vqfq", - "modified": "2025-03-06T22:35:37Z", + "modified": "2025-03-19T21:30:45Z", "published": "2025-03-06T21:31:26Z", "aliases": [ "CVE-2025-26699" @@ -90,6 +90,10 @@ "type": "WEB", "url": "https://groups.google.com/g/django-announce" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00012.html" + }, { "type": "WEB", "url": "https://www.djangoproject.com/weblog/2025/mar/06/security-releases" diff --git a/advisories/unreviewed/2022/01/GHSA-78w8-55r3-m9mq/GHSA-78w8-55r3-m9mq.json b/advisories/unreviewed/2022/01/GHSA-78w8-55r3-m9mq/GHSA-78w8-55r3-m9mq.json index dbde0c33c1e..a8d4d06053a 100644 --- a/advisories/unreviewed/2022/01/GHSA-78w8-55r3-m9mq/GHSA-78w8-55r3-m9mq.json +++ b/advisories/unreviewed/2022/01/GHSA-78w8-55r3-m9mq/GHSA-78w8-55r3-m9mq.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-78w8-55r3-m9mq", - "modified": "2022-01-20T00:02:12Z", + "modified": "2025-03-19T21:30:35Z", "published": "2022-01-14T00:02:08Z", "aliases": [ "CVE-2021-45422" ], "details": "Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process \"count\" parameter via GET. No authentication is required.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-45422" }, + { + "type": "WEB", + "url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2021-45422/RLM%2014.2%20Cross%20Site%20Scripting.txt" + }, { "type": "WEB", "url": "https://seclists.org/fulldisclosure/2022/Jan/31" diff --git a/advisories/unreviewed/2022/05/GHSA-5p56-56jf-wfv2/GHSA-5p56-56jf-wfv2.json b/advisories/unreviewed/2022/05/GHSA-5p56-56jf-wfv2/GHSA-5p56-56jf-wfv2.json index 13afd03da38..86ac3bfa090 100644 --- a/advisories/unreviewed/2022/05/GHSA-5p56-56jf-wfv2/GHSA-5p56-56jf-wfv2.json +++ b/advisories/unreviewed/2022/05/GHSA-5p56-56jf-wfv2/GHSA-5p56-56jf-wfv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5p56-56jf-wfv2", - "modified": "2022-05-13T01:10:43Z", + "modified": "2025-03-19T21:30:35Z", "published": "2022-05-13T01:10:43Z", "aliases": [ "CVE-2017-12637" diff --git a/advisories/unreviewed/2022/05/GHSA-8775-h79w-g4rq/GHSA-8775-h79w-g4rq.json b/advisories/unreviewed/2022/05/GHSA-8775-h79w-g4rq/GHSA-8775-h79w-g4rq.json index 2dcf628bece..4e8f6fd162f 100644 --- a/advisories/unreviewed/2022/05/GHSA-8775-h79w-g4rq/GHSA-8775-h79w-g4rq.json +++ b/advisories/unreviewed/2022/05/GHSA-8775-h79w-g4rq/GHSA-8775-h79w-g4rq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8775-h79w-g4rq", - "modified": "2024-04-04T01:15:07Z", + "modified": "2025-03-19T21:30:35Z", "published": "2022-05-24T16:50:08Z", "aliases": [ "CVE-2019-13029" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13029" }, + { + "type": "WEB", + "url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2019-13029/REDCap%20Cross%20Site%20Scripting.txt" + }, { "type": "WEB", "url": "https://gitlab.com/snippets/1874216" diff --git a/advisories/unreviewed/2022/05/GHSA-h2cr-7p52-q7p6/GHSA-h2cr-7p52-q7p6.json b/advisories/unreviewed/2022/05/GHSA-h2cr-7p52-q7p6/GHSA-h2cr-7p52-q7p6.json index a7cbbe2a1f4..b6a65ae87c3 100644 --- a/advisories/unreviewed/2022/05/GHSA-h2cr-7p52-q7p6/GHSA-h2cr-7p52-q7p6.json +++ b/advisories/unreviewed/2022/05/GHSA-h2cr-7p52-q7p6/GHSA-h2cr-7p52-q7p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2cr-7p52-q7p6", - "modified": "2022-05-14T03:41:03Z", + "modified": "2025-03-19T21:30:34Z", "published": "2022-05-14T03:41:03Z", "aliases": [ "CVE-2018-6867" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://exploit-db.com/exploits/44171" + }, + { + "type": "WEB", + "url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2018-6867/Alibaba%20Clone%20Script%201.0.2%20Cross%20Site%20Scripting.txt" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-w832-4843-q4m8/GHSA-w832-4843-q4m8.json b/advisories/unreviewed/2022/05/GHSA-w832-4843-q4m8/GHSA-w832-4843-q4m8.json index 21528f56182..d4fc091eac2 100644 --- a/advisories/unreviewed/2022/05/GHSA-w832-4843-q4m8/GHSA-w832-4843-q4m8.json +++ b/advisories/unreviewed/2022/05/GHSA-w832-4843-q4m8/GHSA-w832-4843-q4m8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w832-4843-q4m8", - "modified": "2022-05-13T01:09:56Z", + "modified": "2025-03-19T21:30:35Z", "published": "2022-05-13T01:09:56Z", "aliases": [ "CVE-2019-1000018" @@ -23,10 +23,26 @@ "type": "WEB", "url": "https://esnet-security.github.io/vulnerabilities/20190115_rssh" }, + { + "type": "WEB", + "url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2021-33216%2CCVE-2019-1000018/CommScope%20Ruckus%20IoT%20Controller%201.7.1.0%20Undocumented%20Account.txt" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2019/01/msg00027.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HO3MDU3AH5SLYBKHH5PJ6PHC63ASIF42" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KR2OHTHMJVV4DO3HDRFQQZ5JENHDJQEN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T42YYNWJZG422GATWAHAEK4A24OKY557" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HO3MDU3AH5SLYBKHH5PJ6PHC63ASIF42" diff --git a/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json b/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json index 2df0843b53e..8dab316e4ed 100644 --- a/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json +++ b/advisories/unreviewed/2023/02/GHSA-7x63-c2xp-r5c2/GHSA-7x63-c2xp-r5c2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-p5ph-q447-9jqq/GHSA-p5ph-q447-9jqq.json b/advisories/unreviewed/2023/06/GHSA-p5ph-q447-9jqq/GHSA-p5ph-q447-9jqq.json index d7c6fe74646..e3deb67a1c6 100644 --- a/advisories/unreviewed/2023/06/GHSA-p5ph-q447-9jqq/GHSA-p5ph-q447-9jqq.json +++ b/advisories/unreviewed/2023/06/GHSA-p5ph-q447-9jqq/GHSA-p5ph-q447-9jqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p5ph-q447-9jqq", - "modified": "2024-04-04T04:49:16Z", + "modified": "2025-03-19T21:30:37Z", "published": "2023-06-14T00:30:41Z", "aliases": [ "CVE-2023-33140" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33140" }, + { + "type": "WEB", + "url": "https://github.com/WlX-33/PoC-for-CVE/blob/main/CVE-2023-33140/Microsoft%20OneNote%20(Version%202305%20Build%2016.0.16501.20074)%2064-bit%20-%20Spoofing%20Vulnerability.txt" + }, { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33140" diff --git a/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json b/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json index 9ba40533679..7207dd64f62 100644 --- a/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json +++ b/advisories/unreviewed/2023/07/GHSA-gjmv-6p6x-5mrf/GHSA-gjmv-6p6x-5mrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjmv-6p6x-5mrf", - "modified": "2024-04-04T05:33:40Z", + "modified": "2025-03-19T21:30:37Z", "published": "2023-07-06T19:24:10Z", "aliases": [ "CVE-2022-27677" diff --git a/advisories/unreviewed/2024/02/GHSA-ffc2-v2cp-6fq5/GHSA-ffc2-v2cp-6fq5.json b/advisories/unreviewed/2024/02/GHSA-ffc2-v2cp-6fq5/GHSA-ffc2-v2cp-6fq5.json index bd49e0e3416..4d12baaca9b 100644 --- a/advisories/unreviewed/2024/02/GHSA-ffc2-v2cp-6fq5/GHSA-ffc2-v2cp-6fq5.json +++ b/advisories/unreviewed/2024/02/GHSA-ffc2-v2cp-6fq5/GHSA-ffc2-v2cp-6fq5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6cr3-7r4p-pwrg/GHSA-6cr3-7r4p-pwrg.json b/advisories/unreviewed/2024/03/GHSA-6cr3-7r4p-pwrg/GHSA-6cr3-7r4p-pwrg.json index 9692c56cb0a..0e6e4659243 100644 --- a/advisories/unreviewed/2024/03/GHSA-6cr3-7r4p-pwrg/GHSA-6cr3-7r4p-pwrg.json +++ b/advisories/unreviewed/2024/03/GHSA-6cr3-7r4p-pwrg/GHSA-6cr3-7r4p-pwrg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6cr3-7r4p-pwrg", - "modified": "2024-03-26T21:30:47Z", + "modified": "2025-03-19T21:30:38Z", "published": "2024-03-26T21:30:47Z", "aliases": [ "CVE-2023-47873" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-95cq-m3g2-g9qh/GHSA-95cq-m3g2-g9qh.json b/advisories/unreviewed/2024/03/GHSA-95cq-m3g2-g9qh/GHSA-95cq-m3g2-g9qh.json index d1e3bea08e6..1d5609993ad 100644 --- a/advisories/unreviewed/2024/03/GHSA-95cq-m3g2-g9qh/GHSA-95cq-m3g2-g9qh.json +++ b/advisories/unreviewed/2024/03/GHSA-95cq-m3g2-g9qh/GHSA-95cq-m3g2-g9qh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-95cq-m3g2-g9qh", - "modified": "2024-03-27T06:30:33Z", + "modified": "2025-03-19T21:30:38Z", "published": "2024-03-27T06:30:32Z", "aliases": [ "CVE-2024-25920" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-h882-2wqp-8p7h/GHSA-h882-2wqp-8p7h.json b/advisories/unreviewed/2024/03/GHSA-h882-2wqp-8p7h/GHSA-h882-2wqp-8p7h.json index 76639dfdd0c..edc192ff05e 100644 --- a/advisories/unreviewed/2024/03/GHSA-h882-2wqp-8p7h/GHSA-h882-2wqp-8p7h.json +++ b/advisories/unreviewed/2024/03/GHSA-h882-2wqp-8p7h/GHSA-h882-2wqp-8p7h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h882-2wqp-8p7h", - "modified": "2024-03-27T09:30:40Z", + "modified": "2025-03-19T21:30:39Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-29915" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-hcq9-8j5c-v9xw/GHSA-hcq9-8j5c-v9xw.json b/advisories/unreviewed/2024/03/GHSA-hcq9-8j5c-v9xw/GHSA-hcq9-8j5c-v9xw.json index fb7619ff653..03eddd28dfc 100644 --- a/advisories/unreviewed/2024/03/GHSA-hcq9-8j5c-v9xw/GHSA-hcq9-8j5c-v9xw.json +++ b/advisories/unreviewed/2024/03/GHSA-hcq9-8j5c-v9xw/GHSA-hcq9-8j5c-v9xw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hcq9-8j5c-v9xw", - "modified": "2024-03-26T21:30:47Z", + "modified": "2025-03-19T21:30:38Z", "published": "2024-03-26T21:30:47Z", "aliases": [ "CVE-2023-47846" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-phgj-f9rj-3h57/GHSA-phgj-f9rj-3h57.json b/advisories/unreviewed/2024/03/GHSA-phgj-f9rj-3h57/GHSA-phgj-f9rj-3h57.json index a36770d8884..f65131ba63a 100644 --- a/advisories/unreviewed/2024/03/GHSA-phgj-f9rj-3h57/GHSA-phgj-f9rj-3h57.json +++ b/advisories/unreviewed/2024/03/GHSA-phgj-f9rj-3h57/GHSA-phgj-f9rj-3h57.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-phgj-f9rj-3h57", - "modified": "2024-03-26T06:30:53Z", + "modified": "2025-03-19T21:30:38Z", "published": "2024-03-26T06:30:53Z", "aliases": [ "CVE-2024-2888" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.26.2.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.26.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json b/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json index 0dd606eb100..16f8d23dbc0 100644 --- a/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json +++ b/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qrhf-rx22-ww4h", - "modified": "2024-03-29T18:30:43Z", + "modified": "2025-03-19T21:30:39Z", "published": "2024-03-29T18:30:43Z", "aliases": [ "CVE-2024-30454" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json b/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json index cc1843ca66b..f4cf4f42c13 100644 --- a/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json +++ b/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wvw8-hcw4-jwqp", - "modified": "2024-03-25T06:30:24Z", + "modified": "2025-03-19T21:30:38Z", "published": "2024-03-25T06:30:24Z", "aliases": [ "CVE-2024-1231" ], "details": "The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T05:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json b/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json index 80622a996cf..765eecbeea4 100644 --- a/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json +++ b/advisories/unreviewed/2024/04/GHSA-46wg-cm84-p5p3/GHSA-46wg-cm84-p5p3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-32q4-6g3f-wq36/GHSA-32q4-6g3f-wq36.json b/advisories/unreviewed/2024/05/GHSA-32q4-6g3f-wq36/GHSA-32q4-6g3f-wq36.json index 8c8fbd23aef..412b9de09af 100644 --- a/advisories/unreviewed/2024/05/GHSA-32q4-6g3f-wq36/GHSA-32q4-6g3f-wq36.json +++ b/advisories/unreviewed/2024/05/GHSA-32q4-6g3f-wq36/GHSA-32q4-6g3f-wq36.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-32q4-6g3f-wq36", - "modified": "2024-05-14T18:30:51Z", + "modified": "2025-03-19T21:30:39Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-34811" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-5g7f-9v94-gj5g/GHSA-5g7f-9v94-gj5g.json b/advisories/unreviewed/2024/05/GHSA-5g7f-9v94-gj5g/GHSA-5g7f-9v94-gj5g.json index 2998da53830..bf468eeaa26 100644 --- a/advisories/unreviewed/2024/05/GHSA-5g7f-9v94-gj5g/GHSA-5g7f-9v94-gj5g.json +++ b/advisories/unreviewed/2024/05/GHSA-5g7f-9v94-gj5g/GHSA-5g7f-9v94-gj5g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5g7f-9v94-gj5g", - "modified": "2024-05-14T18:30:47Z", + "modified": "2025-03-19T21:30:39Z", "published": "2024-05-14T18:30:47Z", "aliases": [ "CVE-2024-32712" ], - "details": "Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.\n\n", + "details": "Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.", "severity": [ { "type": "CVSS_V3", @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/05/GHSA-f72p-cqvh-qg6q/GHSA-f72p-cqvh-qg6q.json b/advisories/unreviewed/2024/05/GHSA-f72p-cqvh-qg6q/GHSA-f72p-cqvh-qg6q.json index 50fa8f22aea..3ad6a0e5e64 100644 --- a/advisories/unreviewed/2024/05/GHSA-f72p-cqvh-qg6q/GHSA-f72p-cqvh-qg6q.json +++ b/advisories/unreviewed/2024/05/GHSA-f72p-cqvh-qg6q/GHSA-f72p-cqvh-qg6q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f72p-cqvh-qg6q", - "modified": "2024-05-03T09:30:51Z", + "modified": "2025-03-19T21:30:39Z", "published": "2024-05-03T09:30:51Z", "aliases": [ "CVE-2024-33928" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS.This issue affects CodeBard's Patron Button and Widgets for Patreon: from n/a through 2.2.0.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS.This issue affects CodeBard's Patron Button and Widgets for Patreon: from n/a through 2.2.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json b/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json index 1b4863ad93f..00ffa6a7919 100644 --- a/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json +++ b/advisories/unreviewed/2024/06/GHSA-fvxr-pgg5-fxr4/GHSA-fvxr-pgg5-fxr4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fvxr-pgg5-fxr4", - "modified": "2024-07-03T18:44:05Z", + "modified": "2025-03-19T21:30:39Z", "published": "2024-06-03T06:30:53Z", "aliases": [ "CVE-2023-51436" ], - "details": "Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product. ", + "details": "Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product.", "severity": [ { "type": "CVSS_V3", @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json index dabeb92ef97..c907b36ed45 100644 --- a/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json +++ b/advisories/unreviewed/2024/06/GHSA-xhxm-p3qv-qprc/GHSA-xhxm-p3qv-qprc.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json b/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json index 8e5be20baf0..35f096b500a 100644 --- a/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json +++ b/advisories/unreviewed/2024/07/GHSA-2f5p-xhq6-2f67/GHSA-2f5p-xhq6-2f67.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-5488-c7c3-vx9f/GHSA-5488-c7c3-vx9f.json b/advisories/unreviewed/2024/07/GHSA-5488-c7c3-vx9f/GHSA-5488-c7c3-vx9f.json index 2c413521007..7b94ac33835 100644 --- a/advisories/unreviewed/2024/07/GHSA-5488-c7c3-vx9f/GHSA-5488-c7c3-vx9f.json +++ b/advisories/unreviewed/2024/07/GHSA-5488-c7c3-vx9f/GHSA-5488-c7c3-vx9f.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json b/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json index afe1480361d..cc04659c3f3 100644 --- a/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json +++ b/advisories/unreviewed/2024/07/GHSA-552v-q4m3-2x72/GHSA-552v-q4m3-2x72.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json b/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json index 1e76c56a51d..7d4de4a3518 100644 --- a/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json +++ b/advisories/unreviewed/2024/07/GHSA-v8wj-qf3f-5p7v/GHSA-v8wj-qf3f-5p7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8wj-qf3f-5p7v", - "modified": "2024-08-22T18:31:19Z", + "modified": "2025-03-19T21:30:40Z", "published": "2024-07-19T09:32:06Z", "aliases": [ "CVE-2024-39457" diff --git a/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json b/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json index 93379ee3166..a11c3a83029 100644 --- a/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json +++ b/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-6xw6-r35g-4w48/GHSA-6xw6-r35g-4w48.json b/advisories/unreviewed/2024/09/GHSA-6xw6-r35g-4w48/GHSA-6xw6-r35g-4w48.json index 01936e4acb1..c645333cc24 100644 --- a/advisories/unreviewed/2024/09/GHSA-6xw6-r35g-4w48/GHSA-6xw6-r35g-4w48.json +++ b/advisories/unreviewed/2024/09/GHSA-6xw6-r35g-4w48/GHSA-6xw6-r35g-4w48.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json b/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json index dd37b3cba01..e85d878021b 100644 --- a/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json +++ b/advisories/unreviewed/2024/09/GHSA-hqp9-2fgf-h6cx/GHSA-hqp9-2fgf-h6cx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json b/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json index 52c40902678..66f441f5d82 100644 --- a/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json +++ b/advisories/unreviewed/2024/10/GHSA-fh9m-mpjc-38hg/GHSA-fh9m-mpjc-38hg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json b/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json index b8eefe544b8..508513a1aea 100644 --- a/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json +++ b/advisories/unreviewed/2024/10/GHSA-fj8g-7f3j-g879/GHSA-fj8g-7f3j-g879.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json index 011170439bb..1c13cd55216 100644 --- a/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json +++ b/advisories/unreviewed/2024/10/GHSA-w2p9-j475-2wp5/GHSA-w2p9-j475-2wp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2p9-j475-2wp5", - "modified": "2024-10-16T21:31:08Z", + "modified": "2025-03-19T21:30:41Z", "published": "2024-10-15T21:30:39Z", "aliases": [ "CVE-2024-9956" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://issues.chromium.org/issues/370482421" + }, + { + "type": "WEB", + "url": "https://mastersplinter.work/research/passkey" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json b/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json index f3024b6a954..8a7cf9579d0 100644 --- a/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json +++ b/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-706", "CWE-98" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json b/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json index b8720829e0d..7db4f948f95 100644 --- a/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json +++ b/advisories/unreviewed/2025/01/GHSA-25qq-8gc4-fhg4/GHSA-25qq-8gc4-fhg4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-770" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-4pmj-qpm8-x7gv/GHSA-4pmj-qpm8-x7gv.json b/advisories/unreviewed/2025/01/GHSA-4pmj-qpm8-x7gv/GHSA-4pmj-qpm8-x7gv.json index 7a478517e4f..9ffe3ef0fc4 100644 --- a/advisories/unreviewed/2025/01/GHSA-4pmj-qpm8-x7gv/GHSA-4pmj-qpm8-x7gv.json +++ b/advisories/unreviewed/2025/01/GHSA-4pmj-qpm8-x7gv/GHSA-4pmj-qpm8-x7gv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json b/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json index 927e8b2f39f..5528945afc1 100644 --- a/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json +++ b/advisories/unreviewed/2025/01/GHSA-5g74-fw23-w3jp/GHSA-5g74-fw23-w3jp.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-7m93-7r9r-p7jm/GHSA-7m93-7r9r-p7jm.json b/advisories/unreviewed/2025/01/GHSA-7m93-7r9r-p7jm/GHSA-7m93-7r9r-p7jm.json index c3ac3e42115..4e6675d09a5 100644 --- a/advisories/unreviewed/2025/01/GHSA-7m93-7r9r-p7jm/GHSA-7m93-7r9r-p7jm.json +++ b/advisories/unreviewed/2025/01/GHSA-7m93-7r9r-p7jm/GHSA-7m93-7r9r-p7jm.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-290" + "CWE-290", + "CWE-451" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-pxjw-qpm2-c9fw/GHSA-pxjw-qpm2-c9fw.json b/advisories/unreviewed/2025/01/GHSA-pxjw-qpm2-c9fw/GHSA-pxjw-qpm2-c9fw.json index 6df040548e3..aff880b3ade 100644 --- a/advisories/unreviewed/2025/01/GHSA-pxjw-qpm2-c9fw/GHSA-pxjw-qpm2-c9fw.json +++ b/advisories/unreviewed/2025/01/GHSA-pxjw-qpm2-c9fw/GHSA-pxjw-qpm2-c9fw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-601" + "CWE-601", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-q7cq-v47g-g2v2/GHSA-q7cq-v47g-g2v2.json b/advisories/unreviewed/2025/01/GHSA-q7cq-v47g-g2v2/GHSA-q7cq-v47g-g2v2.json index 640e083f634..848b31363e3 100644 --- a/advisories/unreviewed/2025/01/GHSA-q7cq-v47g-g2v2/GHSA-q7cq-v47g-g2v2.json +++ b/advisories/unreviewed/2025/01/GHSA-q7cq-v47g-g2v2/GHSA-q7cq-v47g-g2v2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-7c29-93mg-22jf/GHSA-7c29-93mg-22jf.json b/advisories/unreviewed/2025/02/GHSA-7c29-93mg-22jf/GHSA-7c29-93mg-22jf.json index 3d10e67f076..3f91122b84f 100644 --- a/advisories/unreviewed/2025/02/GHSA-7c29-93mg-22jf/GHSA-7c29-93mg-22jf.json +++ b/advisories/unreviewed/2025/02/GHSA-7c29-93mg-22jf/GHSA-7c29-93mg-22jf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7c29-93mg-22jf", - "modified": "2025-02-14T00:30:44Z", + "modified": "2025-03-19T21:30:44Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2024-53310" ], "details": "A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory corruption. This can result in arbitrary code execution or denial of service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json b/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json index f3b8a842fad..fce26b08c3b 100644 --- a/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json +++ b/advisories/unreviewed/2025/02/GHSA-qw4v-473w-8hq5/GHSA-qw4v-473w-8hq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qw4v-473w-8hq5", - "modified": "2025-02-28T00:30:52Z", + "modified": "2025-03-19T21:30:45Z", "published": "2025-02-28T00:30:52Z", "aliases": [ "CVE-2025-25728" ], "details": "Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T00:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json b/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json index d6e8d1a3f0c..daea4741623 100644 --- a/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json +++ b/advisories/unreviewed/2025/02/GHSA-rp3f-whm7-36hq/GHSA-rp3f-whm7-36hq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rp3f-whm7-36hq", - "modified": "2025-02-11T18:31:36Z", + "modified": "2025-03-19T21:30:44Z", "published": "2025-02-11T18:31:36Z", "aliases": [ "CVE-2025-24472" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json b/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json index b6f23d6697a..a3ca9e72078 100644 --- a/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json +++ b/advisories/unreviewed/2025/02/GHSA-rwpx-f8qj-4h9h/GHSA-rwpx-f8qj-4h9h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rwpx-f8qj-4h9h", - "modified": "2025-02-28T00:30:52Z", + "modified": "2025-03-19T21:30:45Z", "published": "2025-02-28T00:30:52Z", "aliases": [ "CVE-2025-25727" ], "details": "Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T00:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json b/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json index 621078918df..a1a3d1df36c 100644 --- a/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json +++ b/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1321" + "CWE-1321", + "CWE-400" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-xjg3-c793-7v2j/GHSA-xjg3-c793-7v2j.json b/advisories/unreviewed/2025/02/GHSA-xjg3-c793-7v2j/GHSA-xjg3-c793-7v2j.json index a3cf5d359cb..6e09f569dbe 100644 --- a/advisories/unreviewed/2025/02/GHSA-xjg3-c793-7v2j/GHSA-xjg3-c793-7v2j.json +++ b/advisories/unreviewed/2025/02/GHSA-xjg3-c793-7v2j/GHSA-xjg3-c793-7v2j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-24wp-3277-85vf/GHSA-24wp-3277-85vf.json b/advisories/unreviewed/2025/03/GHSA-24wp-3277-85vf/GHSA-24wp-3277-85vf.json new file mode 100644 index 00000000000..46dae009ee1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-24wp-3277-85vf/GHSA-24wp-3277-85vf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24wp-3277-85vf", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2024-57061" + ], + "details": "An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57061" + }, + { + "type": "WEB", + "url": "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-proces-abuse/macos-electron-applications-injection" + }, + { + "type": "WEB", + "url": "https://sha999.medium.com/cve-2024-57061-termius-insufficient-electron-fuses-configuration-limited-disclosure-ab00d0970159" + }, + { + "type": "WEB", + "url": "https://www.electron.build/tutorials/adding-electron-fuses.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T19:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2r26-hfxw-87wc/GHSA-2r26-hfxw-87wc.json b/advisories/unreviewed/2025/03/GHSA-2r26-hfxw-87wc/GHSA-2r26-hfxw-87wc.json index 1e92f0edafb..a7ad8ea92fa 100644 --- a/advisories/unreviewed/2025/03/GHSA-2r26-hfxw-87wc/GHSA-2r26-hfxw-87wc.json +++ b/advisories/unreviewed/2025/03/GHSA-2r26-hfxw-87wc/GHSA-2r26-hfxw-87wc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r26-hfxw-87wc", - "modified": "2025-03-14T03:31:24Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-14T03:31:24Z", "aliases": [ "CVE-2025-26163" ], "details": "CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T03:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-345v-2g26-546w/GHSA-345v-2g26-546w.json b/advisories/unreviewed/2025/03/GHSA-345v-2g26-546w/GHSA-345v-2g26-546w.json index 39cc72e4216..6b4e8631582 100644 --- a/advisories/unreviewed/2025/03/GHSA-345v-2g26-546w/GHSA-345v-2g26-546w.json +++ b/advisories/unreviewed/2025/03/GHSA-345v-2g26-546w/GHSA-345v-2g26-546w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-345v-2g26-546w", - "modified": "2025-03-13T21:31:19Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-13T21:31:19Z", "aliases": [ "CVE-2024-55060" ], "details": "A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T21:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json b/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json index 62cc8313f0f..f01fdac37f5 100644 --- a/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json +++ b/advisories/unreviewed/2025/03/GHSA-368g-gpf5-m486/GHSA-368g-gpf5-m486.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-368g-gpf5-m486", - "modified": "2025-03-19T18:30:51Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-19T18:30:51Z", "aliases": [ "CVE-2025-29137" ], "details": "Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-19T16:15:31Z" diff --git a/advisories/unreviewed/2025/03/GHSA-3fr8-v66h-2g57/GHSA-3fr8-v66h-2g57.json b/advisories/unreviewed/2025/03/GHSA-3fr8-v66h-2g57/GHSA-3fr8-v66h-2g57.json new file mode 100644 index 00000000000..70eb81f7c08 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3fr8-v66h-2g57/GHSA-3fr8-v66h-2g57.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fr8-v66h-2g57", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2024-55009" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55009" + }, + { + "type": "WEB", + "url": "https://medium.com/@r3dd1t/poc-cve-0b3ad0535631" + }, + { + "type": "WEB", + "url": "https://youtu.be/1mSgChs-a8Q" + }, + { + "type": "WEB", + "url": "https://youtu.be/SHk3mdsd2mI" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T21:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json b/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json index ac8f0b6adc4..397bd36f16f 100644 --- a/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json +++ b/advisories/unreviewed/2025/03/GHSA-3jqw-73hh-rjm4/GHSA-3jqw-73hh-rjm4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3jqw-73hh-rjm4", - "modified": "2025-03-17T21:30:34Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-17T21:30:34Z", "aliases": [ "CVE-2025-29425" ], "details": "Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T19:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-422v-qjrr-7jh4/GHSA-422v-qjrr-7jh4.json b/advisories/unreviewed/2025/03/GHSA-422v-qjrr-7jh4/GHSA-422v-qjrr-7jh4.json new file mode 100644 index 00000000000..afcab3fcb49 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-422v-qjrr-7jh4/GHSA-422v-qjrr-7jh4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-422v-qjrr-7jh4", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2025-2476" + ], + "details": "Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2476" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_19.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/401029609" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cfm-6q3x-wgvm/GHSA-4cfm-6q3x-wgvm.json b/advisories/unreviewed/2025/03/GHSA-4cfm-6q3x-wgvm/GHSA-4cfm-6q3x-wgvm.json index ed404e20d7f..74db19d72ea 100644 --- a/advisories/unreviewed/2025/03/GHSA-4cfm-6q3x-wgvm/GHSA-4cfm-6q3x-wgvm.json +++ b/advisories/unreviewed/2025/03/GHSA-4cfm-6q3x-wgvm/GHSA-4cfm-6q3x-wgvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4cfm-6q3x-wgvm", - "modified": "2025-03-13T15:32:58Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:58Z", "aliases": [ "CVE-2024-28803" ], "details": "Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:24Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5fhm-w463-rhq6/GHSA-5fhm-w463-rhq6.json b/advisories/unreviewed/2025/03/GHSA-5fhm-w463-rhq6/GHSA-5fhm-w463-rhq6.json index 25700256236..e3cb946fdee 100644 --- a/advisories/unreviewed/2025/03/GHSA-5fhm-w463-rhq6/GHSA-5fhm-w463-rhq6.json +++ b/advisories/unreviewed/2025/03/GHSA-5fhm-w463-rhq6/GHSA-5fhm-w463-rhq6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5fhm-w463-rhq6", - "modified": "2025-03-13T18:32:23Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-13T18:32:23Z", "aliases": [ "CVE-2025-28011" ], "details": "A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T17:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5rjg-pf4q-hgcr/GHSA-5rjg-pf4q-hgcr.json b/advisories/unreviewed/2025/03/GHSA-5rjg-pf4q-hgcr/GHSA-5rjg-pf4q-hgcr.json new file mode 100644 index 00000000000..d8eb921c1ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5rjg-pf4q-hgcr/GHSA-5rjg-pf4q-hgcr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rjg-pf4q-hgcr", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2025-30258" + ], + "details": "In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30258" + }, + { + "type": "WEB", + "url": "https://dev.gnupg.org/T7527" + }, + { + "type": "WEB", + "url": "https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158" + }, + { + "type": "WEB", + "url": "https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5xcr-jr93-3x2g/GHSA-5xcr-jr93-3x2g.json b/advisories/unreviewed/2025/03/GHSA-5xcr-jr93-3x2g/GHSA-5xcr-jr93-3x2g.json index ddd9c62f5da..a360c2b53e4 100644 --- a/advisories/unreviewed/2025/03/GHSA-5xcr-jr93-3x2g/GHSA-5xcr-jr93-3x2g.json +++ b/advisories/unreviewed/2025/03/GHSA-5xcr-jr93-3x2g/GHSA-5xcr-jr93-3x2g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5xcr-jr93-3x2g", - "modified": "2025-03-14T15:32:03Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-14T15:32:03Z", "aliases": [ "CVE-2025-29032" ], "details": "Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T14:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-62xc-8hfg-r382/GHSA-62xc-8hfg-r382.json b/advisories/unreviewed/2025/03/GHSA-62xc-8hfg-r382/GHSA-62xc-8hfg-r382.json index 65cf6bf0a36..c484dffa7f6 100644 --- a/advisories/unreviewed/2025/03/GHSA-62xc-8hfg-r382/GHSA-62xc-8hfg-r382.json +++ b/advisories/unreviewed/2025/03/GHSA-62xc-8hfg-r382/GHSA-62xc-8hfg-r382.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62xc-8hfg-r382", - "modified": "2025-03-13T15:32:59Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:59Z", "aliases": [ "CVE-2025-29360" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-69x5-hjg4-m267/GHSA-69x5-hjg4-m267.json b/advisories/unreviewed/2025/03/GHSA-69x5-hjg4-m267/GHSA-69x5-hjg4-m267.json new file mode 100644 index 00000000000..2935acdc42a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69x5-hjg4-m267/GHSA-69x5-hjg4-m267.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69x5-hjg4-m267", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2024-7631" + ], + "details": "A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can manipulate the path to retrieve any JSON files on the console's pod by using sequences of ../ and valid directory paths.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7631" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-7631" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2296053" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T19:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json b/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json index e8b73c88acf..7df6d85e8d6 100644 --- a/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json +++ b/advisories/unreviewed/2025/03/GHSA-6hc9-74fh-6p7m/GHSA-6hc9-74fh-6p7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hc9-74fh-6p7m", - "modified": "2025-03-18T15:30:49Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-18T15:30:49Z", "aliases": [ "CVE-2025-25590" ], "details": "yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6rjg-2hv4-xq68/GHSA-6rjg-2hv4-xq68.json b/advisories/unreviewed/2025/03/GHSA-6rjg-2hv4-xq68/GHSA-6rjg-2hv4-xq68.json index 4dedbfa771b..08a3f7509a2 100644 --- a/advisories/unreviewed/2025/03/GHSA-6rjg-2hv4-xq68/GHSA-6rjg-2hv4-xq68.json +++ b/advisories/unreviewed/2025/03/GHSA-6rjg-2hv4-xq68/GHSA-6rjg-2hv4-xq68.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6rjg-2hv4-xq68", - "modified": "2025-03-13T15:33:00Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:33:00Z", "aliases": [ "CVE-2024-55198" ], "details": "User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T15:15:49Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6wvj-vm69-9pqc/GHSA-6wvj-vm69-9pqc.json b/advisories/unreviewed/2025/03/GHSA-6wvj-vm69-9pqc/GHSA-6wvj-vm69-9pqc.json new file mode 100644 index 00000000000..fef6d0f6d1f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6wvj-vm69-9pqc/GHSA-6wvj-vm69-9pqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wvj-vm69-9pqc", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2025-27704" + ], + "details": "There is a cross-site scripting vulnerability in the Secure\nAccess administrative console of Absolute Secure Access prior to version 13.53.\nAttackers with system administrator permissions can interfere with another\nsystem administrator’s use of the management console when the second\nadministrator logs in. Attack complexity is high, attack requirements are\npresent, privileges required are none, user interaction is required. The impact\nto confidentiality is low, the impact to availability is none, and the impact\nto system integrity is none.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27704" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T19:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json b/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json index b12dd5a9954..8bb11c1c1e9 100644 --- a/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json +++ b/advisories/unreviewed/2025/03/GHSA-763f-93r5-54qv/GHSA-763f-93r5-54qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-763f-93r5-54qv", - "modified": "2025-03-12T18:32:53Z", + "modified": "2025-03-19T21:30:45Z", "published": "2025-03-12T18:32:53Z", "aliases": [ "CVE-2025-25567" ], "details": "SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T16:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json b/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json index f7b98f6db28..d8a88d95e22 100644 --- a/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json +++ b/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78pj-pg5h-qf98", - "modified": "2025-03-17T15:31:50Z", + "modified": "2025-03-19T21:30:48Z", "published": "2025-03-17T15:31:50Z", "aliases": [ "CVE-2025-25650" ], "details": "An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T15:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-7vrv-rgqg-9p2j/GHSA-7vrv-rgqg-9p2j.json b/advisories/unreviewed/2025/03/GHSA-7vrv-rgqg-9p2j/GHSA-7vrv-rgqg-9p2j.json index 0e2c327d1a6..8087ba8c6e1 100644 --- a/advisories/unreviewed/2025/03/GHSA-7vrv-rgqg-9p2j/GHSA-7vrv-rgqg-9p2j.json +++ b/advisories/unreviewed/2025/03/GHSA-7vrv-rgqg-9p2j/GHSA-7vrv-rgqg-9p2j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7vrv-rgqg-9p2j", - "modified": "2025-03-13T18:32:23Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-13T18:32:23Z", "aliases": [ "CVE-2025-25363" ], "details": "An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload into the HTML field of a template.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T18:15:50Z" diff --git a/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json b/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json index 32d31ee9c7d..bad5ea0b699 100644 --- a/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json +++ b/advisories/unreviewed/2025/03/GHSA-82xf-2h8m-pmc5/GHSA-82xf-2h8m-pmc5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-82xf-2h8m-pmc5", - "modified": "2025-03-18T15:30:49Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-18T15:30:49Z", "aliases": [ "CVE-2025-25585" ], "details": "Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-8jj7-95mm-h6g2/GHSA-8jj7-95mm-h6g2.json b/advisories/unreviewed/2025/03/GHSA-8jj7-95mm-h6g2/GHSA-8jj7-95mm-h6g2.json new file mode 100644 index 00000000000..276ab2646a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8jj7-95mm-h6g2/GHSA-8jj7-95mm-h6g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jj7-95mm-h6g2", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2025-27705" + ], + "details": "There is a cross-site scripting vulnerability in the Secure\nAccess administrative console of Absolute Secure Access prior to version 13.53.\nAttackers with system administrator permissions can interfere with another\nsystem administrator’s use of the management console when the second\nadministrator logs in. Attack complexity is high, attack requirements are\npresent, privileges required are none, user interaction is required. The impact\nto confidentiality is low, the impact to availability is none, and the impact\nto system integrity is none.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27705" + }, + { + "type": "WEB", + "url": "https://www.absolute.com/platform/security-information/vulnerability-archive/secure-access-1353" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json b/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json index 524bfe99202..d0057216f30 100644 --- a/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json +++ b/advisories/unreviewed/2025/03/GHSA-8vw4-jqcw-6334/GHSA-8vw4-jqcw-6334.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vw4-jqcw-6334", - "modified": "2025-03-19T18:30:52Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-19T18:30:52Z", "aliases": [ "CVE-2025-29118" ], "details": "Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-19T17:15:41Z" diff --git a/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json b/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json index 5b4924287cc..ba291aa8352 100644 --- a/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json +++ b/advisories/unreviewed/2025/03/GHSA-966q-fgpf-cj7x/GHSA-966q-fgpf-cj7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-966q-fgpf-cj7x", - "modified": "2025-03-18T15:30:48Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-18T15:30:48Z", "aliases": [ "CVE-2025-25580" ], "details": "yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T15:16:00Z" diff --git a/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json b/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json new file mode 100644 index 00000000000..7074dcf10dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ch85-v3jm-42jh/GHSA-ch85-v3jm-42jh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch85-v3jm-42jh", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2025-26816" + ], + "details": "A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26816" + }, + { + "type": "WEB", + "url": "https://security.intrexx.com/en/security-advisories/ixsa-20250310-01" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T21:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json b/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json index 98df0f8fbea..5c1e2462c82 100644 --- a/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json +++ b/advisories/unreviewed/2025/03/GHSA-cqjc-pfg6-24mx/GHSA-cqjc-pfg6-24mx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqjc-pfg6-24mx", - "modified": "2025-03-18T21:32:01Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-18T21:32:01Z", "aliases": [ "CVE-2024-57151" ], "details": "SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T21:15:31Z" diff --git a/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json b/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json index 436f2ee175c..6ca574e2878 100644 --- a/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json +++ b/advisories/unreviewed/2025/03/GHSA-cr97-553h-m39w/GHSA-cr97-553h-m39w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cr97-553h-m39w", - "modified": "2025-03-12T18:32:53Z", + "modified": "2025-03-19T21:30:45Z", "published": "2025-03-12T18:32:53Z", "aliases": [ "CVE-2025-25568" ], "details": "SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T16:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f5cq-p3m3-57vm/GHSA-f5cq-p3m3-57vm.json b/advisories/unreviewed/2025/03/GHSA-f5cq-p3m3-57vm/GHSA-f5cq-p3m3-57vm.json index 95258635d4d..df959a0498c 100644 --- a/advisories/unreviewed/2025/03/GHSA-f5cq-p3m3-57vm/GHSA-f5cq-p3m3-57vm.json +++ b/advisories/unreviewed/2025/03/GHSA-f5cq-p3m3-57vm/GHSA-f5cq-p3m3-57vm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f5cq-p3m3-57vm", - "modified": "2025-03-13T15:32:59Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:59Z", "aliases": [ "CVE-2025-29361" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/SetVirtualServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-f7g9-932q-g34j/GHSA-f7g9-932q-g34j.json b/advisories/unreviewed/2025/03/GHSA-f7g9-932q-g34j/GHSA-f7g9-932q-g34j.json index 57c9fbde71f..03e0af65cca 100644 --- a/advisories/unreviewed/2025/03/GHSA-f7g9-932q-g34j/GHSA-f7g9-932q-g34j.json +++ b/advisories/unreviewed/2025/03/GHSA-f7g9-932q-g34j/GHSA-f7g9-932q-g34j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f7g9-932q-g34j", - "modified": "2025-03-13T15:32:58Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:58Z", "aliases": [ "CVE-2025-29358" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the firewallEn parameter at /goform/SetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-ghpv-8q38-9qmg/GHSA-ghpv-8q38-9qmg.json b/advisories/unreviewed/2025/03/GHSA-ghpv-8q38-9qmg/GHSA-ghpv-8q38-9qmg.json index ffab6551cdc..12d0934277c 100644 --- a/advisories/unreviewed/2025/03/GHSA-ghpv-8q38-9qmg/GHSA-ghpv-8q38-9qmg.json +++ b/advisories/unreviewed/2025/03/GHSA-ghpv-8q38-9qmg/GHSA-ghpv-8q38-9qmg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ghpv-8q38-9qmg", - "modified": "2025-03-13T15:32:59Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:59Z", "aliases": [ "CVE-2025-29362" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-gxrx-rhrv-qqv3/GHSA-gxrx-rhrv-qqv3.json b/advisories/unreviewed/2025/03/GHSA-gxrx-rhrv-qqv3/GHSA-gxrx-rhrv-qqv3.json index bb06a0facc8..55e23304666 100644 --- a/advisories/unreviewed/2025/03/GHSA-gxrx-rhrv-qqv3/GHSA-gxrx-rhrv-qqv3.json +++ b/advisories/unreviewed/2025/03/GHSA-gxrx-rhrv-qqv3/GHSA-gxrx-rhrv-qqv3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxrx-rhrv-qqv3", - "modified": "2025-03-14T18:30:50Z", + "modified": "2025-03-19T21:30:48Z", "published": "2025-03-14T18:30:50Z", "aliases": [ "CVE-2025-25872" ], "details": "An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T16:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h26c-c6vw-jjjm/GHSA-h26c-c6vw-jjjm.json b/advisories/unreviewed/2025/03/GHSA-h26c-c6vw-jjjm/GHSA-h26c-c6vw-jjjm.json index c1a826154b9..972fa1758e7 100644 --- a/advisories/unreviewed/2025/03/GHSA-h26c-c6vw-jjjm/GHSA-h26c-c6vw-jjjm.json +++ b/advisories/unreviewed/2025/03/GHSA-h26c-c6vw-jjjm/GHSA-h26c-c6vw-jjjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h26c-c6vw-jjjm", - "modified": "2025-03-18T18:30:49Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-18T18:30:49Z", "aliases": [ "CVE-2025-25586" ], "details": "yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T16:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h2p2-xwjr-gfhq/GHSA-h2p2-xwjr-gfhq.json b/advisories/unreviewed/2025/03/GHSA-h2p2-xwjr-gfhq/GHSA-h2p2-xwjr-gfhq.json index a012822a4c0..6675d9aab0b 100644 --- a/advisories/unreviewed/2025/03/GHSA-h2p2-xwjr-gfhq/GHSA-h2p2-xwjr-gfhq.json +++ b/advisories/unreviewed/2025/03/GHSA-h2p2-xwjr-gfhq/GHSA-h2p2-xwjr-gfhq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h2p2-xwjr-gfhq", - "modified": "2025-03-14T18:30:51Z", + "modified": "2025-03-19T21:30:48Z", "published": "2025-03-14T18:30:50Z", "aliases": [ "CVE-2025-25873" ], "details": "Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T16:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-h83j-jr29-xw3m/GHSA-h83j-jr29-xw3m.json b/advisories/unreviewed/2025/03/GHSA-h83j-jr29-xw3m/GHSA-h83j-jr29-xw3m.json new file mode 100644 index 00000000000..28bfba5bec9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h83j-jr29-xw3m/GHSA-h83j-jr29-xw3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h83j-jr29-xw3m", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2024-51459" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51459" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7185056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T19:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hrc4-p2h3-pjqw/GHSA-hrc4-p2h3-pjqw.json b/advisories/unreviewed/2025/03/GHSA-hrc4-p2h3-pjqw/GHSA-hrc4-p2h3-pjqw.json new file mode 100644 index 00000000000..9525418e398 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hrc4-p2h3-pjqw/GHSA-hrc4-p2h3-pjqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrc4-p2h3-pjqw", + "modified": "2025-03-19T21:30:52Z", + "published": "2025-03-19T21:30:52Z", + "aliases": [ + "CVE-2025-2536" + ], + "details": "Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's layout-taglib/__liferay__/index.js allows remote attackers to inject arbitrary web script or HTML via toastData parameter", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2536" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-2536" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j238-4ph7-9jqw/GHSA-j238-4ph7-9jqw.json b/advisories/unreviewed/2025/03/GHSA-j238-4ph7-9jqw/GHSA-j238-4ph7-9jqw.json index 77bdced83ec..db6cffb39cb 100644 --- a/advisories/unreviewed/2025/03/GHSA-j238-4ph7-9jqw/GHSA-j238-4ph7-9jqw.json +++ b/advisories/unreviewed/2025/03/GHSA-j238-4ph7-9jqw/GHSA-j238-4ph7-9jqw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j238-4ph7-9jqw", - "modified": "2025-03-14T03:31:24Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-14T03:31:24Z", "aliases": [ "CVE-2025-30022" ], "details": "CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T03:15:45Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j34m-h4fc-h7vh/GHSA-j34m-h4fc-h7vh.json b/advisories/unreviewed/2025/03/GHSA-j34m-h4fc-h7vh/GHSA-j34m-h4fc-h7vh.json index 92c0edda37c..a3a52c9c217 100644 --- a/advisories/unreviewed/2025/03/GHSA-j34m-h4fc-h7vh/GHSA-j34m-h4fc-h7vh.json +++ b/advisories/unreviewed/2025/03/GHSA-j34m-h4fc-h7vh/GHSA-j34m-h4fc-h7vh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j34m-h4fc-h7vh", - "modified": "2025-03-13T18:32:21Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T18:32:21Z", "aliases": [ "CVE-2025-28015" ], "details": "A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary HTML code via the fname, lname, and contact parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T16:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-j6qw-mm8g-6fjw/GHSA-j6qw-mm8g-6fjw.json b/advisories/unreviewed/2025/03/GHSA-j6qw-mm8g-6fjw/GHSA-j6qw-mm8g-6fjw.json new file mode 100644 index 00000000000..2d5c2091428 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j6qw-mm8g-6fjw/GHSA-j6qw-mm8g-6fjw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6qw-mm8g-6fjw", + "modified": "2025-03-19T21:30:53Z", + "published": "2025-03-19T21:30:53Z", + "aliases": [ + "CVE-2025-30092" + ], + "details": "Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30092" + }, + { + "type": "WEB", + "url": "https://security.intrexx.com/en/security-advisories/ixsa-20250310-02" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json b/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json index b0bc6f095b3..c6749424641 100644 --- a/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json +++ b/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4xp-3x5f-vcrx", - "modified": "2025-03-17T18:31:52Z", + "modified": "2025-03-19T21:30:49Z", "published": "2025-03-17T18:31:52Z", "aliases": [ "CVE-2025-29431" ], "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T17:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p9px-9grx-vp7w/GHSA-p9px-9grx-vp7w.json b/advisories/unreviewed/2025/03/GHSA-p9px-9grx-vp7w/GHSA-p9px-9grx-vp7w.json index c8e69fa4668..297dc882037 100644 --- a/advisories/unreviewed/2025/03/GHSA-p9px-9grx-vp7w/GHSA-p9px-9grx-vp7w.json +++ b/advisories/unreviewed/2025/03/GHSA-p9px-9grx-vp7w/GHSA-p9px-9grx-vp7w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p9px-9grx-vp7w", - "modified": "2025-03-13T15:33:00Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:33:00Z", "aliases": [ "CVE-2025-29363" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:37Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pfg4-r8vj-qqm4/GHSA-pfg4-r8vj-qqm4.json b/advisories/unreviewed/2025/03/GHSA-pfg4-r8vj-qqm4/GHSA-pfg4-r8vj-qqm4.json index a349ca415ba..241c30c227e 100644 --- a/advisories/unreviewed/2025/03/GHSA-pfg4-r8vj-qqm4/GHSA-pfg4-r8vj-qqm4.json +++ b/advisories/unreviewed/2025/03/GHSA-pfg4-r8vj-qqm4/GHSA-pfg4-r8vj-qqm4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pfg4-r8vj-qqm4", - "modified": "2025-03-18T18:30:49Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-18T18:30:49Z", "aliases": [ "CVE-2025-25589" ], "details": "An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-91" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T16:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json b/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json index 1a245b78049..3b7a35851c8 100644 --- a/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json +++ b/advisories/unreviewed/2025/03/GHSA-pg35-89w5-5c5h/GHSA-pg35-89w5-5c5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pg35-89w5-5c5h", - "modified": "2025-03-12T18:32:53Z", + "modified": "2025-03-19T21:30:45Z", "published": "2025-03-12T18:32:53Z", "aliases": [ "CVE-2025-25565" ], "details": "SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T16:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json b/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json index 49f3ba78a18..23a577005e8 100644 --- a/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json +++ b/advisories/unreviewed/2025/03/GHSA-pwcr-fjcv-q783/GHSA-pwcr-fjcv-q783.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pwcr-fjcv-q783", - "modified": "2025-03-19T18:30:52Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-19T18:30:52Z", "aliases": [ "CVE-2025-29405" ], "details": "An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-19T18:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json b/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json index 77979a71dc9..d1d6eee58c7 100644 --- a/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json +++ b/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qh4r-rffh-prr5", - "modified": "2025-03-17T18:31:53Z", + "modified": "2025-03-19T21:30:50Z", "published": "2025-03-17T18:31:53Z", "aliases": [ "CVE-2025-29430" ], "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T18:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json b/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json index bd1eb51d618..cd25439f71e 100644 --- a/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json +++ b/advisories/unreviewed/2025/03/GHSA-r398-vw7q-9j92/GHSA-r398-vw7q-9j92.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r398-vw7q-9j92", - "modified": "2025-03-17T21:30:34Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-17T21:30:34Z", "aliases": [ "CVE-2025-29427" ], "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r8qx-v69g-vm92/GHSA-r8qx-v69g-vm92.json b/advisories/unreviewed/2025/03/GHSA-r8qx-v69g-vm92/GHSA-r8qx-v69g-vm92.json index ba35a9bb97c..03d43a1fd00 100644 --- a/advisories/unreviewed/2025/03/GHSA-r8qx-v69g-vm92/GHSA-r8qx-v69g-vm92.json +++ b/advisories/unreviewed/2025/03/GHSA-r8qx-v69g-vm92/GHSA-r8qx-v69g-vm92.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r8qx-v69g-vm92", - "modified": "2025-03-13T15:33:00Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:33:00Z", "aliases": [ "CVE-2025-25625" ], "details": "FS Inc S3150 8T2F Switch s3150-8t2f-switch-fsos-220d_118101 has a stored cross-site scripting (XSS) vulnerability in the web management interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T15:15:53Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r95g-mx5p-6q87/GHSA-r95g-mx5p-6q87.json b/advisories/unreviewed/2025/03/GHSA-r95g-mx5p-6q87/GHSA-r95g-mx5p-6q87.json index 6683bb0b39f..5b0f255f62e 100644 --- a/advisories/unreviewed/2025/03/GHSA-r95g-mx5p-6q87/GHSA-r95g-mx5p-6q87.json +++ b/advisories/unreviewed/2025/03/GHSA-r95g-mx5p-6q87/GHSA-r95g-mx5p-6q87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r95g-mx5p-6q87", - "modified": "2025-03-14T18:30:50Z", + "modified": "2025-03-19T21:30:48Z", "published": "2025-03-14T18:30:50Z", "aliases": [ "CVE-2025-25871" ], "details": "An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T16:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rcc9-57x7-m8wm/GHSA-rcc9-57x7-m8wm.json b/advisories/unreviewed/2025/03/GHSA-rcc9-57x7-m8wm/GHSA-rcc9-57x7-m8wm.json index 3a22180e469..b7d682228ae 100644 --- a/advisories/unreviewed/2025/03/GHSA-rcc9-57x7-m8wm/GHSA-rcc9-57x7-m8wm.json +++ b/advisories/unreviewed/2025/03/GHSA-rcc9-57x7-m8wm/GHSA-rcc9-57x7-m8wm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcc9-57x7-m8wm", - "modified": "2025-03-13T18:32:22Z", + "modified": "2025-03-19T21:30:47Z", "published": "2025-03-13T18:32:22Z", "aliases": [ "CVE-2024-53406" ], "details": "Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T17:15:33Z" diff --git a/advisories/unreviewed/2025/03/GHSA-rgfv-pm9m-qwf8/GHSA-rgfv-pm9m-qwf8.json b/advisories/unreviewed/2025/03/GHSA-rgfv-pm9m-qwf8/GHSA-rgfv-pm9m-qwf8.json index 92abf2a60d6..3ad05f94d10 100644 --- a/advisories/unreviewed/2025/03/GHSA-rgfv-pm9m-qwf8/GHSA-rgfv-pm9m-qwf8.json +++ b/advisories/unreviewed/2025/03/GHSA-rgfv-pm9m-qwf8/GHSA-rgfv-pm9m-qwf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgfv-pm9m-qwf8", - "modified": "2025-03-13T15:32:58Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:58Z", "aliases": [ "CVE-2024-22880" ], "details": "Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary code via a crafted script to the webchat component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json b/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json index 2de8d0efe4d..13f725a68e9 100644 --- a/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json +++ b/advisories/unreviewed/2025/03/GHSA-w4r7-mmm7-q5mj/GHSA-w4r7-mmm7-q5mj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w4r7-mmm7-q5mj", - "modified": "2025-03-17T21:30:35Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-17T21:30:35Z", "aliases": [ "CVE-2025-29426" ], "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T21:15:14Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w7x2-7963-ff8f/GHSA-w7x2-7963-ff8f.json b/advisories/unreviewed/2025/03/GHSA-w7x2-7963-ff8f/GHSA-w7x2-7963-ff8f.json index 22d3cd952b2..67b362dfa8b 100644 --- a/advisories/unreviewed/2025/03/GHSA-w7x2-7963-ff8f/GHSA-w7x2-7963-ff8f.json +++ b/advisories/unreviewed/2025/03/GHSA-w7x2-7963-ff8f/GHSA-w7x2-7963-ff8f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7x2-7963-ff8f", - "modified": "2025-03-13T15:32:58Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T15:32:58Z", "aliases": [ "CVE-2025-29359" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json b/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json index a485ab9b2d6..e82a5fe98bf 100644 --- a/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json +++ b/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w9c3-8j7h-3cq6", - "modified": "2025-03-17T18:31:52Z", + "modified": "2025-03-19T21:30:49Z", "published": "2025-03-17T18:31:52Z", "aliases": [ "CVE-2025-25684" ], "details": "A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the device's file system via a crafted POST request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T17:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json b/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json index 17237eb6dfa..a195a379042 100644 --- a/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json +++ b/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcxv-mc83-gmw5", - "modified": "2025-03-17T18:31:53Z", + "modified": "2025-03-19T21:30:49Z", "published": "2025-03-17T18:31:53Z", "aliases": [ "CVE-2025-26125" ], "details": "An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-782" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T18:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xf38-gpf5-p6f9/GHSA-xf38-gpf5-p6f9.json b/advisories/unreviewed/2025/03/GHSA-xf38-gpf5-p6f9/GHSA-xf38-gpf5-p6f9.json index bc4d6b6a7c3..0f41d4d9384 100644 --- a/advisories/unreviewed/2025/03/GHSA-xf38-gpf5-p6f9/GHSA-xf38-gpf5-p6f9.json +++ b/advisories/unreviewed/2025/03/GHSA-xf38-gpf5-p6f9/GHSA-xf38-gpf5-p6f9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xf38-gpf5-p6f9", - "modified": "2025-03-13T18:32:21Z", + "modified": "2025-03-19T21:30:46Z", "published": "2025-03-13T18:32:21Z", "aliases": [ "CVE-2024-57062" ], "details": "An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T16:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xq3p-5xwv-rm48/GHSA-xq3p-5xwv-rm48.json b/advisories/unreviewed/2025/03/GHSA-xq3p-5xwv-rm48/GHSA-xq3p-5xwv-rm48.json index 616fc30b105..85c4d9735f7 100644 --- a/advisories/unreviewed/2025/03/GHSA-xq3p-5xwv-rm48/GHSA-xq3p-5xwv-rm48.json +++ b/advisories/unreviewed/2025/03/GHSA-xq3p-5xwv-rm48/GHSA-xq3p-5xwv-rm48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xq3p-5xwv-rm48", - "modified": "2025-03-18T18:30:49Z", + "modified": "2025-03-19T21:30:51Z", "published": "2025-03-18T18:30:49Z", "aliases": [ "CVE-2025-25582" ], "details": "yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-18T16:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json b/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json index fcc4deefba1..fd49dabba37 100644 --- a/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json +++ b/advisories/unreviewed/2025/03/GHSA-xw57-qhqx-v67p/GHSA-xw57-qhqx-v67p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xw57-qhqx-v67p", - "modified": "2025-03-17T21:30:34Z", + "modified": "2025-03-19T21:30:50Z", "published": "2025-03-17T21:30:34Z", "aliases": [ "CVE-2024-44866" ], "details": "A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T19:15:22Z" diff --git a/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json b/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json index e12e6c3e852..54ed4846510 100644 --- a/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json +++ b/advisories/unreviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xxrg-mg63-qfpj", - "modified": "2025-03-19T18:30:51Z", + "modified": "2025-03-19T21:30:52Z", "published": "2025-03-19T18:30:51Z", "aliases": [ "CVE-2025-30196" ], "details": "Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-19T16:15:33Z"