From c10a2681eeb1c9430cf244a43ed8c4d7fdfe0922 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Mon, 3 Feb 2025 15:33:12 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-pv36-h7jh-qm62.json | 98 ++++++++++---------
.../GHSA-54w2-m25f-gmqp.json | 9 +-
.../GHSA-9q96-cwq7-cr4m.json | 2 +-
.../GHSA-85q4-vgvj-3q28.json | 2 +-
.../GHSA-h73c-qgg5-q5rp.json | 2 +-
.../GHSA-hp68-7f8q-r2qj.json | 6 +-
.../GHSA-xfv3-jp8h-q7v6.json | 2 +-
.../GHSA-rh53-wvg6-9v8m.json | 2 +-
.../GHSA-4rpf-4vmp-3hfw.json | 15 ++-
.../GHSA-72gm-6qcq-3xmp.json | 15 ++-
.../GHSA-c6q3-xgg3-276c.json | 15 ++-
.../GHSA-f84q-355v-4ww3.json | 15 ++-
.../GHSA-ppcf-3xhc-xrx9.json | 15 ++-
.../GHSA-qcmx-p4h8-4fhq.json | 15 ++-
.../GHSA-pgc5-vrj2-c9w5.json | 15 ++-
.../GHSA-fphh-62qm-fm76.json | 15 ++-
.../GHSA-fxx9-q7vv-g6p2.json | 15 ++-
.../GHSA-rfhq-9xcp-7phj.json | 6 +-
.../GHSA-v2jg-x6cv-qjcg.json | 15 ++-
.../GHSA-8p7h-rvp2-7xrx.json | 15 ++-
.../GHSA-9ppm-qmv9-2f9f.json | 15 ++-
.../GHSA-c86m-78v8-4hvw.json | 15 ++-
.../GHSA-crfq-94qw-vfrw.json | 2 +-
.../GHSA-cvxq-qv5g-cqw6.json | 15 ++-
.../GHSA-fcp2-76rf-pjrc.json | 15 ++-
.../GHSA-h35x-4f36-345v.json | 15 ++-
.../GHSA-m2h6-g9h7-jxfj.json | 15 ++-
.../GHSA-mfcg-4w9q-f9mr.json | 15 ++-
.../GHSA-mp8h-4283-jr44.json | 15 ++-
.../GHSA-qm84-5c9v-92xm.json | 15 ++-
.../GHSA-wmpx-6wwp-cvc6.json | 15 ++-
.../GHSA-xrf5-hv85-5f65.json | 15 ++-
.../GHSA-2767-g28h-69jv.json | 15 ++-
.../GHSA-2w6v-cv9c-qwv2.json | 15 ++-
.../GHSA-5xmq-mwgg-pjp2.json | 15 ++-
.../GHSA-5xr7-3q35-3j73.json | 15 ++-
.../GHSA-88gx-mvc3-9p77.json | 15 ++-
.../GHSA-9hcf-78cf-xwqv.json | 11 ++-
.../GHSA-9x94-vh8x-vrhp.json | 15 ++-
.../GHSA-g29r-ch4v-q6cx.json | 15 ++-
.../GHSA-g6f8-f8f2-6wh5.json | 15 ++-
.../GHSA-hg9v-mfmx-jx2x.json | 15 ++-
.../GHSA-p277-wqpc-75vw.json | 15 ++-
.../GHSA-q8x5-7v94-rwpv.json | 11 ++-
.../GHSA-qq8g-3hpq-mq34.json | 15 ++-
.../GHSA-rhj2-5xgx-23p4.json | 15 ++-
.../GHSA-rwgg-m734-wvjr.json | 15 ++-
.../GHSA-v3w4-79rw-r73c.json | 11 ++-
.../GHSA-v62x-6v8m-46vv.json | 15 ++-
.../GHSA-w46c-ww47-4hf8.json | 15 ++-
.../GHSA-x69f-qgv5-6pgg.json | 15 ++-
.../GHSA-xfvh-9mxf-99vm.json | 15 ++-
.../GHSA-xvfj-8qrf-7mc3.json | 15 ++-
.../GHSA-29c3-5w75-524f.json | 36 +++++++
.../GHSA-2qrh-cw3v-jjq8.json | 36 +++++++
.../GHSA-3f7x-84v6-xqm2.json | 36 +++++++
.../GHSA-4894-q56v-259x.json | 36 +++++++
.../GHSA-4qcm-8vwx-5fcx.json | 36 +++++++
.../GHSA-56cq-6fx2-6w65.json | 36 +++++++
.../GHSA-62mj-f382-xrp2.json | 36 +++++++
.../GHSA-66w3-8239-5462.json | 36 +++++++
.../GHSA-68rh-p39x-55qr.json | 36 +++++++
.../GHSA-6c5r-r7hx-4v27.json | 36 +++++++
.../GHSA-6f82-5qgq-9pf6.json | 36 +++++++
.../GHSA-758x-mffx-rxw8.json | 36 +++++++
.../GHSA-7622-r9xj-6gwh.json | 36 +++++++
.../GHSA-7786-h8f4-86vp.json | 36 +++++++
.../GHSA-7mxv-pwwv-fj25.json | 36 +++++++
.../GHSA-82ch-63xf-6pr3.json | 36 +++++++
.../GHSA-8457-mxpv-x45g.json | 37 +++++++
.../GHSA-8667-mpq3-28qm.json | 36 +++++++
.../GHSA-8cgw-96fc-pr6g.json | 36 +++++++
.../GHSA-8phh-ch6h-hm63.json | 36 +++++++
.../GHSA-9f3p-pqg6-mchm.json | 36 +++++++
.../GHSA-9fxx-wgmh-4c9f.json | 36 +++++++
.../GHSA-9h74-v678-xf3w.json | 36 +++++++
.../GHSA-9hrc-j3gj-6hp9.json | 36 +++++++
.../GHSA-9r2h-5xf6-2vwq.json | 36 +++++++
.../GHSA-c6q5-rrw7-p494.json | 36 +++++++
.../GHSA-c9xr-2j8f-4q5q.json | 36 +++++++
.../GHSA-cfj5-j439-wcw7.json | 36 +++++++
.../GHSA-cqx6-84p5-pwg6.json | 36 +++++++
.../GHSA-f8g4-wp42-47w7.json | 36 +++++++
.../GHSA-fjcm-jgq9-qwjc.json | 36 +++++++
.../GHSA-fqpp-wx48-c63r.json | 36 +++++++
.../GHSA-fv6w-phw6-f2cx.json | 36 +++++++
.../GHSA-fx25-pqmv-qr46.json | 36 +++++++
.../GHSA-fx8w-24qx-p2c5.json | 36 +++++++
.../GHSA-g246-2588-xpcw.json | 36 +++++++
.../GHSA-gwxp-5q7q-w242.json | 29 ++++++
.../GHSA-gxg5-5cmr-3588.json | 36 +++++++
.../GHSA-hv29-c4x3-8863.json | 36 +++++++
.../GHSA-hxh5-3mh2-q6x8.json | 36 +++++++
.../GHSA-j9f5-239f-px34.json | 36 +++++++
.../GHSA-m32x-p663-p4h7.json | 36 +++++++
.../GHSA-mp5r-7qm4-pgc7.json | 36 +++++++
.../GHSA-mrqf-9666-2wqm.json | 36 +++++++
.../GHSA-p22x-7843-884q.json | 36 +++++++
.../GHSA-pchf-fw93-3p2f.json | 36 +++++++
.../GHSA-ppxf-9xvj-v2hm.json | 36 +++++++
.../GHSA-pvg9-854c-47xf.json | 36 +++++++
.../GHSA-q2rj-w884-9q82.json | 36 +++++++
.../GHSA-q3p4-qwqf-7x2q.json | 36 +++++++
.../GHSA-q5gm-6r6x-wwp4.json | 36 +++++++
.../GHSA-q9r4-2743-gqxg.json | 36 +++++++
.../GHSA-qcrm-39j8-mgw2.json | 36 +++++++
.../GHSA-qwgv-9c86-m892.json | 36 +++++++
.../GHSA-qx69-86hp-p6qr.json | 36 +++++++
.../GHSA-rmx2-4jx5-xv9c.json | 36 +++++++
.../GHSA-v24j-7gvf-f7xp.json | 36 +++++++
.../GHSA-v258-v7wv-4g7v.json | 36 +++++++
.../GHSA-v4g5-p637-j32c.json | 36 +++++++
.../GHSA-v57f-fqvf-vc6v.json | 36 +++++++
.../GHSA-v5cc-g4p3-96gv.json | 36 +++++++
.../GHSA-v6rw-775r-c547.json | 36 +++++++
.../GHSA-v9jw-qfrm-3v3x.json | 36 +++++++
.../GHSA-vch5-mvq9-qm23.json | 36 +++++++
.../GHSA-vjxc-9jvg-687w.json | 36 +++++++
.../GHSA-vr4c-cc99-p7vf.json | 36 +++++++
.../GHSA-w4xp-6q8w-6c3g.json | 36 +++++++
.../GHSA-w64r-953q-gv3q.json | 36 +++++++
.../GHSA-whfg-3mpf-fjhx.json | 36 +++++++
.../GHSA-wmhp-g4mm-69rg.json | 36 +++++++
.../GHSA-wp7q-78g7-c67m.json | 36 +++++++
124 files changed, 3086 insertions(+), 228 deletions(-)
create mode 100644 advisories/unreviewed/2025/02/GHSA-29c3-5w75-524f/GHSA-29c3-5w75-524f.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-2qrh-cw3v-jjq8/GHSA-2qrh-cw3v-jjq8.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-3f7x-84v6-xqm2/GHSA-3f7x-84v6-xqm2.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-4894-q56v-259x/GHSA-4894-q56v-259x.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-4qcm-8vwx-5fcx/GHSA-4qcm-8vwx-5fcx.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-56cq-6fx2-6w65/GHSA-56cq-6fx2-6w65.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-62mj-f382-xrp2/GHSA-62mj-f382-xrp2.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-66w3-8239-5462/GHSA-66w3-8239-5462.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-68rh-p39x-55qr/GHSA-68rh-p39x-55qr.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-6c5r-r7hx-4v27/GHSA-6c5r-r7hx-4v27.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-6f82-5qgq-9pf6/GHSA-6f82-5qgq-9pf6.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-758x-mffx-rxw8/GHSA-758x-mffx-rxw8.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-7622-r9xj-6gwh/GHSA-7622-r9xj-6gwh.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-7786-h8f4-86vp/GHSA-7786-h8f4-86vp.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-7mxv-pwwv-fj25/GHSA-7mxv-pwwv-fj25.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-82ch-63xf-6pr3/GHSA-82ch-63xf-6pr3.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-8457-mxpv-x45g/GHSA-8457-mxpv-x45g.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-8667-mpq3-28qm/GHSA-8667-mpq3-28qm.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-8cgw-96fc-pr6g/GHSA-8cgw-96fc-pr6g.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-8phh-ch6h-hm63/GHSA-8phh-ch6h-hm63.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-9f3p-pqg6-mchm/GHSA-9f3p-pqg6-mchm.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-9fxx-wgmh-4c9f/GHSA-9fxx-wgmh-4c9f.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-9h74-v678-xf3w/GHSA-9h74-v678-xf3w.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-9hrc-j3gj-6hp9/GHSA-9hrc-j3gj-6hp9.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-9r2h-5xf6-2vwq/GHSA-9r2h-5xf6-2vwq.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-c6q5-rrw7-p494/GHSA-c6q5-rrw7-p494.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-c9xr-2j8f-4q5q/GHSA-c9xr-2j8f-4q5q.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-cfj5-j439-wcw7/GHSA-cfj5-j439-wcw7.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-cqx6-84p5-pwg6/GHSA-cqx6-84p5-pwg6.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-f8g4-wp42-47w7/GHSA-f8g4-wp42-47w7.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-fjcm-jgq9-qwjc/GHSA-fjcm-jgq9-qwjc.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-fqpp-wx48-c63r/GHSA-fqpp-wx48-c63r.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-fv6w-phw6-f2cx/GHSA-fv6w-phw6-f2cx.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-fx25-pqmv-qr46/GHSA-fx25-pqmv-qr46.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-fx8w-24qx-p2c5/GHSA-fx8w-24qx-p2c5.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-g246-2588-xpcw/GHSA-g246-2588-xpcw.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-gwxp-5q7q-w242/GHSA-gwxp-5q7q-w242.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-gxg5-5cmr-3588/GHSA-gxg5-5cmr-3588.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-hv29-c4x3-8863/GHSA-hv29-c4x3-8863.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-hxh5-3mh2-q6x8/GHSA-hxh5-3mh2-q6x8.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-j9f5-239f-px34/GHSA-j9f5-239f-px34.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-m32x-p663-p4h7/GHSA-m32x-p663-p4h7.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-mp5r-7qm4-pgc7/GHSA-mp5r-7qm4-pgc7.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-mrqf-9666-2wqm/GHSA-mrqf-9666-2wqm.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-p22x-7843-884q/GHSA-p22x-7843-884q.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-pchf-fw93-3p2f/GHSA-pchf-fw93-3p2f.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-ppxf-9xvj-v2hm/GHSA-ppxf-9xvj-v2hm.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-pvg9-854c-47xf/GHSA-pvg9-854c-47xf.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-q2rj-w884-9q82/GHSA-q2rj-w884-9q82.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-q3p4-qwqf-7x2q/GHSA-q3p4-qwqf-7x2q.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-q5gm-6r6x-wwp4/GHSA-q5gm-6r6x-wwp4.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-q9r4-2743-gqxg/GHSA-q9r4-2743-gqxg.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-qcrm-39j8-mgw2/GHSA-qcrm-39j8-mgw2.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-qwgv-9c86-m892/GHSA-qwgv-9c86-m892.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-qx69-86hp-p6qr/GHSA-qx69-86hp-p6qr.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-rmx2-4jx5-xv9c/GHSA-rmx2-4jx5-xv9c.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v24j-7gvf-f7xp/GHSA-v24j-7gvf-f7xp.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v258-v7wv-4g7v/GHSA-v258-v7wv-4g7v.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v4g5-p637-j32c/GHSA-v4g5-p637-j32c.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v57f-fqvf-vc6v/GHSA-v57f-fqvf-vc6v.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v5cc-g4p3-96gv/GHSA-v5cc-g4p3-96gv.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v6rw-775r-c547/GHSA-v6rw-775r-c547.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v9jw-qfrm-3v3x/GHSA-v9jw-qfrm-3v3x.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-vch5-mvq9-qm23/GHSA-vch5-mvq9-qm23.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-vjxc-9jvg-687w/GHSA-vjxc-9jvg-687w.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-vr4c-cc99-p7vf/GHSA-vr4c-cc99-p7vf.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-w4xp-6q8w-6c3g/GHSA-w4xp-6q8w-6c3g.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-w64r-953q-gv3q/GHSA-w64r-953q-gv3q.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-whfg-3mpf-fjhx/GHSA-whfg-3mpf-fjhx.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-wmhp-g4mm-69rg/GHSA-wmhp-g4mm-69rg.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-wp7q-78g7-c67m/GHSA-wp7q-78g7-c67m.json
diff --git a/advisories/github-reviewed/2020/10/GHSA-pv36-h7jh-qm62/GHSA-pv36-h7jh-qm62.json b/advisories/github-reviewed/2020/10/GHSA-pv36-h7jh-qm62/GHSA-pv36-h7jh-qm62.json
index 2137bae5a75..48014c7a158 100644
--- a/advisories/github-reviewed/2020/10/GHSA-pv36-h7jh-qm62/GHSA-pv36-h7jh-qm62.json
+++ b/advisories/github-reviewed/2020/10/GHSA-pv36-h7jh-qm62/GHSA-pv36-h7jh-qm62.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv36-h7jh-qm62",
- "modified": "2024-02-15T14:33:33Z",
+ "modified": "2025-02-03T15:31:58Z",
"published": "2020-10-27T19:47:38Z",
"aliases": [
"CVE-2020-15999"
@@ -103,51 +103,7 @@
},
{
"type": "WEB",
- "url": "https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html"
- },
- {
- "type": "WEB",
- "url": "https://crbug.com/1139963"
- },
- {
- "type": "PACKAGE",
- "url": "https://github.com/cefsharp/CefSharp"
- },
- {
- "type": "WEB",
- "url": "https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html"
- },
- {
- "type": "WEB",
- "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7"
- },
- {
- "type": "WEB",
- "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7"
- },
- {
- "type": "WEB",
- "url": "https://security.gentoo.org/glsa/202011-12"
- },
- {
- "type": "WEB",
- "url": "https://security.gentoo.org/glsa/202012-04"
- },
- {
- "type": "WEB",
- "url": "https://security.gentoo.org/glsa/202401-19"
- },
- {
- "type": "WEB",
- "url": "https://www.debian.org/security/2021/dsa-4824"
- },
- {
- "type": "WEB",
- "url": "https://www.nuget.org/packages/CefSharp.Common"
- },
- {
- "type": "WEB",
- "url": "https://www.nuget.org/packages/CefSharp.WinForms"
+ "url": "https://www.nuget.org/packages/CefSharp.Wpf.HwndHost"
},
{
"type": "WEB",
@@ -155,7 +111,55 @@
},
{
"type": "WEB",
- "url": "https://www.nuget.org/packages/CefSharp.Wpf.HwndHost"
+ "url": "https://www.nuget.org/packages/CefSharp.WinForms"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.nuget.org/packages/CefSharp.Common"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.debian.org/security/2021/dsa-4824"
+ },
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20240812-0001"
+ },
+ {
+ "type": "WEB",
+ "url": "https://security.gentoo.org/glsa/202401-19"
+ },
+ {
+ "type": "WEB",
+ "url": "https://security.gentoo.org/glsa/202012-04"
+ },
+ {
+ "type": "WEB",
+ "url": "https://security.gentoo.org/glsa/202011-12"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.html"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/cefsharp/CefSharp"
+ },
+ {
+ "type": "WEB",
+ "url": "https://crbug.com/1139963"
+ },
+ {
+ "type": "WEB",
+ "url": "https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html"
},
{
"type": "WEB",
diff --git a/advisories/unreviewed/2022/05/GHSA-54w2-m25f-gmqp/GHSA-54w2-m25f-gmqp.json b/advisories/unreviewed/2022/05/GHSA-54w2-m25f-gmqp/GHSA-54w2-m25f-gmqp.json
index 364ed9f2ae5..8cace33a10f 100644
--- a/advisories/unreviewed/2022/05/GHSA-54w2-m25f-gmqp/GHSA-54w2-m25f-gmqp.json
+++ b/advisories/unreviewed/2022/05/GHSA-54w2-m25f-gmqp/GHSA-54w2-m25f-gmqp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-54w2-m25f-gmqp",
- "modified": "2022-05-24T17:42:21Z",
+ "modified": "2025-02-03T15:31:58Z",
"published": "2022-05-24T17:42:21Z",
"aliases": [
"CVE-2021-27104"
],
"details": "Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
diff --git a/advisories/unreviewed/2022/07/GHSA-9q96-cwq7-cr4m/GHSA-9q96-cwq7-cr4m.json b/advisories/unreviewed/2022/07/GHSA-9q96-cwq7-cr4m/GHSA-9q96-cwq7-cr4m.json
index b5d9c8b77da..ba6b73c8c89 100644
--- a/advisories/unreviewed/2022/07/GHSA-9q96-cwq7-cr4m/GHSA-9q96-cwq7-cr4m.json
+++ b/advisories/unreviewed/2022/07/GHSA-9q96-cwq7-cr4m/GHSA-9q96-cwq7-cr4m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q96-cwq7-cr4m",
- "modified": "2022-08-05T00:00:25Z",
+ "modified": "2025-02-03T15:31:58Z",
"published": "2022-07-29T00:00:47Z",
"aliases": [
"CVE-2022-2294"
diff --git a/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json b/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json
index 64e43770d73..d3616e0b89f 100644
--- a/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json
+++ b/advisories/unreviewed/2022/09/GHSA-85q4-vgvj-3q28/GHSA-85q4-vgvj-3q28.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85q4-vgvj-3q28",
- "modified": "2022-09-30T00:00:42Z",
+ "modified": "2025-02-03T15:31:58Z",
"published": "2022-09-27T00:00:23Z",
"aliases": [
"CVE-2022-41352"
diff --git a/advisories/unreviewed/2022/10/GHSA-h73c-qgg5-q5rp/GHSA-h73c-qgg5-q5rp.json b/advisories/unreviewed/2022/10/GHSA-h73c-qgg5-q5rp/GHSA-h73c-qgg5-q5rp.json
index 9087b64eeec..37bf2b3b034 100644
--- a/advisories/unreviewed/2022/10/GHSA-h73c-qgg5-q5rp/GHSA-h73c-qgg5-q5rp.json
+++ b/advisories/unreviewed/2022/10/GHSA-h73c-qgg5-q5rp/GHSA-h73c-qgg5-q5rp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h73c-qgg5-q5rp",
- "modified": "2023-01-23T18:30:18Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2022-10-26T12:00:39Z",
"aliases": [
"CVE-2022-38181"
diff --git a/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json b/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json
index d5d55963aa3..31e91061790 100644
--- a/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json
+++ b/advisories/unreviewed/2023/02/GHSA-hp68-7f8q-r2qj/GHSA-hp68-7f8q-r2qj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hp68-7f8q-r2qj",
- "modified": "2023-02-16T15:30:29Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2023-02-07T18:30:16Z",
"aliases": [
"CVE-2022-24990"
@@ -41,7 +41,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-306"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/04/GHSA-xfv3-jp8h-q7v6/GHSA-xfv3-jp8h-q7v6.json b/advisories/unreviewed/2023/04/GHSA-xfv3-jp8h-q7v6/GHSA-xfv3-jp8h-q7v6.json
index 4796f33c256..7d569761888 100644
--- a/advisories/unreviewed/2023/04/GHSA-xfv3-jp8h-q7v6/GHSA-xfv3-jp8h-q7v6.json
+++ b/advisories/unreviewed/2023/04/GHSA-xfv3-jp8h-q7v6/GHSA-xfv3-jp8h-q7v6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfv3-jp8h-q7v6",
- "modified": "2023-04-11T15:30:31Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2023-04-06T18:30:21Z",
"aliases": [
"CVE-2023-26083"
diff --git a/advisories/unreviewed/2023/06/GHSA-rh53-wvg6-9v8m/GHSA-rh53-wvg6-9v8m.json b/advisories/unreviewed/2023/06/GHSA-rh53-wvg6-9v8m/GHSA-rh53-wvg6-9v8m.json
index 566d19d28d0..facd8a6f3fe 100644
--- a/advisories/unreviewed/2023/06/GHSA-rh53-wvg6-9v8m/GHSA-rh53-wvg6-9v8m.json
+++ b/advisories/unreviewed/2023/06/GHSA-rh53-wvg6-9v8m/GHSA-rh53-wvg6-9v8m.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rh53-wvg6-9v8m",
- "modified": "2023-11-10T06:30:18Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2023-06-23T18:30:26Z",
"aliases": [
"CVE-2023-32439"
diff --git a/advisories/unreviewed/2024/03/GHSA-4rpf-4vmp-3hfw/GHSA-4rpf-4vmp-3hfw.json b/advisories/unreviewed/2024/03/GHSA-4rpf-4vmp-3hfw/GHSA-4rpf-4vmp-3hfw.json
index 49d3856d628..67ff38c816d 100644
--- a/advisories/unreviewed/2024/03/GHSA-4rpf-4vmp-3hfw/GHSA-4rpf-4vmp-3hfw.json
+++ b/advisories/unreviewed/2024/03/GHSA-4rpf-4vmp-3hfw/GHSA-4rpf-4vmp-3hfw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rpf-4vmp-3hfw",
- "modified": "2024-03-05T12:30:31Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-03-05T12:30:31Z",
"aliases": [
"CVE-2022-48630"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ\n\nThe commit referenced in the Fixes tag removed the 'break' from the else\nbranch in qcom_rng_read(), causing an infinite loop whenever 'max' is\nnot a multiple of WORD_SZ. This can be reproduced e.g. by running:\n\n kcapi-rng -b 67 >/dev/null\n\nThere are many ways to fix this without adding back the 'break', but\nthey all seem more awkward than simply adding it back, so do just that.\n\nTested on a machine with Qualcomm Amberwing processor.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-835"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T12:15:45Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-72gm-6qcq-3xmp/GHSA-72gm-6qcq-3xmp.json b/advisories/unreviewed/2024/03/GHSA-72gm-6qcq-3xmp/GHSA-72gm-6qcq-3xmp.json
index ee6ca08d7f2..5ea234ecfc0 100644
--- a/advisories/unreviewed/2024/03/GHSA-72gm-6qcq-3xmp/GHSA-72gm-6qcq-3xmp.json
+++ b/advisories/unreviewed/2024/03/GHSA-72gm-6qcq-3xmp/GHSA-72gm-6qcq-3xmp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72gm-6qcq-3xmp",
- "modified": "2024-03-04T18:30:39Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-03-04T18:30:39Z",
"aliases": [
"CVE-2021-47101"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nasix: fix uninit-value in asix_mdio_read()\n\nasix_read_cmd() may read less than sizeof(smsr) bytes and in this case\nsmsr will be uninitialized.\n\nFail log:\nBUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline]\nBUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497\nBUG: KMSAN: uninit-value in asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497\n asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline]\n asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497\n asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-c6q3-xgg3-276c/GHSA-c6q3-xgg3-276c.json b/advisories/unreviewed/2024/03/GHSA-c6q3-xgg3-276c/GHSA-c6q3-xgg3-276c.json
index 8fbd2708565..ed26dd02868 100644
--- a/advisories/unreviewed/2024/03/GHSA-c6q3-xgg3-276c/GHSA-c6q3-xgg3-276c.json
+++ b/advisories/unreviewed/2024/03/GHSA-c6q3-xgg3-276c/GHSA-c6q3-xgg3-276c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c6q3-xgg3-276c",
- "modified": "2024-03-04T18:30:38Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-03-04T18:30:38Z",
"aliases": [
"CVE-2021-47091"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: fix locking in ieee80211_start_ap error path\n\nWe need to hold the local->mtx to release the channel context,\nas even encoded by the lockdep_assert_held() there. Fix it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-f84q-355v-4ww3/GHSA-f84q-355v-4ww3.json b/advisories/unreviewed/2024/03/GHSA-f84q-355v-4ww3/GHSA-f84q-355v-4ww3.json
index 79dd7640a2a..2ac15ba74b0 100644
--- a/advisories/unreviewed/2024/03/GHSA-f84q-355v-4ww3/GHSA-f84q-355v-4ww3.json
+++ b/advisories/unreviewed/2024/03/GHSA-f84q-355v-4ww3/GHSA-f84q-355v-4ww3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f84q-355v-4ww3",
- "modified": "2024-03-04T18:30:39Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-03-04T18:30:39Z",
"aliases": [
"CVE-2021-47100"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Fix UAF when uninstall ipmi_si and ipmi_msghandler module\n\nHi,\n\nWhen testing install and uninstall of ipmi_si.ko and ipmi_msghandler.ko,\nthe system crashed.\n\nThe log as follows:\n[ 141.087026] BUG: unable to handle kernel paging request at ffffffffc09b3a5a\n[ 141.087241] PGD 8fe4c0d067 P4D 8fe4c0d067 PUD 8fe4c0f067 PMD 103ad89067 PTE 0\n[ 141.087464] Oops: 0010 [#1] SMP NOPTI\n[ 141.087580] CPU: 67 PID: 668 Comm: kworker/67:1 Kdump: loaded Not tainted 4.18.0.x86_64 #47\n[ 141.088009] Workqueue: events 0xffffffffc09b3a40\n[ 141.088009] RIP: 0010:0xffffffffc09b3a5a\n[ 141.088009] Code: Bad RIP value.\n[ 141.088009] RSP: 0018:ffffb9094e2c3e88 EFLAGS: 00010246\n[ 141.088009] RAX: 0000000000000000 RBX: ffff9abfdb1f04a0 RCX: 0000000000000000\n[ 141.088009] RDX: 0000000000000000 RSI: 0000000000000246 RDI: 0000000000000246\n[ 141.088009] RBP: 0000000000000000 R08: ffff9abfffee3cb8 R09: 00000000000002e1\n[ 141.088009] R10: ffffb9094cb73d90 R11: 00000000000f4240 R12: ffff9abfffee8700\n[ 141.088009] R13: 0000000000000000 R14: ffff9abfdb1f04a0 R15: ffff9abfdb1f04a8\n[ 141.088009] FS: 0000000000000000(0000) GS:ffff9abfffec0000(0000) knlGS:0000000000000000\n[ 141.088009] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 141.088009] CR2: ffffffffc09b3a30 CR3: 0000008fe4c0a001 CR4: 00000000007606e0\n[ 141.088009] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 141.088009] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 141.088009] PKRU: 55555554\n[ 141.088009] Call Trace:\n[ 141.088009] ? process_one_work+0x195/0x390\n[ 141.088009] ? worker_thread+0x30/0x390\n[ 141.088009] ? process_one_work+0x390/0x390\n[ 141.088009] ? kthread+0x10d/0x130\n[ 141.088009] ? kthread_flush_work_fn+0x10/0x10\n[ 141.088009] ? ret_from_fork+0x35/0x40] BUG: unable to handle kernel paging request at ffffffffc0b28a5a\n[ 200.223240] PGD 97fe00d067 P4D 97fe00d067 PUD 97fe00f067 PMD a580cbf067 PTE 0\n[ 200.223464] Oops: 0010 [#1] SMP NOPTI\n[ 200.223579] CPU: 63 PID: 664 Comm: kworker/63:1 Kdump: loaded Not tainted 4.18.0.x86_64 #46\n[ 200.224008] Workqueue: events 0xffffffffc0b28a40\n[ 200.224008] RIP: 0010:0xffffffffc0b28a5a\n[ 200.224008] Code: Bad RIP value.\n[ 200.224008] RSP: 0018:ffffbf3c8e2a3e88 EFLAGS: 00010246\n[ 200.224008] RAX: 0000000000000000 RBX: ffffa0799ad6bca0 RCX: 0000000000000000\n[ 200.224008] RDX: 0000000000000000 RSI: 0000000000000246 RDI: 0000000000000246\n[ 200.224008] RBP: 0000000000000000 R08: ffff9fe43fde3cb8 R09: 00000000000000d5\n[ 200.224008] R10: ffffbf3c8cb53d90 R11: 00000000000f4240 R12: ffff9fe43fde8700\n[ 200.224008] R13: 0000000000000000 R14: ffffa0799ad6bca0 R15: ffffa0799ad6bca8\n[ 200.224008] FS: 0000000000000000(0000) GS:ffff9fe43fdc0000(0000) knlGS:0000000000000000\n[ 200.224008] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 200.224008] CR2: ffffffffc0b28a30 CR3: 00000097fe00a002 CR4: 00000000007606e0\n[ 200.224008] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 200.224008] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 200.224008] PKRU: 55555554\n[ 200.224008] Call Trace:\n[ 200.224008] ? process_one_work+0x195/0x390\n[ 200.224008] ? worker_thread+0x30/0x390\n[ 200.224008] ? process_one_work+0x390/0x390\n[ 200.224008] ? kthread+0x10d/0x130\n[ 200.224008] ? kthread_flush_work_fn+0x10/0x10\n[ 200.224008] ? ret_from_fork+0x35/0x40\n[ 200.224008] kernel fault(0x1) notification starting on CPU 63\n[ 200.224008] kernel fault(0x1) notification finished on CPU 63\n[ 200.224008] CR2: ffffffffc0b28a5a\n[ 200.224008] ---[ end trace c82a412d93f57412 ]---\n\nThe reason is as follows:\nT1: rmmod ipmi_si.\n ->ipmi_unregister_smi()\n -> ipmi_bmc_unregister()\n -> __ipmi_bmc_unregister()\n -> kref_put(&bmc->usecount, cleanup_bmc_device);\n -> schedule_work(&bmc->remove_work);\n\nT2: rmmod ipmi_msghandl\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-ppcf-3xhc-xrx9/GHSA-ppcf-3xhc-xrx9.json b/advisories/unreviewed/2024/03/GHSA-ppcf-3xhc-xrx9/GHSA-ppcf-3xhc-xrx9.json
index 4bb10babc14..d026c0f9deb 100644
--- a/advisories/unreviewed/2024/03/GHSA-ppcf-3xhc-xrx9/GHSA-ppcf-3xhc-xrx9.json
+++ b/advisories/unreviewed/2024/03/GHSA-ppcf-3xhc-xrx9/GHSA-ppcf-3xhc-xrx9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppcf-3xhc-xrx9",
- "modified": "2024-06-27T15:30:38Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-03-06T09:30:26Z",
"aliases": [
"CVE-2023-52583"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix deadlock or deadcode of misusing dget()\n\nThe lock order is incorrect between denty and its parent, we should\nalways make sure that the parent get the lock first.\n\nBut since this deadcode is never used and the parent dir will always\nbe set from the callers, let's just remove it.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-06T07:15:06Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-qcmx-p4h8-4fhq/GHSA-qcmx-p4h8-4fhq.json b/advisories/unreviewed/2024/03/GHSA-qcmx-p4h8-4fhq/GHSA-qcmx-p4h8-4fhq.json
index ed86be3f138..407dbf02d6b 100644
--- a/advisories/unreviewed/2024/03/GHSA-qcmx-p4h8-4fhq/GHSA-qcmx-p4h8-4fhq.json
+++ b/advisories/unreviewed/2024/03/GHSA-qcmx-p4h8-4fhq/GHSA-qcmx-p4h8-4fhq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qcmx-p4h8-4fhq",
- "modified": "2024-03-04T18:30:39Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-03-04T18:30:39Z",
"aliases": [
"CVE-2021-47098"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations\n\nCommit b50aa49638c7 (\"hwmon: (lm90) Prevent integer underflows of\ntemperature calculations\") addressed a number of underflow situations\nwhen writing temperature limits. However, it missed one situation, seen\nwhen an attempt is made to set the hysteresis value to MAX_LONG and the\ncritical temperature limit is negative.\n\nUse clamp_val() when setting the hysteresis temperature to ensure that\nthe provided value can never overflow or underflow.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:08Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json
index c4665a7897f..a83481be62d 100644
--- a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json
+++ b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pgc5-vrj2-c9w5",
- "modified": "2024-06-25T21:31:12Z",
+ "modified": "2025-02-03T15:31:59Z",
"published": "2024-04-01T09:30:31Z",
"aliases": [
"CVE-2024-26654"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: sh: aica: reorder cleanup operations to avoid UAF bugs\n\nThe dreamcastcard->timer could schedule the spu_dma_work and the\nspu_dma_work could also arm the dreamcastcard->timer.\n\nWhen the snd_pcm_substream is closing, the aica_channel will be\ndeallocated. But it could still be dereferenced in the worker\nthread. The reason is that del_timer() will return directly\nregardless of whether the timer handler is running or not and\nthe worker could be rescheduled in the timer handler. As a result,\nthe UAF bug will happen. The racy situation is shown below:\n\n (Thread 1) | (Thread 2)\nsnd_aicapcm_pcm_close() |\n ... | run_spu_dma() //worker\n | mod_timer()\n flush_work() |\n del_timer() | aica_period_elapsed() //timer\n kfree(dreamcastcard->channel) | schedule_work()\n | run_spu_dma() //worker\n ... | dreamcastcard->channel-> //USE\n\nIn order to mitigate this bug and other possible corner cases,\ncall mod_timer() conditionally in run_spu_dma(), then implement\nPCM sync_stop op to cancel both the timer and worker. The sync_stop\nop will be called from PCM core appropriately when needed.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-01T09:15:51Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json b/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json
index 3c076872b6f..e0e5441db71 100644
--- a/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json
+++ b/advisories/unreviewed/2024/07/GHSA-fphh-62qm-fm76/GHSA-fphh-62qm-fm76.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fphh-62qm-fm76",
- "modified": "2024-07-29T18:30:42Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-07-29T18:30:42Z",
"aliases": [
"CVE-2024-42089"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl-asoc-card: set priv->pdev before using it\n\npriv->pdev pointer was set after being used in\nfsl_asoc_card_audmux_init().\nMove this assignment at the start of the probe function, so\nsub-functions can correctly use pdev through priv.\n\nfsl_asoc_card_audmux_init() dereferences priv->pdev to get access to the\ndev struct, used with dev_err macros.\nAs priv is zero-initialised, there would be a NULL pointer dereference.\nNote that if priv->dev is dereferenced before assignment but never used,\nfor example if there is no error to be printed, the driver won't crash\nprobably due to compiler optimisations.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-29T17:15:11Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json b/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json
index b2be6e5bff9..031f2022f8e 100644
--- a/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json
+++ b/advisories/unreviewed/2024/07/GHSA-fxx9-q7vv-g6p2/GHSA-fxx9-q7vv-g6p2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxx9-q7vv-g6p2",
- "modified": "2024-07-29T15:30:47Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-07-29T15:30:47Z",
"aliases": [
"CVE-2024-41077"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnull_blk: fix validation of block size\n\nBlock size should be between 512 and PAGE_SIZE and be a power of 2. The current\ncheck does not validate this, so update the check.\n\nWithout this patch, null_blk would Oops due to a null pointer deref when\nloaded with bs=1536 [1].\n\n\n[axboe: remove unnecessary braces and != 0 check]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-29T15:15:15Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-rfhq-9xcp-7phj/GHSA-rfhq-9xcp-7phj.json b/advisories/unreviewed/2024/07/GHSA-rfhq-9xcp-7phj/GHSA-rfhq-9xcp-7phj.json
index 8f7db157be2..1a0b01ec4bc 100644
--- a/advisories/unreviewed/2024/07/GHSA-rfhq-9xcp-7phj/GHSA-rfhq-9xcp-7phj.json
+++ b/advisories/unreviewed/2024/07/GHSA-rfhq-9xcp-7phj/GHSA-rfhq-9xcp-7phj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rfhq-9xcp-7phj",
- "modified": "2024-07-10T03:30:35Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-07-10T03:30:35Z",
"aliases": [
"CVE-2024-4866"
@@ -45,7 +45,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-v2jg-x6cv-qjcg/GHSA-v2jg-x6cv-qjcg.json b/advisories/unreviewed/2024/07/GHSA-v2jg-x6cv-qjcg/GHSA-v2jg-x6cv-qjcg.json
index abdba6b39dc..88c5f870710 100644
--- a/advisories/unreviewed/2024/07/GHSA-v2jg-x6cv-qjcg/GHSA-v2jg-x6cv-qjcg.json
+++ b/advisories/unreviewed/2024/07/GHSA-v2jg-x6cv-qjcg/GHSA-v2jg-x6cv-qjcg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v2jg-x6cv-qjcg",
- "modified": "2024-07-30T09:31:51Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-07-30T09:31:51Z",
"aliases": [
"CVE-2024-42106"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet_diag: Initialize pad field in struct inet_diag_req_v2\n\nKMSAN reported uninit-value access in raw_lookup() [1]. Diag for raw\nsockets uses the pad field in struct inet_diag_req_v2 for the\nunderlying protocol. This field corresponds to the sdiag_raw_protocol\nfield in struct inet_diag_req_raw.\n\ninet_diag_get_exact_compat() converts inet_diag_req to\ninet_diag_req_v2, but leaves the pad field uninitialized. So the issue\noccurs when raw_lookup() accesses the sdiag_raw_protocol field.\n\nFix this by initializing the pad field in\ninet_diag_get_exact_compat(). Also, do the same fix in\ninet_diag_dump_compat() to avoid the similar issue in the future.\n\n[1]\nBUG: KMSAN: uninit-value in raw_lookup net/ipv4/raw_diag.c:49 [inline]\nBUG: KMSAN: uninit-value in raw_sock_get+0x657/0x800 net/ipv4/raw_diag.c:71\n raw_lookup net/ipv4/raw_diag.c:49 [inline]\n raw_sock_get+0x657/0x800 net/ipv4/raw_diag.c:71\n raw_diag_dump_one+0xa1/0x660 net/ipv4/raw_diag.c:99\n inet_diag_cmd_exact+0x7d9/0x980\n inet_diag_get_exact_compat net/ipv4/inet_diag.c:1404 [inline]\n inet_diag_rcv_msg_compat+0x469/0x530 net/ipv4/inet_diag.c:1426\n sock_diag_rcv_msg+0x23d/0x740 net/core/sock_diag.c:282\n netlink_rcv_skb+0x537/0x670 net/netlink/af_netlink.c:2564\n sock_diag_rcv+0x35/0x40 net/core/sock_diag.c:297\n netlink_unicast_kernel net/netlink/af_netlink.c:1335 [inline]\n netlink_unicast+0xe74/0x1240 net/netlink/af_netlink.c:1361\n netlink_sendmsg+0x10c6/0x1260 net/netlink/af_netlink.c:1905\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x332/0x3d0 net/socket.c:745\n ____sys_sendmsg+0x7f0/0xb70 net/socket.c:2585\n ___sys_sendmsg+0x271/0x3b0 net/socket.c:2639\n __sys_sendmsg net/socket.c:2668 [inline]\n __do_sys_sendmsg net/socket.c:2677 [inline]\n __se_sys_sendmsg net/socket.c:2675 [inline]\n __x64_sys_sendmsg+0x27e/0x4a0 net/socket.c:2675\n x64_sys_call+0x135e/0x3ce0 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd9/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was stored to memory at:\n raw_sock_get+0x650/0x800 net/ipv4/raw_diag.c:71\n raw_diag_dump_one+0xa1/0x660 net/ipv4/raw_diag.c:99\n inet_diag_cmd_exact+0x7d9/0x980\n inet_diag_get_exact_compat net/ipv4/inet_diag.c:1404 [inline]\n inet_diag_rcv_msg_compat+0x469/0x530 net/ipv4/inet_diag.c:1426\n sock_diag_rcv_msg+0x23d/0x740 net/core/sock_diag.c:282\n netlink_rcv_skb+0x537/0x670 net/netlink/af_netlink.c:2564\n sock_diag_rcv+0x35/0x40 net/core/sock_diag.c:297\n netlink_unicast_kernel net/netlink/af_netlink.c:1335 [inline]\n netlink_unicast+0xe74/0x1240 net/netlink/af_netlink.c:1361\n netlink_sendmsg+0x10c6/0x1260 net/netlink/af_netlink.c:1905\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x332/0x3d0 net/socket.c:745\n ____sys_sendmsg+0x7f0/0xb70 net/socket.c:2585\n ___sys_sendmsg+0x271/0x3b0 net/socket.c:2639\n __sys_sendmsg net/socket.c:2668 [inline]\n __do_sys_sendmsg net/socket.c:2677 [inline]\n __se_sys_sendmsg net/socket.c:2675 [inline]\n __x64_sys_sendmsg+0x27e/0x4a0 net/socket.c:2675\n x64_sys_call+0x135e/0x3ce0 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd9/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nLocal variable req.i created at:\n inet_diag_get_exact_compat net/ipv4/inet_diag.c:1396 [inline]\n inet_diag_rcv_msg_compat+0x2a6/0x530 net/ipv4/inet_diag.c:1426\n sock_diag_rcv_msg+0x23d/0x740 net/core/sock_diag.c:282\n\nCPU: 1 PID: 8888 Comm: syz-executor.6 Not tainted 6.10.0-rc4-00217-g35bb670d65fc #32\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:03Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-8p7h-rvp2-7xrx/GHSA-8p7h-rvp2-7xrx.json b/advisories/unreviewed/2024/12/GHSA-8p7h-rvp2-7xrx/GHSA-8p7h-rvp2-7xrx.json
index 76fb94c8880..0265af32b99 100644
--- a/advisories/unreviewed/2024/12/GHSA-8p7h-rvp2-7xrx/GHSA-8p7h-rvp2-7xrx.json
+++ b/advisories/unreviewed/2024/12/GHSA-8p7h-rvp2-7xrx/GHSA-8p7h-rvp2-7xrx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p7h-rvp2-7xrx",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53224"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Move events notifier registration to be after device registration\n\nMove pkey change work initialization and cleanup from device resources\nstage to notifier stage, since this is the stage which handles this work\nevents.\n\nFix a race between the device deregistration and pkey change work by moving\nMLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to\nensure that the notifier is deregistered before the device during cleanup.\nWhich ensures there are no works that are being executed after the\ndevice has already unregistered which can cause the panic below.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1\nHardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023\nWorkqueue: events pkey_change_handler [mlx5_ib]\nRIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib]\nCode: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 <4c> 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40\nRSP: 0018:ffffbcc54068be20 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36\nRDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128\nRBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001\nR10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000\nR13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905\nFS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\nmlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib]\nprocess_one_work+0x1e8/0x3c0\nworker_thread+0x50/0x3b0\n? rescuer_thread+0x380/0x380\nkthread+0x149/0x170\n? set_kthread_struct+0x50/0x50\nret_from_fork+0x22/0x30\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core]\nCR2: 0000000000000000\n---[ end trace f6f8be4eae12f7bc ]---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:30Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-9ppm-qmv9-2f9f/GHSA-9ppm-qmv9-2f9f.json b/advisories/unreviewed/2024/12/GHSA-9ppm-qmv9-2f9f/GHSA-9ppm-qmv9-2f9f.json
index 6be5af5a22d..6de4ee7a6db 100644
--- a/advisories/unreviewed/2024/12/GHSA-9ppm-qmv9-2f9f/GHSA-9ppm-qmv9-2f9f.json
+++ b/advisories/unreviewed/2024/12/GHSA-9ppm-qmv9-2f9f/GHSA-9ppm-qmv9-2f9f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ppm-qmv9-2f9f",
- "modified": "2024-12-27T15:31:50Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:50Z",
"aliases": [
"CVE-2024-53168"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: fix one UAF issue caused by sunrpc kernel tcp socket\n\nBUG: KASAN: slab-use-after-free in tcp_write_timer_handler+0x156/0x3e0\nRead of size 1 at addr ffff888111f322cd by task swapper/0/0\n\nCPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.12.0-rc4-dirty #7\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1\nCall Trace:\n \n dump_stack_lvl+0x68/0xa0\n print_address_description.constprop.0+0x2c/0x3d0\n print_report+0xb4/0x270\n kasan_report+0xbd/0xf0\n tcp_write_timer_handler+0x156/0x3e0\n tcp_write_timer+0x66/0x170\n call_timer_fn+0xfb/0x1d0\n __run_timers+0x3f8/0x480\n run_timer_softirq+0x9b/0x100\n handle_softirqs+0x153/0x390\n __irq_exit_rcu+0x103/0x120\n irq_exit_rcu+0xe/0x20\n sysvec_apic_timer_interrupt+0x76/0x90\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20\nRIP: 0010:default_idle+0xf/0x20\nCode: 4c 01 c7 4c 29 c2 e9 72 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90\n 90 90 90 90 f3 0f 1e fa 66 90 0f 00 2d 33 f8 25 00 fb f4 c3 cc cc cc\n cc 66 66 2e 0f 1f 84 00 00 00 00 00 90 90 90 90 90\nRSP: 0018:ffffffffa2007e28 EFLAGS: 00000242\nRAX: 00000000000f3b31 RBX: 1ffffffff4400fc7 RCX: ffffffffa09c3196\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff9f00590f\nRBP: 0000000000000000 R08: 0000000000000001 R09: ffffed102360835d\nR10: ffff88811b041aeb R11: 0000000000000001 R12: 0000000000000000\nR13: ffffffffa202d7c0 R14: 0000000000000000 R15: 00000000000147d0\n default_idle_call+0x6b/0xa0\n cpuidle_idle_call+0x1af/0x1f0\n do_idle+0xbc/0x130\n cpu_startup_entry+0x33/0x40\n rest_init+0x11f/0x210\n start_kernel+0x39a/0x420\n x86_64_start_reservations+0x18/0x30\n x86_64_start_kernel+0x97/0xa0\n common_startup_64+0x13e/0x141\n \n\nAllocated by task 595:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n __kasan_slab_alloc+0x87/0x90\n kmem_cache_alloc_noprof+0x12b/0x3f0\n copy_net_ns+0x94/0x380\n create_new_namespaces+0x24c/0x500\n unshare_nsproxy_namespaces+0x75/0xf0\n ksys_unshare+0x24e/0x4f0\n __x64_sys_unshare+0x1f/0x30\n do_syscall_64+0x70/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 100:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x54/0x70\n kmem_cache_free+0x156/0x5d0\n cleanup_net+0x5d3/0x670\n process_one_work+0x776/0xa90\n worker_thread+0x2e2/0x560\n kthread+0x1a8/0x1f0\n ret_from_fork+0x34/0x60\n ret_from_fork_asm+0x1a/0x30\n\nReproduction script:\n\nmkdir -p /mnt/nfsshare\nmkdir -p /mnt/nfs/netns_1\nmkfs.ext4 /dev/sdb\nmount /dev/sdb /mnt/nfsshare\nsystemctl restart nfs-server\nchmod 777 /mnt/nfsshare\nexportfs -i -o rw,no_root_squash *:/mnt/nfsshare\n\nip netns add netns_1\nip link add name veth_1_peer type veth peer veth_1\nifconfig veth_1_peer 11.11.0.254 up\nip link set veth_1 netns netns_1\nip netns exec netns_1 ifconfig veth_1 11.11.0.1\n\nip netns exec netns_1 /root/iptables -A OUTPUT -d 11.11.0.254 -p tcp \\\n\t--tcp-flags FIN FIN -j DROP\n\n(note: In my environment, a DESTROY_CLIENTID operation is always sent\n immediately, breaking the nfs tcp connection.)\nip netns exec netns_1 timeout -s 9 300 mount -t nfs -o proto=tcp,vers=4.1 \\\n\t11.11.0.254:/mnt/nfsshare /mnt/nfs/netns_1\n\nip netns del netns_1\n\nThe reason here is that the tcp socket in netns_1 (nfs side) has been\nshutdown and closed (done in xs_destroy), but the FIN message (with ack)\nis discarded, and the nfsd side keeps sending retransmission messages.\nAs a result, when the tcp sock in netns_1 processes the received message,\nit sends the message (FIN message) in the sending queue, and the tcp timer\nis re-established. When the network namespace is deleted, the net structure\naccessed by tcp's timer handler function causes problems.\n\nTo fix this problem, let's hold netns refcnt for the tcp kernel socket as\ndone in other modules. This is an ugly hack which can easily be backported\nto earlier kernels. A proper fix which cleans up the interfaces will\nfollow, but may not be so easy to backport.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-c86m-78v8-4hvw/GHSA-c86m-78v8-4hvw.json b/advisories/unreviewed/2024/12/GHSA-c86m-78v8-4hvw/GHSA-c86m-78v8-4hvw.json
index 2fb34f245b4..ceae217f71b 100644
--- a/advisories/unreviewed/2024/12/GHSA-c86m-78v8-4hvw/GHSA-c86m-78v8-4hvw.json
+++ b/advisories/unreviewed/2024/12/GHSA-c86m-78v8-4hvw/GHSA-c86m-78v8-4hvw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c86m-78v8-4hvw",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53232"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/s390: Implement blocking domain\n\nThis fixes a crash when surprise hot-unplugging a PCI device. This crash\nhappens because during hot-unplug __iommu_group_set_domain_nofail()\nattaching the default domain fails when the platform no longer\nrecognizes the device as it has already been removed and we end up with\na NULL domain pointer and UAF. This is exactly the case referred to in\nthe second comment in __iommu_device_set_domain() and just as stated\nthere if we can instead attach the blocking domain the UAF is prevented\nas this can handle the already removed device. Implement the blocking\ndomain to use this handling. With this change, the crash is fixed but\nwe still hit a warning attempting to change DMA ownership on a blocked\ndevice.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:31Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json b/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json
index 05f604ab5fc..c1c3098050e 100644
--- a/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json
+++ b/advisories/unreviewed/2024/12/GHSA-crfq-94qw-vfrw/GHSA-crfq-94qw-vfrw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crfq-94qw-vfrw",
- "modified": "2024-12-09T15:31:33Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-09T15:31:33Z",
"aliases": [
"CVE-2023-23715"
diff --git a/advisories/unreviewed/2024/12/GHSA-cvxq-qv5g-cqw6/GHSA-cvxq-qv5g-cqw6.json b/advisories/unreviewed/2024/12/GHSA-cvxq-qv5g-cqw6/GHSA-cvxq-qv5g-cqw6.json
index bdc3389cd04..0d81ed699c0 100644
--- a/advisories/unreviewed/2024/12/GHSA-cvxq-qv5g-cqw6/GHSA-cvxq-qv5g-cqw6.json
+++ b/advisories/unreviewed/2024/12/GHSA-cvxq-qv5g-cqw6/GHSA-cvxq-qv5g-cqw6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvxq-qv5g-cqw6",
- "modified": "2024-12-28T12:30:48Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2024-12-28T12:30:47Z",
"aliases": [
"CVE-2024-56702"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Mark raw_tp arguments with PTR_MAYBE_NULL\n\nArguments to a raw tracepoint are tagged as trusted, which carries the\nsemantics that the pointer will be non-NULL. However, in certain cases,\na raw tracepoint argument may end up being NULL. More context about this\nissue is available in [0].\n\nThus, there is a discrepancy between the reality, that raw_tp arguments\ncan actually be NULL, and the verifier's knowledge, that they are never\nNULL, causing explicit NULL checks to be deleted, and accesses to such\npointers potentially crashing the kernel.\n\nTo fix this, mark raw_tp arguments as PTR_MAYBE_NULL, and then special\ncase the dereference and pointer arithmetic to permit it, and allow\npassing them into helpers/kfuncs; these exceptions are made for raw_tp\nprograms only. Ensure that we don't do this when ref_obj_id > 0, as in\nthat case this is an acquired object and doesn't need such adjustment.\n\nThe reason we do mask_raw_tp_trusted_reg logic is because other will\nrecheck in places whether the register is a trusted_reg, and then\nconsider our register as untrusted when detecting the presence of the\nPTR_MAYBE_NULL flag.\n\nTo allow safe dereference, we enable PROBE_MEM marking when we see loads\ninto trusted pointers with PTR_MAYBE_NULL.\n\nWhile trusted raw_tp arguments can also be passed into helpers or kfuncs\nwhere such broken assumption may cause issues, a future patch set will\ntackle their case separately, as PTR_TO_BTF_ID (without PTR_TRUSTED) can\nalready be passed into helpers and causes similar problems. Thus, they\nare left alone for now.\n\nIt is possible that these checks also permit passing non-raw_tp args\nthat are trusted PTR_TO_BTF_ID with null marking. In such a case,\nallowing dereference when pointer is NULL expands allowed behavior, so\nwon't regress existing programs, and the case of passing these into\nhelpers is the same as above and will be dealt with later.\n\nAlso update the failure case in tp_btf_nullable selftest to capture the\nnew behavior, as the verifier will no longer cause an error when\ndirectly dereference a raw tracepoint argument marked as __nullable.\n\n [0]: https://lore.kernel.org/bpf/ZrCZS6nisraEqehw@jlelli-thinkpadt14gen4.remote.csb",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-28T10:15:17Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-fcp2-76rf-pjrc/GHSA-fcp2-76rf-pjrc.json b/advisories/unreviewed/2024/12/GHSA-fcp2-76rf-pjrc/GHSA-fcp2-76rf-pjrc.json
index cb826eba456..626422099b3 100644
--- a/advisories/unreviewed/2024/12/GHSA-fcp2-76rf-pjrc/GHSA-fcp2-76rf-pjrc.json
+++ b/advisories/unreviewed/2024/12/GHSA-fcp2-76rf-pjrc/GHSA-fcp2-76rf-pjrc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcp2-76rf-pjrc",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53215"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()\n\nThere's issue as follows:\nRPC: Registered rdma transport module.\nRPC: Registered rdma backchannel transport module.\nRPC: Unregistered rdma transport module.\nRPC: Unregistered rdma backchannel transport module.\nBUG: unable to handle page fault for address: fffffbfff80c609a\nPGD 123fee067 P4D 123fee067 PUD 123fea067 PMD 10c624067 PTE 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN NOPTI\nRIP: 0010:percpu_counter_destroy_many+0xf7/0x2a0\nCall Trace:\n \n __die+0x1f/0x70\n page_fault_oops+0x2cd/0x860\n spurious_kernel_fault+0x36/0x450\n do_kern_addr_fault+0xca/0x100\n exc_page_fault+0x128/0x150\n asm_exc_page_fault+0x26/0x30\n percpu_counter_destroy_many+0xf7/0x2a0\n mmdrop+0x209/0x350\n finish_task_switch.isra.0+0x481/0x840\n schedule_tail+0xe/0xd0\n ret_from_fork+0x23/0x80\n ret_from_fork_asm+0x1a/0x30\n \n\nIf register_sysctl() return NULL, then svc_rdma_proc_cleanup() will not\ndestroy the percpu counters which init in svc_rdma_proc_init().\nIf CONFIG_HOTPLUG_CPU is enabled, residual nodes may be in the\n'percpu_counters' list. The above issue may occur once the module is\nremoved. If the CONFIG_HOTPLUG_CPU configuration is not enabled, memory\nleakage occurs.\nTo solve above issue just destroy all percpu counters when\nregister_sysctl() return NULL.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:29Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-h35x-4f36-345v/GHSA-h35x-4f36-345v.json b/advisories/unreviewed/2024/12/GHSA-h35x-4f36-345v/GHSA-h35x-4f36-345v.json
index fc00242d180..28fa6a1c657 100644
--- a/advisories/unreviewed/2024/12/GHSA-h35x-4f36-345v/GHSA-h35x-4f36-345v.json
+++ b/advisories/unreviewed/2024/12/GHSA-h35x-4f36-345v/GHSA-h35x-4f36-345v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h35x-4f36-345v",
- "modified": "2024-12-27T15:31:53Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:53Z",
"aliases": [
"CVE-2024-56540"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/ivpu: Prevent recovery invocation during probe and resume\n\nRefactor IPC send and receive functions to allow correct\nhandling of operations that should not trigger a recovery process.\n\nExpose ivpu_send_receive_internal(), which is now utilized by the D0i3\nentry, DCT initialization, and HWS initialization functions.\nThese functions have been modified to return error codes gracefully,\nrather than initiating recovery.\n\nThe updated functions are invoked within ivpu_probe() and ivpu_resume(),\nensuring that any errors encountered during these stages result in a proper\nteardown or shutdown sequence. The previous approach of triggering recovery\nwithin these functions could lead to a race condition, potentially causing\nundefined behavior and kernel crashes due to null pointer dereferences.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:33Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-m2h6-g9h7-jxfj/GHSA-m2h6-g9h7-jxfj.json b/advisories/unreviewed/2024/12/GHSA-m2h6-g9h7-jxfj/GHSA-m2h6-g9h7-jxfj.json
index b8e1761cacf..bb5585f62c0 100644
--- a/advisories/unreviewed/2024/12/GHSA-m2h6-g9h7-jxfj/GHSA-m2h6-g9h7-jxfj.json
+++ b/advisories/unreviewed/2024/12/GHSA-m2h6-g9h7-jxfj/GHSA-m2h6-g9h7-jxfj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m2h6-g9h7-jxfj",
- "modified": "2024-12-27T15:31:55Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2024-12-27T15:31:55Z",
"aliases": [
"CVE-2024-56635"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: avoid potential UAF in default_operstate()\n\nsyzbot reported an UAF in default_operstate() [1]\n\nIssue is a race between device and netns dismantles.\n\nAfter calling __rtnl_unlock() from netdev_run_todo(),\nwe can not assume the netns of each device is still alive.\n\nMake sure the device is not in NETREG_UNREGISTERED state,\nand add an ASSERT_RTNL() before the call to\n__dev_get_by_index().\n\nWe might move this ASSERT_RTNL() in __dev_get_by_index()\nin the future.\n\n[1]\n\nBUG: KASAN: slab-use-after-free in __dev_get_by_index+0x5d/0x110 net/core/dev.c:852\nRead of size 8 at addr ffff888043eba1b0 by task syz.0.0/5339\n\nCPU: 0 UID: 0 PID: 5339 Comm: syz.0.0 Not tainted 6.12.0-syzkaller-10296-gaaf20f870da0 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:489\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n __dev_get_by_index+0x5d/0x110 net/core/dev.c:852\n default_operstate net/core/link_watch.c:51 [inline]\n rfc2863_policy+0x224/0x300 net/core/link_watch.c:67\n linkwatch_do_dev+0x3e/0x170 net/core/link_watch.c:170\n netdev_run_todo+0x461/0x1000 net/core/dev.c:10894\n rtnl_unlock net/core/rtnetlink.c:152 [inline]\n rtnl_net_unlock include/linux/rtnetlink.h:133 [inline]\n rtnl_dellink+0x760/0x8d0 net/core/rtnetlink.c:3520\n rtnetlink_rcv_msg+0x791/0xcf0 net/core/rtnetlink.c:6911\n netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2541\n netlink_unicast_kernel net/netlink/af_netlink.c:1321 [inline]\n netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1347\n netlink_sendmsg+0x8e4/0xcb0 net/netlink/af_netlink.c:1891\n sock_sendmsg_nosec net/socket.c:711 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:726\n ____sys_sendmsg+0x52a/0x7e0 net/socket.c:2583\n ___sys_sendmsg net/socket.c:2637 [inline]\n __sys_sendmsg+0x269/0x350 net/socket.c:2669\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f2a3cb80809\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f2a3d9cd058 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f2a3cd45fa0 RCX: 00007f2a3cb80809\nRDX: 0000000000000000 RSI: 0000000020000000 RDI: 0000000000000008\nRBP: 00007f2a3cbf393e R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f2a3cd45fa0 R15: 00007ffd03bc65c8\n \n\nAllocated by task 5339:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4314\n kmalloc_noprof include/linux/slab.h:901 [inline]\n kmalloc_array_noprof include/linux/slab.h:945 [inline]\n netdev_create_hash net/core/dev.c:11870 [inline]\n netdev_init+0x10c/0x250 net/core/dev.c:11890\n ops_init+0x31e/0x590 net/core/net_namespace.c:138\n setup_net+0x287/0x9e0 net/core/net_namespace.c:362\n copy_net_ns+0x33f/0x570 net/core/net_namespace.c:500\n create_new_namespaces+0x425/0x7b0 kernel/nsproxy.c:110\n unshare_nsproxy_namespaces+0x124/0x180 kernel/nsproxy.c:228\n ksys_unshare+0x57d/0xa70 kernel/fork.c:3314\n __do_sys_unshare kernel/fork.c:3385 [inline]\n __se_sys_unshare kernel/fork.c:3383 [inline]\n __x64_sys_unshare+0x38/0x40 kernel/fork.c:3383\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x8\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-mfcg-4w9q-f9mr/GHSA-mfcg-4w9q-f9mr.json b/advisories/unreviewed/2024/12/GHSA-mfcg-4w9q-f9mr/GHSA-mfcg-4w9q-f9mr.json
index 5c0baf02e88..ee91590dfb7 100644
--- a/advisories/unreviewed/2024/12/GHSA-mfcg-4w9q-f9mr/GHSA-mfcg-4w9q-f9mr.json
+++ b/advisories/unreviewed/2024/12/GHSA-mfcg-4w9q-f9mr/GHSA-mfcg-4w9q-f9mr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfcg-4w9q-f9mr",
- "modified": "2024-12-27T15:31:54Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:54Z",
"aliases": [
"CVE-2024-56568"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/arm-smmu: Defer probe of clients after smmu device bound\n\nNull pointer dereference occurs due to a race between smmu\ndriver probe and client driver probe, when of_dma_configure()\nfor client is called after the iommu_device_register() for smmu driver\nprobe has executed but before the driver_bound() for smmu driver\nhas been called.\n\nFollowing is how the race occurs:\n\nT1:Smmu device probe\t\tT2: Client device probe\n\nreally_probe()\narm_smmu_device_probe()\niommu_device_register()\n\t\t\t\t\treally_probe()\n\t\t\t\t\tplatform_dma_configure()\n\t\t\t\t\tof_dma_configure()\n\t\t\t\t\tof_dma_configure_id()\n\t\t\t\t\tof_iommu_configure()\n\t\t\t\t\tiommu_probe_device()\n\t\t\t\t\tiommu_init_device()\n\t\t\t\t\tarm_smmu_probe_device()\n\t\t\t\t\tarm_smmu_get_by_fwnode()\n\t\t\t\t\t\tdriver_find_device_by_fwnode()\n\t\t\t\t\t\tdriver_find_device()\n\t\t\t\t\t\tnext_device()\n\t\t\t\t\t\tklist_next()\n\t\t\t\t\t\t /* null ptr\n\t\t\t\t\t\t assigned to smmu */\n\t\t\t\t\t/* null ptr dereference\n\t\t\t\t\t while smmu->streamid_mask */\ndriver_bound()\n\tklist_add_tail()\n\nWhen this null smmu pointer is dereferenced later in\narm_smmu_probe_device, the device crashes.\n\nFix this by deferring the probe of the client device\nuntil the smmu device has bound to the arm smmu driver.\n\n[will: Add comment]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-362"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:15Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-mp8h-4283-jr44/GHSA-mp8h-4283-jr44.json b/advisories/unreviewed/2024/12/GHSA-mp8h-4283-jr44/GHSA-mp8h-4283-jr44.json
index e2427ede57e..e9538a4fd98 100644
--- a/advisories/unreviewed/2024/12/GHSA-mp8h-4283-jr44/GHSA-mp8h-4283-jr44.json
+++ b/advisories/unreviewed/2024/12/GHSA-mp8h-4283-jr44/GHSA-mp8h-4283-jr44.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mp8h-4283-jr44",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53161"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/bluefield: Fix potential integer overflow\n\nThe 64-bit argument for the \"get DIMM info\" SMC call consists of mem_ctrl_idx\nleft-shifted 16 bits and OR-ed with DIMM index. With mem_ctrl_idx defined as\n32-bits wide the left-shift operation truncates the upper 16 bits of\ninformation during the calculation of the SMC argument.\n\nThe mem_ctrl_idx stack variable must be defined as 64-bits wide to prevent any\npotential integer overflow, i.e. loss of data from upper 16 bits.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-qm84-5c9v-92xm/GHSA-qm84-5c9v-92xm.json b/advisories/unreviewed/2024/12/GHSA-qm84-5c9v-92xm/GHSA-qm84-5c9v-92xm.json
index 7c1bbcfd68b..53c36bc5d30 100644
--- a/advisories/unreviewed/2024/12/GHSA-qm84-5c9v-92xm/GHSA-qm84-5c9v-92xm.json
+++ b/advisories/unreviewed/2024/12/GHSA-qm84-5c9v-92xm/GHSA-qm84-5c9v-92xm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qm84-5c9v-92xm",
- "modified": "2024-12-27T15:31:50Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:50Z",
"aliases": [
"CVE-2024-53175"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipc: fix memleak if msg_init_ns failed in create_ipc_ns\n\nPercpu memory allocation may failed during create_ipc_ns however this\nfail is not handled properly since ipc sysctls and mq sysctls is not\nreleased properly. Fix this by release these two resource when failure.\n\nHere is the kmemleak stack when percpu failed:\n\nunreferenced object 0xffff88819de2a600 (size 512):\n comm \"shmem_2nstest\", pid 120711, jiffies 4300542254\n hex dump (first 32 bytes):\n 60 aa 9d 84 ff ff ff ff fc 18 48 b2 84 88 ff ff `.........H.....\n 04 00 00 00 a4 01 00 00 20 e4 56 81 ff ff ff ff ........ .V.....\n backtrace (crc be7cba35):\n [] __kmalloc_node_track_caller_noprof+0x333/0x420\n [] kmemdup_noprof+0x26/0x50\n [] setup_mq_sysctls+0x57/0x1d0\n [] copy_ipcs+0x29c/0x3b0\n [] create_new_namespaces+0x1d0/0x920\n [] copy_namespaces+0x2e9/0x3e0\n [] copy_process+0x29f3/0x7ff0\n [] kernel_clone+0xc0/0x650\n [] __do_sys_clone+0xa1/0xe0\n [] do_syscall_64+0xbf/0x1c0\n [] entry_SYSCALL_64_after_hwframe+0x4b/0x53",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-401"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-wmpx-6wwp-cvc6/GHSA-wmpx-6wwp-cvc6.json b/advisories/unreviewed/2024/12/GHSA-wmpx-6wwp-cvc6/GHSA-wmpx-6wwp-cvc6.json
index 8a5845f66cb..f3cf62959d0 100644
--- a/advisories/unreviewed/2024/12/GHSA-wmpx-6wwp-cvc6/GHSA-wmpx-6wwp-cvc6.json
+++ b/advisories/unreviewed/2024/12/GHSA-wmpx-6wwp-cvc6/GHSA-wmpx-6wwp-cvc6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmpx-6wwp-cvc6",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-02-03T15:32:00Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53239"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: Release resources at card release\n\nThe current 6fire code tries to release the resources right after the\ncall of usb6fire_chip_abort(). But at this moment, the card object\nmight be still in use (as we're calling snd_card_free_when_closed()).\n\nFor avoid potential UAFs, move the release of resources to the card's\nprivate_free instead of the manual call of usb6fire_chip_destroy() at\nthe USB disconnect callback.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:32Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-xrf5-hv85-5f65/GHSA-xrf5-hv85-5f65.json b/advisories/unreviewed/2024/12/GHSA-xrf5-hv85-5f65/GHSA-xrf5-hv85-5f65.json
index 0aee4b032e0..e4c3fcf4932 100644
--- a/advisories/unreviewed/2024/12/GHSA-xrf5-hv85-5f65/GHSA-xrf5-hv85-5f65.json
+++ b/advisories/unreviewed/2024/12/GHSA-xrf5-hv85-5f65/GHSA-xrf5-hv85-5f65.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xrf5-hv85-5f65",
- "modified": "2024-12-27T15:31:53Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2024-12-27T15:31:53Z",
"aliases": [
"CVE-2024-56544"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudmabuf: change folios array from kmalloc to kvmalloc\n\nWhen PAGE_SIZE 4096, MAX_PAGE_ORDER 10, 64bit machine,\npage_alloc only support 4MB.\nIf above this, trigger this warn and return NULL.\n\nudmabuf can change size limit, if change it to 3072(3GB), and then alloc\n3GB udmabuf, will fail create.\n\n[ 4080.876581] ------------[ cut here ]------------\n[ 4080.876843] WARNING: CPU: 3 PID: 2015 at mm/page_alloc.c:4556 __alloc_pages+0x2c8/0x350\n[ 4080.878839] RIP: 0010:__alloc_pages+0x2c8/0x350\n[ 4080.879470] Call Trace:\n[ 4080.879473] \n[ 4080.879473] ? __alloc_pages+0x2c8/0x350\n[ 4080.879475] ? __warn.cold+0x8e/0xe8\n[ 4080.880647] ? __alloc_pages+0x2c8/0x350\n[ 4080.880909] ? report_bug+0xff/0x140\n[ 4080.881175] ? handle_bug+0x3c/0x80\n[ 4080.881556] ? exc_invalid_op+0x17/0x70\n[ 4080.881559] ? asm_exc_invalid_op+0x1a/0x20\n[ 4080.882077] ? udmabuf_create+0x131/0x400\n\nBecause MAX_PAGE_ORDER, kmalloc can max alloc 4096 * (1 << 10), 4MB\nmemory, each array entry is pointer(8byte), so can save 524288 pages(2GB).\n\nFurther more, costly order(order 3) may not be guaranteed that it can be\napplied for, due to fragmentation.\n\nThis patch change udmabuf array use kvmalloc_array, this can fallback\nalloc into vmalloc, which can guarantee allocation for any size and does\nnot affect the performance of kmalloc allocations.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:34Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-2767-g28h-69jv/GHSA-2767-g28h-69jv.json b/advisories/unreviewed/2025/01/GHSA-2767-g28h-69jv/GHSA-2767-g28h-69jv.json
index 1dfc721efec..49a2eba0bb9 100644
--- a/advisories/unreviewed/2025/01/GHSA-2767-g28h-69jv/GHSA-2767-g28h-69jv.json
+++ b/advisories/unreviewed/2025/01/GHSA-2767-g28h-69jv/GHSA-2767-g28h-69jv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2767-g28h-69jv",
- "modified": "2025-01-21T12:30:48Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-21T12:30:48Z",
"aliases": [
"CVE-2024-57934"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfgraph: Add READ_ONCE() when accessing fgraph_array[]\n\nIn __ftrace_return_to_handler(), a loop iterates over the fgraph_array[]\nelements, which are fgraph_ops. The loop checks if an element is a\nfgraph_stub to prevent using a fgraph_stub afterward.\n\nHowever, if the compiler reloads fgraph_array[] after this check, it might\nrace with an update to fgraph_array[] that introduces a fgraph_stub. This\ncould result in the stub being processed, but the stub contains a null\n\"func_hash\" field, leading to a NULL pointer dereference.\n\nTo ensure that the gops compared against the fgraph_stub matches the gops\nprocessed later, add a READ_ONCE(). A similar patch appears in commit\n63a8dfb (\"function_graph: Add READ_ONCE() when accessing fgraph_array[]\").",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-21T12:15:27Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-2w6v-cv9c-qwv2/GHSA-2w6v-cv9c-qwv2.json b/advisories/unreviewed/2025/01/GHSA-2w6v-cv9c-qwv2/GHSA-2w6v-cv9c-qwv2.json
index b360547e24c..492808ced21 100644
--- a/advisories/unreviewed/2025/01/GHSA-2w6v-cv9c-qwv2/GHSA-2w6v-cv9c-qwv2.json
+++ b/advisories/unreviewed/2025/01/GHSA-2w6v-cv9c-qwv2/GHSA-2w6v-cv9c-qwv2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2w6v-cv9c-qwv2",
- "modified": "2025-02-02T12:30:24Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-19T12:31:26Z",
"aliases": [
"CVE-2024-57911"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer\n\nThe 'data' array is allocated via kmalloc() and it is used to push data\nto user space from a triggered buffer, but it does not set values for\ninactive channels, as it only uses iio_for_each_active_channel()\nto assign new values.\n\nUse kzalloc for the memory allocation to avoid pushing uninitialized\ninformation to userspace.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-19T12:15:25Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json b/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json
index 93c03c50d73..5bed17ef067 100644
--- a/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json
+++ b/advisories/unreviewed/2025/01/GHSA-5xmq-mwgg-pjp2/GHSA-5xmq-mwgg-pjp2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xmq-mwgg-pjp2",
- "modified": "2025-01-22T18:31:55Z",
+ "modified": "2025-02-03T15:32:02Z",
"published": "2025-01-22T18:31:55Z",
"aliases": [
"CVE-2024-24429"
],
"details": "A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-617"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-22T16:15:28Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-5xr7-3q35-3j73/GHSA-5xr7-3q35-3j73.json b/advisories/unreviewed/2025/01/GHSA-5xr7-3q35-3j73/GHSA-5xr7-3q35-3j73.json
index 409cbb8255a..c1d4e0e255a 100644
--- a/advisories/unreviewed/2025/01/GHSA-5xr7-3q35-3j73/GHSA-5xr7-3q35-3j73.json
+++ b/advisories/unreviewed/2025/01/GHSA-5xr7-3q35-3j73/GHSA-5xr7-3q35-3j73.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xr7-3q35-3j73",
- "modified": "2025-01-16T00:31:22Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-16T00:31:22Z",
"aliases": [
"CVE-2024-39967"
],
"details": "Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-732"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-15T23:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-88gx-mvc3-9p77/GHSA-88gx-mvc3-9p77.json b/advisories/unreviewed/2025/01/GHSA-88gx-mvc3-9p77/GHSA-88gx-mvc3-9p77.json
index ebe04c97b45..d95443643ea 100644
--- a/advisories/unreviewed/2025/01/GHSA-88gx-mvc3-9p77/GHSA-88gx-mvc3-9p77.json
+++ b/advisories/unreviewed/2025/01/GHSA-88gx-mvc3-9p77/GHSA-88gx-mvc3-9p77.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88gx-mvc3-9p77",
- "modified": "2025-01-14T00:30:45Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-14T00:30:45Z",
"aliases": [
"CVE-2023-42234"
],
"details": "Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-13T22:15:11Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-9hcf-78cf-xwqv/GHSA-9hcf-78cf-xwqv.json b/advisories/unreviewed/2025/01/GHSA-9hcf-78cf-xwqv/GHSA-9hcf-78cf-xwqv.json
index c7cc5e8d636..3a2b02a5ec1 100644
--- a/advisories/unreviewed/2025/01/GHSA-9hcf-78cf-xwqv/GHSA-9hcf-78cf-xwqv.json
+++ b/advisories/unreviewed/2025/01/GHSA-9hcf-78cf-xwqv/GHSA-9hcf-78cf-xwqv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hcf-78cf-xwqv",
- "modified": "2025-01-27T06:30:26Z",
+ "modified": "2025-02-03T15:32:02Z",
"published": "2025-01-27T06:30:26Z",
"aliases": [
"CVE-2024-13117"
],
"details": "The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-27T06:15:23Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-9x94-vh8x-vrhp/GHSA-9x94-vh8x-vrhp.json b/advisories/unreviewed/2025/01/GHSA-9x94-vh8x-vrhp/GHSA-9x94-vh8x-vrhp.json
index 597b8933449..3f1e13acf3b 100644
--- a/advisories/unreviewed/2025/01/GHSA-9x94-vh8x-vrhp/GHSA-9x94-vh8x-vrhp.json
+++ b/advisories/unreviewed/2025/01/GHSA-9x94-vh8x-vrhp/GHSA-9x94-vh8x-vrhp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x94-vh8x-vrhp",
- "modified": "2025-01-11T15:30:29Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:29Z",
"aliases": [
"CVE-2024-57798"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req()\n\nWhile receiving an MST up request message from one thread in\ndrm_dp_mst_handle_up_req(), the MST topology could be removed from\nanother thread via drm_dp_mst_topology_mgr_set_mst(false), freeing\nmst_primary and setting drm_dp_mst_topology_mgr::mst_primary to NULL.\nThis could lead to a NULL deref/use-after-free of mst_primary in\ndrm_dp_mst_handle_up_req().\n\nAvoid the above by holding a reference for mst_primary in\ndrm_dp_mst_handle_up_req() while it's used.\n\nv2: Fix kfreeing the request if getting an mst_primary reference fails.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:29Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-g29r-ch4v-q6cx/GHSA-g29r-ch4v-q6cx.json b/advisories/unreviewed/2025/01/GHSA-g29r-ch4v-q6cx/GHSA-g29r-ch4v-q6cx.json
index ff61bbf1295..209a2c60bbf 100644
--- a/advisories/unreviewed/2025/01/GHSA-g29r-ch4v-q6cx/GHSA-g29r-ch4v-q6cx.json
+++ b/advisories/unreviewed/2025/01/GHSA-g29r-ch4v-q6cx/GHSA-g29r-ch4v-q6cx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g29r-ch4v-q6cx",
- "modified": "2025-01-11T15:30:28Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:28Z",
"aliases": [
"CVE-2024-47143"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-debug: fix a possible deadlock on radix_lock\n\nradix_lock() shouldn't be held while holding dma_hash_entry[idx].lock\notherwise, there's a possible deadlock scenario when\ndma debug API is called holding rq_lock():\n\nCPU0 CPU1 CPU2\ndma_free_attrs()\ncheck_unmap() add_dma_entry() __schedule() //out\n (A) rq_lock()\nget_hash_bucket()\n(A) dma_entry_hash\n check_sync()\n (A) radix_lock() (W) dma_entry_hash\ndma_entry_free()\n(W) radix_lock()\n // CPU2's one\n (W) rq_lock()\n\nCPU1 situation can happen when it extending radix tree and\nit tries to wake up kswapd via wake_all_kswapd().\n\nCPU2 situation can happen while perf_event_task_sched_out()\n(i.e. dma sync operation is called while deleting perf_event using\n etm and etr tmc which are Arm Coresight hwtracing driver backends).\n\nTo remove this possible situation, call dma_entry_free() after\nput_hash_bucket() in check_unmap().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:22Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-g6f8-f8f2-6wh5/GHSA-g6f8-f8f2-6wh5.json b/advisories/unreviewed/2025/01/GHSA-g6f8-f8f2-6wh5/GHSA-g6f8-f8f2-6wh5.json
index 472bdcc63d4..3ca972250dc 100644
--- a/advisories/unreviewed/2025/01/GHSA-g6f8-f8f2-6wh5/GHSA-g6f8-f8f2-6wh5.json
+++ b/advisories/unreviewed/2025/01/GHSA-g6f8-f8f2-6wh5/GHSA-g6f8-f8f2-6wh5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g6f8-f8f2-6wh5",
- "modified": "2025-01-11T15:30:27Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:27Z",
"aliases": [
"CVE-2024-43098"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock\n\nA deadlock may happen since the i3c_master_register() acquires\n&i3cbus->lock twice. See the log below.\nUse i3cdev->desc->info instead of calling i3c_device_info() to\navoid acquiring the lock twice.\n\nv2:\n - Modified the title and commit message\n\n============================================\nWARNING: possible recursive locking detected\n6.11.0-mainline\n--------------------------------------------\ninit/1 is trying to acquire lock:\nf1ffff80a6a40dc0 (&i3cbus->lock){++++}-{3:3}, at: i3c_bus_normaluse_lock\n\nbut task is already holding lock:\nf1ffff80a6a40dc0 (&i3cbus->lock){++++}-{3:3}, at: i3c_master_register\n\nother info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(&i3cbus->lock);\n lock(&i3cbus->lock);\n\n *** DEADLOCK ***\n\n May be due to missing lock nesting notation\n\n2 locks held by init/1:\n #0: fcffff809b6798f8 (&dev->mutex){....}-{3:3}, at: __driver_attach\n #1: f1ffff80a6a40dc0 (&i3cbus->lock){++++}-{3:3}, at: i3c_master_register\n\nstack backtrace:\nCPU: 6 UID: 0 PID: 1 Comm: init\nCall trace:\n dump_backtrace+0xfc/0x17c\n show_stack+0x18/0x28\n dump_stack_lvl+0x40/0xc0\n dump_stack+0x18/0x24\n print_deadlock_bug+0x388/0x390\n __lock_acquire+0x18bc/0x32ec\n lock_acquire+0x134/0x2b0\n down_read+0x50/0x19c\n i3c_bus_normaluse_lock+0x14/0x24\n i3c_device_get_info+0x24/0x58\n i3c_device_uevent+0x34/0xa4\n dev_uevent+0x310/0x384\n kobject_uevent_env+0x244/0x414\n kobject_uevent+0x14/0x20\n device_add+0x278/0x460\n device_register+0x20/0x34\n i3c_master_register_new_i3c_devs+0x78/0x154\n i3c_master_register+0x6a0/0x6d4\n mtk_i3c_master_probe+0x3b8/0x4d8\n platform_probe+0xa0/0xe0\n really_probe+0x114/0x454\n __driver_probe_device+0xa0/0x15c\n driver_probe_device+0x3c/0x1ac\n __driver_attach+0xc4/0x1f0\n bus_for_each_dev+0x104/0x160\n driver_attach+0x24/0x34\n bus_add_driver+0x14c/0x294\n driver_register+0x68/0x104\n __platform_driver_register+0x20/0x30\n init_module+0x20/0xfe4\n do_one_initcall+0x184/0x464\n do_init_module+0x58/0x1ec\n load_module+0xefc/0x10c8\n __arm64_sys_finit_module+0x238/0x33c\n invoke_syscall+0x58/0x10c\n el0_svc_common+0xa8/0xdc\n do_el0_svc+0x1c/0x28\n el0_svc+0x50/0xac\n el0t_64_sync_handler+0x70/0xbc\n el0t_64_sync+0x1a8/0x1ac",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:21Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-hg9v-mfmx-jx2x/GHSA-hg9v-mfmx-jx2x.json b/advisories/unreviewed/2025/01/GHSA-hg9v-mfmx-jx2x/GHSA-hg9v-mfmx-jx2x.json
index 48f3bf33648..53570366797 100644
--- a/advisories/unreviewed/2025/01/GHSA-hg9v-mfmx-jx2x/GHSA-hg9v-mfmx-jx2x.json
+++ b/advisories/unreviewed/2025/01/GHSA-hg9v-mfmx-jx2x/GHSA-hg9v-mfmx-jx2x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hg9v-mfmx-jx2x",
- "modified": "2025-01-11T15:30:28Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:28Z",
"aliases": [
"CVE-2024-48875"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't take dev_replace rwsem on task already holding it\n\nRunning fstests btrfs/011 with MKFS_OPTIONS=\"-O rst\" to force the usage of\nthe RAID stripe-tree, we get the following splat from lockdep:\n\n BTRFS info (device sdd): dev_replace from /dev/sdd (devid 1) to /dev/sdb started\n\n ============================================\n WARNING: possible recursive locking detected\n 6.11.0-rc3-btrfs-for-next #599 Not tainted\n --------------------------------------------\n btrfs/2326 is trying to acquire lock:\n ffff88810f215c98 (&fs_info->dev_replace.rwsem){++++}-{3:3}, at: btrfs_map_block+0x39f/0x2250\n\n but task is already holding lock:\n ffff88810f215c98 (&fs_info->dev_replace.rwsem){++++}-{3:3}, at: btrfs_map_block+0x39f/0x2250\n\n other info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(&fs_info->dev_replace.rwsem);\n lock(&fs_info->dev_replace.rwsem);\n\n *** DEADLOCK ***\n\n May be due to missing lock nesting notation\n\n 1 lock held by btrfs/2326:\n #0: ffff88810f215c98 (&fs_info->dev_replace.rwsem){++++}-{3:3}, at: btrfs_map_block+0x39f/0x2250\n\n stack backtrace:\n CPU: 1 UID: 0 PID: 2326 Comm: btrfs Not tainted 6.11.0-rc3-btrfs-for-next #599\n Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n Call Trace:\n \n dump_stack_lvl+0x5b/0x80\n __lock_acquire+0x2798/0x69d0\n ? __pfx___lock_acquire+0x10/0x10\n ? __pfx___lock_acquire+0x10/0x10\n lock_acquire+0x19d/0x4a0\n ? btrfs_map_block+0x39f/0x2250\n ? __pfx_lock_acquire+0x10/0x10\n ? find_held_lock+0x2d/0x110\n ? lock_is_held_type+0x8f/0x100\n down_read+0x8e/0x440\n ? btrfs_map_block+0x39f/0x2250\n ? __pfx_down_read+0x10/0x10\n ? do_raw_read_unlock+0x44/0x70\n ? _raw_read_unlock+0x23/0x40\n btrfs_map_block+0x39f/0x2250\n ? btrfs_dev_replace_by_ioctl+0xd69/0x1d00\n ? btrfs_bio_counter_inc_blocked+0xd9/0x2e0\n ? __kasan_slab_alloc+0x6e/0x70\n ? __pfx_btrfs_map_block+0x10/0x10\n ? __pfx_btrfs_bio_counter_inc_blocked+0x10/0x10\n ? kmem_cache_alloc_noprof+0x1f2/0x300\n ? mempool_alloc_noprof+0xed/0x2b0\n btrfs_submit_chunk+0x28d/0x17e0\n ? __pfx_btrfs_submit_chunk+0x10/0x10\n ? bvec_alloc+0xd7/0x1b0\n ? bio_add_folio+0x171/0x270\n ? __pfx_bio_add_folio+0x10/0x10\n ? __kasan_check_read+0x20/0x20\n btrfs_submit_bio+0x37/0x80\n read_extent_buffer_pages+0x3df/0x6c0\n btrfs_read_extent_buffer+0x13e/0x5f0\n read_tree_block+0x81/0xe0\n read_block_for_search+0x4bd/0x7a0\n ? __pfx_read_block_for_search+0x10/0x10\n btrfs_search_slot+0x78d/0x2720\n ? __pfx_btrfs_search_slot+0x10/0x10\n ? lock_is_held_type+0x8f/0x100\n ? kasan_save_track+0x14/0x30\n ? __kasan_slab_alloc+0x6e/0x70\n ? kmem_cache_alloc_noprof+0x1f2/0x300\n btrfs_get_raid_extent_offset+0x181/0x820\n ? __pfx_lock_acquire+0x10/0x10\n ? __pfx_btrfs_get_raid_extent_offset+0x10/0x10\n ? down_read+0x194/0x440\n ? __pfx_down_read+0x10/0x10\n ? do_raw_read_unlock+0x44/0x70\n ? _raw_read_unlock+0x23/0x40\n btrfs_map_block+0x5b5/0x2250\n ? __pfx_btrfs_map_block+0x10/0x10\n scrub_submit_initial_read+0x8fe/0x11b0\n ? __pfx_scrub_submit_initial_read+0x10/0x10\n submit_initial_group_read+0x161/0x3a0\n ? lock_release+0x20e/0x710\n ? __pfx_submit_initial_group_read+0x10/0x10\n ? __pfx_lock_release+0x10/0x10\n scrub_simple_mirror.isra.0+0x3eb/0x580\n scrub_stripe+0xe4d/0x1440\n ? lock_release+0x20e/0x710\n ? __pfx_scrub_stripe+0x10/0x10\n ? __pfx_lock_release+0x10/0x10\n ? do_raw_read_unlock+0x44/0x70\n ? _raw_read_unlock+0x23/0x40\n scrub_chunk+0x257/0x4a0\n scrub_enumerate_chunks+0x64c/0xf70\n ? __mutex_unlock_slowpath+0x147/0x5f0\n ? __pfx_scrub_enumerate_chunks+0x10/0x10\n ? bit_wait_timeout+0xb0/0x170\n ? __up_read+0x189/0x700\n ? scrub_workers_get+0x231/0x300\n ? up_write+0x490/0x4f0\n btrfs_scrub_dev+0x52e/0xcd0\n ? create_pending_snapshots+0x230/0x250\n ? __pfx_btrfs_scrub_dev+0x10/0x10\n btrfs_dev_replace_by_ioctl+0xd69/0x1d00\n ? lock_acquire+0x19d/0x4a0\n ? __pfx_btrfs_dev_replace_by_ioctl+0x10/0x10\n ?\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:22Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-p277-wqpc-75vw/GHSA-p277-wqpc-75vw.json b/advisories/unreviewed/2025/01/GHSA-p277-wqpc-75vw/GHSA-p277-wqpc-75vw.json
index 3624b9bc776..0991ea2b6d6 100644
--- a/advisories/unreviewed/2025/01/GHSA-p277-wqpc-75vw/GHSA-p277-wqpc-75vw.json
+++ b/advisories/unreviewed/2025/01/GHSA-p277-wqpc-75vw/GHSA-p277-wqpc-75vw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p277-wqpc-75vw",
- "modified": "2025-01-19T12:31:26Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-19T12:31:26Z",
"aliases": [
"CVE-2025-21652"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvlan: Fix use-after-free in ipvlan_get_iflink().\n\nsyzbot presented an use-after-free report [0] regarding ipvlan and\nlinkwatch.\n\nipvlan does not hold a refcnt of the lower device unlike vlan and\nmacvlan.\n\nIf the linkwatch work is triggered for the ipvlan dev, the lower dev\nmight have already been freed, resulting in UAF of ipvlan->phy_dev in\nipvlan_get_iflink().\n\nWe can delay the lower dev unregistration like vlan and macvlan by\nholding the lower dev's refcnt in dev->netdev_ops->ndo_init() and\nreleasing it in dev->priv_destructor().\n\nJakub pointed out calling .ndo_XXX after unregister_netdevice() has\nreturned is error prone and suggested [1] addressing this UAF in the\ncore by taking commit 750e51603395 (\"net: avoid potential UAF in\ndefault_operstate()\") further.\n\nLet's assume unregistering devices DOWN and use RCU protection in\ndefault_operstate() not to race with the device unregistration.\n\n[0]:\nBUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353\nRead of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944\n\nCPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47\nHardware name: linux,dummy-virt (DT)\nWorkqueue: events_unbound linkwatch_event\nCall trace:\n show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xbc/0x108 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x16c/0x6f0 mm/kasan/report.c:489\n kasan_report+0xc0/0x120 mm/kasan/report.c:602\n __asan_report_load4_noabort+0x20/0x30 mm/kasan/report_generic.c:380\n ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353\n dev_get_iflink+0x7c/0xd8 net/core/dev.c:674\n default_operstate net/core/link_watch.c:45 [inline]\n rfc2863_policy+0x144/0x360 net/core/link_watch.c:72\n linkwatch_do_dev+0x60/0x228 net/core/link_watch.c:175\n __linkwatch_run_queue+0x2f4/0x5b8 net/core/link_watch.c:239\n linkwatch_event+0x64/0xa8 net/core/link_watch.c:282\n process_one_work+0x700/0x1398 kernel/workqueue.c:3229\n process_scheduled_works kernel/workqueue.c:3310 [inline]\n worker_thread+0x8c4/0xe10 kernel/workqueue.c:3391\n kthread+0x2b0/0x360 kernel/kthread.c:389\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:862\n\nAllocated by task 9303:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x30/0x68 mm/kasan/common.c:68\n kasan_save_alloc_info+0x44/0x58 mm/kasan/generic.c:568\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x84/0xa0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4283 [inline]\n __kmalloc_node_noprof+0x2a0/0x560 mm/slub.c:4289\n __kvmalloc_node_noprof+0x9c/0x230 mm/util.c:650\n alloc_netdev_mqs+0xb4/0x1118 net/core/dev.c:11209\n rtnl_create_link+0x2b8/0xb60 net/core/rtnetlink.c:3595\n rtnl_newlink_create+0x19c/0x868 net/core/rtnetlink.c:3771\n __rtnl_newlink net/core/rtnetlink.c:3896 [inline]\n rtnl_newlink+0x122c/0x15c0 net/core/rtnetlink.c:4011\n rtnetlink_rcv_msg+0x61c/0x918 net/core/rtnetlink.c:6901\n netlink_rcv_skb+0x1dc/0x398 net/netlink/af_netlink.c:2542\n rtnetlink_rcv+0x34/0x50 net/core/rtnetlink.c:6928\n netlink_unicast_kernel net/netlink/af_netlink.c:1321 [inline]\n netlink_unicast+0x618/0x838 net/netlink/af_netlink.c:1347\n netlink_sendmsg+0x5fc/0x8b0 net/netlink/af_netlink.c:1891\n sock_sendmsg_nosec net/socket.c:711 [inline]\n __sock_sendmsg net/socket.c:726 [inline]\n __sys_sendto+0x2ec/0x438 net/socket.c:2197\n __do_sys_sendto net/socket.c:2204 [inline]\n __se_sys_sendto net/socket.c:2200 [inline]\n __arm64_sys_sendto+0xe4/0x110 net/socket.c:2200\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x90/0x278 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x13c/0x250 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x54/0x70 arch/arm64/kernel/syscall.c:151\n el\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-19T11:15:10Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json b/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json
index da460e57cde..f95d28d0843 100644
--- a/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json
+++ b/advisories/unreviewed/2025/01/GHSA-q8x5-7v94-rwpv/GHSA-q8x5-7v94-rwpv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8x5-7v94-rwpv",
- "modified": "2025-01-22T18:31:55Z",
+ "modified": "2025-02-03T15:32:02Z",
"published": "2025-01-22T18:31:55Z",
"aliases": [
"CVE-2024-10929"
],
"details": "In certain circumstances, an issue in Arm Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-22T16:15:28Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-qq8g-3hpq-mq34/GHSA-qq8g-3hpq-mq34.json b/advisories/unreviewed/2025/01/GHSA-qq8g-3hpq-mq34/GHSA-qq8g-3hpq-mq34.json
index 26a52d3a727..7a02bdc41fe 100644
--- a/advisories/unreviewed/2025/01/GHSA-qq8g-3hpq-mq34/GHSA-qq8g-3hpq-mq34.json
+++ b/advisories/unreviewed/2025/01/GHSA-qq8g-3hpq-mq34/GHSA-qq8g-3hpq-mq34.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qq8g-3hpq-mq34",
- "modified": "2025-01-11T15:30:28Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:28Z",
"aliases": [
"CVE-2024-50051"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mpc52xx: Add cancel_work_sync before module remove\n\nIf we remove the module which will call mpc52xx_spi_remove\nit will free 'ms' through spi_unregister_controller.\nwhile the work ms->work will be used. The sequence of operations\nthat may lead to a UAF bug.\n\nFix it by ensuring that the work is canceled before proceeding with\nthe cleanup in mpc52xx_spi_remove.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:24Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-rhj2-5xgx-23p4/GHSA-rhj2-5xgx-23p4.json b/advisories/unreviewed/2025/01/GHSA-rhj2-5xgx-23p4/GHSA-rhj2-5xgx-23p4.json
index fd5a1e2cf9c..12ede98fdd1 100644
--- a/advisories/unreviewed/2025/01/GHSA-rhj2-5xgx-23p4/GHSA-rhj2-5xgx-23p4.json
+++ b/advisories/unreviewed/2025/01/GHSA-rhj2-5xgx-23p4/GHSA-rhj2-5xgx-23p4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhj2-5xgx-23p4",
- "modified": "2025-01-17T00:30:49Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-17T00:30:49Z",
"aliases": [
"CVE-2024-40513"
],
"details": "An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-434"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-16T23:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-rwgg-m734-wvjr/GHSA-rwgg-m734-wvjr.json b/advisories/unreviewed/2025/01/GHSA-rwgg-m734-wvjr/GHSA-rwgg-m734-wvjr.json
index 6335cb29685..ffb4cbdda81 100644
--- a/advisories/unreviewed/2025/01/GHSA-rwgg-m734-wvjr/GHSA-rwgg-m734-wvjr.json
+++ b/advisories/unreviewed/2025/01/GHSA-rwgg-m734-wvjr/GHSA-rwgg-m734-wvjr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwgg-m734-wvjr",
- "modified": "2025-02-02T12:30:24Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-19T12:31:26Z",
"aliases": [
"CVE-2024-57910"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: vcnl4035: fix information leak in triggered buffer\n\nThe 'buffer' local array is used to push data to userspace from a\ntriggered buffer, but it does not set an initial value for the single\ndata element, which is an u16 aligned to 8 bytes. That leaves at least\n4 bytes uninitialized even after writing an integer value with\nregmap_read().\n\nInitialize the array to zero before using it to avoid pushing\nuninitialized information to userspace.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-19T12:15:25Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json b/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json
index 1c5679be00e..145d3e185ae 100644
--- a/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json
+++ b/advisories/unreviewed/2025/01/GHSA-v3w4-79rw-r73c/GHSA-v3w4-79rw-r73c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3w4-79rw-r73c",
- "modified": "2025-01-27T06:30:26Z",
+ "modified": "2025-02-03T15:32:02Z",
"published": "2025-01-27T06:30:26Z",
"aliases": [
"CVE-2024-13116"
],
"details": "The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-27T06:15:23Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-v62x-6v8m-46vv/GHSA-v62x-6v8m-46vv.json b/advisories/unreviewed/2025/01/GHSA-v62x-6v8m-46vv/GHSA-v62x-6v8m-46vv.json
index eba1b1d9578..c0227674010 100644
--- a/advisories/unreviewed/2025/01/GHSA-v62x-6v8m-46vv/GHSA-v62x-6v8m-46vv.json
+++ b/advisories/unreviewed/2025/01/GHSA-v62x-6v8m-46vv/GHSA-v62x-6v8m-46vv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v62x-6v8m-46vv",
- "modified": "2025-01-19T12:31:24Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-19T12:31:24Z",
"aliases": [
"CVE-2025-21634"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: remove kernfs active break\n\nA warning was found:\n\nWARNING: CPU: 10 PID: 3486953 at fs/kernfs/file.c:828\nCPU: 10 PID: 3486953 Comm: rmdir Kdump: loaded Tainted: G\nRIP: 0010:kernfs_should_drain_open_files+0x1a1/0x1b0\nRSP: 0018:ffff8881107ef9e0 EFLAGS: 00010202\nRAX: 0000000080000002 RBX: ffff888154738c00 RCX: dffffc0000000000\nRDX: 0000000000000007 RSI: 0000000000000004 RDI: ffff888154738c04\nRBP: ffff888154738c04 R08: ffffffffaf27fa15 R09: ffffed102a8e7180\nR10: ffff888154738c07 R11: 0000000000000000 R12: ffff888154738c08\nR13: ffff888750f8c000 R14: ffff888750f8c0e8 R15: ffff888154738ca0\nFS: 00007f84cd0be740(0000) GS:ffff8887ddc00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000555f9fbe00c8 CR3: 0000000153eec001 CR4: 0000000000370ee0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n kernfs_drain+0x15e/0x2f0\n __kernfs_remove+0x165/0x300\n kernfs_remove_by_name_ns+0x7b/0xc0\n cgroup_rm_file+0x154/0x1c0\n cgroup_addrm_files+0x1c2/0x1f0\n css_clear_dir+0x77/0x110\n kill_css+0x4c/0x1b0\n cgroup_destroy_locked+0x194/0x380\n cgroup_rmdir+0x2a/0x140\n\nIt can be explained by:\nrmdir \t\t\t\techo 1 > cpuset.cpus\n\t\t\t\tkernfs_fop_write_iter // active=0\ncgroup_rm_file\nkernfs_remove_by_name_ns\tkernfs_get_active // active=1\n__kernfs_remove\t\t\t\t\t // active=0x80000002\nkernfs_drain\t\t\tcpuset_write_resmask\nwait_event\n//waiting (active == 0x80000001)\n\t\t\t\tkernfs_break_active_protection\n\t\t\t\t// active = 0x80000001\n// continue\n\t\t\t\tkernfs_unbreak_active_protection\n\t\t\t\t// active = 0x80000002\n...\nkernfs_should_drain_open_files\n// warning occurs\n\t\t\t\tkernfs_put_active\n\nThis warning is caused by 'kernfs_break_active_protection' when it is\nwriting to cpuset.cpus, and the cgroup is removed concurrently.\n\nThe commit 3a5a6d0c2b03 (\"cpuset: don't nest cgroup_mutex inside\nget_online_cpus()\") made cpuset_hotplug_workfn asynchronous, This change\ninvolves calling flush_work(), which can create a multiple processes\ncircular locking dependency that involve cgroup_mutex, potentially leading\nto a deadlock. To avoid deadlock. the commit 76bb5ab8f6e3 (\"cpuset: break\nkernfs active protection in cpuset_write_resmask()\") added\n'kernfs_break_active_protection' in the cpuset_write_resmask. This could\nlead to this warning.\n\nAfter the commit 2125c0034c5d (\"cgroup/cpuset: Make cpuset hotplug\nprocessing synchronous\"), the cpuset_write_resmask no longer needs to\nwait the hotplug to finish, which means that concurrent hotplug and cpuset\noperations are no longer possible. Therefore, the deadlock doesn't exist\nanymore and it does not have to 'break active protection' now. To fix this\nwarning, just remove kernfs_break_active_protection operation in the\n'cpuset_write_resmask'.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-19T11:15:08Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-w46c-ww47-4hf8/GHSA-w46c-ww47-4hf8.json b/advisories/unreviewed/2025/01/GHSA-w46c-ww47-4hf8/GHSA-w46c-ww47-4hf8.json
index 54d6c1f0df3..51d7f74e926 100644
--- a/advisories/unreviewed/2025/01/GHSA-w46c-ww47-4hf8/GHSA-w46c-ww47-4hf8.json
+++ b/advisories/unreviewed/2025/01/GHSA-w46c-ww47-4hf8/GHSA-w46c-ww47-4hf8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w46c-ww47-4hf8",
- "modified": "2025-01-11T15:30:30Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:30Z",
"aliases": [
"CVE-2024-57878"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR\n\nCurrently fpmr_set() doesn't initialize the temporary 'fpmr' variable,\nand a SETREGSET call with a length of zero will leave this\nuninitialized. Consequently an arbitrary value will be written back to\ntarget->thread.uw.fpmr, potentially leaking up to 64 bits of memory from\nthe kernel stack. The read is limited to a specific slot on the stack,\nand the issue does not provide a write mechanism.\n\nFix this by initializing the temporary value before copying the regset\nfrom userspace, as for other regsets (e.g. NT_PRSTATUS, NT_PRFPREG,\nNT_ARM_SYSTEM_CALL). In the case of a zero-length write, the existing\ncontents of FPMR will be retained.\n\nBefore this patch:\n\n| # ./fpmr-test\n| Attempting to write NT_ARM_FPMR::fpmr = 0x900d900d900d900d\n| SETREGSET(nt=0x40e, len=8) wrote 8 bytes\n|\n| Attempting to read NT_ARM_FPMR::fpmr\n| GETREGSET(nt=0x40e, len=8) read 8 bytes\n| Read NT_ARM_FPMR::fpmr = 0x900d900d900d900d\n|\n| Attempting to write NT_ARM_FPMR (zero length)\n| SETREGSET(nt=0x40e, len=0) wrote 0 bytes\n|\n| Attempting to read NT_ARM_FPMR::fpmr\n| GETREGSET(nt=0x40e, len=8) read 8 bytes\n| Read NT_ARM_FPMR::fpmr = 0xffff800083963d50\n\nAfter this patch:\n\n| # ./fpmr-test\n| Attempting to write NT_ARM_FPMR::fpmr = 0x900d900d900d900d\n| SETREGSET(nt=0x40e, len=8) wrote 8 bytes\n|\n| Attempting to read NT_ARM_FPMR::fpmr\n| GETREGSET(nt=0x40e, len=8) read 8 bytes\n| Read NT_ARM_FPMR::fpmr = 0x900d900d900d900d\n|\n| Attempting to write NT_ARM_FPMR (zero length)\n| SETREGSET(nt=0x40e, len=0) wrote 0 bytes\n|\n| Attempting to read NT_ARM_FPMR::fpmr\n| GETREGSET(nt=0x40e, len=8) read 8 bytes\n| Read NT_ARM_FPMR::fpmr = 0x900d900d900d900d",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T15:15:08Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-x69f-qgv5-6pgg/GHSA-x69f-qgv5-6pgg.json b/advisories/unreviewed/2025/01/GHSA-x69f-qgv5-6pgg/GHSA-x69f-qgv5-6pgg.json
index 77352dad9d5..3416f443f8b 100644
--- a/advisories/unreviewed/2025/01/GHSA-x69f-qgv5-6pgg/GHSA-x69f-qgv5-6pgg.json
+++ b/advisories/unreviewed/2025/01/GHSA-x69f-qgv5-6pgg/GHSA-x69f-qgv5-6pgg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x69f-qgv5-6pgg",
- "modified": "2025-01-23T18:31:17Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-19T12:31:24Z",
"aliases": [
"CVE-2025-21631"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix waker_bfqq UAF after bfq_split_bfqq()\n\nOur syzkaller report a following UAF for v6.6:\n\nBUG: KASAN: slab-use-after-free in bfq_init_rq+0x175d/0x17a0 block/bfq-iosched.c:6958\nRead of size 8 at addr ffff8881b57147d8 by task fsstress/232726\n\nCPU: 2 PID: 232726 Comm: fsstress Not tainted 6.6.0-g3629d1885222 #39\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x91/0xf0 lib/dump_stack.c:106\n print_address_description.constprop.0+0x66/0x300 mm/kasan/report.c:364\n print_report+0x3e/0x70 mm/kasan/report.c:475\n kasan_report+0xb8/0xf0 mm/kasan/report.c:588\n hlist_add_head include/linux/list.h:1023 [inline]\n bfq_init_rq+0x175d/0x17a0 block/bfq-iosched.c:6958\n bfq_insert_request.isra.0+0xe8/0xa20 block/bfq-iosched.c:6271\n bfq_insert_requests+0x27f/0x390 block/bfq-iosched.c:6323\n blk_mq_insert_request+0x290/0x8f0 block/blk-mq.c:2660\n blk_mq_submit_bio+0x1021/0x15e0 block/blk-mq.c:3143\n __submit_bio+0xa0/0x6b0 block/blk-core.c:639\n __submit_bio_noacct_mq block/blk-core.c:718 [inline]\n submit_bio_noacct_nocheck+0x5b7/0x810 block/blk-core.c:747\n submit_bio_noacct+0xca0/0x1990 block/blk-core.c:847\n __ext4_read_bh fs/ext4/super.c:205 [inline]\n ext4_read_bh+0x15e/0x2e0 fs/ext4/super.c:230\n __read_extent_tree_block+0x304/0x6f0 fs/ext4/extents.c:567\n ext4_find_extent+0x479/0xd20 fs/ext4/extents.c:947\n ext4_ext_map_blocks+0x1a3/0x2680 fs/ext4/extents.c:4182\n ext4_map_blocks+0x929/0x15a0 fs/ext4/inode.c:660\n ext4_iomap_begin_report+0x298/0x480 fs/ext4/inode.c:3569\n iomap_iter+0x3dd/0x1010 fs/iomap/iter.c:91\n iomap_fiemap+0x1f4/0x360 fs/iomap/fiemap.c:80\n ext4_fiemap+0x181/0x210 fs/ext4/extents.c:5051\n ioctl_fiemap.isra.0+0x1b4/0x290 fs/ioctl.c:220\n do_vfs_ioctl+0x31c/0x11a0 fs/ioctl.c:811\n __do_sys_ioctl fs/ioctl.c:869 [inline]\n __se_sys_ioctl+0xae/0x190 fs/ioctl.c:857\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x70/0x120 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x78/0xe2\n\nAllocated by task 232719:\n kasan_save_stack+0x22/0x50 mm/kasan/common.c:45\n kasan_set_track+0x25/0x30 mm/kasan/common.c:52\n __kasan_slab_alloc+0x87/0x90 mm/kasan/common.c:328\n kasan_slab_alloc include/linux/kasan.h:188 [inline]\n slab_post_alloc_hook mm/slab.h:768 [inline]\n slab_alloc_node mm/slub.c:3492 [inline]\n kmem_cache_alloc_node+0x1b8/0x6f0 mm/slub.c:3537\n bfq_get_queue+0x215/0x1f00 block/bfq-iosched.c:5869\n bfq_get_bfqq_handle_split+0x167/0x5f0 block/bfq-iosched.c:6776\n bfq_init_rq+0x13a4/0x17a0 block/bfq-iosched.c:6938\n bfq_insert_request.isra.0+0xe8/0xa20 block/bfq-iosched.c:6271\n bfq_insert_requests+0x27f/0x390 block/bfq-iosched.c:6323\n blk_mq_insert_request+0x290/0x8f0 block/blk-mq.c:2660\n blk_mq_submit_bio+0x1021/0x15e0 block/blk-mq.c:3143\n __submit_bio+0xa0/0x6b0 block/blk-core.c:639\n __submit_bio_noacct_mq block/blk-core.c:718 [inline]\n submit_bio_noacct_nocheck+0x5b7/0x810 block/blk-core.c:747\n submit_bio_noacct+0xca0/0x1990 block/blk-core.c:847\n __ext4_read_bh fs/ext4/super.c:205 [inline]\n ext4_read_bh_nowait+0x15a/0x240 fs/ext4/super.c:217\n ext4_read_bh_lock+0xac/0xd0 fs/ext4/super.c:242\n ext4_bread_batch+0x268/0x500 fs/ext4/inode.c:958\n __ext4_find_entry+0x448/0x10f0 fs/ext4/namei.c:1671\n ext4_lookup_entry fs/ext4/namei.c:1774 [inline]\n ext4_lookup.part.0+0x359/0x6f0 fs/ext4/namei.c:1842\n ext4_lookup+0x72/0x90 fs/ext4/namei.c:1839\n __lookup_slow+0x257/0x480 fs/namei.c:1696\n lookup_slow fs/namei.c:1713 [inline]\n walk_component+0x454/0x5c0 fs/namei.c:2004\n link_path_walk.part.0+0x773/0xda0 fs/namei.c:2331\n link_path_walk fs/namei.c:3826 [inline]\n path_openat+0x1b9/0x520 fs/namei.c:3826\n do_filp_open+0x1b7/0x400 fs/namei.c:3857\n do_sys_openat2+0x5dc/0x6e0 fs/open.c:1428\n do_sys_open fs/open.c:1443 [inline]\n __do_sys_openat fs/open.c:1459 [inline]\n __se_sys_openat fs/open.c:1454 [inline]\n __x64_sys_openat+0x148/0x200 fs/open.c:1454\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_6\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-19T11:15:07Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-xfvh-9mxf-99vm/GHSA-xfvh-9mxf-99vm.json b/advisories/unreviewed/2025/01/GHSA-xfvh-9mxf-99vm/GHSA-xfvh-9mxf-99vm.json
index f57b6685644..722e7e733b3 100644
--- a/advisories/unreviewed/2025/01/GHSA-xfvh-9mxf-99vm/GHSA-xfvh-9mxf-99vm.json
+++ b/advisories/unreviewed/2025/01/GHSA-xfvh-9mxf-99vm/GHSA-xfvh-9mxf-99vm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfvh-9mxf-99vm",
- "modified": "2025-01-11T15:30:30Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:29Z",
"aliases": [
"CVE-2024-57877"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: ptrace: fix partial SETREGSET for NT_ARM_POE\n\nCurrently poe_set() doesn't initialize the temporary 'ctrl' variable,\nand a SETREGSET call with a length of zero will leave this\nuninitialized. Consequently an arbitrary value will be written back to\ntarget->thread.por_el0, potentially leaking up to 64 bits of memory from\nthe kernel stack. The read is limited to a specific slot on the stack,\nand the issue does not provide a write mechanism.\n\nFix this by initializing the temporary value before copying the regset\nfrom userspace, as for other regsets (e.g. NT_PRSTATUS, NT_PRFPREG,\nNT_ARM_SYSTEM_CALL). In the case of a zero-length write, the existing\ncontents of POR_EL1 will be retained.\n\nBefore this patch:\n\n| # ./poe-test\n| Attempting to write NT_ARM_POE::por_el0 = 0x900d900d900d900d\n| SETREGSET(nt=0x40f, len=8) wrote 8 bytes\n|\n| Attempting to read NT_ARM_POE::por_el0\n| GETREGSET(nt=0x40f, len=8) read 8 bytes\n| Read NT_ARM_POE::por_el0 = 0x900d900d900d900d\n|\n| Attempting to write NT_ARM_POE (zero length)\n| SETREGSET(nt=0x40f, len=0) wrote 0 bytes\n|\n| Attempting to read NT_ARM_POE::por_el0\n| GETREGSET(nt=0x40f, len=8) read 8 bytes\n| Read NT_ARM_POE::por_el0 = 0xffff8000839c3d50\n\nAfter this patch:\n\n| # ./poe-test\n| Attempting to write NT_ARM_POE::por_el0 = 0x900d900d900d900d\n| SETREGSET(nt=0x40f, len=8) wrote 8 bytes\n|\n| Attempting to read NT_ARM_POE::por_el0\n| GETREGSET(nt=0x40f, len=8) read 8 bytes\n| Read NT_ARM_POE::por_el0 = 0x900d900d900d900d\n|\n| Attempting to write NT_ARM_POE (zero length)\n| SETREGSET(nt=0x40f, len=0) wrote 0 bytes\n|\n| Attempting to read NT_ARM_POE::por_el0\n| GETREGSET(nt=0x40f, len=8) read 8 bytes\n| Read NT_ARM_POE::por_el0 = 0x900d900d900d900d",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T15:15:08Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-xvfj-8qrf-7mc3/GHSA-xvfj-8qrf-7mc3.json b/advisories/unreviewed/2025/01/GHSA-xvfj-8qrf-7mc3/GHSA-xvfj-8qrf-7mc3.json
index 6a1e22fe652..947e0a80ad6 100644
--- a/advisories/unreviewed/2025/01/GHSA-xvfj-8qrf-7mc3/GHSA-xvfj-8qrf-7mc3.json
+++ b/advisories/unreviewed/2025/01/GHSA-xvfj-8qrf-7mc3/GHSA-xvfj-8qrf-7mc3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvfj-8qrf-7mc3",
- "modified": "2025-01-11T15:30:30Z",
+ "modified": "2025-02-03T15:32:01Z",
"published": "2025-01-11T15:30:29Z",
"aliases": [
"CVE-2024-57874"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL\n\nCurrently tagged_addr_ctrl_set() doesn't initialize the temporary 'ctrl'\nvariable, and a SETREGSET call with a length of zero will leave this\nuninitialized. Consequently tagged_addr_ctrl_set() will consume an\narbitrary value, potentially leaking up to 64 bits of memory from the\nkernel stack. The read is limited to a specific slot on the stack, and\nthe issue does not provide a write mechanism.\n\nAs set_tagged_addr_ctrl() only accepts values where bits [63:4] zero and\nrejects other values, a partial SETREGSET attempt will randomly succeed\nor fail depending on the value of the uninitialized value, and the\nexposure is significantly limited.\n\nFix this by initializing the temporary value before copying the regset\nfrom userspace, as for other regsets (e.g. NT_PRSTATUS, NT_PRFPREG,\nNT_ARM_SYSTEM_CALL). In the case of a zero-length write, the existing\nvalue of the tagged address ctrl will be retained.\n\nThe NT_ARM_TAGGED_ADDR_CTRL regset is only visible in the\nuser_aarch64_view used by a native AArch64 task to manipulate another\nnative AArch64 task. As get_tagged_addr_ctrl() only returns an error\nvalue when called for a compat task, tagged_addr_ctrl_get() and\ntagged_addr_ctrl_set() should never observe an error value from\nget_tagged_addr_ctrl(). Add a WARN_ON_ONCE() to both to indicate that\nsuch an error would be unexpected, and error handlnig is not missing in\neither case.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T15:15:07Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-29c3-5w75-524f/GHSA-29c3-5w75-524f.json b/advisories/unreviewed/2025/02/GHSA-29c3-5w75-524f/GHSA-29c3-5w75-524f.json
new file mode 100644
index 00000000000..58df76ee487
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-29c3-5w75-524f/GHSA-29c3-5w75-524f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-29c3-5w75-524f",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23527"
+ ],
+ "details": "Missing Authorization vulnerability in Hemnath Mouli WC Wallet allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WC Wallet: from n/a through 2.2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23527"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wc-wallet/vulnerability/wordpress-wc-wallet-plugin-2-2-0-arbitrary-content-deletion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-2qrh-cw3v-jjq8/GHSA-2qrh-cw3v-jjq8.json b/advisories/unreviewed/2025/02/GHSA-2qrh-cw3v-jjq8/GHSA-2qrh-cw3v-jjq8.json
new file mode 100644
index 00000000000..5652ce69b0f
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-2qrh-cw3v-jjq8/GHSA-2qrh-cw3v-jjq8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2qrh-cw3v-jjq8",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22694"
+ ],
+ "details": "Missing Authorization vulnerability in theDotstore Hide Shipping Method For WooCommerce. This issue affects Hide Shipping Method For WooCommerce: from n/a through 1.5.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22694"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hide-shipping-method-for-woocommerce/vulnerability/wordpress-hide-shipping-method-for-woocommerce-plugin-1-5-0-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3f7x-84v6-xqm2/GHSA-3f7x-84v6-xqm2.json b/advisories/unreviewed/2025/02/GHSA-3f7x-84v6-xqm2/GHSA-3f7x-84v6-xqm2.json
new file mode 100644
index 00000000000..4c3799a6031
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3f7x-84v6-xqm2/GHSA-3f7x-84v6-xqm2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3f7x-84v6-xqm2",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22681"
+ ],
+ "details": "Missing Authorization vulnerability in Xfinity Soft Content Cloner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Content Cloner: from n/a through 1.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22681"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/super-seo-content-cloner/vulnerability/wordpress-content-cloner-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-4894-q56v-259x/GHSA-4894-q56v-259x.json b/advisories/unreviewed/2025/02/GHSA-4894-q56v-259x/GHSA-4894-q56v-259x.json
new file mode 100644
index 00000000000..8f0464b2a06
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-4894-q56v-259x/GHSA-4894-q56v-259x.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4894-q56v-259x",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23590"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Burtay Arat Dezdy allows Reflected XSS. This issue affects Dezdy: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23590"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/dezdy-mcommerce/vulnerability/wordpress-dezdy-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-4qcm-8vwx-5fcx/GHSA-4qcm-8vwx-5fcx.json b/advisories/unreviewed/2025/02/GHSA-4qcm-8vwx-5fcx/GHSA-4qcm-8vwx-5fcx.json
new file mode 100644
index 00000000000..97ec0af087d
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-4qcm-8vwx-5fcx/GHSA-4qcm-8vwx-5fcx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4qcm-8vwx-5fcx",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23593"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EmailPress allows Reflected XSS. This issue affects EmailPress: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23593"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/emailpress/vulnerability/wordpress-emailpress-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-56cq-6fx2-6w65/GHSA-56cq-6fx2-6w65.json b/advisories/unreviewed/2025/02/GHSA-56cq-6fx2-6w65/GHSA-56cq-6fx2-6w65.json
new file mode 100644
index 00000000000..7cfd3f5a6eb
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-56cq-6fx2-6w65/GHSA-56cq-6fx2-6w65.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-56cq-6fx2-6w65",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23747"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nitesh Singh Awesome Timeline allows Stored XSS. This issue affects Awesome Timeline: from n/a through 1.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23747"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/awesome-timeline/vulnerability/wordpress-awesome-timeline-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-62mj-f382-xrp2/GHSA-62mj-f382-xrp2.json b/advisories/unreviewed/2025/02/GHSA-62mj-f382-xrp2/GHSA-62mj-f382-xrp2.json
new file mode 100644
index 00000000000..4c8a0609845
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-62mj-f382-xrp2/GHSA-62mj-f382-xrp2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-62mj-f382-xrp2",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22688"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ederson Peka Unlimited Page Sidebars allows Stored XSS. This issue affects Unlimited Page Sidebars: from n/a through 0.2.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22688"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/unlimited-page-sidebars/vulnerability/wordpress-unlimited-page-sidebars-plugin-0-2-6-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-66w3-8239-5462/GHSA-66w3-8239-5462.json b/advisories/unreviewed/2025/02/GHSA-66w3-8239-5462/GHSA-66w3-8239-5462.json
new file mode 100644
index 00000000000..c8c898e91db
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-66w3-8239-5462/GHSA-66w3-8239-5462.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-66w3-8239-5462",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24707"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3 Photo Gallery Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery allows Reflected XSS. This issue affects Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery: from n/a through 2.7.7.24.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24707"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gt3-photo-video-gallery/vulnerability/wordpress-photo-gallery-gt3-image-gallery-gutenberg-block-gallery-plugin-2-7-7-24-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-68rh-p39x-55qr/GHSA-68rh-p39x-55qr.json b/advisories/unreviewed/2025/02/GHSA-68rh-p39x-55qr/GHSA-68rh-p39x-55qr.json
new file mode 100644
index 00000000000..4a49042cbc6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-68rh-p39x-55qr/GHSA-68rh-p39x-55qr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-68rh-p39x-55qr",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-24541"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DK White Label allows Reflected XSS. This issue affects DK White Label: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24541"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/dk-white-label/vulnerability/wordpress-dk-white-label-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6c5r-r7hx-4v27/GHSA-6c5r-r7hx-4v27.json b/advisories/unreviewed/2025/02/GHSA-6c5r-r7hx-4v27/GHSA-6c5r-r7hx-4v27.json
new file mode 100644
index 00000000000..cef3d8eb151
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-6c5r-r7hx-4v27/GHSA-6c5r-r7hx-4v27.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6c5r-r7hx-4v27",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24684"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media Downloader allows Reflected XSS. This issue affects Media Downloader: from n/a through 0.4.7.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24684"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/media-downloader/vulnerability/wordpress-media-downloader-plugin-0-4-7-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6f82-5qgq-9pf6/GHSA-6f82-5qgq-9pf6.json b/advisories/unreviewed/2025/02/GHSA-6f82-5qgq-9pf6/GHSA-6f82-5qgq-9pf6.json
new file mode 100644
index 00000000000..c7f46b16afe
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-6f82-5qgq-9pf6/GHSA-6f82-5qgq-9pf6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6f82-5qgq-9pf6",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23799"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in .TUBE gTLD .TUBE Video Curator allows Reflected XSS. This issue affects .TUBE Video Curator: from n/a through 1.1.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23799"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/tube-video-curator/vulnerability/wordpress-tube-video-curator-plugin-1-1-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-758x-mffx-rxw8/GHSA-758x-mffx-rxw8.json b/advisories/unreviewed/2025/02/GHSA-758x-mffx-rxw8/GHSA-758x-mffx-rxw8.json
new file mode 100644
index 00000000000..81fe905bfed
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-758x-mffx-rxw8/GHSA-758x-mffx-rxw8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-758x-mffx-rxw8",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24660"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership Custom Messages allows Reflected XSS. This issue affects Simple Membership Custom Messages: from n/a through 2.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24660"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/simple-membership-custom-messages/vulnerability/wordpress-simple-membership-custom-messages-plugin-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-7622-r9xj-6gwh/GHSA-7622-r9xj-6gwh.json b/advisories/unreviewed/2025/02/GHSA-7622-r9xj-6gwh/GHSA-7622-r9xj-6gwh.json
new file mode 100644
index 00000000000..dd166b3801b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-7622-r9xj-6gwh/GHSA-7622-r9xj-6gwh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7622-r9xj-6gwh",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24646"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim Glazunov XML for Avito allows Reflected XSS. This issue affects XML for Avito: from n/a through 2.5.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24646"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/xml-for-avito/vulnerability/wordpress-xml-for-avito-plugin-2-5-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-7786-h8f4-86vp/GHSA-7786-h8f4-86vp.json b/advisories/unreviewed/2025/02/GHSA-7786-h8f4-86vp/GHSA-7786-h8f4-86vp.json
new file mode 100644
index 00000000000..82c9a41d686
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-7786-h8f4-86vp/GHSA-7786-h8f4-86vp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7786-h8f4-86vp",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24629"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGear Import Excel to Gravity Forms allows Reflected XSS. This issue affects Import Excel to Gravity Forms: from n/a through 1.18.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24629"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/gf-excel-import/vulnerability/wordpress-import-excel-to-gravity-forms-plugin-1-18-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-7mxv-pwwv-fj25/GHSA-7mxv-pwwv-fj25.json b/advisories/unreviewed/2025/02/GHSA-7mxv-pwwv-fj25/GHSA-7mxv-pwwv-fj25.json
new file mode 100644
index 00000000000..dd4e4212106
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-7mxv-pwwv-fj25/GHSA-7mxv-pwwv-fj25.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7mxv-pwwv-fj25",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23581"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Zoom Studio Demo User DZS allows Stored XSS. This issue affects Demo User DZS: from n/a through 1.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23581"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/demo-user-dzs-showcase-your-admin-safely/vulnerability/wordpress-demo-user-dzs-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-82ch-63xf-6pr3/GHSA-82ch-63xf-6pr3.json b/advisories/unreviewed/2025/02/GHSA-82ch-63xf-6pr3/GHSA-82ch-63xf-6pr3.json
new file mode 100644
index 00000000000..98a3828e6e9
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-82ch-63xf-6pr3/GHSA-82ch-63xf-6pr3.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-82ch-63xf-6pr3",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24642"
+ ],
+ "details": "Missing Authorization vulnerability in theme funda Setup Default Featured Image allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Setup Default Featured Image: from n/a through 1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24642"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/setup-default-feature-image/vulnerability/wordpress-setup-default-featured-image-plugin-1-2-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8457-mxpv-x45g/GHSA-8457-mxpv-x45g.json b/advisories/unreviewed/2025/02/GHSA-8457-mxpv-x45g/GHSA-8457-mxpv-x45g.json
new file mode 100644
index 00000000000..66305a5c41f
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-8457-mxpv-x45g/GHSA-8457-mxpv-x45g.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8457-mxpv-x45g",
+ "modified": "2025-02-03T15:32:00Z",
+ "published": "2025-02-03T15:32:00Z",
+ "aliases": [
+ "CVE-2024-37137"
+ ],
+ "details": "Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37137"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.dell.com/support/kbdoc/en-us/000226476/dsa-2024-294-security-update-for-dell-cloudlink-vulnerability"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1240",
+ "CWE-327"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-28T02:15:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8667-mpq3-28qm/GHSA-8667-mpq3-28qm.json b/advisories/unreviewed/2025/02/GHSA-8667-mpq3-28qm/GHSA-8667-mpq3-28qm.json
new file mode 100644
index 00000000000..17f535997a2
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-8667-mpq3-28qm/GHSA-8667-mpq3-28qm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8667-mpq3-28qm",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22685"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in CheGevara Tags to Keywords allows Stored XSS. This issue affects Tags to Keywords: from n/a through 1.0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22685"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/tags-to-meta-keywords/vulnerability/wordpress-tags-to-keywords-plugin-1-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8cgw-96fc-pr6g/GHSA-8cgw-96fc-pr6g.json b/advisories/unreviewed/2025/02/GHSA-8cgw-96fc-pr6g/GHSA-8cgw-96fc-pr6g.json
new file mode 100644
index 00000000000..8e75f88a35a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-8cgw-96fc-pr6g/GHSA-8cgw-96fc-pr6g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8cgw-96fc-pr6g",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-24544"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandros Georgiou Bitcoin and Altcoin Wallets allows Reflected XSS. This issue affects Bitcoin and Altcoin Wallets: from n/a through 6.3.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24544"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wallets/vulnerability/wordpress-bitcoin-and-altcoin-wallets-plugin-6-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8phh-ch6h-hm63/GHSA-8phh-ch6h-hm63.json b/advisories/unreviewed/2025/02/GHSA-8phh-ch6h-hm63/GHSA-8phh-ch6h-hm63.json
new file mode 100644
index 00000000000..7eaa2381b51
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-8phh-ch6h-hm63/GHSA-8phh-ch6h-hm63.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8phh-ch6h-hm63",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22292"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Powerful Auto Chat allows Stored XSS. This issue affects Powerful Auto Chat: from n/a through 1.9.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22292"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/powers-triggers-of-woo-to-chat/vulnerability/wordpress-powerful-auto-chat-plugin-1-9-8-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9f3p-pqg6-mchm/GHSA-9f3p-pqg6-mchm.json b/advisories/unreviewed/2025/02/GHSA-9f3p-pqg6-mchm/GHSA-9f3p-pqg6-mchm.json
new file mode 100644
index 00000000000..8ff2ff16816
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9f3p-pqg6-mchm/GHSA-9f3p-pqg6-mchm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9f3p-pqg6-mchm",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-24545"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BannerSky.com BSK Forms Validation allows Reflected XSS. This issue affects BSK Forms Validation: from n/a through 1.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24545"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bsk-gravity-forms-custom-validation/vulnerability/wordpress-bsk-forms-validation-plugin-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9fxx-wgmh-4c9f/GHSA-9fxx-wgmh-4c9f.json b/advisories/unreviewed/2025/02/GHSA-9fxx-wgmh-4c9f/GHSA-9fxx-wgmh-4c9f.json
new file mode 100644
index 00000000000..2cd4708db04
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9fxx-wgmh-4c9f/GHSA-9fxx-wgmh-4c9f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9fxx-wgmh-4c9f",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23591"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blu Logistics Pte. Ltd. blu Logistics allows Reflected XSS. This issue affects blu Logistics: from n/a through 1.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23591"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/blu-logistics/vulnerability/wordpress-blu-logistics-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9h74-v678-xf3w/GHSA-9h74-v678-xf3w.json b/advisories/unreviewed/2025/02/GHSA-9h74-v678-xf3w/GHSA-9h74-v678-xf3w.json
new file mode 100644
index 00000000000..812d2d87e92
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9h74-v678-xf3w/GHSA-9h74-v678-xf3w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9h74-v678-xf3w",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24605"
+ ],
+ "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in realmag777 WOLF allows Path Traversal. This issue affects WOLF: from n/a through 1.0.8.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24605"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bulk-editor/vulnerability/wordpress-wolf-plugin-1-0-8-5-path-traversal-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9hrc-j3gj-6hp9/GHSA-9hrc-j3gj-6hp9.json b/advisories/unreviewed/2025/02/GHSA-9hrc-j3gj-6hp9/GHSA-9hrc-j3gj-6hp9.json
new file mode 100644
index 00000000000..5f397d8aa4a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9hrc-j3gj-6hp9/GHSA-9hrc-j3gj-6hp9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9hrc-j3gj-6hp9",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23561"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MLL Audio Player MP3 Ajax allows Stored XSS. This issue affects MLL Audio Player MP3 Ajax: from n/a through 0.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23561"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/music-let-loose-mp3-audio-player/vulnerability/wordpress-mll-audio-player-mp3-ajax-plugin-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9r2h-5xf6-2vwq/GHSA-9r2h-5xf6-2vwq.json b/advisories/unreviewed/2025/02/GHSA-9r2h-5xf6-2vwq/GHSA-9r2h-5xf6-2vwq.json
new file mode 100644
index 00000000000..b6251f3a62c
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9r2h-5xf6-2vwq/GHSA-9r2h-5xf6-2vwq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9r2h-5xf6-2vwq",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23582"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haider Ali Bulk Categories Assign allows Reflected XSS. This issue affects Bulk Categories Assign: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23582"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bulk-categories-assign/vulnerability/wordpress-bulk-categories-assign-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-c6q5-rrw7-p494/GHSA-c6q5-rrw7-p494.json b/advisories/unreviewed/2025/02/GHSA-c6q5-rrw7-p494/GHSA-c6q5-rrw7-p494.json
new file mode 100644
index 00000000000..f54b6773a93
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-c6q5-rrw7-p494/GHSA-c6q5-rrw7-p494.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c6q5-rrw7-p494",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22260"
+ ],
+ "details": "Missing Authorization vulnerability in Pixelite Meta Tag Manager. This issue affects Meta Tag Manager: from n/a through 3.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22260"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/meta-tag-manager/vulnerability/wordpress-meta-tag-manager-plugin-3-1-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-c9xr-2j8f-4q5q/GHSA-c9xr-2j8f-4q5q.json b/advisories/unreviewed/2025/02/GHSA-c9xr-2j8f-4q5q/GHSA-c9xr-2j8f-4q5q.json
new file mode 100644
index 00000000000..2c6c1609f06
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-c9xr-2j8f-4q5q/GHSA-c9xr-2j8f-4q5q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c9xr-2j8f-4q5q",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22686"
+ ],
+ "details": "Missing Authorization vulnerability in GSheetConnector CF7 Google Sheets Connector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Google Sheets Connector: from n/a through 5.0.17.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22686"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cf7-google-sheets-connector/vulnerability/wordpress-cf7-google-sheets-connector-plugin-5-0-17-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-cfj5-j439-wcw7/GHSA-cfj5-j439-wcw7.json b/advisories/unreviewed/2025/02/GHSA-cfj5-j439-wcw7/GHSA-cfj5-j439-wcw7.json
new file mode 100644
index 00000000000..5ae1c75c47a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-cfj5-j439-wcw7/GHSA-cfj5-j439-wcw7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cfj5-j439-wcw7",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22703"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22703"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/forge/vulnerability/wordpress-forge-front-end-page-builder-plugin-1-4-6-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-cqx6-84p5-pwg6/GHSA-cqx6-84p5-pwg6.json b/advisories/unreviewed/2025/02/GHSA-cqx6-84p5-pwg6/GHSA-cqx6-84p5-pwg6.json
new file mode 100644
index 00000000000..56c62db3bf7
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-cqx6-84p5-pwg6/GHSA-cqx6-84p5-pwg6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cqx6-84p5-pwg6",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24569"
+ ],
+ "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder allows Path Traversal. This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through 1.7.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24569"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pdf-generator-addon-for-elementor-page-builder/vulnerability/wordpress-pdf-generator-addon-for-elementor-page-builder-plugin-1-7-5-arbitrary-file-read-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-f8g4-wp42-47w7/GHSA-f8g4-wp42-47w7.json b/advisories/unreviewed/2025/02/GHSA-f8g4-wp42-47w7/GHSA-f8g4-wp42-47w7.json
new file mode 100644
index 00000000000..9786ec1950e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-f8g4-wp42-47w7/GHSA-f8g4-wp42-47w7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f8g4-wp42-47w7",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22691"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel allows SQL Injection. This issue affects WP Travel: from n/a through 10.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22691"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-travel/vulnerability/wordpress-wp-travel-plugin-10-1-0-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fjcm-jgq9-qwjc/GHSA-fjcm-jgq9-qwjc.json b/advisories/unreviewed/2025/02/GHSA-fjcm-jgq9-qwjc/GHSA-fjcm-jgq9-qwjc.json
new file mode 100644
index 00000000000..740037d4e63
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fjcm-jgq9-qwjc/GHSA-fjcm-jgq9-qwjc.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fjcm-jgq9-qwjc",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-24536"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThriveDesk ThriveDesk allows Reflected XSS. This issue affects ThriveDesk: from n/a through 2.0.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24536"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/thrivedesk/vulnerability/wordpress-thrivedesk-plugin-2-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fqpp-wx48-c63r/GHSA-fqpp-wx48-c63r.json b/advisories/unreviewed/2025/02/GHSA-fqpp-wx48-c63r/GHSA-fqpp-wx48-c63r.json
new file mode 100644
index 00000000000..91ba15c25a2
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fqpp-wx48-c63r/GHSA-fqpp-wx48-c63r.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fqpp-wx48-c63r",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22690"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration allows Stored XSS. This issue affects DigiTimber cPanel Integration: from n/a through 1.4.6.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22690"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/digitimber-cpanel-integration/vulnerability/wordpress-digitimber-cpanel-integration-plugin-1-4-6-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fv6w-phw6-f2cx/GHSA-fv6w-phw6-f2cx.json b/advisories/unreviewed/2025/02/GHSA-fv6w-phw6-f2cx/GHSA-fv6w-phw6-f2cx.json
new file mode 100644
index 00000000000..9044dbea7be
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fv6w-phw6-f2cx/GHSA-fv6w-phw6-f2cx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fv6w-phw6-f2cx",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23685"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound RomanCart allows Reflected XSS. This issue affects RomanCart: from n/a through 0.0.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23685"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/romancart-on-wordpress/vulnerability/wordpress-romancart-on-wordpress-plugin-0-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fx25-pqmv-qr46/GHSA-fx25-pqmv-qr46.json b/advisories/unreviewed/2025/02/GHSA-fx25-pqmv-qr46/GHSA-fx25-pqmv-qr46.json
new file mode 100644
index 00000000000..58b48d3522b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fx25-pqmv-qr46/GHSA-fx25-pqmv-qr46.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fx25-pqmv-qr46",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24630"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MantraBrain Sikshya LMS allows Reflected XSS. This issue affects Sikshya LMS: from n/a through 0.0.21.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24630"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/sikshya/vulnerability/wordpress-sikshya-lms-plugin-0-0-21-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fx8w-24qx-p2c5/GHSA-fx8w-24qx-p2c5.json b/advisories/unreviewed/2025/02/GHSA-fx8w-24qx-p2c5/GHSA-fx8w-24qx-p2c5.json
new file mode 100644
index 00000000000..0757554a646
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fx8w-24qx-p2c5/GHSA-fx8w-24qx-p2c5.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fx8w-24qx-p2c5",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24781"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoard allows Reflected XSS. This issue affects WPJobBoard: from n/a through 5.10.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24781"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wpjobboard/vulnerability/wordpress-wpjobboard-plugin-5-10-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-g246-2588-xpcw/GHSA-g246-2588-xpcw.json b/advisories/unreviewed/2025/02/GHSA-g246-2588-xpcw/GHSA-g246-2588-xpcw.json
new file mode 100644
index 00000000000..65ae896bbdc
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-g246-2588-xpcw/GHSA-g246-2588-xpcw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g246-2588-xpcw",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24697"
+ ],
+ "details": "Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Gallery – Responsive Photo Gallery: from n/a through 1.0.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24697"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/awesome-responsive-photo-gallery/vulnerability/wordpress-image-gallery-responsive-photo-gallery-plugin-1-0-5-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gwxp-5q7q-w242/GHSA-gwxp-5q7q-w242.json b/advisories/unreviewed/2025/02/GHSA-gwxp-5q7q-w242/GHSA-gwxp-5q7q-w242.json
new file mode 100644
index 00000000000..85cea1c9810
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gwxp-5q7q-w242/GHSA-gwxp-5q7q-w242.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gwxp-5q7q-w242",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2024-57522"
+ ],
+ "details": "SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57522"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/HackWidMaddy/CVE-2024-57522"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T13:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gxg5-5cmr-3588/GHSA-gxg5-5cmr-3588.json b/advisories/unreviewed/2025/02/GHSA-gxg5-5cmr-3588/GHSA-gxg5-5cmr-3588.json
new file mode 100644
index 00000000000..7f21c22bc02
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gxg5-5cmr-3588/GHSA-gxg5-5cmr-3588.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gxg5-5cmr-3588",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22679"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows Reflected XSS. This issue affects Job Board Manager: from n/a through 2.1.60.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22679"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/job-board-manager/vulnerability/wordpress-job-board-manager-plugin-2-1-60-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hv29-c4x3-8863/GHSA-hv29-c4x3-8863.json b/advisories/unreviewed/2025/02/GHSA-hv29-c4x3-8863/GHSA-hv29-c4x3-8863.json
new file mode 100644
index 00000000000..d2a1373b79a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hv29-c4x3-8863/GHSA-hv29-c4x3-8863.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hv29-c4x3-8863",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24656"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Provisioning allows Reflected XSS. This issue affects Realtyna Provisioning: from n/a through 1.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24656"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/realtyna-provisioning/vulnerability/wordpress-realtyna-provisioning-plugin-1-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hxh5-3mh2-q6x8/GHSA-hxh5-3mh2-q6x8.json b/advisories/unreviewed/2025/02/GHSA-hxh5-3mh2-q6x8/GHSA-hxh5-3mh2-q6x8.json
new file mode 100644
index 00000000000..df9ea3666db
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hxh5-3mh2-q6x8/GHSA-hxh5-3mh2-q6x8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hxh5-3mh2-q6x8",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24556"
+ ],
+ "details": "Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle allows Retrieve Embedded Sensitive Data. This issue affects MooWoodle: from n/a through 3.2.4.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24556"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/moowoodle/vulnerability/wordpress-moowoodle-plugin-3-2-4-sensitive-data-exposure-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-532"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-j9f5-239f-px34/GHSA-j9f5-239f-px34.json b/advisories/unreviewed/2025/02/GHSA-j9f5-239f-px34/GHSA-j9f5-239f-px34.json
new file mode 100644
index 00000000000..62d75808633
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-j9f5-239f-px34/GHSA-j9f5-239f-px34.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j9f5-239f-px34",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23588"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WOW WordPress WOW Best CSS Compiler allows Reflected XSS. This issue affects WOW Best CSS Compiler: from n/a through 2.0.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23588"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/best-css-compiler/vulnerability/wordpress-wow-best-css-compiler-plugin-2-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-m32x-p663-p4h7/GHSA-m32x-p663-p4h7.json b/advisories/unreviewed/2025/02/GHSA-m32x-p663-p4h7/GHSA-m32x-p663-p4h7.json
new file mode 100644
index 00000000000..0d53935cf74
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-m32x-p663-p4h7/GHSA-m32x-p663-p4h7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m32x-p663-p4h7",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22683"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper NotificationX allows Stored XSS. This issue affects NotificationX: from n/a through 2.9.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22683"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/notificationx/vulnerability/wordpress-notificationx-plugin-2-9-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-mp5r-7qm4-pgc7/GHSA-mp5r-7qm4-pgc7.json b/advisories/unreviewed/2025/02/GHSA-mp5r-7qm4-pgc7/GHSA-mp5r-7qm4-pgc7.json
new file mode 100644
index 00000000000..d1ba3840191
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-mp5r-7qm4-pgc7/GHSA-mp5r-7qm4-pgc7.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mp5r-7qm4-pgc7",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2024-43333"
+ ],
+ "details": "Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43333"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/admin-site-enhancements-pro/vulnerability/wordpress-admin-and-site-enhancements-ase-pro-plugin-7-6-2-1-privilege-escalation-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-266"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-mrqf-9666-2wqm/GHSA-mrqf-9666-2wqm.json b/advisories/unreviewed/2025/02/GHSA-mrqf-9666-2wqm/GHSA-mrqf-9666-2wqm.json
new file mode 100644
index 00000000000..df2139bc9b8
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-mrqf-9666-2wqm/GHSA-mrqf-9666-2wqm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mrqf-9666-2wqm",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24661"
+ ],
+ "details": "Deserialization of Untrusted Data vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Object Injection. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.1.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24661"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/ecab-taxi-booking-manager/vulnerability/wordpress-taxi-booking-manager-for-woocommerce-plugin-1-1-8-php-object-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-p22x-7843-884q/GHSA-p22x-7843-884q.json b/advisories/unreviewed/2025/02/GHSA-p22x-7843-884q/GHSA-p22x-7843-884q.json
new file mode 100644
index 00000000000..ced952b9a87
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-p22x-7843-884q/GHSA-p22x-7843-884q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p22x-7843-884q",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24643"
+ ],
+ "details": "Missing Authorization vulnerability in Amento Tech Pvt ltd WPGuppy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPGuppy: from n/a through 1.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24643"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wpguppy-lite/vulnerability/wordpress-wpguppy-plugin-1-1-0-broken-authentication-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-pchf-fw93-3p2f/GHSA-pchf-fw93-3p2f.json b/advisories/unreviewed/2025/02/GHSA-pchf-fw93-3p2f/GHSA-pchf-fw93-3p2f.json
new file mode 100644
index 00000000000..5a3217ef3d6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-pchf-fw93-3p2f/GHSA-pchf-fw93-3p2f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pchf-fw93-3p2f",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23819"
+ ],
+ "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound WP Cloud allows Absolute Path Traversal. This issue affects WP Cloud: from n/a through 1.4.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23819"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/cloud/vulnerability/wordpress-wp-cloud-plugin-1-4-3-arbitrary-file-deletion-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-ppxf-9xvj-v2hm/GHSA-ppxf-9xvj-v2hm.json b/advisories/unreviewed/2025/02/GHSA-ppxf-9xvj-v2hm/GHSA-ppxf-9xvj-v2hm.json
new file mode 100644
index 00000000000..10a9367c172
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-ppxf-9xvj-v2hm/GHSA-ppxf-9xvj-v2hm.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-ppxf-9xvj-v2hm",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23923"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Lockets allows Reflected XSS. This issue affects Lockets: from n/a through 0.999.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23923"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/lockets/vulnerability/wordpress-lockets-plugin-0-999-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-pvg9-854c-47xf/GHSA-pvg9-854c-47xf.json b/advisories/unreviewed/2025/02/GHSA-pvg9-854c-47xf/GHSA-pvg9-854c-47xf.json
new file mode 100644
index 00000000000..798739c422f
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-pvg9-854c-47xf/GHSA-pvg9-854c-47xf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pvg9-854c-47xf",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23491"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikashsrivastava1111989 VSTEMPLATE Creator allows Reflected XSS. This issue affects VSTEMPLATE Creator: from n/a through 2.0.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23491"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/vstemplate-creator/vulnerability/wordpress-vstemplate-creator-plugin-2-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-q2rj-w884-9q82/GHSA-q2rj-w884-9q82.json b/advisories/unreviewed/2025/02/GHSA-q2rj-w884-9q82/GHSA-q2rj-w884-9q82.json
new file mode 100644
index 00000000000..1521792c02f
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-q2rj-w884-9q82/GHSA-q2rj-w884-9q82.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q2rj-w884-9q82",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24559"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster allows Reflected XSS. This issue affects WP Mailster: from n/a through 1.8.15.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24559"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-15-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-q3p4-qwqf-7x2q/GHSA-q3p4-qwqf-7x2q.json b/advisories/unreviewed/2025/02/GHSA-q3p4-qwqf-7x2q/GHSA-q3p4-qwqf-7x2q.json
new file mode 100644
index 00000000000..88d11c383e1
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-q3p4-qwqf-7x2q/GHSA-q3p4-qwqf-7x2q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q3p4-qwqf-7x2q",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24620"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AIO Shortcodes allows Stored XSS. This issue affects AIO Shortcodes: from n/a through 1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24620"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/aio-shortcodes/vulnerability/wordpress-aio-shortcodes-plugin-1-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-q5gm-6r6x-wwp4/GHSA-q5gm-6r6x-wwp4.json b/advisories/unreviewed/2025/02/GHSA-q5gm-6r6x-wwp4/GHSA-q5gm-6r6x-wwp4.json
new file mode 100644
index 00000000000..65833fccc15
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-q5gm-6r6x-wwp4/GHSA-q5gm-6r6x-wwp4.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q5gm-6r6x-wwp4",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22693"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery Contest Gallery allows SQL Injection. This issue affects Contest Gallery: from n/a through 25.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22693"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-25-1-0-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-q9r4-2743-gqxg/GHSA-q9r4-2743-gqxg.json b/advisories/unreviewed/2025/02/GHSA-q9r4-2743-gqxg/GHSA-q9r4-2743-gqxg.json
new file mode 100644
index 00000000000..be3759a483a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-q9r4-2743-gqxg/GHSA-q9r4-2743-gqxg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q9r4-2743-gqxg",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-22704"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in Abinav Thakuri WordPress Signature allows Cross Site Request Forgery. This issue affects WordPress Signature: from n/a through 0.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22704"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wordpress-signature/vulnerability/wordpress-wordpress-signature-plugin-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qcrm-39j8-mgw2/GHSA-qcrm-39j8-mgw2.json b/advisories/unreviewed/2025/02/GHSA-qcrm-39j8-mgw2/GHSA-qcrm-39j8-mgw2.json
new file mode 100644
index 00000000000..3ba87714578
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-qcrm-39j8-mgw2/GHSA-qcrm-39j8-mgw2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qcrm-39j8-mgw2",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23755"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PAFacile allows Reflected XSS. This issue affects PAFacile: from n/a through 2.6.1.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23755"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pafacile/vulnerability/wordpress-pafacile-plugin-2-6-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qwgv-9c86-m892/GHSA-qwgv-9c86-m892.json b/advisories/unreviewed/2025/02/GHSA-qwgv-9c86-m892/GHSA-qwgv-9c86-m892.json
new file mode 100644
index 00000000000..5ae1e4867ca
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-qwgv-9c86-m892/GHSA-qwgv-9c86-m892.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qwgv-9c86-m892",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24557"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware.com PlainInventory allows Reflected XSS. This issue affects PlainInventory: from n/a through 3.1.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24557"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/z-inventory-manager/vulnerability/wordpress-plaininventory-plugin-3-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qx69-86hp-p6qr/GHSA-qx69-86hp-p6qr.json b/advisories/unreviewed/2025/02/GHSA-qx69-86hp-p6qr/GHSA-qx69-86hp-p6qr.json
new file mode 100644
index 00000000000..b96e8b18836
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-qx69-86hp-p6qr/GHSA-qx69-86hp-p6qr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qx69-86hp-p6qr",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24631"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PhiloPress BP Email Assign Templates allows Reflected XSS. This issue affects BP Email Assign Templates: from n/a through 1.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24631"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/bp-email-assign-templates/vulnerability/wordpress-bp-email-assign-templates-plugin-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-rmx2-4jx5-xv9c/GHSA-rmx2-4jx5-xv9c.json b/advisories/unreviewed/2025/02/GHSA-rmx2-4jx5-xv9c/GHSA-rmx2-4jx5-xv9c.json
new file mode 100644
index 00000000000..e1297fb22ef
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-rmx2-4jx5-xv9c/GHSA-rmx2-4jx5-xv9c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rmx2-4jx5-xv9c",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24574"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev WooCommerce Receipt Uploader allows Reflected XSS. This issue affects PeproDev WooCommerce Receipt Uploader: from n/a through 2.6.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24574"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/pepro-bacs-receipt-upload-for-woocommerce/vulnerability/wordpress-peprodev-woocommerce-receipt-uploader-plugin-2-6-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v24j-7gvf-f7xp/GHSA-v24j-7gvf-f7xp.json b/advisories/unreviewed/2025/02/GHSA-v24j-7gvf-f7xp/GHSA-v24j-7gvf-f7xp.json
new file mode 100644
index 00000000000..af74842ddfd
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v24j-7gvf-f7xp/GHSA-v24j-7gvf-f7xp.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v24j-7gvf-f7xp",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23920"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ApplicantPro ApplicantPro allows Reflected XSS. This issue affects ApplicantPro: from n/a through 1.3.9.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23920"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/applicantpro/vulnerability/wordpress-applicantpro-plugin-1-3-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v258-v7wv-4g7v/GHSA-v258-v7wv-4g7v.json b/advisories/unreviewed/2025/02/GHSA-v258-v7wv-4g7v/GHSA-v258-v7wv-4g7v.json
new file mode 100644
index 00000000000..3580606e666
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v258-v7wv-4g7v/GHSA-v258-v7wv-4g7v.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v258-v7wv-4g7v",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24639"
+ ],
+ "details": "Insertion of Sensitive Information Into Sent Data vulnerability in GREYS Korea for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects Korea for WooCommerce: from n/a through 1.1.11.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24639"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/korea-for-woocommerce/vulnerability/wordpress-korea-for-woocommerce-plugin-1-1-11-sensitive-data-exposure-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-201"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v4g5-p637-j32c/GHSA-v4g5-p637-j32c.json b/advisories/unreviewed/2025/02/GHSA-v4g5-p637-j32c/GHSA-v4g5-p637-j32c.json
new file mode 100644
index 00000000000..57fab851350
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v4g5-p637-j32c/GHSA-v4g5-p637-j32c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v4g5-p637-j32c",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22684"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hakan Ozevin WP BASE Booking allows Stored XSS. This issue affects WP BASE Booking: from n/a through 5.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22684"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-base-booking-of-appointments-services-and-events/vulnerability/wordpress-wp-base-booking-plugin-5-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v57f-fqvf-vc6v/GHSA-v57f-fqvf-vc6v.json b/advisories/unreviewed/2025/02/GHSA-v57f-fqvf-vc6v/GHSA-v57f-fqvf-vc6v.json
new file mode 100644
index 00000000000..4386b8a13ae
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v57f-fqvf-vc6v/GHSA-v57f-fqvf-vc6v.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v57f-fqvf-vc6v",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22701"
+ ],
+ "details": "Server-Side Request Forgery (SSRF) vulnerability in NotFound Traveler Layout Essential For Elementor. This issue affects Traveler Layout Essential For Elementor: from n/a through 1.0.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22701"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/traveler-layout-essential-for-elementor/vulnerability/wordpress-traveler-layout-essential-for-elementor-plugin-1-0-8-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-918"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v5cc-g4p3-96gv/GHSA-v5cc-g4p3-96gv.json b/advisories/unreviewed/2025/02/GHSA-v5cc-g4p3-96gv/GHSA-v5cc-g4p3-96gv.json
new file mode 100644
index 00000000000..a3028b25ee7
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v5cc-g4p3-96gv/GHSA-v5cc-g4p3-96gv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v5cc-g4p3-96gv",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23594"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uzzal mondal Google Map With Fancybox allows Reflected XSS. This issue affects Google Map With Fancybox: from n/a through 2.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23594"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/location-piker/vulnerability/wordpress-google-map-with-fancybox-plugin-2-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:21Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v6rw-775r-c547/GHSA-v6rw-775r-c547.json b/advisories/unreviewed/2025/02/GHSA-v6rw-775r-c547/GHSA-v6rw-775r-c547.json
new file mode 100644
index 00000000000..f8bed694795
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v6rw-775r-c547/GHSA-v6rw-775r-c547.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v6rw-775r-c547",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23614"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nik Sudan WordPress Additional Logins allows Reflected XSS. This issue affects WordPress Additional Logins: from n/a through 1.0.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23614"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/wp-additional-logins/vulnerability/wordpress-wordpress-additional-logins-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v9jw-qfrm-3v3x/GHSA-v9jw-qfrm-3v3x.json b/advisories/unreviewed/2025/02/GHSA-v9jw-qfrm-3v3x/GHSA-v9jw-qfrm-3v3x.json
new file mode 100644
index 00000000000..2f84d12347f
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v9jw-qfrm-3v3x/GHSA-v9jw-qfrm-3v3x.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v9jw-qfrm-3v3x",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23599"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound eMarksheet allows Reflected XSS. This issue affects eMarksheet: from n/a through 5.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23599"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/emarksheet/vulnerability/wordpress-emarksheet-plugin-5-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vch5-mvq9-qm23/GHSA-vch5-mvq9-qm23.json b/advisories/unreviewed/2025/02/GHSA-vch5-mvq9-qm23/GHSA-vch5-mvq9-qm23.json
new file mode 100644
index 00000000000..254397f1493
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vch5-mvq9-qm23/GHSA-vch5-mvq9-qm23.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vch5-mvq9-qm23",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22682"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hesabfa Hesabfa Accounting allows Reflected XSS. This issue affects Hesabfa Accounting: from n/a through 2.1.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22682"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hesabfa-accounting/vulnerability/wordpress-hesabfa-accounting-plugin-2-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vjxc-9jvg-687w/GHSA-vjxc-9jvg-687w.json b/advisories/unreviewed/2025/02/GHSA-vjxc-9jvg-687w/GHSA-vjxc-9jvg-687w.json
new file mode 100644
index 00000000000..9441b2ba18a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vjxc-9jvg-687w/GHSA-vjxc-9jvg-687w.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vjxc-9jvg-687w",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24576"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fatcat Apps Landing Page Cat allows Reflected XSS. This issue affects Landing Page Cat: from n/a through 1.7.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24576"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/landing-page-cat/vulnerability/wordpress-landing-page-cat-plugin-1-7-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vr4c-cc99-p7vf/GHSA-vr4c-cc99-p7vf.json b/advisories/unreviewed/2025/02/GHSA-vr4c-cc99-p7vf/GHSA-vr4c-cc99-p7vf.json
new file mode 100644
index 00000000000..82dfdafb3a4
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vr4c-cc99-p7vf/GHSA-vr4c-cc99-p7vf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vr4c-cc99-p7vf",
+ "modified": "2025-02-03T15:32:04Z",
+ "published": "2025-02-03T15:32:04Z",
+ "aliases": [
+ "CVE-2025-24676"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metatagg Inc Custom WP Store Locator allows Reflected XSS. This issue affects Custom WP Store Locator: from n/a through 1.4.7.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24676"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/custom-store-locator/vulnerability/wordpress-custom-wp-store-locator-plugin-1-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-w4xp-6q8w-6c3g/GHSA-w4xp-6q8w-6c3g.json b/advisories/unreviewed/2025/02/GHSA-w4xp-6q8w-6c3g/GHSA-w4xp-6q8w-6c3g.json
new file mode 100644
index 00000000000..75347eac345
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-w4xp-6q8w-6c3g/GHSA-w4xp-6q8w-6c3g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w4xp-6q8w-6c3g",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22695"
+ ],
+ "details": "Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support. This issue affects Nirweb support: from n/a through 3.0.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22695"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/nirweb-support/vulnerability/wordpress-nirweb-support-plugin-3-0-3-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-639"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-w64r-953q-gv3q/GHSA-w64r-953q-gv3q.json b/advisories/unreviewed/2025/02/GHSA-w64r-953q-gv3q/GHSA-w64r-953q-gv3q.json
new file mode 100644
index 00000000000..1327186b827
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-w64r-953q-gv3q/GHSA-w64r-953q-gv3q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w64r-953q-gv3q",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-23984"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainvireinfo Dynamic URL SEO allows Reflected XSS. This issue affects Dynamic URL SEO: from n/a through 1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23984"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/dynamic-url-seo/vulnerability/wordpress-dynamic-url-seo-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-whfg-3mpf-fjhx/GHSA-whfg-3mpf-fjhx.json b/advisories/unreviewed/2025/02/GHSA-whfg-3mpf-fjhx/GHSA-whfg-3mpf-fjhx.json
new file mode 100644
index 00000000000..b1b43dd9d41
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-whfg-3mpf-fjhx/GHSA-whfg-3mpf-fjhx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-whfg-3mpf-fjhx",
+ "modified": "2025-02-03T15:32:03Z",
+ "published": "2025-02-03T15:32:03Z",
+ "aliases": [
+ "CVE-2025-22775"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idIA Tech Catalog Importer, Scraper & Crawler allows Reflected XSS. This issue affects Catalog Importer, Scraper & Crawler: from n/a through 5.1.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22775"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/intelligent-importer/vulnerability/wordpress-catalog-importer-scraper-crawler-plugin-5-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:20Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-wmhp-g4mm-69rg/GHSA-wmhp-g4mm-69rg.json b/advisories/unreviewed/2025/02/GHSA-wmhp-g4mm-69rg/GHSA-wmhp-g4mm-69rg.json
new file mode 100644
index 00000000000..5df1ce9bd48
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-wmhp-g4mm-69rg/GHSA-wmhp-g4mm-69rg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wmhp-g4mm-69rg",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2024-50500"
+ ],
+ "details": "Missing Authorization vulnerability in By Averta Shortcodes and extra features for Phlox theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50500"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/auxin-elements/vulnerability/wordpress-phlox-core-elements-plugin-2-17-2-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-wp7q-78g7-c67m/GHSA-wp7q-78g7-c67m.json b/advisories/unreviewed/2025/02/GHSA-wp7q-78g7-c67m/GHSA-wp7q-78g7-c67m.json
new file mode 100644
index 00000000000..6bcfd74e303
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-wp7q-78g7-c67m/GHSA-wp7q-78g7-c67m.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wp7q-78g7-c67m",
+ "modified": "2025-02-03T15:32:02Z",
+ "published": "2025-02-03T15:32:02Z",
+ "aliases": [
+ "CVE-2025-22677"
+ ],
+ "details": "Missing Authorization vulnerability in UIUX Lab Uix Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Uix Shortcodes: from n/a through 2.0.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22677"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/uix-shortcodes/vulnerability/wordpress-uix-shortcodes-plugin-2-0-3-arbitrary-shortcode-execution-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-03T15:15:17Z"
+ }
+}
\ No newline at end of file