diff --git a/advisories/unreviewed/2023/05/GHSA-rxp7-w842-wjmh/GHSA-rxp7-w842-wjmh.json b/advisories/unreviewed/2023/05/GHSA-rxp7-w842-wjmh/GHSA-rxp7-w842-wjmh.json index b6ce7c551c8..5406e42edc4 100644 --- a/advisories/unreviewed/2023/05/GHSA-rxp7-w842-wjmh/GHSA-rxp7-w842-wjmh.json +++ b/advisories/unreviewed/2023/05/GHSA-rxp7-w842-wjmh/GHSA-rxp7-w842-wjmh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-46v4-9j9w-fv79/GHSA-46v4-9j9w-fv79.json b/advisories/unreviewed/2024/02/GHSA-46v4-9j9w-fv79/GHSA-46v4-9j9w-fv79.json index 9c4b2c8acac..1e9d60fc411 100644 --- a/advisories/unreviewed/2024/02/GHSA-46v4-9j9w-fv79/GHSA-46v4-9j9w-fv79.json +++ b/advisories/unreviewed/2024/02/GHSA-46v4-9j9w-fv79/GHSA-46v4-9j9w-fv79.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46v4-9j9w-fv79", - "modified": "2024-02-28T09:30:35Z", + "modified": "2025-01-21T15:31:02Z", "published": "2024-02-28T09:30:35Z", "aliases": [ "CVE-2024-27913" ], "details": "ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T07:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2pc5-c325-6frx/GHSA-2pc5-c325-6frx.json b/advisories/unreviewed/2024/04/GHSA-2pc5-c325-6frx/GHSA-2pc5-c325-6frx.json index 0990956327a..751fa77fc0e 100644 --- a/advisories/unreviewed/2024/04/GHSA-2pc5-c325-6frx/GHSA-2pc5-c325-6frx.json +++ b/advisories/unreviewed/2024/04/GHSA-2pc5-c325-6frx/GHSA-2pc5-c325-6frx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-46v6-hq2c-4h25/GHSA-46v6-hq2c-4h25.json b/advisories/unreviewed/2024/04/GHSA-46v6-hq2c-4h25/GHSA-46v6-hq2c-4h25.json index e8c428fa02f..0842824caca 100644 --- a/advisories/unreviewed/2024/04/GHSA-46v6-hq2c-4h25/GHSA-46v6-hq2c-4h25.json +++ b/advisories/unreviewed/2024/04/GHSA-46v6-hq2c-4h25/GHSA-46v6-hq2c-4h25.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-gpx2-xmvq-g28h/GHSA-gpx2-xmvq-g28h.json b/advisories/unreviewed/2024/04/GHSA-gpx2-xmvq-g28h/GHSA-gpx2-xmvq-g28h.json index 4883ab56c3c..e216872233b 100644 --- a/advisories/unreviewed/2024/04/GHSA-gpx2-xmvq-g28h/GHSA-gpx2-xmvq-g28h.json +++ b/advisories/unreviewed/2024/04/GHSA-gpx2-xmvq-g28h/GHSA-gpx2-xmvq-g28h.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-rqvm-vjc6-3wxj/GHSA-rqvm-vjc6-3wxj.json b/advisories/unreviewed/2024/04/GHSA-rqvm-vjc6-3wxj/GHSA-rqvm-vjc6-3wxj.json index 38f1ea7d317..765a99ce921 100644 --- a/advisories/unreviewed/2024/04/GHSA-rqvm-vjc6-3wxj/GHSA-rqvm-vjc6-3wxj.json +++ b/advisories/unreviewed/2024/04/GHSA-rqvm-vjc6-3wxj/GHSA-rqvm-vjc6-3wxj.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-v5mj-788q-w766/GHSA-v5mj-788q-w766.json b/advisories/unreviewed/2024/04/GHSA-v5mj-788q-w766/GHSA-v5mj-788q-w766.json index 4ea36433532..1a48f912f48 100644 --- a/advisories/unreviewed/2024/04/GHSA-v5mj-788q-w766/GHSA-v5mj-788q-w766.json +++ b/advisories/unreviewed/2024/04/GHSA-v5mj-788q-w766/GHSA-v5mj-788q-w766.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json b/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json index 9cdd916c03c..e1a20768a06 100644 --- a/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json +++ b/advisories/unreviewed/2024/06/GHSA-w5cj-9xrv-rhgm/GHSA-w5cj-9xrv-rhgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5cj-9xrv-rhgm", - "modified": "2024-06-25T06:30:39Z", + "modified": "2025-01-21T15:31:03Z", "published": "2024-06-25T06:30:39Z", "aliases": [ "CVE-2024-4197" diff --git a/advisories/unreviewed/2025/01/GHSA-27gx-f94v-f7hr/GHSA-27gx-f94v-f7hr.json b/advisories/unreviewed/2025/01/GHSA-27gx-f94v-f7hr/GHSA-27gx-f94v-f7hr.json new file mode 100644 index 00000000000..ac5d81dea07 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-27gx-f94v-f7hr/GHSA-27gx-f94v-f7hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27gx-f94v-f7hr", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22719" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22719" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vikappointments/vulnerability/wordpress-vikappointments-services-booking-calendar-plugin-1-2-16-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2f47-g943-j472/GHSA-2f47-g943-j472.json b/advisories/unreviewed/2025/01/GHSA-2f47-g943-j472/GHSA-2f47-g943-j472.json new file mode 100644 index 00000000000..501b65e0968 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2f47-g943-j472/GHSA-2f47-g943-j472.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f47-g943-j472", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-56998" + ], + "details": "PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56998" + }, + { + "type": "WEB", + "url": "https://github.com/kirito999/HMS_stored_XSS/blob/main/stored%20XSS2%20in%20HMS4.0/stored%20XSS2%20in%20HMS.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2fhv-pxmp-gpwh/GHSA-2fhv-pxmp-gpwh.json b/advisories/unreviewed/2025/01/GHSA-2fhv-pxmp-gpwh/GHSA-2fhv-pxmp-gpwh.json index 309f2b8209f..a8857f903e3 100644 --- a/advisories/unreviewed/2025/01/GHSA-2fhv-pxmp-gpwh/GHSA-2fhv-pxmp-gpwh.json +++ b/advisories/unreviewed/2025/01/GHSA-2fhv-pxmp-gpwh/GHSA-2fhv-pxmp-gpwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2fhv-pxmp-gpwh", - "modified": "2025-01-21T06:30:45Z", + "modified": "2025-01-21T15:31:03Z", "published": "2025-01-21T06:30:45Z", "aliases": [ "CVE-2025-23086" ], "details": "On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T05:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2g47-jxc2-73xh/GHSA-2g47-jxc2-73xh.json b/advisories/unreviewed/2025/01/GHSA-2g47-jxc2-73xh/GHSA-2g47-jxc2-73xh.json new file mode 100644 index 00000000000..6de2a04b838 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2g47-jxc2-73xh/GHSA-2g47-jxc2-73xh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g47-jxc2-73xh", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21656" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur\n\nscsi_execute_cmd() function can return both negative (linux codes) and\npositive (scsi_cmnd result field) error codes.\n\nCurrently the driver just passes error codes of scsi_execute_cmd() to\nhwmon core, which is incorrect because hwmon only checks for negative\nerror codes. This leads to hwmon reporting uninitialized data to\nuserspace in case of SCSI errors (for example if the disk drive was\ndisconnected).\n\nThis patch checks scsi_execute_cmd() output and returns -EIO if it's\nerror code is positive.\n\n[groeck: Avoid inline variable declaration for portability]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21656" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42268d885e44af875a6474f7bba519cc6cea6a9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53e25b10a28edaf8c2a1d3916fd8929501a50dfc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82163d63ae7a4c36142cd252388737205bb7e4b9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2ww6-2gwx-v942/GHSA-2ww6-2gwx-v942.json b/advisories/unreviewed/2025/01/GHSA-2ww6-2gwx-v942/GHSA-2ww6-2gwx-v942.json new file mode 100644 index 00000000000..41ae0b9c3dc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2ww6-2gwx-v942/GHSA-2ww6-2gwx-v942.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ww6-2gwx-v942", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21662" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix variable not being completed when function returns\n\nWhen cmd_alloc_index(), fails cmd_work_handler() needs\nto complete ent->slotted before returning early.\nOtherwise the task which issued the command may hang:\n\n mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry\n INFO: task kworker/13:2:4055883 blocked for more than 120 seconds.\n Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n kworker/13:2 D 0 4055883 2 0x00000228\n Workqueue: events mlx5e_tx_dim_work [mlx5_core]\n Call trace:\n __switch_to+0xe8/0x150\n __schedule+0x2a8/0x9b8\n schedule+0x2c/0x88\n schedule_timeout+0x204/0x478\n wait_for_common+0x154/0x250\n wait_for_completion+0x28/0x38\n cmd_exec+0x7a0/0xa00 [mlx5_core]\n mlx5_cmd_exec+0x54/0x80 [mlx5_core]\n mlx5_core_modify_cq+0x6c/0x80 [mlx5_core]\n mlx5_core_modify_cq_moderation+0xa0/0xb8 [mlx5_core]\n mlx5e_tx_dim_work+0x54/0x68 [mlx5_core]\n process_one_work+0x1b0/0x448\n worker_thread+0x54/0x468\n kthread+0x134/0x138\n ret_from_fork+0x10/0x18", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21662" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e2909c6bec9048f49d0c8e16887c63b50b14647" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/229cc10284373fbe754e623b7033dca7e7470ec8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36124081f6ffd9dfaad48830bdf106bb82a9457d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0a2808767ac39f64b1d9a0ff865c255073cf3d4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-42xc-c24r-x3cc/GHSA-42xc-c24r-x3cc.json b/advisories/unreviewed/2025/01/GHSA-42xc-c24r-x3cc/GHSA-42xc-c24r-x3cc.json new file mode 100644 index 00000000000..e5e379cf68d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-42xc-c24r-x3cc/GHSA-42xc-c24r-x3cc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42xc-c24r-x3cc", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21663" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: dwmac-tegra: Read iommu stream id from device tree\n\nNvidia's Tegra MGBE controllers require the IOMMU \"Stream ID\" (SID) to be\nwritten to the MGBE_WRAP_AXI_ASID0_CTRL register.\n\nThe current driver is hard coded to use MGBE0's SID for all controllers.\nThis causes softirq time outs and kernel panics when using controllers\nother than MGBE0.\n\nExample dmesg errors when an ethernet cable is connected to MGBE1:\n\n[ 116.133290] tegra-mgbe 6910000.ethernet eth1: Link is Up - 1Gbps/Full - flow control rx/tx\n[ 121.851283] tegra-mgbe 6910000.ethernet eth1: NETDEV WATCHDOG: CPU: 5: transmit queue 0 timed out 5690 ms\n[ 121.851782] tegra-mgbe 6910000.ethernet eth1: Reset adapter.\n[ 121.892464] tegra-mgbe 6910000.ethernet eth1: Register MEM_TYPE_PAGE_POOL RxQ-0\n[ 121.905920] tegra-mgbe 6910000.ethernet eth1: PHY [stmmac-1:00] driver [Aquantia AQR113] (irq=171)\n[ 121.907356] tegra-mgbe 6910000.ethernet eth1: Enabling Safety Features\n[ 121.907578] tegra-mgbe 6910000.ethernet eth1: IEEE 1588-2008 Advanced Timestamp supported\n[ 121.908399] tegra-mgbe 6910000.ethernet eth1: registered PTP clock\n[ 121.908582] tegra-mgbe 6910000.ethernet eth1: configuring for phy/10gbase-r link mode\n[ 125.961292] tegra-mgbe 6910000.ethernet eth1: Link is Up - 1Gbps/Full - flow control rx/tx\n[ 181.921198] rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:\n[ 181.921404] rcu: \t7-....: (1 GPs behind) idle=540c/1/0x4000000000000002 softirq=1748/1749 fqs=2337\n[ 181.921684] rcu: \t(detected by 4, t=6002 jiffies, g=1357, q=1254 ncpus=8)\n[ 181.921878] Sending NMI from CPU 4 to CPUs 7:\n[ 181.921886] NMI backtrace for cpu 7\n[ 181.922131] CPU: 7 UID: 0 PID: 0 Comm: swapper/7 Kdump: loaded Not tainted 6.13.0-rc3+ #6\n[ 181.922390] Hardware name: NVIDIA CTI Forge + Orin AGX/Jetson, BIOS 202402.1-Unknown 10/28/2024\n[ 181.922658] pstate: 40400009 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 181.922847] pc : handle_softirqs+0x98/0x368\n[ 181.922978] lr : __do_softirq+0x18/0x20\n[ 181.923095] sp : ffff80008003bf50\n[ 181.923189] x29: ffff80008003bf50 x28: 0000000000000008 x27: 0000000000000000\n[ 181.923379] x26: ffffce78ea277000 x25: 0000000000000000 x24: 0000001c61befda0\n[ 181.924486] x23: 0000000060400009 x22: ffffce78e99918bc x21: ffff80008018bd70\n[ 181.925568] x20: ffffce78e8bb00d8 x19: ffff80008018bc20 x18: 0000000000000000\n[ 181.926655] x17: ffff318ebe7d3000 x16: ffff800080038000 x15: 0000000000000000\n[ 181.931455] x14: ffff000080816680 x13: ffff318ebe7d3000 x12: 000000003464d91d\n[ 181.938628] x11: 0000000000000040 x10: ffff000080165a70 x9 : ffffce78e8bb0160\n[ 181.945804] x8 : ffff8000827b3160 x7 : f9157b241586f343 x6 : eeb6502a01c81c74\n[ 181.953068] x5 : a4acfcdd2e8096bb x4 : ffffce78ea277340 x3 : 00000000ffffd1e1\n[ 181.960329] x2 : 0000000000000101 x1 : ffffce78ea277340 x0 : ffff318ebe7d3000\n[ 181.967591] Call trace:\n[ 181.970043] handle_softirqs+0x98/0x368 (P)\n[ 181.974240] __do_softirq+0x18/0x20\n[ 181.977743] ____do_softirq+0x14/0x28\n[ 181.981415] call_on_irq_stack+0x24/0x30\n[ 181.985180] do_softirq_own_stack+0x20/0x30\n[ 181.989379] __irq_exit_rcu+0x114/0x140\n[ 181.993142] irq_exit_rcu+0x14/0x28\n[ 181.996816] el1_interrupt+0x44/0xb8\n[ 182.000316] el1h_64_irq_handler+0x14/0x20\n[ 182.004343] el1h_64_irq+0x80/0x88\n[ 182.007755] cpuidle_enter_state+0xc4/0x4a8 (P)\n[ 182.012305] cpuidle_enter+0x3c/0x58\n[ 182.015980] cpuidle_idle_call+0x128/0x1c0\n[ 182.020005] do_idle+0xe0/0xf0\n[ 182.023155] cpu_startup_entry+0x3c/0x48\n[ 182.026917] secondary_start_kernel+0xdc/0x120\n[ 182.031379] __secondary_switched+0x74/0x78\n[ 212.971162] rcu: INFO: rcu_preempt detected expedited stalls on CPUs/tasks: { 7-.... } 6103 jiffies s: 417 root: 0x80/.\n[ 212.985935] rcu: blocking rcu_node structures (internal RCU debug):\n[ 212.992758] Sending NMI from CPU 0 to CPUs 7:\n[ 212.998539] NMI backtrace for cpu 7\n[ 213.004304] CPU: 7 UID: 0 PI\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21663" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/235419f0956e8c60e597aa1619ded8bda7460bb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/426046e2d62dd19533808661e912b8e8a9eaec16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b04d33cdbc958a3fd57f3544d4f78b99d9d11909" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-45wg-5jjc-jrwh/GHSA-45wg-5jjc-jrwh.json b/advisories/unreviewed/2025/01/GHSA-45wg-5jjc-jrwh/GHSA-45wg-5jjc-jrwh.json new file mode 100644 index 00000000000..aef50562507 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-45wg-5jjc-jrwh/GHSA-45wg-5jjc-jrwh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45wg-5jjc-jrwh", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22732" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Admiral Ad Blocking Detector allows Stored XSS. This issue affects Ad Blocking Detector: from n/a through 3.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22732" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ad-blocking-detector/vulnerability/wordpress-ad-blocking-detector-plugin-3-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-47w8-68x4-mmm6/GHSA-47w8-68x4-mmm6.json b/advisories/unreviewed/2025/01/GHSA-47w8-68x4-mmm6/GHSA-47w8-68x4-mmm6.json new file mode 100644 index 00000000000..37c0c579d51 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-47w8-68x4-mmm6/GHSA-47w8-68x4-mmm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47w8-68x4-mmm6", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49688" + ], + "details": "Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49688" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arprice/vulnerability/wordpress-arprice-plugin-4-0-3-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4fjh-cw7f-3pp5/GHSA-4fjh-cw7f-3pp5.json b/advisories/unreviewed/2025/01/GHSA-4fjh-cw7f-3pp5/GHSA-4fjh-cw7f-3pp5.json new file mode 100644 index 00000000000..f9a45de4444 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4fjh-cw7f-3pp5/GHSA-4fjh-cw7f-3pp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fjh-cw7f-3pp5", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49699" + ], + "details": "Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49699" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arprice/vulnerability/wordpress-arprice-plugin-4-0-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4p4q-xgpq-cfjx/GHSA-4p4q-xgpq-cfjx.json b/advisories/unreviewed/2025/01/GHSA-4p4q-xgpq-cfjx/GHSA-4p4q-xgpq-cfjx.json new file mode 100644 index 00000000000..98df6a062c2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4p4q-xgpq-cfjx/GHSA-4p4q-xgpq-cfjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p4q-xgpq-cfjx", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22262" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bonjour Bar allows Stored XSS. This issue affects Bonjour Bar: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bonjour-bar/vulnerability/wordpress-bonjour-bar-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4wrh-8j8q-8frq/GHSA-4wrh-8j8q-8frq.json b/advisories/unreviewed/2025/01/GHSA-4wrh-8j8q-8frq/GHSA-4wrh-8j8q-8frq.json new file mode 100644 index 00000000000..0783d0884ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4wrh-8j8q-8frq/GHSA-4wrh-8j8q-8frq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wrh-8j8q-8frq", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49655" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arprice/vulnerability/wordpress-arprice-plugin-4-0-3-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json b/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json new file mode 100644 index 00000000000..407d1d3209e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-743f-m6p2-83h6/GHSA-743f-m6p2-83h6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-743f-m6p2-83h6", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57945" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: mm: Fix the out of bound issue of vmemmap address\n\nIn sparse vmemmap model, the virtual address of vmemmap is calculated as:\n((struct page *)VMEMMAP_START - (phys_ram_base >> PAGE_SHIFT)).\nAnd the struct page's va can be calculated with an offset:\n(vmemmap + (pfn)).\n\nHowever, when initializing struct pages, kernel actually starts from the\nfirst page from the same section that phys_ram_base belongs to. If the\nfirst page's physical address is not (phys_ram_base >> PAGE_SHIFT), then\nwe get an va below VMEMMAP_START when calculating va for it's struct page.\n\nFor example, if phys_ram_base starts from 0x82000000 with pfn 0x82000, the\nfirst page in the same section is actually pfn 0x80000. During\ninit_unavailable_range(), we will initialize struct page for pfn 0x80000\nwith virtual address ((struct page *)VMEMMAP_START - 0x2000), which is\nbelow VMEMMAP_START as well as PCI_IO_END.\n\nThis commit fixes this bug by introducing a new variable\n'vmemmap_start_pfn' which is aligned with memory section size and using\nit to calculate vmemmap address instead of phys_ram_base.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57945" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4a7ac3d266008018f05fae53060fcb331151a14" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2bd51954ac8377c2f1eb1813e694788998add66" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f754f27e98f88428aaf6be6e00f5cbce97f62d4b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-79cx-c495-ffvx/GHSA-79cx-c495-ffvx.json b/advisories/unreviewed/2025/01/GHSA-79cx-c495-ffvx/GHSA-79cx-c495-ffvx.json new file mode 100644 index 00000000000..85525d918da --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-79cx-c495-ffvx/GHSA-79cx-c495-ffvx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79cx-c495-ffvx", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21657" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Replace rq_lock() to raw_spin_rq_lock() in scx_ops_bypass()\n\nscx_ops_bypass() iterates all CPUs to re-enqueue all the scx tasks.\nFor each CPU, it acquires a lock using rq_lock() regardless of whether\na CPU is offline or the CPU is currently running a task in a higher\nscheduler class (e.g., deadline). The rq_lock() is supposed to be used\nfor online CPUs, and the use of rq_lock() may trigger an unnecessary\nwarning in rq_pin_lock(). Therefore, replace rq_lock() to\nraw_spin_rq_lock() in scx_ops_bypass().\n\nWithout this change, we observe the following warning:\n\n===== START =====\n[ 6.615205] rq->balance_callback && rq->balance_callback != &balance_push_callback\n[ 6.615208] WARNING: CPU: 2 PID: 0 at kernel/sched/sched.h:1730 __schedule+0x1130/0x1c90\n===== END =====", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21657" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6268d5bc10354fc2ab8d44a0cd3b042d49a0417e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9e446dd63cee7161717a6a8414ba9c6435af764" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-862v-8qcr-m359/GHSA-862v-8qcr-m359.json b/advisories/unreviewed/2025/01/GHSA-862v-8qcr-m359/GHSA-862v-8qcr-m359.json index 50061e6c6ef..ef214e0f62c 100644 --- a/advisories/unreviewed/2025/01/GHSA-862v-8qcr-m359/GHSA-862v-8qcr-m359.json +++ b/advisories/unreviewed/2025/01/GHSA-862v-8qcr-m359/GHSA-862v-8qcr-m359.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-862v-8qcr-m359", - "modified": "2025-01-20T09:30:46Z", + "modified": "2025-01-21T15:31:03Z", "published": "2025-01-20T09:30:46Z", "aliases": [ "CVE-2025-0590" ], "details": "Improper permission settings for mobile applications (com.transsion.carlcare) may lead to \n\ninformation leakage risk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-732" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-20T07:17:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8fv4-m6f4-qgvp/GHSA-8fv4-m6f4-qgvp.json b/advisories/unreviewed/2025/01/GHSA-8fv4-m6f4-qgvp/GHSA-8fv4-m6f4-qgvp.json new file mode 100644 index 00000000000..43c892fc5a2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8fv4-m6f4-qgvp/GHSA-8fv4-m6f4-qgvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fv4-m6f4-qgvp", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-24001" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PPO Việt Nam (ppo.vn) PPO Call To Actions allows Cross Site Request Forgery. This issue affects PPO Call To Actions: from n/a through 0.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ppo-call-to-actions/vulnerability/wordpress-ppo-call-to-actions-plugin-0-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8jjg-qm9p-m97c/GHSA-8jjg-qm9p-m97c.json b/advisories/unreviewed/2025/01/GHSA-8jjg-qm9p-m97c/GHSA-8jjg-qm9p-m97c.json new file mode 100644 index 00000000000..b17076e213e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8jjg-qm9p-m97c/GHSA-8jjg-qm9p-m97c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jjg-qm9p-m97c", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22711" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Maier Image Source Control allows Reflected XSS. This issue affects Image Source Control: from n/a through 2.29.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22711" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-source-control-isc/vulnerability/wordpress-image-source-control-lite-plugin-2-29-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8pw9-7gv3-535c/GHSA-8pw9-7gv3-535c.json b/advisories/unreviewed/2025/01/GHSA-8pw9-7gv3-535c/GHSA-8pw9-7gv3-535c.json new file mode 100644 index 00000000000..ed3bd1ad940 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8pw9-7gv3-535c/GHSA-8pw9-7gv3-535c.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pw9-7gv3-535c", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57940" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix the infinite loop in exfat_readdir()\n\nIf the file system is corrupted so that a cluster is linked to\nitself in the cluster chain, and there is an unused directory\nentry in the cluster, 'dentry' will not be incremented, causing\ncondition 'dentry < max_dentries' unable to prevent an infinite\nloop.\n\nThis infinite loop causes s_lock not to be released, and other\ntasks will hang, such as exfat_sync_fs().\n\nThis commit stops traversing the cluster chain when there is unused\ndirectory entry in the cluster to avoid this infinite loop.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57940" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31beabd0f47f8c3ed9965ba861c9e5b252d4920a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9ea94f5cd117d56e573696d0045ab3044185a15" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc1d7afceb982e8f666e70a582e6b5aa806de063" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fee873761bd978d077d8c55334b4966ac4cb7b59" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-983w-hqxf-c48p/GHSA-983w-hqxf-c48p.json b/advisories/unreviewed/2025/01/GHSA-983w-hqxf-c48p/GHSA-983w-hqxf-c48p.json new file mode 100644 index 00000000000..97614e381d0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-983w-hqxf-c48p/GHSA-983w-hqxf-c48p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-983w-hqxf-c48p", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57942" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix ceph copy to cache on write-begin\n\nAt the end of netfs_unlock_read_folio() in which folios are marked\nappropriately for copying to the cache (either with by being marked dirty\nand having their private data set or by having PG_private_2 set) and then\nunlocked, the folio_queue struct has the entry pointing to the folio\ncleared. This presents a problem for netfs_pgpriv2_write_to_the_cache(),\nwhich is used to write folios marked with PG_private_2 to the cache as it\nexpects to be able to trawl the folio_queue list thereafter to find the\nrelevant folios, leading to a hang.\n\nFix this by not clearing the folio_queue entry if we're going to do the\ndeprecated copy-to-cache. The clearance will be done instead as the folios\nare written to the cache.\n\nThis can be reproduced by starting cachefiles, mounting a ceph filesystem\nwith \"-o fsc\" and writing to it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57942" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38cf8e945721ffe708fa675507465da7f4f2a9f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/43b8d3249b0b71bad239d42dbe08ce6c938ba000" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9pph-vqgh-3wmp/GHSA-9pph-vqgh-3wmp.json b/advisories/unreviewed/2025/01/GHSA-9pph-vqgh-3wmp/GHSA-9pph-vqgh-3wmp.json new file mode 100644 index 00000000000..9f7029cf9fb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9pph-vqgh-3wmp/GHSA-9pph-vqgh-3wmp.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pph-vqgh-3wmp", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57939" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Fix sleeping in invalid context in die()\n\ndie() can be called in exception handler, and therefore cannot sleep.\nHowever, die() takes spinlock_t which can sleep with PREEMPT_RT enabled.\nThat causes the following warning:\n\nBUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\nin_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 285, name: mutex\npreempt_count: 110001, expected: 0\nRCU nest depth: 0, expected: 0\nCPU: 0 UID: 0 PID: 285 Comm: mutex Not tainted 6.12.0-rc7-00022-ge19049cf7d56-dirty #234\nHardware name: riscv-virtio,qemu (DT)\nCall Trace:\n dump_backtrace+0x1c/0x24\n show_stack+0x2c/0x38\n dump_stack_lvl+0x5a/0x72\n dump_stack+0x14/0x1c\n __might_resched+0x130/0x13a\n rt_spin_lock+0x2a/0x5c\n die+0x24/0x112\n do_trap_insn_illegal+0xa0/0xea\n _new_vmalloc_restore_context_a0+0xcc/0xd8\nOops - illegal instruction [#1]\n\nSwitch to use raw_spinlock_t, which does not sleep even with PREEMPT_RT\nenabled.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57939" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a97f4118ac07cfdc316433f385dbdc12af5025e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76ab0afcdbe8c9685b589016ee1c0e25fe596707" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c21df31fc2a4afc02a6e56511364e9e793ea92ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f48f060a4b36b5e96628f6c3fb1540f1e8dedb69" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9qhx-c3g8-3492/GHSA-9qhx-c3g8-3492.json b/advisories/unreviewed/2025/01/GHSA-9qhx-c3g8-3492/GHSA-9qhx-c3g8-3492.json new file mode 100644 index 00000000000..dcb313bca48 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9qhx-c3g8-3492/GHSA-9qhx-c3g8-3492.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qhx-c3g8-3492", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22318" + ], + "details": "Missing Authorization vulnerability in Eniture Technology Standard Box Sizes – for WooCommerce. This issue affects Standard Box Sizes – for WooCommerce: from n/a through 1.6.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22318" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/standard-box-sizes/vulnerability/wordpress-standard-box-sizes-plugin-1-6-12-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9v5c-6fwm-w457/GHSA-9v5c-6fwm-w457.json b/advisories/unreviewed/2025/01/GHSA-9v5c-6fwm-w457/GHSA-9v5c-6fwm-w457.json new file mode 100644 index 00000000000..d7b85bb125c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9v5c-6fwm-w457/GHSA-9v5c-6fwm-w457.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v5c-6fwm-w457", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49333" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49333" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hmenu/vulnerability/wordpress-hero-menu-plugin-1-16-5-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9xpx-98qw-j5jv/GHSA-9xpx-98qw-j5jv.json b/advisories/unreviewed/2025/01/GHSA-9xpx-98qw-j5jv/GHSA-9xpx-98qw-j5jv.json new file mode 100644 index 00000000000..2705b1cc0c1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9xpx-98qw-j5jv/GHSA-9xpx-98qw-j5jv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xpx-98qw-j5jv", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-56277" + ], + "details": "Improper Encoding or Escaping of Output vulnerability in Poll Maker Team Poll Maker. This issue affects Poll Maker: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-plugin-5-5-5-html-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-116" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f3vp-27j4-hrcw/GHSA-f3vp-27j4-hrcw.json b/advisories/unreviewed/2025/01/GHSA-f3vp-27j4-hrcw/GHSA-f3vp-27j4-hrcw.json new file mode 100644 index 00000000000..dd7ca2ffdc3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f3vp-27j4-hrcw/GHSA-f3vp-27j4-hrcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3vp-27j4-hrcw", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-51888" + ], + "details": "Incorrect Privilege Assignment vulnerability in NotFound Homey Login Register allows Privilege Escalation. This issue affects Homey Login Register: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51888" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/homey-login-register/vulnerability/wordpress-homey-login-register-plugin-2-4-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gh66-q8v2-v5pc/GHSA-gh66-q8v2-v5pc.json b/advisories/unreviewed/2025/01/GHSA-gh66-q8v2-v5pc/GHSA-gh66-q8v2-v5pc.json new file mode 100644 index 00000000000..84dca870b04 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gh66-q8v2-v5pc/GHSA-gh66-q8v2-v5pc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh66-q8v2-v5pc", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-32555" + ], + "details": "Incorrect Privilege Assignment vulnerability in NotFound Easy Real Estate allows Privilege Escalation. This issue affects Easy Real Estate: from n/a through 2.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-real-estate/vulnerability/wordpress-easy-real-estate-plugin-2-2-6-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h738-p7mj-mggx/GHSA-h738-p7mj-mggx.json b/advisories/unreviewed/2025/01/GHSA-h738-p7mj-mggx/GHSA-h738-p7mj-mggx.json new file mode 100644 index 00000000000..5bdf830866b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h738-p7mj-mggx/GHSA-h738-p7mj-mggx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h738-p7mj-mggx", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22710" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StoreApps Smart Manager allows Blind SQL Injection. This issue affects Smart Manager: from n/a through 8.52.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22710" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-manager-for-wp-e-commerce/vulnerability/wordpress-smart-manager-plugin-8-52-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h85x-rxvw-x49j/GHSA-h85x-rxvw-x49j.json b/advisories/unreviewed/2025/01/GHSA-h85x-rxvw-x49j/GHSA-h85x-rxvw-x49j.json new file mode 100644 index 00000000000..aba7bdf6c72 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h85x-rxvw-x49j/GHSA-h85x-rxvw-x49j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h85x-rxvw-x49j", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21661" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: virtuser: fix missing lookup table cleanups\n\nWhen a virtuser device is created via configfs and the probe fails due\nto an incorrect lookup table, the table is not removed. This prevents\nsubsequent probe attempts from succeeding, even if the issue is\ncorrected, unless the device is released. Additionally, cleanup is also\nneeded in the less likely case of platform_device_register_full()\nfailure.\n\nBesides, a consistent memory leak in lookup_table->dev_id was spotted\nusing kmemleak by toggling the live state between 0 and 1 with a correct\nlookup table.\n\nIntroduce gpio_virtuser_remove_lookup_table() as the counterpart to the\nexisting gpio_virtuser_make_lookup_table() and call it from all\nnecessary points to ensure proper cleanup.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21661" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a619cba8c69c434258ff4101d463322cd63e1bdc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d72d0126b1f6981f6ce8b4247305f359958c11b5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hgm3-gq5f-vjwg/GHSA-hgm3-gq5f-vjwg.json b/advisories/unreviewed/2025/01/GHSA-hgm3-gq5f-vjwg/GHSA-hgm3-gq5f-vjwg.json new file mode 100644 index 00000000000..1a153c60489 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hgm3-gq5f-vjwg/GHSA-hgm3-gq5f-vjwg.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgm3-gq5f-vjwg", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57946" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-blk: don't keep queue frozen during system suspend\n\nCommit 4ce6e2db00de (\"virtio-blk: Ensure no requests in virtqueues before\ndeleting vqs.\") replaces queue quiesce with queue freeze in virtio-blk's\nPM callbacks. And the motivation is to drain inflight IOs before suspending.\n\nblock layer's queue freeze looks very handy, but it is also easy to cause\ndeadlock, such as, any attempt to call into bio_queue_enter() may run into\ndeadlock if the queue is frozen in current context. There are all kinds\nof ->suspend() called in suspend context, so keeping queue frozen in the\nwhole suspend context isn't one good idea. And Marek reported lockdep\nwarning[1] caused by virtio-blk's freeze queue in virtblk_freeze().\n\n[1] https://lore.kernel.org/linux-block/ca16370e-d646-4eee-b9cc-87277c89c43c@samsung.com/\n\nGiven the motivation is to drain in-flight IOs, it can be done by calling\nfreeze & unfreeze, meantime restore to previous behavior by keeping queue\nquiesced during suspend.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57946" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12c0ddd6c551c1e438b087f874b4f1223a75f7ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dea8e3de59928974bf157dd0499d3958d744ae4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7678abee0867e6b7fb89aa40f6e9f575f755fb37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92d5139b91147ab372a17daf5dc27a5b9278e516" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ca428c6397abaa8c38f5c69133a2299e1efbbf2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e323f856cf4963120e0e3892a84ef8bd764a0e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d738f3215bb4f88911ff4579780a44960c8e0ca5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j4j4-3gm3-wpx2/GHSA-j4j4-3gm3-wpx2.json b/advisories/unreviewed/2025/01/GHSA-j4j4-3gm3-wpx2/GHSA-j4j4-3gm3-wpx2.json new file mode 100644 index 00000000000..c5522dc8b8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j4j4-3gm3-wpx2/GHSA-j4j4-3gm3-wpx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4j4-3gm3-wpx2", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-23998" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rara Theme UltraLight allows Reflected XSS. This issue affects UltraLight: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23998" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/the-ultralight/vulnerability/wordpress-ultralight-theme-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j752-m9pw-j2v5/GHSA-j752-m9pw-j2v5.json b/advisories/unreviewed/2025/01/GHSA-j752-m9pw-j2v5/GHSA-j752-m9pw-j2v5.json new file mode 100644 index 00000000000..5c1561e31ca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j752-m9pw-j2v5/GHSA-j752-m9pw-j2v5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j752-m9pw-j2v5", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-51818" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51818" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fancy-product-designer/vulnerability/wordpress-fancy-product-designer-plugin-6-4-3-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jj94-6v6v-cc35/GHSA-jj94-6v6v-cc35.json b/advisories/unreviewed/2025/01/GHSA-jj94-6v6v-cc35/GHSA-jj94-6v6v-cc35.json new file mode 100644 index 00000000000..e3b5ff74ab0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jj94-6v6v-cc35/GHSA-jj94-6v6v-cc35.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj94-6v6v-cc35", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21660" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked\n\nWhen `ksmbd_vfs_kern_path_locked` met an error and it is not the last\nentry, it will exit without restoring changed path buffer. But later this\nbuffer may be used as the filename for creation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21660" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13e41c58c74baa71f34c0830eaa3c29d53a6e964" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ac538e40278a2c0c051cca81bcaafc547d61372" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51669f4af5f7959565b48e55691ba92fabf5c587" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65b31b9d992c0fb0685c51a0cf09993832734fc4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m6xv-fv5h-w6qh/GHSA-m6xv-fv5h-w6qh.json b/advisories/unreviewed/2025/01/GHSA-m6xv-fv5h-w6qh/GHSA-m6xv-fv5h-w6qh.json new file mode 100644 index 00000000000..8bdf0abba31 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m6xv-fv5h-w6qh/GHSA-m6xv-fv5h-w6qh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6xv-fv5h-w6qh", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22763" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro allows Reflected XSS. This issue affects Brizy Pro: from n/a through 2.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/brizy-pro/vulnerability/wordpress-brizy-pro-plugin-2-6-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mg35-fw68-x22w/GHSA-mg35-fw68-x22w.json b/advisories/unreviewed/2025/01/GHSA-mg35-fw68-x22w/GHSA-mg35-fw68-x22w.json new file mode 100644 index 00000000000..ab7da8fdc33 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mg35-fw68-x22w/GHSA-mg35-fw68-x22w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg35-fw68-x22w", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21659" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetdev: prevent accessing NAPI instances from another namespace\n\nThe NAPI IDs were not fully exposed to user space prior to the netlink\nAPI, so they were never namespaced. The netlink API must ensure that\nat the very least NAPI instance belongs to the same netns as the owner\nof the genl sock.\n\nnapi_by_id() can become static now, but it needs to move because of\ndev_get_by_napi_id().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21659" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b683ba0df11ff563cc237eb1b74d6adfa77226bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1cacd74776895f6435941f86a1130e58f6dd226" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mh65-27wg-9p5h/GHSA-mh65-27wg-9p5h.json b/advisories/unreviewed/2025/01/GHSA-mh65-27wg-9p5h/GHSA-mh65-27wg-9p5h.json new file mode 100644 index 00000000000..f6b04f49b36 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mh65-27wg-9p5h/GHSA-mh65-27wg-9p5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh65-27wg-9p5h", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22311" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Private Messages for UserPro. This issue affects Private Messages for UserPro: from n/a through 4.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22311" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userpro-messaging/vulnerability/wordpress-private-messages-for-userpro-plugin-4-10-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mhm3-7xrh-62qv/GHSA-mhm3-7xrh-62qv.json b/advisories/unreviewed/2025/01/GHSA-mhm3-7xrh-62qv/GHSA-mhm3-7xrh-62qv.json new file mode 100644 index 00000000000..fe76d272079 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mhm3-7xrh-62qv/GHSA-mhm3-7xrh-62qv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhm3-7xrh-62qv", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49300" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows Reflected XSS. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49300" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hmenu/vulnerability/wordpress-hero-menu-plugin-1-16-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mqhv-2wr5-7crw/GHSA-mqhv-2wr5-7crw.json b/advisories/unreviewed/2025/01/GHSA-mqhv-2wr5-7crw/GHSA-mqhv-2wr5-7crw.json new file mode 100644 index 00000000000..239c99cf69f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mqhv-2wr5-7crw/GHSA-mqhv-2wr5-7crw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqhv-2wr5-7crw", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22717" + ], + "details": "Missing Authorization vulnerability in Joe Dolson My Tickets allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects My Tickets: from n/a through 2.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22717" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/my-tickets/vulnerability/wordpress-my-tickets-plugin-2-0-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p9vv-hm69-8j9v/GHSA-p9vv-hm69-8j9v.json b/advisories/unreviewed/2025/01/GHSA-p9vv-hm69-8j9v/GHSA-p9vv-hm69-8j9v.json new file mode 100644 index 00000000000..7b7280c1f7e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p9vv-hm69-8j9v/GHSA-p9vv-hm69-8j9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9vv-hm69-8j9v", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22553" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Multiple Carousel allows SQL Injection. This issue affects Multiple Carousel: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multicarousel/vulnerability/wordpress-multiple-carousel-plugin-2-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p9vw-f8rg-c624/GHSA-p9vw-f8rg-c624.json b/advisories/unreviewed/2025/01/GHSA-p9vw-f8rg-c624/GHSA-p9vw-f8rg-c624.json new file mode 100644 index 00000000000..938826af0dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p9vw-f8rg-c624/GHSA-p9vw-f8rg-c624.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9vw-f8rg-c624", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57943" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix the new buffer was not zeroed before writing\n\nBefore writing, if a buffer_head marked as new, its data must\nbe zeroed, otherwise uninitialized data in the page cache will\nbe written.\n\nSo this commit uses folio_zero_new_buffers() to zero the new\nbuffers before ->write_end().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57943" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/942c6f91ab8d82a41650e717940b4e577173762f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98e2fb26d1a9eafe79f46d15d54e68e014d81d8c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-phh3-rpf3-3q9p/GHSA-phh3-rpf3-3q9p.json b/advisories/unreviewed/2025/01/GHSA-phh3-rpf3-3q9p/GHSA-phh3-rpf3-3q9p.json new file mode 100644 index 00000000000..b21f25e3f3a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-phh3-rpf3-3q9p/GHSA-phh3-rpf3-3q9p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phh3-rpf3-3q9p", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21658" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: avoid NULL pointer dereference if no valid extent tree\n\n[BUG]\nSyzbot reported a crash with the following call trace:\n\n BTRFS info (device loop0): scrub: started on devid 1\n BUG: kernel NULL pointer dereference, address: 0000000000000208\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 106e70067 P4D 106e70067 PUD 107143067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 1 UID: 0 PID: 689 Comm: repro Kdump: loaded Tainted: G O 6.13.0-rc4-custom+ #206\n Tainted: [O]=OOT_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022\n RIP: 0010:find_first_extent_item+0x26/0x1f0 [btrfs]\n Call Trace:\n \n scrub_find_fill_first_stripe+0x13d/0x3b0 [btrfs]\n scrub_simple_mirror+0x175/0x260 [btrfs]\n scrub_stripe+0x5d4/0x6c0 [btrfs]\n scrub_chunk+0xbb/0x170 [btrfs]\n scrub_enumerate_chunks+0x2f4/0x5f0 [btrfs]\n btrfs_scrub_dev+0x240/0x600 [btrfs]\n btrfs_ioctl+0x1dc8/0x2fa0 [btrfs]\n ? do_sys_openat2+0xa5/0xf0\n __x64_sys_ioctl+0x97/0xc0\n do_syscall_64+0x4f/0x120\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n \n\n[CAUSE]\nThe reproducer is using a corrupted image where extent tree root is\ncorrupted, thus forcing to use \"rescue=all,ro\" mount option to mount the\nimage.\n\nThen it triggered a scrub, but since scrub relies on extent tree to find\nwhere the data/metadata extents are, scrub_find_fill_first_stripe()\nrelies on an non-empty extent root.\n\nBut unfortunately scrub_find_fill_first_stripe() doesn't really expect\nan NULL pointer for extent root, it use extent_root to grab fs_info and\ntriggered a NULL pointer dereference.\n\n[FIX]\nAdd an extra check for a valid extent root at the beginning of\nscrub_find_fill_first_stripe().\n\nThe new error path is introduced by 42437a6386ff (\"btrfs: introduce\nmount option rescue=ignorebadroots\"), but that's pretty old, and later\ncommit b979547513ff (\"btrfs: scrub: introduce helper to find and fill\nsector info for a scrub_stripe\") changed how we do scrub.\n\nSo for kernels older than 6.6, the fix will need manual backport.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21658" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24b85a8b0310e0144da9ab30be42e87e6476638a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6aecd91a5c5b68939cf4169e32bc49f3cd2dd329" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aee5f69f3e6cd82bfefaca1b70b40b6cd8f3f784" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pjq5-5rc2-6pp7/GHSA-pjq5-5rc2-6pp7.json b/advisories/unreviewed/2025/01/GHSA-pjq5-5rc2-6pp7/GHSA-pjq5-5rc2-6pp7.json new file mode 100644 index 00000000000..914f1bb8f3e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pjq5-5rc2-6pp7/GHSA-pjq5-5rc2-6pp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjq5-5rc2-6pp7", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49303" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49303" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hmenu/vulnerability/wordpress-hero-menu-plugin-1-16-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pwq9-r746-qmmp/GHSA-pwq9-r746-qmmp.json b/advisories/unreviewed/2025/01/GHSA-pwq9-r746-qmmp/GHSA-pwq9-r746-qmmp.json new file mode 100644 index 00000000000..6973350d1d3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pwq9-r746-qmmp/GHSA-pwq9-r746-qmmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwq9-r746-qmmp", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22825" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Desk Flexible PDF Coupons allows Stored XSS. This issue affects Flexible PDF Coupons: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22825" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexible-coupons/vulnerability/wordpress-flexible-pdf-coupons-plugin-1-10-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q38q-p8xv-67g9/GHSA-q38q-p8xv-67g9.json b/advisories/unreviewed/2025/01/GHSA-q38q-p8xv-67g9/GHSA-q38q-p8xv-67g9.json new file mode 100644 index 00000000000..c9c5f769f3c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q38q-p8xv-67g9/GHSA-q38q-p8xv-67g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q38q-p8xv-67g9", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22723" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Upload a Web Shell to a Web Server. This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22723" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/vulnerability/wordpress-barcode-scanner-and-inventory-manager-plugin-1-6-7-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qhrx-h236-jpc8/GHSA-qhrx-h236-jpc8.json b/advisories/unreviewed/2025/01/GHSA-qhrx-h236-jpc8/GHSA-qhrx-h236-jpc8.json new file mode 100644 index 00000000000..16c9d8266dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qhrx-h236-jpc8/GHSA-qhrx-h236-jpc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhrx-h236-jpc8", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-49700" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ARPrice allows Reflected XSS. This issue affects ARPrice: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49700" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arprice/vulnerability/wordpress-arprice-plugin-4-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qr7r-p292-xqvq/GHSA-qr7r-p292-xqvq.json b/advisories/unreviewed/2025/01/GHSA-qr7r-p292-xqvq/GHSA-qr7r-p292-xqvq.json new file mode 100644 index 00000000000..62669f73970 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qr7r-p292-xqvq/GHSA-qr7r-p292-xqvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr7r-p292-xqvq", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-51919" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51919" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fancy-product-designer/vulnerability/wordpress-fancy-product-designer-plugin-6-4-3-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qwp3-qccp-m6pg/GHSA-qwp3-qccp-m6pg.json b/advisories/unreviewed/2025/01/GHSA-qwp3-qccp-m6pg/GHSA-qwp3-qccp-m6pg.json new file mode 100644 index 00000000000..4aa564036d8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qwp3-qccp-m6pg/GHSA-qwp3-qccp-m6pg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwp3-qccp-m6pg", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2024-56997" + ], + "details": "PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Email' parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56997" + }, + { + "type": "WEB", + "url": "https://github.com/kirito999/HMS_stored_XSS/blob/main/stored%20XSS5%20in%20HMS4.0/stored%20XSS5%20in%20HMS.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rj76-j4fr-rh37/GHSA-rj76-j4fr-rh37.json b/advisories/unreviewed/2025/01/GHSA-rj76-j4fr-rh37/GHSA-rj76-j4fr-rh37.json new file mode 100644 index 00000000000..f6410780d8d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rj76-j4fr-rh37/GHSA-rj76-j4fr-rh37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj76-j4fr-rh37", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22716" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Taskbuilder Team Taskbuilder allows SQL Injection. This issue affects Taskbuilder: from n/a through 3.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22716" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taskbuilder/vulnerability/wordpress-taskbuilder-plugin-3-0-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rjjv-v2f9-mvc3/GHSA-rjjv-v2f9-mvc3.json b/advisories/unreviewed/2025/01/GHSA-rjjv-v2f9-mvc3/GHSA-rjjv-v2f9-mvc3.json new file mode 100644 index 00000000000..9fb093a08de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rjjv-v2f9-mvc3/GHSA-rjjv-v2f9-mvc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjjv-v2f9-mvc3", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22718" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roninwp FAT Event Lite allows Stored XSS. This issue affects FAT Event Lite: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22718" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fat-event-lite/vulnerability/wordpress-fat-event-lite-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rrmx-hq42-947r/GHSA-rrmx-hq42-947r.json b/advisories/unreviewed/2025/01/GHSA-rrmx-hq42-947r/GHSA-rrmx-hq42-947r.json new file mode 100644 index 00000000000..c602f746dfc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rrmx-hq42-947r/GHSA-rrmx-hq42-947r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrmx-hq42-947r", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57944" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1298: Add NULL check in ads1298_init\n\ndevm_kasprintf() can return a NULL pointer on failure. A check on the\nreturn value of such a call in ads1298_init() is missing. Add it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57944" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69b680bbac9bd611aaa308769d6c71e3e70eb3c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcb394bb28e55312cace75362b8e489eb0e02a30" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vfrm-8x77-ccpw/GHSA-vfrm-8x77-ccpw.json b/advisories/unreviewed/2025/01/GHSA-vfrm-8x77-ccpw/GHSA-vfrm-8x77-ccpw.json new file mode 100644 index 00000000000..a33ce037442 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vfrm-8x77-ccpw/GHSA-vfrm-8x77-ccpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfrm-8x77-ccpw", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22706" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.mihai Social Pug: Author Box allows Reflected XSS. This issue affects Social Pug: Author Box: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22706" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-pug-author-box/vulnerability/wordpress-social-pug-author-box-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vfxx-4xcx-mgvh/GHSA-vfxx-4xcx-mgvh.json b/advisories/unreviewed/2025/01/GHSA-vfxx-4xcx-mgvh/GHSA-vfxx-4xcx-mgvh.json new file mode 100644 index 00000000000..17c110d6808 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vfxx-4xcx-mgvh/GHSA-vfxx-4xcx-mgvh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfxx-4xcx-mgvh", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-57941" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix the (non-)cancellation of copy when cache is temporarily disabled\n\nWhen the caching for a cookie is temporarily disabled (e.g. due to a DIO\nwrite on that file), future copying to the cache for that file is disabled\nuntil all fds open on that file are closed. However, if netfslib is using\nthe deprecated PG_private_2 method (such as is currently used by ceph), and\ndecides it wants to copy to the cache, netfs_advance_write() will just bail\nat the first check seeing that the cache stream is unavailable, and\nindicate that it dealt with all the content.\n\nThis means that we have no subrequests to provide notifications to drive\nthe state machine or even to pin the request and the request just gets\ndiscarded, leaving the folios with PG_private_2 set.\n\nFix this by jumping directly to cancel the request if the cache is not\navailable. That way, we don't remove mark3 from the folio_queue list and\nnetfs_pgpriv2_cancel() will clean up the folios.\n\nThis was found by running the generic/013 xfstest against ceph with an\nactive cache and the \"-o fsc\" option passed to ceph. That would usually\nhang", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57941" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba37bdfe59fb43e80dd79290340a21864ba4b61e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0327c824338cdccad058723a31d038ecd553409" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vp4f-mc7f-v3pc/GHSA-vp4f-mc7f-v3pc.json b/advisories/unreviewed/2025/01/GHSA-vp4f-mc7f-v3pc/GHSA-vp4f-mc7f-v3pc.json new file mode 100644 index 00000000000..220073671f2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vp4f-mc7f-v3pc/GHSA-vp4f-mc7f-v3pc.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp4f-mc7f-v3pc", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2025-21664" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm thin: make get_first_thin use rcu-safe list first function\n\nThe documentation in rculist.h explains the absence of list_empty_rcu()\nand cautions programmers against relying on a list_empty() ->\nlist_first() sequence in RCU safe code. This is because each of these\nfunctions performs its own READ_ONCE() of the list head. This can lead\nto a situation where the list_empty() sees a valid list entry, but the\nsubsequent list_first() sees a different view of list head state after a\nmodification.\n\nIn the case of dm-thin, this author had a production box crash from a GP\nfault in the process_deferred_bios path. This function saw a valid list\nhead in get_first_thin() but when it subsequently dereferenced that and\nturned it into a thin_c, it got the inside of the struct pool, since the\nlist was now empty and referring to itself. The kernel on which this\noccurred printed both a warning about a refcount_t being saturated, and\na UBSAN error for an out-of-bounds cpuid access in the queued spinlock,\nprior to the fault itself. When the resulting kdump was examined, it\nwas possible to see another thread patiently waiting in thin_dtr's\nsynchronize_rcu.\n\nThe thin_dtr call managed to pull the thin_c out of the active thins\nlist (and have it be the last entry in the active_thins list) at just\nthe wrong moment which lead to this crash.\n\nFortunately, the fix here is straight forward. Switch get_first_thin()\nfunction to use list_first_or_null_rcu() which performs just a single\nREAD_ONCE() and returns NULL if the list is already empty.\n\nThis was run against the devicemapper test suite's thin-provisioning\nsuites for delete and suspend and no regressions were observed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21664" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12771050b6d059eea096993bf2001da9da9fddff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b305e98de0d225ccebfb225730a9f560d28ecb0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80f130bfad1dab93b95683fc39b87235682b8f72" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbd0d5ecfa390ac29c5380200147d09c381b2ac6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w2xm-9v29-725f/GHSA-w2xm-9v29-725f.json b/advisories/unreviewed/2025/01/GHSA-w2xm-9v29-725f/GHSA-w2xm-9v29-725f.json new file mode 100644 index 00000000000..a32f1495639 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w2xm-9v29-725f/GHSA-w2xm-9v29-725f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2xm-9v29-725f", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22733" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPHocus My auctions allegro allows Reflected XSS. This issue affects My auctions allegro: from n/a through 3.6.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22733" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/my-auctions-allegro-free-edition/vulnerability/wordpress-my-auctions-allegro-plugin-3-6-18-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w5hf-f5m8-7wvq/GHSA-w5hf-f5m8-7wvq.json b/advisories/unreviewed/2025/01/GHSA-w5hf-f5m8-7wvq/GHSA-w5hf-f5m8-7wvq.json new file mode 100644 index 00000000000..e8bd06f3911 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w5hf-f5m8-7wvq/GHSA-w5hf-f5m8-7wvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5hf-f5m8-7wvq", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22322" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Private Messages for UserPro allows Reflected XSS. This issue affects Private Messages for UserPro: from n/a through 4.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22322" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userpro-messaging/vulnerability/wordpress-private-messages-for-userpro-plugin-4-10-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w86j-9c7c-f9xf/GHSA-w86j-9c7c-f9xf.json b/advisories/unreviewed/2025/01/GHSA-w86j-9c7c-f9xf/GHSA-w86j-9c7c-f9xf.json new file mode 100644 index 00000000000..aaa89eefb18 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w86j-9c7c-f9xf/GHSA-w86j-9c7c-f9xf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w86j-9c7c-f9xf", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22735" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TaxoPress WordPress Tag Cloud Plugin – Tag Groups allows Reflected XSS. This issue affects WordPress Tag Cloud Plugin – Tag Groups: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22735" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tag-groups/vulnerability/wordpress-tag-cloud-plugin-tag-groups-plugin-2-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-whwp-53wx-h4ph/GHSA-whwp-53wx-h4ph.json b/advisories/unreviewed/2025/01/GHSA-whwp-53wx-h4ph/GHSA-whwp-53wx-h4ph.json new file mode 100644 index 00000000000..d1e39f81604 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-whwp-53wx-h4ph/GHSA-whwp-53wx-h4ph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whwp-53wx-h4ph", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22727" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChimp Subscribe Forms allows Stored XSS. This issue affects MailChimp Subscribe Forms : from n/a through 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22727" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mailchimp-subscribe-sm/vulnerability/wordpress-mailchimp-subscribe-form-plugin-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x2vh-h2v5-9rrm/GHSA-x2vh-h2v5-9rrm.json b/advisories/unreviewed/2025/01/GHSA-x2vh-h2v5-9rrm/GHSA-x2vh-h2v5-9rrm.json new file mode 100644 index 00000000000..ec0b251436e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x2vh-h2v5-9rrm/GHSA-x2vh-h2v5-9rrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2vh-h2v5-9rrm", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-22709" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22709" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verge3d/vulnerability/wordpress-verge3d-publishing-and-e-commerce-plugin-4-8-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x6qq-9wqw-82vj/GHSA-x6qq-9wqw-82vj.json b/advisories/unreviewed/2025/01/GHSA-x6qq-9wqw-82vj/GHSA-x6qq-9wqw-82vj.json new file mode 100644 index 00000000000..1523875a410 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x6qq-9wqw-82vj/GHSA-x6qq-9wqw-82vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6qq-9wqw-82vj", + "modified": "2025-01-21T15:31:03Z", + "published": "2025-01-21T15:31:03Z", + "aliases": [ + "CVE-2024-49666" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49666" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arprice/vulnerability/wordpress-arprice-plugin-4-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xvmc-jc86-5v7v/GHSA-xvmc-jc86-5v7v.json b/advisories/unreviewed/2025/01/GHSA-xvmc-jc86-5v7v/GHSA-xvmc-jc86-5v7v.json new file mode 100644 index 00000000000..c759e5261ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xvmc-jc86-5v7v/GHSA-xvmc-jc86-5v7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvmc-jc86-5v7v", + "modified": "2025-01-21T15:31:04Z", + "published": "2025-01-21T15:31:04Z", + "aliases": [ + "CVE-2025-23997" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dev@tamara.co Tamara Checkout allows Stored XSS. This issue affects Tamara Checkout: from n/a through 1.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tamara-checkout/vulnerability/wordpress-tamara-checkout-plugin-1-9-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T14:15:13Z" + } +} \ No newline at end of file