From dad5df99e575ee554bdebae450ec3ba9dbafa8f8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 10 Apr 2025 21:32:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jj96-j367-3jx7.json | 3 +- .../GHSA-qc52-6cw2-7g23.json | 2 +- .../GHSA-w8f5-jp95-mq35.json | 3 +- .../GHSA-28q5-2h4q-627v.json | 4 +- .../GHSA-2xwg-7hvq-gvq8.json | 3 +- .../GHSA-3wp9-gvwq-96mc.json | 3 +- .../GHSA-8p8p-qfhf-2jj8.json | 4 +- .../GHSA-cr28-68mj-mpg4.json | 6 ++- .../GHSA-f92h-3c3j-gghq.json | 3 +- .../GHSA-v5q9-jw9j-25cw.json | 3 +- .../GHSA-5w6r-7h9g-pfhr.json | 4 +- .../GHSA-73p2-7vjh-9qx4.json | 4 +- .../GHSA-799h-8vpw-vp7q.json | 4 +- .../GHSA-7rhj-qr35-3pvg.json | 4 +- .../GHSA-9mcp-v29j-j4hp.json | 2 +- .../GHSA-f5cm-53fc-8x22.json | 2 +- .../GHSA-wp7f-xph3-r8ph.json | 4 +- .../GHSA-xjqr-jw8j-hv44.json | 4 +- .../GHSA-228j-w5v9-347h.json | 5 ++- .../GHSA-5g3j-v298-jm95.json | 2 +- .../GHSA-9vp4-vqrh-26wq.json | 4 +- .../GHSA-hp65-g55r-jqcw.json | 2 +- .../GHSA-j7fr-7wrw-rww2.json | 2 +- .../GHSA-m7p8-hcw4-p377.json | 2 +- .../GHSA-43fc-v55w-5mx4.json | 2 +- .../GHSA-4ww3-585w-6p9r.json | 4 +- .../GHSA-6gj8-fxh3-h3j9.json | 8 +++- .../GHSA-6jfg-4px6-v4c9.json | 4 +- .../GHSA-7hfh-vfcv-wfqp.json | 4 +- .../GHSA-8fvm-73q4-3j6f.json | 2 +- .../GHSA-c3rj-rhqm-q53c.json | 2 +- .../GHSA-qgq8-952v-8jwq.json | 2 +- .../GHSA-rh3c-7xc7-jjwj.json | 8 +++- .../GHSA-rj8v-47w4-c66w.json | 4 +- .../GHSA-h47g-q8q7-fgrv.json | 2 +- .../GHSA-hj5g-whq8-wmhg.json | 3 +- .../GHSA-mgwg-4hc9-rq52.json | 4 +- .../GHSA-rf3v-2m2g-6xwj.json | 3 +- .../GHSA-xvm6-65jm-mc4g.json | 2 +- .../GHSA-fc63-998f-r568.json | 2 +- .../GHSA-39f7-qgxq-ff45.json | 2 +- .../GHSA-f8p7-qq6w-9fjc.json | 2 +- .../GHSA-gjm5-824v-4vq3.json | 2 +- .../GHSA-gmw9-73pf-rc65.json | 2 +- .../GHSA-p8c4-gpq2-4cr4.json | 2 +- .../GHSA-r4rm-4xhc-jxj7.json | 2 +- .../GHSA-3vp6-4284-wj7c.json | 2 +- .../GHSA-58pv-8xf3-c5r4.json | 2 +- .../GHSA-78x5-mw8r-c5mr.json | 2 +- .../GHSA-g6hx-mx2f-fvx9.json | 2 +- .../GHSA-x749-4jc5-gxmr.json | 3 +- .../GHSA-39wv-3h9m-9hpc.json | 2 +- .../GHSA-78qv-q99m-4f2r.json | 2 +- .../GHSA-3m82-fj9p-m6vq.json | 3 +- .../GHSA-gccq-88r2-w9m4.json | 3 +- .../GHSA-2cxw-wgvv-24jj.json | 5 ++- .../GHSA-2qh6-98mm-p9vr.json | 2 +- .../GHSA-4v9h-49hf-v7f8.json | 2 +- .../GHSA-5783-252r-fxpm.json | 2 +- .../GHSA-5ggx-8w3f-h4gf.json | 2 +- .../GHSA-6w26-66hj-8g45.json | 2 +- .../GHSA-7855-vcjh-5fv2.json | 2 +- .../GHSA-7w3m-9pfq-8m82.json | 2 +- .../GHSA-8m3r-jg6f-34jp.json | 2 +- .../GHSA-9h9v-jch8-f29w.json | 2 +- .../GHSA-cg48-xw7q-cpc8.json | 2 +- .../GHSA-cwhx-ww39-3h7h.json | 2 +- .../GHSA-cxm9-pc6x-88r5.json | 2 +- .../GHSA-fr2q-29x3-38rp.json | 2 +- .../GHSA-fxxp-38jc-7cfq.json | 2 +- .../GHSA-gr9w-6j99-f5q5.json | 2 +- .../GHSA-h49w-5mwr-frr5.json | 2 +- .../GHSA-hr72-4f8w-mw62.json | 2 +- .../GHSA-m4jp-jx56-47gq.json | 2 +- .../GHSA-mrpg-q4r4-m4g9.json | 2 +- .../GHSA-pgw2-vj22-3w7g.json | 2 +- .../GHSA-pph8-wh6p-w5m7.json | 4 +- .../GHSA-r47p-3h3g-wvw7.json | 2 +- .../GHSA-w8g5-2237-xmj2.json | 2 +- .../GHSA-6gv3-7gp2-wqgf.json | 15 +++++-- .../GHSA-7jc7-7vhf-f7fg.json | 36 +++++++++++++++ .../GHSA-9f82-pr9c-9f3x.json | 36 +++++++++++++++ .../GHSA-9gwp-748x-fwg9.json | 36 +++++++++++++++ .../GHSA-f562-mmxh-p76r.json | 36 +++++++++++++++ .../GHSA-f5r8-5xjg-g5f9.json | 36 +++++++++++++++ .../GHSA-f626-w254-w424.json | 44 +++++++++++++++++++ .../GHSA-gpcp-cp2q-wj86.json | 15 +++++-- .../GHSA-gwjc-9mv6-q8q2.json | 11 +++-- .../GHSA-hh2q-7x5p-j2g2.json | 36 +++++++++++++++ .../GHSA-mf9p-6469-jcwh.json | 15 +++++-- .../GHSA-p549-c3cg-f4qm.json | 15 +++++-- .../GHSA-pq7c-cvqp-fq9x.json | 36 +++++++++++++++ .../GHSA-vmvf-5r44-m57g.json | 15 +++++-- .../GHSA-wvjf-p8qj-4524.json | 36 +++++++++++++++ 94 files changed, 520 insertions(+), 119 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-7jc7-7vhf-f7fg/GHSA-7jc7-7vhf-f7fg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9f82-pr9c-9f3x/GHSA-9f82-pr9c-9f3x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9gwp-748x-fwg9/GHSA-9gwp-748x-fwg9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f562-mmxh-p76r/GHSA-f562-mmxh-p76r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f5r8-5xjg-g5f9/GHSA-f5r8-5xjg-g5f9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f626-w254-w424/GHSA-f626-w254-w424.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hh2q-7x5p-j2g2/GHSA-hh2q-7x5p-j2g2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pq7c-cvqp-fq9x/GHSA-pq7c-cvqp-fq9x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wvjf-p8qj-4524/GHSA-wvjf-p8qj-4524.json diff --git a/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json b/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json index 4626f143db8..342c1cd16a1 100644 --- a/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json +++ b/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-qc52-6cw2-7g23/GHSA-qc52-6cw2-7g23.json b/advisories/unreviewed/2022/12/GHSA-qc52-6cw2-7g23/GHSA-qc52-6cw2-7g23.json index 04215259ece..6eee2311f26 100644 --- a/advisories/unreviewed/2022/12/GHSA-qc52-6cw2-7g23/GHSA-qc52-6cw2-7g23.json +++ b/advisories/unreviewed/2022/12/GHSA-qc52-6cw2-7g23/GHSA-qc52-6cw2-7g23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc52-6cw2-7g23", - "modified": "2023-01-10T15:30:25Z", + "modified": "2025-04-10T21:30:33Z", "published": "2022-12-30T09:30:21Z", "aliases": [ "CVE-2022-48196" diff --git a/advisories/unreviewed/2022/12/GHSA-w8f5-jp95-mq35/GHSA-w8f5-jp95-mq35.json b/advisories/unreviewed/2022/12/GHSA-w8f5-jp95-mq35/GHSA-w8f5-jp95-mq35.json index cab8bf26510..8464b112379 100644 --- a/advisories/unreviewed/2022/12/GHSA-w8f5-jp95-mq35/GHSA-w8f5-jp95-mq35.json +++ b/advisories/unreviewed/2022/12/GHSA-w8f5-jp95-mq35/GHSA-w8f5-jp95-mq35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8f5-jp95-mq35", - "modified": "2023-01-06T18:30:18Z", + "modified": "2025-04-10T21:30:32Z", "published": "2022-12-29T00:30:35Z", "aliases": [ "CVE-2022-4779" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-287" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/01/GHSA-28q5-2h4q-627v/GHSA-28q5-2h4q-627v.json b/advisories/unreviewed/2023/01/GHSA-28q5-2h4q-627v/GHSA-28q5-2h4q-627v.json index 3e990c1507b..674a72903e8 100644 --- a/advisories/unreviewed/2023/01/GHSA-28q5-2h4q-627v/GHSA-28q5-2h4q-627v.json +++ b/advisories/unreviewed/2023/01/GHSA-28q5-2h4q-627v/GHSA-28q5-2h4q-627v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-2xwg-7hvq-gvq8/GHSA-2xwg-7hvq-gvq8.json b/advisories/unreviewed/2023/01/GHSA-2xwg-7hvq-gvq8/GHSA-2xwg-7hvq-gvq8.json index 9fdc2bc4857..b6c3db0664a 100644 --- a/advisories/unreviewed/2023/01/GHSA-2xwg-7hvq-gvq8/GHSA-2xwg-7hvq-gvq8.json +++ b/advisories/unreviewed/2023/01/GHSA-2xwg-7hvq-gvq8/GHSA-2xwg-7hvq-gvq8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-3wp9-gvwq-96mc/GHSA-3wp9-gvwq-96mc.json b/advisories/unreviewed/2023/01/GHSA-3wp9-gvwq-96mc/GHSA-3wp9-gvwq-96mc.json index 8b8170d79cc..b32f2520ec3 100644 --- a/advisories/unreviewed/2023/01/GHSA-3wp9-gvwq-96mc/GHSA-3wp9-gvwq-96mc.json +++ b/advisories/unreviewed/2023/01/GHSA-3wp9-gvwq-96mc/GHSA-3wp9-gvwq-96mc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-8p8p-qfhf-2jj8/GHSA-8p8p-qfhf-2jj8.json b/advisories/unreviewed/2023/01/GHSA-8p8p-qfhf-2jj8/GHSA-8p8p-qfhf-2jj8.json index 4e7380c9326..86a48bf29c7 100644 --- a/advisories/unreviewed/2023/01/GHSA-8p8p-qfhf-2jj8/GHSA-8p8p-qfhf-2jj8.json +++ b/advisories/unreviewed/2023/01/GHSA-8p8p-qfhf-2jj8/GHSA-8p8p-qfhf-2jj8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-cr28-68mj-mpg4/GHSA-cr28-68mj-mpg4.json b/advisories/unreviewed/2023/01/GHSA-cr28-68mj-mpg4/GHSA-cr28-68mj-mpg4.json index 49a31667ddc..b826a64f26c 100644 --- a/advisories/unreviewed/2023/01/GHSA-cr28-68mj-mpg4/GHSA-cr28-68mj-mpg4.json +++ b/advisories/unreviewed/2023/01/GHSA-cr28-68mj-mpg4/GHSA-cr28-68mj-mpg4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr28-68mj-mpg4", - "modified": "2023-01-09T18:30:33Z", + "modified": "2025-04-10T21:30:34Z", "published": "2023-01-01T09:30:20Z", "aliases": [ "CVE-2022-45213" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-73" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-f92h-3c3j-gghq/GHSA-f92h-3c3j-gghq.json b/advisories/unreviewed/2023/01/GHSA-f92h-3c3j-gghq/GHSA-f92h-3c3j-gghq.json index 28fd10b4e83..4cdd9f1d97a 100644 --- a/advisories/unreviewed/2023/01/GHSA-f92h-3c3j-gghq/GHSA-f92h-3c3j-gghq.json +++ b/advisories/unreviewed/2023/01/GHSA-f92h-3c3j-gghq/GHSA-f92h-3c3j-gghq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-v5q9-jw9j-25cw/GHSA-v5q9-jw9j-25cw.json b/advisories/unreviewed/2023/01/GHSA-v5q9-jw9j-25cw/GHSA-v5q9-jw9j-25cw.json index 72f04bdb92a..4bc73c55d58 100644 --- a/advisories/unreviewed/2023/01/GHSA-v5q9-jw9j-25cw/GHSA-v5q9-jw9j-25cw.json +++ b/advisories/unreviewed/2023/01/GHSA-v5q9-jw9j-25cw/GHSA-v5q9-jw9j-25cw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-5w6r-7h9g-pfhr/GHSA-5w6r-7h9g-pfhr.json b/advisories/unreviewed/2023/07/GHSA-5w6r-7h9g-pfhr/GHSA-5w6r-7h9g-pfhr.json index dadebb8afb7..462754c0eea 100644 --- a/advisories/unreviewed/2023/07/GHSA-5w6r-7h9g-pfhr/GHSA-5w6r-7h9g-pfhr.json +++ b/advisories/unreviewed/2023/07/GHSA-5w6r-7h9g-pfhr/GHSA-5w6r-7h9g-pfhr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5w6r-7h9g-pfhr", - "modified": "2024-10-08T18:33:04Z", + "modified": "2025-04-10T21:30:41Z", "published": "2023-07-21T06:30:17Z", "aliases": [ "CVE-2023-25836" ], - "details": "\nThere is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.\n\n\n\n", + "details": "There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-73p2-7vjh-9qx4/GHSA-73p2-7vjh-9qx4.json b/advisories/unreviewed/2023/07/GHSA-73p2-7vjh-9qx4/GHSA-73p2-7vjh-9qx4.json index 049a8405718..bf3d20fe903 100644 --- a/advisories/unreviewed/2023/07/GHSA-73p2-7vjh-9qx4/GHSA-73p2-7vjh-9qx4.json +++ b/advisories/unreviewed/2023/07/GHSA-73p2-7vjh-9qx4/GHSA-73p2-7vjh-9qx4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-73p2-7vjh-9qx4", - "modified": "2024-10-08T18:33:04Z", + "modified": "2025-04-10T21:30:41Z", "published": "2023-07-21T00:30:23Z", "aliases": [ "CVE-2023-25835" ], - "details": "\nThere is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.\n\n\n\n", + "details": "There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json b/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json index a94f48e71c9..22eb36477ea 100644 --- a/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json +++ b/advisories/unreviewed/2023/07/GHSA-799h-8vpw-vp7q/GHSA-799h-8vpw-vp7q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-799h-8vpw-vp7q", - "modified": "2024-10-08T18:33:04Z", + "modified": "2025-04-10T21:30:42Z", "published": "2023-07-21T21:30:31Z", "aliases": [ "CVE-2023-25841" ], - "details": "\nThere is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 10.8.1 – 11.0 on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.\n\nMitigation: Disable anonymous access to ArcGIS Feature services with edit capabilities.\n\n\n", + "details": "There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 10.8.1 – 11.0 on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.\n\nMitigation: Disable anonymous access to ArcGIS Feature services with edit capabilities.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-7rhj-qr35-3pvg/GHSA-7rhj-qr35-3pvg.json b/advisories/unreviewed/2023/07/GHSA-7rhj-qr35-3pvg/GHSA-7rhj-qr35-3pvg.json index 0e8deca577b..8febe6f5513 100644 --- a/advisories/unreviewed/2023/07/GHSA-7rhj-qr35-3pvg/GHSA-7rhj-qr35-3pvg.json +++ b/advisories/unreviewed/2023/07/GHSA-7rhj-qr35-3pvg/GHSA-7rhj-qr35-3pvg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7rhj-qr35-3pvg", - "modified": "2024-10-08T18:33:04Z", + "modified": "2025-04-10T21:30:42Z", "published": "2023-07-21T06:30:17Z", "aliases": [ "CVE-2023-25837" ], - "details": "\nThere is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.\n\n\n\n", + "details": "There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json b/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json index 8a1f83f1bf1..27079f27163 100644 --- a/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json +++ b/advisories/unreviewed/2023/07/GHSA-9mcp-v29j-j4hp/GHSA-9mcp-v29j-j4hp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9mcp-v29j-j4hp", - "modified": "2025-02-13T18:31:34Z", + "modified": "2025-04-10T21:30:40Z", "published": "2023-07-06T21:14:53Z", "aliases": [ "CVE-2023-28724" diff --git a/advisories/unreviewed/2023/07/GHSA-f5cm-53fc-8x22/GHSA-f5cm-53fc-8x22.json b/advisories/unreviewed/2023/07/GHSA-f5cm-53fc-8x22/GHSA-f5cm-53fc-8x22.json index ee51dfb819e..b8ada871326 100644 --- a/advisories/unreviewed/2023/07/GHSA-f5cm-53fc-8x22/GHSA-f5cm-53fc-8x22.json +++ b/advisories/unreviewed/2023/07/GHSA-f5cm-53fc-8x22/GHSA-f5cm-53fc-8x22.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5cm-53fc-8x22", - "modified": "2024-04-04T05:41:39Z", + "modified": "2025-04-10T21:30:40Z", "published": "2023-07-06T21:14:55Z", "aliases": [ "CVE-2023-25830" diff --git a/advisories/unreviewed/2023/07/GHSA-wp7f-xph3-r8ph/GHSA-wp7f-xph3-r8ph.json b/advisories/unreviewed/2023/07/GHSA-wp7f-xph3-r8ph/GHSA-wp7f-xph3-r8ph.json index be4dfc4c371..32c719f9a49 100644 --- a/advisories/unreviewed/2023/07/GHSA-wp7f-xph3-r8ph/GHSA-wp7f-xph3-r8ph.json +++ b/advisories/unreviewed/2023/07/GHSA-wp7f-xph3-r8ph/GHSA-wp7f-xph3-r8ph.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-wp7f-xph3-r8ph", - "modified": "2024-10-08T18:33:04Z", + "modified": "2025-04-10T21:30:42Z", "published": "2023-07-21T21:30:31Z", "aliases": [ "CVE-2023-25840" ], - "details": "\nThere is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high.\n\n\n\n", + "details": "There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser.  The privileges required to execute this attack are high.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/07/GHSA-xjqr-jw8j-hv44/GHSA-xjqr-jw8j-hv44.json b/advisories/unreviewed/2023/07/GHSA-xjqr-jw8j-hv44/GHSA-xjqr-jw8j-hv44.json index 4731ba7303c..46c8e105720 100644 --- a/advisories/unreviewed/2023/07/GHSA-xjqr-jw8j-hv44/GHSA-xjqr-jw8j-hv44.json +++ b/advisories/unreviewed/2023/07/GHSA-xjqr-jw8j-hv44/GHSA-xjqr-jw8j-hv44.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xjqr-jw8j-hv44", - "modified": "2024-04-04T05:41:41Z", + "modified": "2025-04-10T21:30:40Z", "published": "2023-07-06T21:14:55Z", "aliases": [ "CVE-2023-25831" ], - "details": "There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.\n", + "details": "There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1, 10.8.1 and 10.7.1 which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-228j-w5v9-347h/GHSA-228j-w5v9-347h.json b/advisories/unreviewed/2024/03/GHSA-228j-w5v9-347h/GHSA-228j-w5v9-347h.json index 99c567f42dc..975d60c2c20 100644 --- a/advisories/unreviewed/2024/03/GHSA-228j-w5v9-347h/GHSA-228j-w5v9-347h.json +++ b/advisories/unreviewed/2024/03/GHSA-228j-w5v9-347h/GHSA-228j-w5v9-347h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-228j-w5v9-347h", - "modified": "2024-03-05T12:30:31Z", + "modified": "2025-04-10T21:30:45Z", "published": "2024-03-05T12:30:31Z", "aliases": [ "CVE-2023-45591" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5g3j-v298-jm95/GHSA-5g3j-v298-jm95.json b/advisories/unreviewed/2024/03/GHSA-5g3j-v298-jm95/GHSA-5g3j-v298-jm95.json index 6011ba00251..25c2e81f4fd 100644 --- a/advisories/unreviewed/2024/03/GHSA-5g3j-v298-jm95/GHSA-5g3j-v298-jm95.json +++ b/advisories/unreviewed/2024/03/GHSA-5g3j-v298-jm95/GHSA-5g3j-v298-jm95.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5g3j-v298-jm95", - "modified": "2024-03-05T12:30:32Z", + "modified": "2025-04-10T21:30:45Z", "published": "2024-03-05T12:30:32Z", "aliases": [ "CVE-2023-45597" diff --git a/advisories/unreviewed/2024/03/GHSA-9vp4-vqrh-26wq/GHSA-9vp4-vqrh-26wq.json b/advisories/unreviewed/2024/03/GHSA-9vp4-vqrh-26wq/GHSA-9vp4-vqrh-26wq.json index 488a975b91c..4cc02cbcd75 100644 --- a/advisories/unreviewed/2024/03/GHSA-9vp4-vqrh-26wq/GHSA-9vp4-vqrh-26wq.json +++ b/advisories/unreviewed/2024/03/GHSA-9vp4-vqrh-26wq/GHSA-9vp4-vqrh-26wq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9vp4-vqrh-26wq", - "modified": "2024-03-29T12:30:42Z", + "modified": "2025-04-10T21:30:45Z", "published": "2024-03-29T12:30:42Z", "aliases": [ "CVE-2023-6191" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security WebPDKS allows SQL Injection.This issue affects WebPDKS: through 20240329. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security WebPDKS allows SQL Injection.This issue affects WebPDKS: through 20240329. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-hp65-g55r-jqcw/GHSA-hp65-g55r-jqcw.json b/advisories/unreviewed/2024/03/GHSA-hp65-g55r-jqcw/GHSA-hp65-g55r-jqcw.json index 1a58d0b5df4..078d3ed8133 100644 --- a/advisories/unreviewed/2024/03/GHSA-hp65-g55r-jqcw/GHSA-hp65-g55r-jqcw.json +++ b/advisories/unreviewed/2024/03/GHSA-hp65-g55r-jqcw/GHSA-hp65-g55r-jqcw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp65-g55r-jqcw", - "modified": "2024-03-05T12:30:31Z", + "modified": "2025-04-10T21:30:45Z", "published": "2024-03-05T12:30:31Z", "aliases": [ "CVE-2023-5456" diff --git a/advisories/unreviewed/2024/03/GHSA-j7fr-7wrw-rww2/GHSA-j7fr-7wrw-rww2.json b/advisories/unreviewed/2024/03/GHSA-j7fr-7wrw-rww2/GHSA-j7fr-7wrw-rww2.json index db9d306c214..20fd3844783 100644 --- a/advisories/unreviewed/2024/03/GHSA-j7fr-7wrw-rww2/GHSA-j7fr-7wrw-rww2.json +++ b/advisories/unreviewed/2024/03/GHSA-j7fr-7wrw-rww2/GHSA-j7fr-7wrw-rww2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7fr-7wrw-rww2", - "modified": "2024-03-05T12:30:31Z", + "modified": "2025-04-10T21:30:45Z", "published": "2024-03-05T12:30:31Z", "aliases": [ "CVE-2023-45592" diff --git a/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json b/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json index 854e0196c99..1732c48a313 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json +++ b/advisories/unreviewed/2024/03/GHSA-m7p8-hcw4-p377/GHSA-m7p8-hcw4-p377.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7p8-hcw4-p377", - "modified": "2024-10-17T12:30:51Z", + "modified": "2025-04-10T21:30:45Z", "published": "2024-03-05T12:30:32Z", "aliases": [ "CVE-2023-45598" diff --git a/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json b/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json index c47a9fb5f4f..2770e7b7dff 100644 --- a/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json +++ b/advisories/unreviewed/2024/04/GHSA-43fc-v55w-5mx4/GHSA-43fc-v55w-5mx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43fc-v55w-5mx4", - "modified": "2025-01-23T18:31:11Z", + "modified": "2025-04-10T21:30:47Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25708" diff --git a/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json b/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json index ed057b79419..d4f7a69f95d 100644 --- a/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json +++ b/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4ww3-585w-6p9r", - "modified": "2024-04-04T18:30:33Z", + "modified": "2025-04-10T21:30:47Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25706" ], - "details": "There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks. ", + "details": "There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote, unauthenticated attacker to craft a URL which, when clicked, could potentially generate a message that may entice an unsuspecting victim to visit an arbitrary website. This could simplify phishing attacks.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-6gj8-fxh3-h3j9/GHSA-6gj8-fxh3-h3j9.json b/advisories/unreviewed/2024/04/GHSA-6gj8-fxh3-h3j9/GHSA-6gj8-fxh3-h3j9.json index 3ea96991a55..12778d020d1 100644 --- a/advisories/unreviewed/2024/04/GHSA-6gj8-fxh3-h3j9/GHSA-6gj8-fxh3-h3j9.json +++ b/advisories/unreviewed/2024/04/GHSA-6gj8-fxh3-h3j9/GHSA-6gj8-fxh3-h3j9.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-6gj8-fxh3-h3j9", - "modified": "2024-05-16T21:31:57Z", + "modified": "2025-04-10T21:30:48Z", "published": "2024-04-12T15:37:22Z", "aliases": [ "CVE-2024-30405" ], - "details": "An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS).\n\nContinued receipt and processing of these specific packets will sustain the Denial of Service condition.\n\nThis issue affects:\nJuniper Networks Junos OS SRX 5000 Series with SPC2 with ALGs enabled.\n * All versions earlier than 21.2R3-S7;\n * 21.4 versions earlier than 21.4R3-S6;\n * 22.1 versions earlier than 22.1R3-S5;\n * 22.2 versions earlier than 22.2R3-S3;\n * 22.3 versions earlier than 22.3R3-S2;\n * 22.4 versions earlier than 22.4R3;\n * 23.2 versions earlier than 23.2R2. \n\n\n", + "details": "An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS).\n\nContinued receipt and processing of these specific packets will sustain the Denial of Service condition.\n\nThis issue affects:\nJuniper Networks Junos OS SRX 5000 Series with SPC2 with ALGs enabled.\n * All versions earlier than 21.2R3-S7;\n * 21.4 versions earlier than 21.4R3-S6;\n * 22.1 versions earlier than 22.1R3-S5;\n * 22.2 versions earlier than 22.2R3-S3;\n * 22.3 versions earlier than 22.3R3-S2;\n * 22.4 versions earlier than 22.4R3;\n * 23.2 versions earlier than 23.2R2. ", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json b/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json index f15872bbadf..35073156064 100644 --- a/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json +++ b/advisories/unreviewed/2024/04/GHSA-6jfg-4px6-v4c9/GHSA-6jfg-4px6-v4c9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6jfg-4px6-v4c9", - "modified": "2024-04-20T00:31:52Z", + "modified": "2025-04-10T21:30:46Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25692" ], - "details": "\nThere is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. ", + "details": "There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker to trick an authorized user into executing unwanted actions via a crafted form. The impact to Confidentiality and Integrity vectors is limited and of low severity. ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json b/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json index aaddabbcfe3..ee8c3124fd4 100644 --- a/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json +++ b/advisories/unreviewed/2024/04/GHSA-7hfh-vfcv-wfqp/GHSA-7hfh-vfcv-wfqp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7hfh-vfcv-wfqp", - "modified": "2024-04-20T00:31:52Z", + "modified": "2025-04-10T21:30:46Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25699" ], - "details": "\nThere is a difficult to exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 10.8.1 through 11.2 on Windows and Linux, and ArcGIS Enterprise 11.1 and below on Kubernetes which, under unique circumstances, could potentially allow a remote, unauthenticated attacker to compromise the confidentiality, integrity, and availability of the software.\n\n\n", + "details": "There is a difficult to exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 10.8.1 through 11.2 on Windows and Linux, and ArcGIS Enterprise 11.1 and below on Kubernetes which, under unique circumstances, could potentially allow a remote, unauthenticated attacker to compromise the confidentiality, integrity, and availability of the software.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json b/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json index d723ec6000f..8f1eee64cc6 100644 --- a/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json +++ b/advisories/unreviewed/2024/04/GHSA-8fvm-73q4-3j6f/GHSA-8fvm-73q4-3j6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8fvm-73q4-3j6f", - "modified": "2025-01-31T15:30:41Z", + "modified": "2025-04-10T21:30:47Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25709" diff --git a/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json b/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json index d47b6461228..3d1c76d8b2a 100644 --- a/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json +++ b/advisories/unreviewed/2024/04/GHSA-c3rj-rhqm-q53c/GHSA-c3rj-rhqm-q53c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3rj-rhqm-q53c", - "modified": "2024-04-25T18:30:38Z", + "modified": "2025-04-10T21:30:46Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25700" diff --git a/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json b/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json index 24955dca9fd..ad597e216e9 100644 --- a/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json +++ b/advisories/unreviewed/2024/04/GHSA-qgq8-952v-8jwq/GHSA-qgq8-952v-8jwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgq8-952v-8jwq", - "modified": "2024-04-20T00:31:52Z", + "modified": "2025-04-10T21:30:46Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25696" diff --git a/advisories/unreviewed/2024/04/GHSA-rh3c-7xc7-jjwj/GHSA-rh3c-7xc7-jjwj.json b/advisories/unreviewed/2024/04/GHSA-rh3c-7xc7-jjwj/GHSA-rh3c-7xc7-jjwj.json index 426d98b2470..cfc15e10dd0 100644 --- a/advisories/unreviewed/2024/04/GHSA-rh3c-7xc7-jjwj/GHSA-rh3c-7xc7-jjwj.json +++ b/advisories/unreviewed/2024/04/GHSA-rh3c-7xc7-jjwj/GHSA-rh3c-7xc7-jjwj.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-rh3c-7xc7-jjwj", - "modified": "2024-05-16T21:31:56Z", + "modified": "2025-04-10T21:30:48Z", "published": "2024-04-12T15:37:22Z", "aliases": [ "CVE-2024-21609" ], - "details": "A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully establish IPsec tunnels to cause a Denial of Service (DoS).\n\nIf specific values for the IPsec parameters local-ip, remote-ip, remote ike-id, and traffic selectors are sent from the peer, a memory leak occurs during every IPsec SA rekey which is carried out with a specific message sequence. This will eventually result in an iked process crash and restart.\n\nThe iked process memory consumption can be checked using the below command:\n  user@host> show system processes extensive | grep iked\n          PID USERNAME   PRI NICE   SIZE   RES   STATE   C TIME WCPU COMMAND\n          56903 root       31   0     4016M 2543M CPU0   0 2:10 10.50% iked\n\nThis issue affects Juniper Networks Junos OS:\n * All versions earlier than 20.4R3-S9;\n * 21.2 versions earlier than 21.2R3-S7;\n * 21.3 versions earlier than 21.3R3-S5;\n * 21.4 versions earlier than 21.4R3-S4;\n * 22.1 versions earlier than 22.1R3-S3;\n * 22.2 versions earlier than 22.2R3-S2;\n * 22.3 versions earlier than 22.3R3;\n * 22.4 versions earlier than 22.4R3;\n * 23.2 versions earlier than 23.2R1-S2, 23.2R2.\n\n\n", + "details": "A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully establish IPsec tunnels to cause a Denial of Service (DoS).\n\nIf specific values for the IPsec parameters local-ip, remote-ip, remote ike-id, and traffic selectors are sent from the peer, a memory leak occurs during every IPsec SA rekey which is carried out with a specific message sequence. This will eventually result in an iked process crash and restart.\n\nThe iked process memory consumption can be checked using the below command:\n  user@host> show system processes extensive | grep iked\n          PID USERNAME   PRI NICE   SIZE   RES   STATE   C TIME WCPU COMMAND\n          56903 root       31   0     4016M 2543M CPU0   0 2:10 10.50% iked\n\nThis issue affects Juniper Networks Junos OS:\n * All versions earlier than 20.4R3-S9;\n * 21.2 versions earlier than 21.2R3-S7;\n * 21.3 versions earlier than 21.3R3-S5;\n * 21.4 versions earlier than 21.4R3-S4;\n * 22.1 versions earlier than 22.1R3-S3;\n * 22.2 versions earlier than 22.2R3-S2;\n * 22.3 versions earlier than 22.3R3;\n * 22.4 versions earlier than 22.4R3;\n * 23.2 versions earlier than 23.2R1-S2, 23.2R2.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json b/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json index 92d7cfaa63f..9fc8bfd52ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json +++ b/advisories/unreviewed/2024/04/GHSA-rj8v-47w4-c66w/GHSA-rj8v-47w4-c66w.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rj8v-47w4-c66w", - "modified": "2024-10-08T18:33:07Z", + "modified": "2025-04-10T21:30:46Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25697" ], - "details": "\nThere is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.\n\n", + "details": "There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <=11.1 that may allow a remote, authenticated attacker to create a crafted link which when opening an authenticated users bio page will render an image in the victims browser.  The privileges required to execute this attack are low.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-h47g-q8q7-fgrv/GHSA-h47g-q8q7-fgrv.json b/advisories/unreviewed/2024/05/GHSA-h47g-q8q7-fgrv/GHSA-h47g-q8q7-fgrv.json index 6af224d9b70..1683bd0899d 100644 --- a/advisories/unreviewed/2024/05/GHSA-h47g-q8q7-fgrv/GHSA-h47g-q8q7-fgrv.json +++ b/advisories/unreviewed/2024/05/GHSA-h47g-q8q7-fgrv/GHSA-h47g-q8q7-fgrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h47g-q8q7-fgrv", - "modified": "2025-03-21T18:31:29Z", + "modified": "2025-04-10T21:30:51Z", "published": "2024-05-17T06:31:17Z", "aliases": [ "CVE-2024-34757" diff --git a/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json b/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json index f8ed3b202f0..c0bd85b51c5 100644 --- a/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json +++ b/advisories/unreviewed/2024/05/GHSA-hj5g-whq8-wmhg/GHSA-hj5g-whq8-wmhg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-mgwg-4hc9-rq52/GHSA-mgwg-4hc9-rq52.json b/advisories/unreviewed/2024/05/GHSA-mgwg-4hc9-rq52/GHSA-mgwg-4hc9-rq52.json index f3cbfd1c946..1019c083890 100644 --- a/advisories/unreviewed/2024/05/GHSA-mgwg-4hc9-rq52/GHSA-mgwg-4hc9-rq52.json +++ b/advisories/unreviewed/2024/05/GHSA-mgwg-4hc9-rq52/GHSA-mgwg-4hc9-rq52.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mgwg-4hc9-rq52", - "modified": "2024-05-03T09:30:52Z", + "modified": "2025-04-10T21:30:49Z", "published": "2024-05-03T09:30:52Z", "aliases": [ "CVE-2024-33914" ], - "details": "Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.\n\n", + "details": "Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-rf3v-2m2g-6xwj/GHSA-rf3v-2m2g-6xwj.json b/advisories/unreviewed/2024/05/GHSA-rf3v-2m2g-6xwj/GHSA-rf3v-2m2g-6xwj.json index debdef1b99b..2c51173bc20 100644 --- a/advisories/unreviewed/2024/05/GHSA-rf3v-2m2g-6xwj/GHSA-rf3v-2m2g-6xwj.json +++ b/advisories/unreviewed/2024/05/GHSA-rf3v-2m2g-6xwj/GHSA-rf3v-2m2g-6xwj.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-384" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-xvm6-65jm-mc4g/GHSA-xvm6-65jm-mc4g.json b/advisories/unreviewed/2024/07/GHSA-xvm6-65jm-mc4g/GHSA-xvm6-65jm-mc4g.json index e4251c98074..7efbe78af3b 100644 --- a/advisories/unreviewed/2024/07/GHSA-xvm6-65jm-mc4g/GHSA-xvm6-65jm-mc4g.json +++ b/advisories/unreviewed/2024/07/GHSA-xvm6-65jm-mc4g/GHSA-xvm6-65jm-mc4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xvm6-65jm-mc4g", - "modified": "2024-07-11T00:32:51Z", + "modified": "2025-04-10T21:30:56Z", "published": "2024-07-11T00:32:51Z", "aliases": [ "CVE-2024-39561" diff --git a/advisories/unreviewed/2024/08/GHSA-fc63-998f-r568/GHSA-fc63-998f-r568.json b/advisories/unreviewed/2024/08/GHSA-fc63-998f-r568/GHSA-fc63-998f-r568.json index 627c2f56466..7fb9103ab09 100644 --- a/advisories/unreviewed/2024/08/GHSA-fc63-998f-r568/GHSA-fc63-998f-r568.json +++ b/advisories/unreviewed/2024/08/GHSA-fc63-998f-r568/GHSA-fc63-998f-r568.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc63-998f-r568", - "modified": "2025-03-01T03:30:55Z", + "modified": "2025-04-10T21:30:56Z", "published": "2024-08-03T09:30:35Z", "aliases": [ "CVE-2024-7031" diff --git a/advisories/unreviewed/2024/10/GHSA-39f7-qgxq-ff45/GHSA-39f7-qgxq-ff45.json b/advisories/unreviewed/2024/10/GHSA-39f7-qgxq-ff45/GHSA-39f7-qgxq-ff45.json index d2bce9e5d2f..98f5da1abd7 100644 --- a/advisories/unreviewed/2024/10/GHSA-39f7-qgxq-ff45/GHSA-39f7-qgxq-ff45.json +++ b/advisories/unreviewed/2024/10/GHSA-39f7-qgxq-ff45/GHSA-39f7-qgxq-ff45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-39f7-qgxq-ff45", - "modified": "2024-10-04T18:31:10Z", + "modified": "2025-04-10T21:30:57Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-25694" diff --git a/advisories/unreviewed/2024/10/GHSA-f8p7-qq6w-9fjc/GHSA-f8p7-qq6w-9fjc.json b/advisories/unreviewed/2024/10/GHSA-f8p7-qq6w-9fjc/GHSA-f8p7-qq6w-9fjc.json index d2485c5271c..c553cab3aba 100644 --- a/advisories/unreviewed/2024/10/GHSA-f8p7-qq6w-9fjc/GHSA-f8p7-qq6w-9fjc.json +++ b/advisories/unreviewed/2024/10/GHSA-f8p7-qq6w-9fjc/GHSA-f8p7-qq6w-9fjc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f8p7-qq6w-9fjc", - "modified": "2024-10-04T18:31:10Z", + "modified": "2025-04-10T21:30:56Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-25691" diff --git a/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json b/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json index d0de654bf02..9d1e7d66ec2 100644 --- a/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json +++ b/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjm5-824v-4vq3", - "modified": "2024-10-15T15:30:45Z", + "modified": "2025-04-10T21:30:58Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-38036" diff --git a/advisories/unreviewed/2024/10/GHSA-gmw9-73pf-rc65/GHSA-gmw9-73pf-rc65.json b/advisories/unreviewed/2024/10/GHSA-gmw9-73pf-rc65/GHSA-gmw9-73pf-rc65.json index 4090015bd8b..f0008e728e6 100644 --- a/advisories/unreviewed/2024/10/GHSA-gmw9-73pf-rc65/GHSA-gmw9-73pf-rc65.json +++ b/advisories/unreviewed/2024/10/GHSA-gmw9-73pf-rc65/GHSA-gmw9-73pf-rc65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmw9-73pf-rc65", - "modified": "2024-10-04T18:31:11Z", + "modified": "2025-04-10T21:30:58Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-38038" diff --git a/advisories/unreviewed/2024/10/GHSA-p8c4-gpq2-4cr4/GHSA-p8c4-gpq2-4cr4.json b/advisories/unreviewed/2024/10/GHSA-p8c4-gpq2-4cr4/GHSA-p8c4-gpq2-4cr4.json index 18754366db6..bf0e42ba6b5 100644 --- a/advisories/unreviewed/2024/10/GHSA-p8c4-gpq2-4cr4/GHSA-p8c4-gpq2-4cr4.json +++ b/advisories/unreviewed/2024/10/GHSA-p8c4-gpq2-4cr4/GHSA-p8c4-gpq2-4cr4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8c4-gpq2-4cr4", - "modified": "2024-10-04T18:31:10Z", + "modified": "2025-04-10T21:30:57Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-25702" diff --git a/advisories/unreviewed/2024/10/GHSA-r4rm-4xhc-jxj7/GHSA-r4rm-4xhc-jxj7.json b/advisories/unreviewed/2024/10/GHSA-r4rm-4xhc-jxj7/GHSA-r4rm-4xhc-jxj7.json index c1841112e58..defd16b29c9 100644 --- a/advisories/unreviewed/2024/10/GHSA-r4rm-4xhc-jxj7/GHSA-r4rm-4xhc-jxj7.json +++ b/advisories/unreviewed/2024/10/GHSA-r4rm-4xhc-jxj7/GHSA-r4rm-4xhc-jxj7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r4rm-4xhc-jxj7", - "modified": "2024-10-04T18:31:10Z", + "modified": "2025-04-10T21:30:57Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-25701" diff --git a/advisories/unreviewed/2024/11/GHSA-3vp6-4284-wj7c/GHSA-3vp6-4284-wj7c.json b/advisories/unreviewed/2024/11/GHSA-3vp6-4284-wj7c/GHSA-3vp6-4284-wj7c.json index 92427a4056f..8b581cf15a5 100644 --- a/advisories/unreviewed/2024/11/GHSA-3vp6-4284-wj7c/GHSA-3vp6-4284-wj7c.json +++ b/advisories/unreviewed/2024/11/GHSA-3vp6-4284-wj7c/GHSA-3vp6-4284-wj7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vp6-4284-wj7c", - "modified": "2024-11-22T21:32:14Z", + "modified": "2025-04-10T21:31:00Z", "published": "2024-11-22T21:32:14Z", "aliases": [ "CVE-2023-24466" diff --git a/advisories/unreviewed/2024/11/GHSA-58pv-8xf3-c5r4/GHSA-58pv-8xf3-c5r4.json b/advisories/unreviewed/2024/11/GHSA-58pv-8xf3-c5r4/GHSA-58pv-8xf3-c5r4.json index c6420c4fe5b..2b2413f2658 100644 --- a/advisories/unreviewed/2024/11/GHSA-58pv-8xf3-c5r4/GHSA-58pv-8xf3-c5r4.json +++ b/advisories/unreviewed/2024/11/GHSA-58pv-8xf3-c5r4/GHSA-58pv-8xf3-c5r4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58pv-8xf3-c5r4", - "modified": "2024-11-22T21:32:14Z", + "modified": "2025-04-10T21:31:00Z", "published": "2024-11-22T21:32:14Z", "aliases": [ "CVE-2022-26324" diff --git a/advisories/unreviewed/2024/11/GHSA-78x5-mw8r-c5mr/GHSA-78x5-mw8r-c5mr.json b/advisories/unreviewed/2024/11/GHSA-78x5-mw8r-c5mr/GHSA-78x5-mw8r-c5mr.json index 3e14fa25780..c81c78cd4e1 100644 --- a/advisories/unreviewed/2024/11/GHSA-78x5-mw8r-c5mr/GHSA-78x5-mw8r-c5mr.json +++ b/advisories/unreviewed/2024/11/GHSA-78x5-mw8r-c5mr/GHSA-78x5-mw8r-c5mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78x5-mw8r-c5mr", - "modified": "2024-11-22T21:32:14Z", + "modified": "2025-04-10T21:31:00Z", "published": "2024-11-22T21:32:14Z", "aliases": [ "CVE-2021-38116" diff --git a/advisories/unreviewed/2024/11/GHSA-g6hx-mx2f-fvx9/GHSA-g6hx-mx2f-fvx9.json b/advisories/unreviewed/2024/11/GHSA-g6hx-mx2f-fvx9/GHSA-g6hx-mx2f-fvx9.json index 2e4b3136414..9060417860a 100644 --- a/advisories/unreviewed/2024/11/GHSA-g6hx-mx2f-fvx9/GHSA-g6hx-mx2f-fvx9.json +++ b/advisories/unreviewed/2024/11/GHSA-g6hx-mx2f-fvx9/GHSA-g6hx-mx2f-fvx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g6hx-mx2f-fvx9", - "modified": "2024-11-22T21:32:14Z", + "modified": "2025-04-10T21:31:01Z", "published": "2024-11-22T21:32:14Z", "aliases": [ "CVE-2023-24467" diff --git a/advisories/unreviewed/2024/11/GHSA-x749-4jc5-gxmr/GHSA-x749-4jc5-gxmr.json b/advisories/unreviewed/2024/11/GHSA-x749-4jc5-gxmr/GHSA-x749-4jc5-gxmr.json index 2dc59a5d62d..d4712109125 100644 --- a/advisories/unreviewed/2024/11/GHSA-x749-4jc5-gxmr/GHSA-x749-4jc5-gxmr.json +++ b/advisories/unreviewed/2024/11/GHSA-x749-4jc5-gxmr/GHSA-x749-4jc5-gxmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x749-4jc5-gxmr", - "modified": "2024-11-22T21:32:14Z", + "modified": "2025-04-10T21:31:00Z", "published": "2024-11-22T21:32:14Z", "aliases": [ "CVE-2021-38117" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-39wv-3h9m-9hpc/GHSA-39wv-3h9m-9hpc.json b/advisories/unreviewed/2024/12/GHSA-39wv-3h9m-9hpc/GHSA-39wv-3h9m-9hpc.json index f6332ddea10..a97c311f304 100644 --- a/advisories/unreviewed/2024/12/GHSA-39wv-3h9m-9hpc/GHSA-39wv-3h9m-9hpc.json +++ b/advisories/unreviewed/2024/12/GHSA-39wv-3h9m-9hpc/GHSA-39wv-3h9m-9hpc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-39wv-3h9m-9hpc", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-04-10T21:31:01Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-11316" diff --git a/advisories/unreviewed/2024/12/GHSA-78qv-q99m-4f2r/GHSA-78qv-q99m-4f2r.json b/advisories/unreviewed/2024/12/GHSA-78qv-q99m-4f2r/GHSA-78qv-q99m-4f2r.json index c12495ba92a..0a815c61e92 100644 --- a/advisories/unreviewed/2024/12/GHSA-78qv-q99m-4f2r/GHSA-78qv-q99m-4f2r.json +++ b/advisories/unreviewed/2024/12/GHSA-78qv-q99m-4f2r/GHSA-78qv-q99m-4f2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78qv-q99m-4f2r", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-04-10T21:31:01Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-6784" diff --git a/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json b/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json index b3c198621a5..7af7f2200b6 100644 --- a/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json +++ b/advisories/unreviewed/2025/02/GHSA-3m82-fj9p-m6vq/GHSA-3m82-fj9p-m6vq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-gccq-88r2-w9m4/GHSA-gccq-88r2-w9m4.json b/advisories/unreviewed/2025/02/GHSA-gccq-88r2-w9m4/GHSA-gccq-88r2-w9m4.json index 63ec8989885..28d1d5ab02c 100644 --- a/advisories/unreviewed/2025/02/GHSA-gccq-88r2-w9m4/GHSA-gccq-88r2-w9m4.json +++ b/advisories/unreviewed/2025/02/GHSA-gccq-88r2-w9m4/GHSA-gccq-88r2-w9m4.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json b/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json index c0f529e85a9..8a4749b74a3 100644 --- a/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json +++ b/advisories/unreviewed/2025/03/GHSA-2cxw-wgvv-24jj/GHSA-2cxw-wgvv-24jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cxw-wgvv-24jj", - "modified": "2025-03-04T18:33:39Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-04T12:30:32Z", "aliases": [ "CVE-2025-22225" @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-123" + "CWE-123", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json b/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json index 673e3a467d3..9d219ea62ee 100644 --- a/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json +++ b/advisories/unreviewed/2025/03/GHSA-2qh6-98mm-p9vr/GHSA-2qh6-98mm-p9vr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qh6-98mm-p9vr", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51953" diff --git a/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json b/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json index 90d9fa5cf04..8d8d2276333 100644 --- a/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json +++ b/advisories/unreviewed/2025/03/GHSA-4v9h-49hf-v7f8/GHSA-4v9h-49hf-v7f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v9h-49hf-v7f8", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51956" diff --git a/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json b/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json index a1265ab7ef6..ba1f2701c50 100644 --- a/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json +++ b/advisories/unreviewed/2025/03/GHSA-5783-252r-fxpm/GHSA-5783-252r-fxpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5783-252r-fxpm", - "modified": "2025-03-03T21:30:59Z", + "modified": "2025-04-10T21:31:04Z", "published": "2025-03-03T21:30:59Z", "aliases": [ "CVE-2024-10904" diff --git a/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json b/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json index 0017b40e8e0..4385b6ed154 100644 --- a/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json +++ b/advisories/unreviewed/2025/03/GHSA-5ggx-8w3f-h4gf/GHSA-5ggx-8w3f-h4gf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5ggx-8w3f-h4gf", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51957" diff --git a/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json b/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json index 9a41ec073d0..81953ed65db 100644 --- a/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json +++ b/advisories/unreviewed/2025/03/GHSA-6w26-66hj-8g45/GHSA-6w26-66hj-8g45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6w26-66hj-8g45", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:04Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51942" diff --git a/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json b/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json index 1f78f2bb62b..ee10519c4cf 100644 --- a/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json +++ b/advisories/unreviewed/2025/03/GHSA-7855-vcjh-5fv2/GHSA-7855-vcjh-5fv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7855-vcjh-5fv2", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:05Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51945" diff --git a/advisories/unreviewed/2025/03/GHSA-7w3m-9pfq-8m82/GHSA-7w3m-9pfq-8m82.json b/advisories/unreviewed/2025/03/GHSA-7w3m-9pfq-8m82/GHSA-7w3m-9pfq-8m82.json index 18e36af745b..3b2677e6a55 100644 --- a/advisories/unreviewed/2025/03/GHSA-7w3m-9pfq-8m82/GHSA-7w3m-9pfq-8m82.json +++ b/advisories/unreviewed/2025/03/GHSA-7w3m-9pfq-8m82/GHSA-7w3m-9pfq-8m82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w3m-9pfq-8m82", - "modified": "2025-03-04T03:31:20Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-04T03:31:20Z", "aliases": [ "CVE-2025-1695" diff --git a/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json b/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json index 7a933d32021..74a98cddf0d 100644 --- a/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json +++ b/advisories/unreviewed/2025/03/GHSA-8m3r-jg6f-34jp/GHSA-8m3r-jg6f-34jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8m3r-jg6f-34jp", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-5888" diff --git a/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json b/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json index cdb4f67bf81..4903fdae1c2 100644 --- a/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json +++ b/advisories/unreviewed/2025/03/GHSA-9h9v-jch8-f29w/GHSA-9h9v-jch8-f29w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9h9v-jch8-f29w", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51950" diff --git a/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json b/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json index 451f446b3d3..c9269d24d26 100644 --- a/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json +++ b/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cg48-xw7q-cpc8", - "modified": "2025-03-06T15:34:45Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51961" diff --git a/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json b/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json index d94b2546860..34f60dd084e 100644 --- a/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json +++ b/advisories/unreviewed/2025/03/GHSA-cwhx-ww39-3h7h/GHSA-cwhx-ww39-3h7h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cwhx-ww39-3h7h", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51958" diff --git a/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json b/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json index 5c9cd820c1d..3dd728f174b 100644 --- a/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json +++ b/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxm9-pc6x-88r5", - "modified": "2025-03-06T15:34:45Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51954" diff --git a/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json b/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json index 524fce27822..70df04d3573 100644 --- a/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json +++ b/advisories/unreviewed/2025/03/GHSA-fr2q-29x3-38rp/GHSA-fr2q-29x3-38rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr2q-29x3-38rp", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51951" diff --git a/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json b/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json index 6f9b1b58158..0abe3228ede 100644 --- a/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json +++ b/advisories/unreviewed/2025/03/GHSA-fxxp-38jc-7cfq/GHSA-fxxp-38jc-7cfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fxxp-38jc-7cfq", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51959" diff --git a/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json b/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json index 6be27b4f83a..38a3aa29818 100644 --- a/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json +++ b/advisories/unreviewed/2025/03/GHSA-gr9w-6j99-f5q5/GHSA-gr9w-6j99-f5q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gr9w-6j99-f5q5", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51947" diff --git a/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json b/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json index 7c5a9a91d98..40d0c3fd91d 100644 --- a/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json +++ b/advisories/unreviewed/2025/03/GHSA-h49w-5mwr-frr5/GHSA-h49w-5mwr-frr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h49w-5mwr-frr5", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51949" diff --git a/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json b/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json index 632b9c625d7..fb612d821f0 100644 --- a/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json +++ b/advisories/unreviewed/2025/03/GHSA-hr72-4f8w-mw62/GHSA-hr72-4f8w-mw62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr72-4f8w-mw62", - "modified": "2025-03-06T12:30:42Z", + "modified": "2025-04-10T21:31:05Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51944" diff --git a/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json b/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json index 1ae7187f987..e1510e3393d 100644 --- a/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json +++ b/advisories/unreviewed/2025/03/GHSA-m4jp-jx56-47gq/GHSA-m4jp-jx56-47gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4jp-jx56-47gq", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51960" diff --git a/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json b/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json index 018b4b8da9c..281689740e2 100644 --- a/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json +++ b/advisories/unreviewed/2025/03/GHSA-mrpg-q4r4-m4g9/GHSA-mrpg-q4r4-m4g9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mrpg-q4r4-m4g9", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51952" diff --git a/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json b/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json index 3eb865b9bec..cd4551f5333 100644 --- a/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json +++ b/advisories/unreviewed/2025/03/GHSA-pgw2-vj22-3w7g/GHSA-pgw2-vj22-3w7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgw2-vj22-3w7g", - "modified": "2025-03-03T21:31:01Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51963" diff --git a/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json b/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json index affcd6cabfb..1c68c099552 100644 --- a/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json +++ b/advisories/unreviewed/2025/03/GHSA-pph8-wh6p-w5m7/GHSA-pph8-wh6p-w5m7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json b/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json index 2631c08eab5..96a4ffe31f8 100644 --- a/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json +++ b/advisories/unreviewed/2025/03/GHSA-r47p-3h3g-wvw7/GHSA-r47p-3h3g-wvw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r47p-3h3g-wvw7", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51948" diff --git a/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json b/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json index 2b4aa273dbe..97d8eea8d4b 100644 --- a/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json +++ b/advisories/unreviewed/2025/03/GHSA-w8g5-2237-xmj2/GHSA-w8g5-2237-xmj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8g5-2237-xmj2", - "modified": "2025-03-03T21:31:00Z", + "modified": "2025-04-10T21:31:06Z", "published": "2025-03-03T21:31:00Z", "aliases": [ "CVE-2024-51946" diff --git a/advisories/unreviewed/2025/04/GHSA-6gv3-7gp2-wqgf/GHSA-6gv3-7gp2-wqgf.json b/advisories/unreviewed/2025/04/GHSA-6gv3-7gp2-wqgf/GHSA-6gv3-7gp2-wqgf.json index 835d32b0cda..119b165631a 100644 --- a/advisories/unreviewed/2025/04/GHSA-6gv3-7gp2-wqgf/GHSA-6gv3-7gp2-wqgf.json +++ b/advisories/unreviewed/2025/04/GHSA-6gv3-7gp2-wqgf/GHSA-6gv3-7gp2-wqgf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6gv3-7gp2-wqgf", - "modified": "2025-04-09T21:31:42Z", + "modified": "2025-04-10T21:31:08Z", "published": "2025-04-09T21:31:42Z", "aliases": [ "CVE-2024-55210" ], "details": "An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-09T20:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7jc7-7vhf-f7fg/GHSA-7jc7-7vhf-f7fg.json b/advisories/unreviewed/2025/04/GHSA-7jc7-7vhf-f7fg/GHSA-7jc7-7vhf-f7fg.json new file mode 100644 index 00000000000..34c6bf0067e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7jc7-7vhf-f7fg/GHSA-7jc7-7vhf-f7fg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jc7-7vhf-f7fg", + "modified": "2025-04-10T21:31:10Z", + "published": "2025-04-10T21:31:10Z", + "aliases": [ + "CVE-2025-3469" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php.\n\nThis issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3469" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T358689" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9f82-pr9c-9f3x/GHSA-9f82-pr9c-9f3x.json b/advisories/unreviewed/2025/04/GHSA-9f82-pr9c-9f3x/GHSA-9f82-pr9c-9f3x.json new file mode 100644 index 00000000000..ccc42a6f396 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9f82-pr9c-9f3x/GHSA-9f82-pr9c-9f3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f82-pr9c-9f3x", + "modified": "2025-04-10T21:31:09Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-23008" + ], + "details": "An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker to modify configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23008" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9gwp-748x-fwg9/GHSA-9gwp-748x-fwg9.json b/advisories/unreviewed/2025/04/GHSA-9gwp-748x-fwg9/GHSA-9gwp-748x-fwg9.json new file mode 100644 index 00000000000..c17d1668515 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gwp-748x-fwg9/GHSA-9gwp-748x-fwg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gwp-748x-fwg9", + "modified": "2025-04-10T21:31:09Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-32696" + ], + "details": "Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php.\n\nThis issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32696" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T304474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f562-mmxh-p76r/GHSA-f562-mmxh-p76r.json b/advisories/unreviewed/2025/04/GHSA-f562-mmxh-p76r/GHSA-f562-mmxh-p76r.json new file mode 100644 index 00000000000..210d3f901be --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f562-mmxh-p76r/GHSA-f562-mmxh-p76r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f562-mmxh-p76r", + "modified": "2025-04-10T21:31:10Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-32700" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseLog.Php, includes/Pager/AbuseLogPager.Php, includes/Special/SpecialAbuseLog.Php, includes/View/AbuseFilterViewExamine.Php.\n\nThis issue affects AbuseFilter: from >= 1.43.0 before 1.43.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32700" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T389235" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f5r8-5xjg-g5f9/GHSA-f5r8-5xjg-g5f9.json b/advisories/unreviewed/2025/04/GHSA-f5r8-5xjg-g5f9/GHSA-f5r8-5xjg-g5f9.json new file mode 100644 index 00000000000..98dc01627e2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f5r8-5xjg-g5f9/GHSA-f5r8-5xjg-g5f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5r8-5xjg-g5f9", + "modified": "2025-04-10T21:31:09Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-23010" + ], + "details": "An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file paths.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23010" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f626-w254-w424/GHSA-f626-w254-w424.json b/advisories/unreviewed/2025/04/GHSA-f626-w254-w424/GHSA-f626-w254-w424.json new file mode 100644 index 00000000000..58e490be375 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f626-w254-w424/GHSA-f626-w254-w424.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f626-w254-w424", + "modified": "2025-04-10T21:31:09Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-32697" + ], + "details": "Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php.\n\nThis issue affects MediaWiki: before 1.42.6, 1.43.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32697" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T140010" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T24521" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T62109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gpcp-cp2q-wj86/GHSA-gpcp-cp2q-wj86.json b/advisories/unreviewed/2025/04/GHSA-gpcp-cp2q-wj86/GHSA-gpcp-cp2q-wj86.json index ddf4143f994..c292da507bb 100644 --- a/advisories/unreviewed/2025/04/GHSA-gpcp-cp2q-wj86/GHSA-gpcp-cp2q-wj86.json +++ b/advisories/unreviewed/2025/04/GHSA-gpcp-cp2q-wj86/GHSA-gpcp-cp2q-wj86.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gpcp-cp2q-wj86", - "modified": "2025-04-03T15:31:13Z", + "modified": "2025-04-10T21:31:08Z", "published": "2025-04-03T15:31:13Z", "aliases": [ "CVE-2025-22926" ], "details": "An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T14:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json b/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json index 523f49c8385..ca50feb01ac 100644 --- a/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json +++ b/advisories/unreviewed/2025/04/GHSA-gwjc-9mv6-q8q2/GHSA-gwjc-9mv6-q8q2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gwjc-9mv6-q8q2", - "modified": "2025-04-10T09:30:23Z", + "modified": "2025-04-10T21:31:08Z", "published": "2025-04-10T09:30:23Z", "aliases": [ "CVE-2024-13874" ], "details": "The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-10T07:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hh2q-7x5p-j2g2/GHSA-hh2q-7x5p-j2g2.json b/advisories/unreviewed/2025/04/GHSA-hh2q-7x5p-j2g2/GHSA-hh2q-7x5p-j2g2.json new file mode 100644 index 00000000000..dc4293ba583 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hh2q-7x5p-j2g2/GHSA-hh2q-7x5p-j2g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh2q-7x5p-j2g2", + "modified": "2025-04-10T21:31:09Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-32698" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/LogPager.Php.\n\nThis issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32698" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T385958" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mf9p-6469-jcwh/GHSA-mf9p-6469-jcwh.json b/advisories/unreviewed/2025/04/GHSA-mf9p-6469-jcwh/GHSA-mf9p-6469-jcwh.json index f42396d0a07..f741882cbf6 100644 --- a/advisories/unreviewed/2025/04/GHSA-mf9p-6469-jcwh/GHSA-mf9p-6469-jcwh.json +++ b/advisories/unreviewed/2025/04/GHSA-mf9p-6469-jcwh/GHSA-mf9p-6469-jcwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mf9p-6469-jcwh", - "modified": "2025-04-02T03:31:43Z", + "modified": "2025-04-10T21:31:08Z", "published": "2025-04-02T03:31:43Z", "aliases": [ "CVE-2025-3071" ], "details": "Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T01:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json b/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json index 328b0ce5a73..21c087edb69 100644 --- a/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json +++ b/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p549-c3cg-f4qm", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-10T21:31:07Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3035" ], "details": "By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-359" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pq7c-cvqp-fq9x/GHSA-pq7c-cvqp-fq9x.json b/advisories/unreviewed/2025/04/GHSA-pq7c-cvqp-fq9x/GHSA-pq7c-cvqp-fq9x.json new file mode 100644 index 00000000000..01d36cf6e1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pq7c-cvqp-fq9x/GHSA-pq7c-cvqp-fq9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq7c-cvqp-fq9x", + "modified": "2025-04-10T21:31:10Z", + "published": "2025-04-10T21:31:10Z", + "aliases": [ + "CVE-2025-32699" + ], + "details": "Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32699" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T387130" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vmvf-5r44-m57g/GHSA-vmvf-5r44-m57g.json b/advisories/unreviewed/2025/04/GHSA-vmvf-5r44-m57g/GHSA-vmvf-5r44-m57g.json index aed81f42c9b..cf09aa618b8 100644 --- a/advisories/unreviewed/2025/04/GHSA-vmvf-5r44-m57g/GHSA-vmvf-5r44-m57g.json +++ b/advisories/unreviewed/2025/04/GHSA-vmvf-5r44-m57g/GHSA-vmvf-5r44-m57g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmvf-5r44-m57g", - "modified": "2025-04-03T15:31:14Z", + "modified": "2025-04-10T21:31:08Z", "published": "2025-04-03T15:31:14Z", "aliases": [ "CVE-2025-29369" ], "details": "Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T14:15:31Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wvjf-p8qj-4524/GHSA-wvjf-p8qj-4524.json b/advisories/unreviewed/2025/04/GHSA-wvjf-p8qj-4524/GHSA-wvjf-p8qj-4524.json new file mode 100644 index 00000000000..ed8715bf4ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wvjf-p8qj-4524/GHSA-wvjf-p8qj-4524.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvjf-p8qj-4524", + "modified": "2025-04-10T21:31:09Z", + "published": "2025-04-10T21:31:09Z", + "aliases": [ + "CVE-2025-23009" + ], + "details": "A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23009" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T19:16:00Z" + } +} \ No newline at end of file