From dcb20670c4af52690970b9ab593142880e06b984 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 21 Feb 2025 21:33:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-349c-6q2h-wwhm.json | 4 +- .../GHSA-894f-rh68-m2vm.json | 4 +- .../GHSA-fwrh-xmxv-qj39.json | 4 +- .../GHSA-2462-qrqm-7hxr.json | 15 ++++-- .../GHSA-2gpg-5qhm-v86q.json | 6 ++- .../GHSA-3cwv-x695-72xm.json | 6 ++- .../GHSA-3wv2-ww7w-98gm.json | 6 ++- .../GHSA-677j-rh7m-pr6j.json | 6 ++- .../GHSA-7x39-8rpm-5hm4.json | 15 ++++-- .../GHSA-8gq8-vqf9-3x48.json | 6 ++- .../GHSA-97q3-wprp-9xjv.json | 6 ++- .../GHSA-9q3j-vp3j-6rc7.json | 6 ++- .../GHSA-9qvh-qx28-p5p7.json | 6 ++- .../GHSA-9x94-xcqm-57hf.json | 6 ++- .../GHSA-j7cp-f9gr-cjj8.json | 6 ++- .../GHSA-jrjg-p2fp-6rhw.json | 6 ++- .../GHSA-27wp-chg4-ffw3.json | 15 ++++-- .../GHSA-3vwg-x7c5-rg6m.json | 15 ++++-- .../GHSA-472m-7rg9-p78j.json | 40 ++++++++++++++ .../GHSA-4hwx-j6w8-9w2r.json | 29 +++++++++++ .../GHSA-4mp4-36x3-25jw.json | 29 +++++++++++ .../GHSA-4rhc-2pqf-hqj3.json | 15 ++++-- .../GHSA-5429-63wr-8cgm.json | 29 +++++++++++ .../GHSA-57q4-cgqr-6cw7.json | 15 ++++-- .../GHSA-5mxv-j9vc-66x9.json | 15 ++++-- .../GHSA-6c6v-3v49-q93r.json | 15 ++++-- .../GHSA-7crh-q834-jm56.json | 15 ++++-- .../GHSA-7v2p-6g6r-9hjw.json | 15 ++++-- .../GHSA-995j-3cj2-3p49.json | 15 ++++-- .../GHSA-fq4q-m37q-rfrh.json | 15 ++++-- .../GHSA-g7x3-m53h-j2jq.json | 15 ++++-- .../GHSA-h76r-mvr3-76xg.json | 29 +++++++++++ .../GHSA-hc6p-5pr7-xvv5.json | 36 +++++++++++++ .../GHSA-j946-qf4c-jrjh.json | 15 ++++-- .../GHSA-jj9w-p5wc-95q5.json | 52 +++++++++++++++++++ .../GHSA-r4wq-76x5-pwj9.json | 29 +++++++++++ .../GHSA-v8m7-99rg-xp5c.json | 22 +++++++- .../GHSA-vmh9-7gfq-4r2p.json | 15 ++++-- .../GHSA-vr7m-6pgw-3493.json | 15 ++++-- .../GHSA-x5vg-jxxx-qgwx.json | 15 ++++-- .../GHSA-xrf3-35rj-g634.json | 36 +++++++++++++ 41 files changed, 578 insertions(+), 86 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-472m-7rg9-p78j/GHSA-472m-7rg9-p78j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4mp4-36x3-25jw/GHSA-4mp4-36x3-25jw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5429-63wr-8cgm/GHSA-5429-63wr-8cgm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hc6p-5pr7-xvv5/GHSA-hc6p-5pr7-xvv5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jj9w-p5wc-95q5/GHSA-jj9w-p5wc-95q5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r4wq-76x5-pwj9/GHSA-r4wq-76x5-pwj9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xrf3-35rj-g634/GHSA-xrf3-35rj-g634.json diff --git a/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json b/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json index eb56795fd13..ea8d6f06ba7 100644 --- a/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json +++ b/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-349c-6q2h-wwhm", - "modified": "2024-04-29T06:30:42Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-04-29T06:30:42Z", "aliases": [ "CVE-2024-33551" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json b/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json index 025989a56eb..5fda50e9e82 100644 --- a/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json +++ b/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-894f-rh68-m2vm", - "modified": "2024-04-29T06:30:42Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-04-29T06:30:42Z", "aliases": [ "CVE-2024-33554" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json b/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json index 1cb6cfcdaa0..a4d56d4faaf 100644 --- a/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json +++ b/advisories/unreviewed/2024/04/GHSA-fwrh-xmxv-qj39/GHSA-fwrh-xmxv-qj39.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fwrh-xmxv-qj39", - "modified": "2024-04-29T09:31:52Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-04-29T09:31:52Z", "aliases": [ "CVE-2024-33553" ], - "details": "Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json b/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json index 834800b3b06..47be7209560 100644 --- a/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json +++ b/advisories/unreviewed/2024/05/GHSA-2462-qrqm-7hxr/GHSA-2462-qrqm-7hxr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2462-qrqm-7hxr", - "modified": "2024-05-01T21:30:34Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-01T21:30:34Z", "aliases": [ "CVE-2023-23021" ], "details": "Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2gpg-5qhm-v86q/GHSA-2gpg-5qhm-v86q.json b/advisories/unreviewed/2024/05/GHSA-2gpg-5qhm-v86q/GHSA-2gpg-5qhm-v86q.json index 7f658e05ca3..acc9e1a574f 100644 --- a/advisories/unreviewed/2024/05/GHSA-2gpg-5qhm-v86q/GHSA-2gpg-5qhm-v86q.json +++ b/advisories/unreviewed/2024/05/GHSA-2gpg-5qhm-v86q/GHSA-2gpg-5qhm-v86q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gpg-5qhm-v86q", - "modified": "2024-05-20T06:30:34Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T06:30:34Z", "aliases": [ "CVE-2024-5115" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-3cwv-x695-72xm/GHSA-3cwv-x695-72xm.json b/advisories/unreviewed/2024/05/GHSA-3cwv-x695-72xm/GHSA-3cwv-x695-72xm.json index 9795102fe34..e1d54c3e315 100644 --- a/advisories/unreviewed/2024/05/GHSA-3cwv-x695-72xm/GHSA-3cwv-x695-72xm.json +++ b/advisories/unreviewed/2024/05/GHSA-3cwv-x695-72xm/GHSA-3cwv-x695-72xm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3cwv-x695-72xm", - "modified": "2024-05-20T00:30:26Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T00:30:26Z", "aliases": [ "CVE-2024-5108" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-3wv2-ww7w-98gm/GHSA-3wv2-ww7w-98gm.json b/advisories/unreviewed/2024/05/GHSA-3wv2-ww7w-98gm/GHSA-3wv2-ww7w-98gm.json index 2a4d196b494..d3f0cf351d6 100644 --- a/advisories/unreviewed/2024/05/GHSA-3wv2-ww7w-98gm/GHSA-3wv2-ww7w-98gm.json +++ b/advisories/unreviewed/2024/05/GHSA-3wv2-ww7w-98gm/GHSA-3wv2-ww7w-98gm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wv2-ww7w-98gm", - "modified": "2024-05-20T03:30:30Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T03:30:30Z", "aliases": [ "CVE-2024-5110" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-677j-rh7m-pr6j/GHSA-677j-rh7m-pr6j.json b/advisories/unreviewed/2024/05/GHSA-677j-rh7m-pr6j/GHSA-677j-rh7m-pr6j.json index f4fcd3b1ab8..886bb19f564 100644 --- a/advisories/unreviewed/2024/05/GHSA-677j-rh7m-pr6j/GHSA-677j-rh7m-pr6j.json +++ b/advisories/unreviewed/2024/05/GHSA-677j-rh7m-pr6j/GHSA-677j-rh7m-pr6j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-677j-rh7m-pr6j", - "modified": "2024-05-20T03:30:29Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T03:30:29Z", "aliases": [ "CVE-2024-5109" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7x39-8rpm-5hm4/GHSA-7x39-8rpm-5hm4.json b/advisories/unreviewed/2024/05/GHSA-7x39-8rpm-5hm4/GHSA-7x39-8rpm-5hm4.json index 9137c34f1cc..bb4e6451ce5 100644 --- a/advisories/unreviewed/2024/05/GHSA-7x39-8rpm-5hm4/GHSA-7x39-8rpm-5hm4.json +++ b/advisories/unreviewed/2024/05/GHSA-7x39-8rpm-5hm4/GHSA-7x39-8rpm-5hm4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7x39-8rpm-5hm4", - "modified": "2024-05-01T21:30:36Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-01T21:30:36Z", "aliases": [ "CVE-2023-23022" ], "details": "Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows attackers to execute arbitrary code via the code, title, from_date and to_date inputs in file Main.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T19:15:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8gq8-vqf9-3x48/GHSA-8gq8-vqf9-3x48.json b/advisories/unreviewed/2024/05/GHSA-8gq8-vqf9-3x48/GHSA-8gq8-vqf9-3x48.json index e568389a5f7..9d77daa7ced 100644 --- a/advisories/unreviewed/2024/05/GHSA-8gq8-vqf9-3x48/GHSA-8gq8-vqf9-3x48.json +++ b/advisories/unreviewed/2024/05/GHSA-8gq8-vqf9-3x48/GHSA-8gq8-vqf9-3x48.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8gq8-vqf9-3x48", - "modified": "2024-05-20T03:30:30Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T03:30:30Z", "aliases": [ "CVE-2024-5111" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-97q3-wprp-9xjv/GHSA-97q3-wprp-9xjv.json b/advisories/unreviewed/2024/05/GHSA-97q3-wprp-9xjv/GHSA-97q3-wprp-9xjv.json index b92f112e537..314032762e6 100644 --- a/advisories/unreviewed/2024/05/GHSA-97q3-wprp-9xjv/GHSA-97q3-wprp-9xjv.json +++ b/advisories/unreviewed/2024/05/GHSA-97q3-wprp-9xjv/GHSA-97q3-wprp-9xjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97q3-wprp-9xjv", - "modified": "2024-05-20T03:30:30Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T03:30:30Z", "aliases": [ "CVE-2024-5113" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-9q3j-vp3j-6rc7/GHSA-9q3j-vp3j-6rc7.json b/advisories/unreviewed/2024/05/GHSA-9q3j-vp3j-6rc7/GHSA-9q3j-vp3j-6rc7.json index 796c1a49a03..efb770c5cea 100644 --- a/advisories/unreviewed/2024/05/GHSA-9q3j-vp3j-6rc7/GHSA-9q3j-vp3j-6rc7.json +++ b/advisories/unreviewed/2024/05/GHSA-9q3j-vp3j-6rc7/GHSA-9q3j-vp3j-6rc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9q3j-vp3j-6rc7", - "modified": "2024-05-20T03:30:30Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T03:30:30Z", "aliases": [ "CVE-2024-5112" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-9qvh-qx28-p5p7/GHSA-9qvh-qx28-p5p7.json b/advisories/unreviewed/2024/05/GHSA-9qvh-qx28-p5p7/GHSA-9qvh-qx28-p5p7.json index 9f8ebe18825..1c83de7ced7 100644 --- a/advisories/unreviewed/2024/05/GHSA-9qvh-qx28-p5p7/GHSA-9qvh-qx28-p5p7.json +++ b/advisories/unreviewed/2024/05/GHSA-9qvh-qx28-p5p7/GHSA-9qvh-qx28-p5p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qvh-qx28-p5p7", - "modified": "2024-05-20T03:30:31Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T03:30:31Z", "aliases": [ "CVE-2024-5114" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-9x94-xcqm-57hf/GHSA-9x94-xcqm-57hf.json b/advisories/unreviewed/2024/05/GHSA-9x94-xcqm-57hf/GHSA-9x94-xcqm-57hf.json index ba0a94561bc..93d8cee780a 100644 --- a/advisories/unreviewed/2024/05/GHSA-9x94-xcqm-57hf/GHSA-9x94-xcqm-57hf.json +++ b/advisories/unreviewed/2024/05/GHSA-9x94-xcqm-57hf/GHSA-9x94-xcqm-57hf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9x94-xcqm-57hf", - "modified": "2024-05-20T09:30:50Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T09:30:50Z", "aliases": [ "CVE-2024-5136" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-j7cp-f9gr-cjj8/GHSA-j7cp-f9gr-cjj8.json b/advisories/unreviewed/2024/05/GHSA-j7cp-f9gr-cjj8/GHSA-j7cp-f9gr-cjj8.json index ba1afe0a758..58383e734da 100644 --- a/advisories/unreviewed/2024/05/GHSA-j7cp-f9gr-cjj8/GHSA-j7cp-f9gr-cjj8.json +++ b/advisories/unreviewed/2024/05/GHSA-j7cp-f9gr-cjj8/GHSA-j7cp-f9gr-cjj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7cp-f9gr-cjj8", - "modified": "2024-05-20T00:30:26Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T00:30:26Z", "aliases": [ "CVE-2024-5107" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-jrjg-p2fp-6rhw/GHSA-jrjg-p2fp-6rhw.json b/advisories/unreviewed/2024/05/GHSA-jrjg-p2fp-6rhw/GHSA-jrjg-p2fp-6rhw.json index 8270c74e7a6..5e56fe08e19 100644 --- a/advisories/unreviewed/2024/05/GHSA-jrjg-p2fp-6rhw/GHSA-jrjg-p2fp-6rhw.json +++ b/advisories/unreviewed/2024/05/GHSA-jrjg-p2fp-6rhw/GHSA-jrjg-p2fp-6rhw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jrjg-p2fp-6rhw", - "modified": "2024-05-20T09:30:50Z", + "modified": "2025-02-21T21:32:03Z", "published": "2024-05-20T09:30:50Z", "aliases": [ "CVE-2024-5135" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/02/GHSA-27wp-chg4-ffw3/GHSA-27wp-chg4-ffw3.json b/advisories/unreviewed/2025/02/GHSA-27wp-chg4-ffw3/GHSA-27wp-chg4-ffw3.json index 23fdfcdc619..d78ea1cc2e3 100644 --- a/advisories/unreviewed/2025/02/GHSA-27wp-chg4-ffw3/GHSA-27wp-chg4-ffw3.json +++ b/advisories/unreviewed/2025/02/GHSA-27wp-chg4-ffw3/GHSA-27wp-chg4-ffw3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-27wp-chg4-ffw3", - "modified": "2025-02-21T18:31:13Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-21T18:31:13Z", "aliases": [ "CVE-2025-26013" ], "details": "An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-540" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T16:15:33Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3vwg-x7c5-rg6m/GHSA-3vwg-x7c5-rg6m.json b/advisories/unreviewed/2025/02/GHSA-3vwg-x7c5-rg6m/GHSA-3vwg-x7c5-rg6m.json index 447035274af..1a408d7cc0b 100644 --- a/advisories/unreviewed/2025/02/GHSA-3vwg-x7c5-rg6m/GHSA-3vwg-x7c5-rg6m.json +++ b/advisories/unreviewed/2025/02/GHSA-3vwg-x7c5-rg6m/GHSA-3vwg-x7c5-rg6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vwg-x7c5-rg6m", - "modified": "2025-02-21T18:31:14Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2025-25505" ], "details": "Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T17:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-472m-7rg9-p78j/GHSA-472m-7rg9-p78j.json b/advisories/unreviewed/2025/02/GHSA-472m-7rg9-p78j/GHSA-472m-7rg9-p78j.json new file mode 100644 index 00000000000..f26debdc8ae --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-472m-7rg9-p78j/GHSA-472m-7rg9-p78j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-472m-7rg9-p78j", + "modified": "2025-02-21T21:32:07Z", + "published": "2025-02-21T21:32:07Z", + "aliases": [ + "CVE-2020-19248" + ], + "details": "SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-19248" + }, + { + "type": "WEB", + "url": "https://github.com/SticKManII/SticKManII.github.io/tree/master/2019/07/31/PbootCMSv1-4-1-%E5%89%8D%E5%8F%B0%E6%90%9C%E7%B4%A2%E9%A1%B5%E9%9D%A2%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5" + }, + { + "type": "WEB", + "url": "https://unh3x.github.io/2019/07/19/PbootCMSv1.4.1_Template_Injection" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json b/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json new file mode 100644 index 00000000000..6a8d068be25 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4hwx-j6w8-9w2r/GHSA-4hwx-j6w8-9w2r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hwx-j6w8-9w2r", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-25767" + ], + "details": "A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25767" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/a6170a19-032b-462d-8bf9-06ab139f78ba" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4mp4-36x3-25jw/GHSA-4mp4-36x3-25jw.json b/advisories/unreviewed/2025/02/GHSA-4mp4-36x3-25jw/GHSA-4mp4-36x3-25jw.json new file mode 100644 index 00000000000..7372d1b5e67 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4mp4-36x3-25jw/GHSA-4mp4-36x3-25jw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mp4-36x3-25jw", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-25769" + ], + "details": "Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25769" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/56c86622-1e4d-47ed-923c-9e37aff00079" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json b/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json index a91763bdb17..d11a8afea9e 100644 --- a/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json +++ b/advisories/unreviewed/2025/02/GHSA-4rhc-2pqf-hqj3/GHSA-4rhc-2pqf-hqj3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rhc-2pqf-hqj3", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:05Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51321" ], "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5429-63wr-8cgm/GHSA-5429-63wr-8cgm.json b/advisories/unreviewed/2025/02/GHSA-5429-63wr-8cgm/GHSA-5429-63wr-8cgm.json new file mode 100644 index 00000000000..c657676025b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5429-63wr-8cgm/GHSA-5429-63wr-8cgm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5429-63wr-8cgm", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-25770" + ], + "details": "Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25770" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/dddbd17e-e459-46c7-b3f9-9c9a90cee804" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json b/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json index 68945a28422..5417e44abce 100644 --- a/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json +++ b/advisories/unreviewed/2025/02/GHSA-57q4-cgqr-6cw7/GHSA-57q4-cgqr-6cw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57q4-cgqr-6cw7", - "modified": "2025-02-21T15:32:03Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-21T15:32:03Z", "aliases": [ "CVE-2020-6158" ], "details": "Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user into providing sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T14:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json b/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json index c37d3919ee1..97781c8104d 100644 --- a/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json +++ b/advisories/unreviewed/2025/02/GHSA-5mxv-j9vc-66x9/GHSA-5mxv-j9vc-66x9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5mxv-j9vc-66x9", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:06Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51324" ], "details": "PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json b/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json index 68bc35ad6da..dedafaa46ef 100644 --- a/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json +++ b/advisories/unreviewed/2025/02/GHSA-6c6v-3v49-q93r/GHSA-6c6v-3v49-q93r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6c6v-3v49-q93r", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:06Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51326" ], "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7crh-q834-jm56/GHSA-7crh-q834-jm56.json b/advisories/unreviewed/2025/02/GHSA-7crh-q834-jm56/GHSA-7crh-q834-jm56.json index d672463e1d6..ced749df9ea 100644 --- a/advisories/unreviewed/2025/02/GHSA-7crh-q834-jm56/GHSA-7crh-q834-jm56.json +++ b/advisories/unreviewed/2025/02/GHSA-7crh-q834-jm56/GHSA-7crh-q834-jm56.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7crh-q834-jm56", - "modified": "2025-02-21T18:31:14Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2025-25507" ], "details": "There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T17:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json b/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json index bb611caaf8b..f7d331d2136 100644 --- a/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json +++ b/advisories/unreviewed/2025/02/GHSA-7v2p-6g6r-9hjw/GHSA-7v2p-6g6r-9hjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7v2p-6g6r-9hjw", - "modified": "2025-02-20T18:31:24Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-20T18:31:24Z", "aliases": [ "CVE-2025-26305" ], "details": "A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-244" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T17:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json b/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json index 0388a8eca06..ead2381e45a 100644 --- a/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json +++ b/advisories/unreviewed/2025/02/GHSA-995j-3cj2-3p49/GHSA-995j-3cj2-3p49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-995j-3cj2-3p49", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:06Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51327" ], "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json b/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json index c59977d7e83..e3f3d791c75 100644 --- a/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json +++ b/advisories/unreviewed/2025/02/GHSA-fq4q-m37q-rfrh/GHSA-fq4q-m37q-rfrh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fq4q-m37q-rfrh", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:06Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51331" ], "details": "PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json b/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json index c1871d7d6bf..9b7ea39d535 100644 --- a/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json +++ b/advisories/unreviewed/2025/02/GHSA-g7x3-m53h-j2jq/GHSA-g7x3-m53h-j2jq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7x3-m53h-j2jq", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:05Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51320" ], "details": "PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json b/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json new file mode 100644 index 00000000000..8ecedb4207b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h76r-mvr3-76xg/GHSA-h76r-mvr3-76xg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h76r-mvr3-76xg", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-25768" + ], + "details": "MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \\servlet\\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25768" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/8838861d-0b32-4314-a13d-edb22b72cebc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hc6p-5pr7-xvv5/GHSA-hc6p-5pr7-xvv5.json b/advisories/unreviewed/2025/02/GHSA-hc6p-5pr7-xvv5/GHSA-hc6p-5pr7-xvv5.json new file mode 100644 index 00000000000..00202ff1506 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hc6p-5pr7-xvv5/GHSA-hc6p-5pr7-xvv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc6p-5pr7-xvv5", + "modified": "2025-02-21T21:32:07Z", + "published": "2025-02-21T21:32:07Z", + "aliases": [ + "CVE-2025-25604" + ], + "details": "Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25604" + }, + { + "type": "WEB", + "url": "https://github.com/sezangel/IOT-vul/tree/main/Totolink/X5000R/5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json b/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json index e78b4ad873f..7fbd20cb9d7 100644 --- a/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json +++ b/advisories/unreviewed/2025/02/GHSA-j946-qf4c-jrjh/GHSA-j946-qf4c-jrjh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j946-qf4c-jrjh", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:05Z", "published": "2025-02-20T18:31:23Z", "aliases": [ "CVE-2023-51323" ], "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jj9w-p5wc-95q5/GHSA-jj9w-p5wc-95q5.json b/advisories/unreviewed/2025/02/GHSA-jj9w-p5wc-95q5/GHSA-jj9w-p5wc-95q5.json new file mode 100644 index 00000000000..5be4544bae2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jj9w-p5wc-95q5/GHSA-jj9w-p5wc-95q5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj9w-p5wc-95q5", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-1555" + ], + "details": "A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1555" + }, + { + "type": "WEB", + "url": "https://github.com/Rain1er/report/blob/main/CDG/bnhiMg%3D%3D.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296506" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296506" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496932" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r4wq-76x5-pwj9/GHSA-r4wq-76x5-pwj9.json b/advisories/unreviewed/2025/02/GHSA-r4wq-76x5-pwj9/GHSA-r4wq-76x5-pwj9.json new file mode 100644 index 00000000000..de85d3ec662 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r4wq-76x5-pwj9/GHSA-r4wq-76x5-pwj9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4wq-76x5-pwj9", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-25772" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25772" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/u123456789-6sobi/cdgcbq/pkwoqmkamcm9854r?singleDoc#%E3%80%8AjspXcms_csrf%E3%80%8B" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json b/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json index a98ddf5a80d..3f2a26a7155 100644 --- a/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json +++ b/advisories/unreviewed/2025/02/GHSA-v8m7-99rg-xp5c/GHSA-v8m7-99rg-xp5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v8m7-99rg-xp5c", - "modified": "2025-02-21T15:32:02Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-21T15:32:02Z", "aliases": [ "CVE-2025-26794" @@ -19,10 +19,30 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26794" }, + { + "type": "WEB", + "url": "https://github.com/NixOS/nixpkgs/pull/383926" + }, + { + "type": "WEB", + "url": "https://github.com/openbsd/ports/commit/584d2c49addce9ca0ae67882cc16969104d7f82d" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1237424" + }, + { + "type": "WEB", + "url": "https://code.exim.org/exim/exim/commit/bfe32b5c6ea033736a26da8421513206db9fe305" + }, { "type": "WEB", "url": "https://exim.org" }, + { + "type": "WEB", + "url": "https://github.com/Exim/exim/wiki/EximSecurity" + }, { "type": "WEB", "url": "https://www.exim.org/static/doc/security/CVE-2025-26794.txt" diff --git a/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json b/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json index f09fe783088..276fc3621f4 100644 --- a/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json +++ b/advisories/unreviewed/2025/02/GHSA-vmh9-7gfq-4r2p/GHSA-vmh9-7gfq-4r2p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmh9-7gfq-4r2p", - "modified": "2025-02-20T18:31:23Z", + "modified": "2025-02-21T21:32:05Z", "published": "2025-02-20T18:31:22Z", "aliases": [ "CVE-2023-51317" ], "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T16:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json b/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json index 4c6c92f8e27..66a76912cde 100644 --- a/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json +++ b/advisories/unreviewed/2025/02/GHSA-vr7m-6pgw-3493/GHSA-vr7m-6pgw-3493.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr7m-6pgw-3493", - "modified": "2025-02-20T18:31:24Z", + "modified": "2025-02-21T21:32:06Z", "published": "2025-02-20T18:31:24Z", "aliases": [ "CVE-2025-26304" ], "details": "A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-244" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-20T17:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-x5vg-jxxx-qgwx/GHSA-x5vg-jxxx-qgwx.json b/advisories/unreviewed/2025/02/GHSA-x5vg-jxxx-qgwx/GHSA-x5vg-jxxx-qgwx.json index beb3a4519f8..0438b37925c 100644 --- a/advisories/unreviewed/2025/02/GHSA-x5vg-jxxx-qgwx/GHSA-x5vg-jxxx-qgwx.json +++ b/advisories/unreviewed/2025/02/GHSA-x5vg-jxxx-qgwx/GHSA-x5vg-jxxx-qgwx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5vg-jxxx-qgwx", - "modified": "2025-02-21T18:31:14Z", + "modified": "2025-02-21T21:32:07Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2025-25510" ], "details": "Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T17:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xrf3-35rj-g634/GHSA-xrf3-35rj-g634.json b/advisories/unreviewed/2025/02/GHSA-xrf3-35rj-g634/GHSA-xrf3-35rj-g634.json new file mode 100644 index 00000000000..653b16e50c4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xrf3-35rj-g634/GHSA-xrf3-35rj-g634.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrf3-35rj-g634", + "modified": "2025-02-21T21:32:08Z", + "published": "2025-02-21T21:32:08Z", + "aliases": [ + "CVE-2025-25605" + ], + "details": "Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25605" + }, + { + "type": "WEB", + "url": "https://github.com/sezangel/IOT-vul/tree/main/Totolink/X5000R/4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T19:15:14Z" + } +} \ No newline at end of file