diff --git a/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json b/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json index 2a32278dd4a..9c295d6fd9f 100644 --- a/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json +++ b/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-xg2h-7cxj-3gvh", - "modified": "2025-02-12T19:33:10Z", + "modified": "2025-02-14T21:30:14Z", "published": "2025-02-12T00:32:17Z", + "withdrawn": "2025-02-14T21:30:14Z", "aliases": [ "CVE-2024-57000" ], - "summary": "Command injection in Ray", - "details": "An issue in Anyscale Inc Ray between v.2.9.3 and v.2.40.0 allows a remote attacker to execute arbitrary code via a crafted script.", + "summary": "Withdrawn Advisory: Command injection in Ray", + "details": "# Withdrawn Advisory\nThis advisory is a duplicate of GHSA-6wgj-66m2-xxp2 / CVE-2023-48022.\n\n# Original Description\nAn issue in Anyscale Inc Ray between v.2.9.3 and v.2.40.0 allows a remote attacker to execute arbitrary code via a crafted script.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2022/05/GHSA-p27r-23gv-6hr2/GHSA-p27r-23gv-6hr2.json b/advisories/unreviewed/2022/05/GHSA-p27r-23gv-6hr2/GHSA-p27r-23gv-6hr2.json index 25304b8e4c7..01e26dc25db 100644 --- a/advisories/unreviewed/2022/05/GHSA-p27r-23gv-6hr2/GHSA-p27r-23gv-6hr2.json +++ b/advisories/unreviewed/2022/05/GHSA-p27r-23gv-6hr2/GHSA-p27r-23gv-6hr2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p27r-23gv-6hr2", - "modified": "2022-05-24T19:16:46Z", + "modified": "2025-02-14T21:31:00Z", "published": "2022-05-24T19:16:46Z", "aliases": [ "CVE-2021-39351" ], "details": "The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/03/GHSA-6mcj-frmm-wmr5/GHSA-6mcj-frmm-wmr5.json b/advisories/unreviewed/2023/03/GHSA-6mcj-frmm-wmr5/GHSA-6mcj-frmm-wmr5.json index 004c44d689d..3635b3e5268 100644 --- a/advisories/unreviewed/2023/03/GHSA-6mcj-frmm-wmr5/GHSA-6mcj-frmm-wmr5.json +++ b/advisories/unreviewed/2023/03/GHSA-6mcj-frmm-wmr5/GHSA-6mcj-frmm-wmr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mcj-frmm-wmr5", - "modified": "2023-04-08T03:30:28Z", + "modified": "2025-02-14T21:31:01Z", "published": "2023-03-31T18:30:20Z", "aliases": [ "CVE-2023-28879" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://ghostscript.readthedocs.io/en/latest/News.html" }, + { + "type": "WEB", + "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=37ed5022cecd584de868933b5b60da2e995b3179" + }, { "type": "WEB", "url": "https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=37ed5022cecd584de868933b5b60da2e995b3179" @@ -35,6 +39,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00003.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHJX62KSRIOBZA6FKONMJP7MEFY7LTH2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MADLP3GWJFLLFVNZGEDNPMDQR6CCXAHN" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CI6UCKM3XMK7PYNIRGAVDJ5VKN6XYZOE" diff --git a/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json b/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json index d05927ba2dd..a2492076a68 100644 --- a/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json +++ b/advisories/unreviewed/2023/03/GHSA-f3hr-rv72-879p/GHSA-f3hr-rv72-879p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-j4f5-gw7r-fr82/GHSA-j4f5-gw7r-fr82.json b/advisories/unreviewed/2023/03/GHSA-j4f5-gw7r-fr82/GHSA-j4f5-gw7r-fr82.json index 2550eb52356..7e363263b19 100644 --- a/advisories/unreviewed/2023/03/GHSA-j4f5-gw7r-fr82/GHSA-j4f5-gw7r-fr82.json +++ b/advisories/unreviewed/2023/03/GHSA-j4f5-gw7r-fr82/GHSA-j4f5-gw7r-fr82.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-mhh7-364w-v3ph/GHSA-mhh7-364w-v3ph.json b/advisories/unreviewed/2023/03/GHSA-mhh7-364w-v3ph/GHSA-mhh7-364w-v3ph.json index 539d794d948..6e302c31a64 100644 --- a/advisories/unreviewed/2023/03/GHSA-mhh7-364w-v3ph/GHSA-mhh7-364w-v3ph.json +++ b/advisories/unreviewed/2023/03/GHSA-mhh7-364w-v3ph/GHSA-mhh7-364w-v3ph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mhh7-364w-v3ph", - "modified": "2023-04-08T03:30:28Z", + "modified": "2025-02-14T21:31:01Z", "published": "2023-03-31T18:30:20Z", "aliases": [ "CVE-2023-28877" @@ -19,13 +19,19 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28877" }, + { + "type": "WEB", + "url": "https://developers.vtex.com/updates/release-notes/deprecation-of-apps-graphql%402.x" + }, { "type": "WEB", "url": "https://developers.vtex.com/updates/release-notes/deprecation-of-apps-graphql@2.x" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-vrfj-56m3-478f/GHSA-vrfj-56m3-478f.json b/advisories/unreviewed/2023/04/GHSA-vrfj-56m3-478f/GHSA-vrfj-56m3-478f.json index c016e198ef0..068dae0ca83 100644 --- a/advisories/unreviewed/2023/04/GHSA-vrfj-56m3-478f/GHSA-vrfj-56m3-478f.json +++ b/advisories/unreviewed/2023/04/GHSA-vrfj-56m3-478f/GHSA-vrfj-56m3-478f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrfj-56m3-478f", - "modified": "2023-04-07T03:30:16Z", + "modified": "2025-02-14T21:31:02Z", "published": "2023-04-04T15:30:27Z", "aliases": [ "CVE-2020-19699" diff --git a/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json b/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json index 7c946a6b62b..f32f44f23a2 100644 --- a/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json +++ b/advisories/unreviewed/2025/02/GHSA-359j-pv49-2m97/GHSA-359j-pv49-2m97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-359j-pv49-2m97", - "modified": "2025-02-12T18:31:35Z", + "modified": "2025-02-14T21:31:03Z", "published": "2025-02-12T18:31:35Z", "aliases": [ "CVE-2025-25351" ], "details": "PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-12T16:15:46Z" diff --git a/advisories/unreviewed/2025/02/GHSA-37rg-82p6-6g3x/GHSA-37rg-82p6-6g3x.json b/advisories/unreviewed/2025/02/GHSA-37rg-82p6-6g3x/GHSA-37rg-82p6-6g3x.json index 24042db85a1..164e7d99093 100644 --- a/advisories/unreviewed/2025/02/GHSA-37rg-82p6-6g3x/GHSA-37rg-82p6-6g3x.json +++ b/advisories/unreviewed/2025/02/GHSA-37rg-82p6-6g3x/GHSA-37rg-82p6-6g3x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-37rg-82p6-6g3x", - "modified": "2025-02-14T00:30:44Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2024-37603" ], "details": "An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-843" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4994-gjh6-5rmr/GHSA-4994-gjh6-5rmr.json b/advisories/unreviewed/2025/02/GHSA-4994-gjh6-5rmr/GHSA-4994-gjh6-5rmr.json index 9119cc723de..108085216ae 100644 --- a/advisories/unreviewed/2025/02/GHSA-4994-gjh6-5rmr/GHSA-4994-gjh6-5rmr.json +++ b/advisories/unreviewed/2025/02/GHSA-4994-gjh6-5rmr/GHSA-4994-gjh6-5rmr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4994-gjh6-5rmr", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25994" ], "details": "SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4gcq-fhhf-j285/GHSA-4gcq-fhhf-j285.json b/advisories/unreviewed/2025/02/GHSA-4gcq-fhhf-j285/GHSA-4gcq-fhhf-j285.json index 608264b108e..a0a0c86e463 100644 --- a/advisories/unreviewed/2025/02/GHSA-4gcq-fhhf-j285/GHSA-4gcq-fhhf-j285.json +++ b/advisories/unreviewed/2025/02/GHSA-4gcq-fhhf-j285/GHSA-4gcq-fhhf-j285.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gcq-fhhf-j285", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25992" ], "details": "SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4h5r-r8cj-6rj3/GHSA-4h5r-r8cj-6rj3.json b/advisories/unreviewed/2025/02/GHSA-4h5r-r8cj-6rj3/GHSA-4h5r-r8cj-6rj3.json index 59a1984c149..fa7df79d34b 100644 --- a/advisories/unreviewed/2025/02/GHSA-4h5r-r8cj-6rj3/GHSA-4h5r-r8cj-6rj3.json +++ b/advisories/unreviewed/2025/02/GHSA-4h5r-r8cj-6rj3/GHSA-4h5r-r8cj-6rj3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-121" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-4hj2-83vx-rh57/GHSA-4hj2-83vx-rh57.json b/advisories/unreviewed/2025/02/GHSA-4hj2-83vx-rh57/GHSA-4hj2-83vx-rh57.json new file mode 100644 index 00000000000..35c0b321237 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4hj2-83vx-rh57/GHSA-4hj2-83vx-rh57.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hj2-83vx-rh57", + "modified": "2025-02-14T21:31:05Z", + "published": "2025-02-14T21:31:05Z", + "aliases": [ + "CVE-2025-0593" + ], + "details": "The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0593" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0002.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0002.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-14T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4xph-hcw4-77x7/GHSA-4xph-hcw4-77x7.json b/advisories/unreviewed/2025/02/GHSA-4xph-hcw4-77x7/GHSA-4xph-hcw4-77x7.json index 7ef38f93f5f..18969e24bd0 100644 --- a/advisories/unreviewed/2025/02/GHSA-4xph-hcw4-77x7/GHSA-4xph-hcw4-77x7.json +++ b/advisories/unreviewed/2025/02/GHSA-4xph-hcw4-77x7/GHSA-4xph-hcw4-77x7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4xph-hcw4-77x7", - "modified": "2025-02-14T18:30:51Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-14T18:30:51Z", "aliases": [ "CVE-2024-57778" ], "details": "An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T16:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json b/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json index 10d19ac8641..520ccd967d5 100644 --- a/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json +++ b/advisories/unreviewed/2025/02/GHSA-6vpc-jmr8-rh6f/GHSA-6vpc-jmr8-rh6f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6vpc-jmr8-rh6f", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-14T21:31:03Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2024-57241" ], "details": "Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T22:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json b/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json index aba462373a7..07b4ddb3555 100644 --- a/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json +++ b/advisories/unreviewed/2025/02/GHSA-739j-9mp5-mmf8/GHSA-739j-9mp5-mmf8.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-739j-9mp5-mmf8", - "modified": "2025-02-13T00:33:07Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-13T00:33:07Z", "aliases": [ "CVE-2024-56939" ], "details": "LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56939" }, + { + "type": "WEB", + "url": "https://github.com/nikolas-ch/CVEs/blob/main/LearnDash_v6.7.1/CVE-2024-56939/StoredXSS_LDCommentBody_LearnDash_v6.7.1.PNG" + }, { "type": "WEB", "url": "https://github.com/nikolas-ch/CVEs/tree/main/LearnDash_v6.7.1" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-12T22:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-73xc-hhcm-f4v8/GHSA-73xc-hhcm-f4v8.json b/advisories/unreviewed/2025/02/GHSA-73xc-hhcm-f4v8/GHSA-73xc-hhcm-f4v8.json index f1f1ca6ed80..5adc674f991 100644 --- a/advisories/unreviewed/2025/02/GHSA-73xc-hhcm-f4v8/GHSA-73xc-hhcm-f4v8.json +++ b/advisories/unreviewed/2025/02/GHSA-73xc-hhcm-f4v8/GHSA-73xc-hhcm-f4v8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-73xc-hhcm-f4v8", - "modified": "2025-02-13T18:32:34Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-13T18:32:34Z", "aliases": [ "CVE-2025-25354" ], "details": "A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T16:16:49Z" diff --git a/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json b/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json index e01d305ecc6..797e3a921c5 100644 --- a/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json +++ b/advisories/unreviewed/2025/02/GHSA-74p9-4v44-wwx5/GHSA-74p9-4v44-wwx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-74p9-4v44-wwx5", - "modified": "2025-02-14T18:30:51Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-14T18:30:51Z", "aliases": [ "CVE-2024-3220" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/CDXW34ND2LSAOYAR5N6UNONP4ZBX4D6R" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/14/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-7fx8-mhcf-6p64/GHSA-7fx8-mhcf-6p64.json b/advisories/unreviewed/2025/02/GHSA-7fx8-mhcf-6p64/GHSA-7fx8-mhcf-6p64.json index e0aa50d868f..d36b5510282 100644 --- a/advisories/unreviewed/2025/02/GHSA-7fx8-mhcf-6p64/GHSA-7fx8-mhcf-6p64.json +++ b/advisories/unreviewed/2025/02/GHSA-7fx8-mhcf-6p64/GHSA-7fx8-mhcf-6p64.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7fx8-mhcf-6p64", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25988" ], "details": "Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7p8p-8grh-gvmj/GHSA-7p8p-8grh-gvmj.json b/advisories/unreviewed/2025/02/GHSA-7p8p-8grh-gvmj/GHSA-7p8p-8grh-gvmj.json index f610961d6f9..c3650cc32ae 100644 --- a/advisories/unreviewed/2025/02/GHSA-7p8p-8grh-gvmj/GHSA-7p8p-8grh-gvmj.json +++ b/advisories/unreviewed/2025/02/GHSA-7p8p-8grh-gvmj/GHSA-7p8p-8grh-gvmj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7p8p-8grh-gvmj", - "modified": "2025-02-13T18:32:34Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-13T18:32:34Z", "aliases": [ "CVE-2025-25352" ], "details": "A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T16:16:49Z" diff --git a/advisories/unreviewed/2025/02/GHSA-8qxw-vh64-m92m/GHSA-8qxw-vh64-m92m.json b/advisories/unreviewed/2025/02/GHSA-8qxw-vh64-m92m/GHSA-8qxw-vh64-m92m.json index c3ea1c6ea2c..2ce92c8ae1f 100644 --- a/advisories/unreviewed/2025/02/GHSA-8qxw-vh64-m92m/GHSA-8qxw-vh64-m92m.json +++ b/advisories/unreviewed/2025/02/GHSA-8qxw-vh64-m92m/GHSA-8qxw-vh64-m92m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8qxw-vh64-m92m", - "modified": "2025-02-14T18:30:51Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-14T18:30:51Z", "aliases": [ "CVE-2024-57725" ], "details": "An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T16:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-8r7c-379q-fg6q/GHSA-8r7c-379q-fg6q.json b/advisories/unreviewed/2025/02/GHSA-8r7c-379q-fg6q/GHSA-8r7c-379q-fg6q.json index 55aef62986a..535213f4ccc 100644 --- a/advisories/unreviewed/2025/02/GHSA-8r7c-379q-fg6q/GHSA-8r7c-379q-fg6q.json +++ b/advisories/unreviewed/2025/02/GHSA-8r7c-379q-fg6q/GHSA-8r7c-379q-fg6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8r7c-379q-fg6q", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25993" ], "details": "SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter \"itemid.\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-97m5-x73g-j7xj/GHSA-97m5-x73g-j7xj.json b/advisories/unreviewed/2025/02/GHSA-97m5-x73g-j7xj/GHSA-97m5-x73g-j7xj.json new file mode 100644 index 00000000000..6df503c9238 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-97m5-x73g-j7xj/GHSA-97m5-x73g-j7xj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97m5-x73g-j7xj", + "modified": "2025-02-14T21:31:05Z", + "published": "2025-02-14T21:31:05Z", + "aliases": [ + "CVE-2022-26083" + ], + "details": "Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26083" + }, + { + "type": "WEB", + "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00667.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1204" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-14T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json b/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json new file mode 100644 index 00000000000..4bd77cf09ad --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fg38-pgj3-5w5f/GHSA-fg38-pgj3-5w5f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg38-pgj3-5w5f", + "modified": "2025-02-14T21:31:05Z", + "published": "2025-02-14T21:31:05Z", + "aliases": [ + "CVE-2024-31144" + ], + "details": "For a brief summary of Xapi terminology, see:\n\n https://xapi-project.github.io/xen-api/overview.html#object-model-overview \n\nXapi contains functionality to backup and restore metadata about Virtual\nMachines and Storage Repositories (SRs).\n\nThe metadata itself is stored in a Virtual Disk Image (VDI) inside an\nSR. This is used for two purposes; a general backup of metadata\n(e.g. to recover from a host failure if the filer is still good), and\nPortable SRs (e.g. using an external hard drive to move VMs to another\nhost).\n\nMetadata is only restored as an explicit administrator action, but\noccurs in cases where the host has no information about the SR, and must\nlocate the metadata VDI in order to retrieve the metadata.\n\nThe metadata VDI is located by searching (in UUID alphanumeric order)\neach VDI, mounting it, and seeing if there is a suitable metadata file\npresent. The first matching VDI is deemed to be the metadata VDI, and\nis restored from.\n\nIn the general case, the content of VDIs are controlled by the VM owner,\nand should not be trusted by the host administrator.\n\nA malicious guest can manipulate its disk to appear to be a metadata\nbackup.\n\nA guest cannot choose the UUIDs of its VDIs, but a guest with one disk\nhas a 50% chance of sorting ahead of the legitimate metadata backup. A\nguest with two disks has a 75% chance, etc.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31144" + }, + { + "type": "WEB", + "url": "https://xenbits.xen.org/xsa/advisory-459.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/16/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-14T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fpr6-384r-x95m/GHSA-fpr6-384r-x95m.json b/advisories/unreviewed/2025/02/GHSA-fpr6-384r-x95m/GHSA-fpr6-384r-x95m.json index 99eccf68f11..fd387c4fa5e 100644 --- a/advisories/unreviewed/2025/02/GHSA-fpr6-384r-x95m/GHSA-fpr6-384r-x95m.json +++ b/advisories/unreviewed/2025/02/GHSA-fpr6-384r-x95m/GHSA-fpr6-384r-x95m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpr6-384r-x95m", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25997" ], "details": "Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:22Z" diff --git a/advisories/unreviewed/2025/02/GHSA-h3cq-pv9v-4qxp/GHSA-h3cq-pv9v-4qxp.json b/advisories/unreviewed/2025/02/GHSA-h3cq-pv9v-4qxp/GHSA-h3cq-pv9v-4qxp.json index fb57b1ab98f..94a0f408906 100644 --- a/advisories/unreviewed/2025/02/GHSA-h3cq-pv9v-4qxp/GHSA-h3cq-pv9v-4qxp.json +++ b/advisories/unreviewed/2025/02/GHSA-h3cq-pv9v-4qxp/GHSA-h3cq-pv9v-4qxp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3cq-pv9v-4qxp", - "modified": "2025-02-13T18:32:34Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-13T18:32:34Z", "aliases": [ "CVE-2025-25356" ], "details": "A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the \" todate\" POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T16:16:49Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m26p-8j2h-c3gc/GHSA-m26p-8j2h-c3gc.json b/advisories/unreviewed/2025/02/GHSA-m26p-8j2h-c3gc/GHSA-m26p-8j2h-c3gc.json index 1625584da8f..4ac25b40f6a 100644 --- a/advisories/unreviewed/2025/02/GHSA-m26p-8j2h-c3gc/GHSA-m26p-8j2h-c3gc.json +++ b/advisories/unreviewed/2025/02/GHSA-m26p-8j2h-c3gc/GHSA-m26p-8j2h-c3gc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m26p-8j2h-c3gc", - "modified": "2025-02-14T18:30:53Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:53Z", "aliases": [ "CVE-2025-26156" ], "details": "A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:22Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m44q-qr9w-w24c/GHSA-m44q-qr9w-w24c.json b/advisories/unreviewed/2025/02/GHSA-m44q-qr9w-w24c/GHSA-m44q-qr9w-w24c.json index 2b84af41af5..16aee12896b 100644 --- a/advisories/unreviewed/2025/02/GHSA-m44q-qr9w-w24c/GHSA-m44q-qr9w-w24c.json +++ b/advisories/unreviewed/2025/02/GHSA-m44q-qr9w-w24c/GHSA-m44q-qr9w-w24c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m44q-qr9w-w24c", - "modified": "2025-02-14T18:30:53Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:53Z", "aliases": [ "CVE-2025-26157" ], "details": "A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:22Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json b/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json index 451929bf7e9..b090220a79c 100644 --- a/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json +++ b/advisories/unreviewed/2025/02/GHSA-qv4j-f75x-4v5x/GHSA-qv4j-f75x-4v5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qv4j-f75x-4v5x", - "modified": "2025-02-12T18:31:35Z", + "modified": "2025-02-14T21:31:03Z", "published": "2025-02-12T18:31:35Z", "aliases": [ "CVE-2025-25349" ], "details": "PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-12T16:15:46Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qx7g-8cqg-c43v/GHSA-qx7g-8cqg-c43v.json b/advisories/unreviewed/2025/02/GHSA-qx7g-8cqg-c43v/GHSA-qx7g-8cqg-c43v.json new file mode 100644 index 00000000000..536339b9468 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qx7g-8cqg-c43v/GHSA-qx7g-8cqg-c43v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx7g-8cqg-c43v", + "modified": "2025-02-14T21:31:05Z", + "published": "2025-02-14T21:31:05Z", + "aliases": [ + "CVE-2025-0592" + ], + "details": "The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0592" + }, + { + "type": "WEB", + "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF" + }, + { + "type": "WEB", + "url": "https://sick.com/psirt" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" + }, + { + "type": "WEB", + "url": "https://www.first.org/cvss/calculator/3.1" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0002.json" + }, + { + "type": "WEB", + "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0002.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-924" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-14T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json b/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json index d4c07aabcd8..e13fa40ef7f 100644 --- a/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json +++ b/advisories/unreviewed/2025/02/GHSA-r5jh-73fq-2vv9/GHSA-r5jh-73fq-2vv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5jh-73fq-2vv9", - "modified": "2025-02-12T00:32:16Z", + "modified": "2025-02-14T21:31:03Z", "published": "2025-02-12T00:32:16Z", "aliases": [ "CVE-2024-57777" ], "details": "Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T22:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-r6q8-2gx7-h3pq/GHSA-r6q8-2gx7-h3pq.json b/advisories/unreviewed/2025/02/GHSA-r6q8-2gx7-h3pq/GHSA-r6q8-2gx7-h3pq.json index d6401537d53..8acfcd45d95 100644 --- a/advisories/unreviewed/2025/02/GHSA-r6q8-2gx7-h3pq/GHSA-r6q8-2gx7-h3pq.json +++ b/advisories/unreviewed/2025/02/GHSA-r6q8-2gx7-h3pq/GHSA-r6q8-2gx7-h3pq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r6q8-2gx7-h3pq", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25991" ], "details": "SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json b/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json index 666d6948231..445007c7160 100644 --- a/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json +++ b/advisories/unreviewed/2025/02/GHSA-rmph-h336-23fp/GHSA-rmph-h336-23fp.json @@ -1,27 +1,38 @@ { "schema_version": "1.4.0", "id": "GHSA-rmph-h336-23fp", - "modified": "2025-02-13T00:33:07Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-13T00:33:07Z", "aliases": [ "CVE-2024-56938" ], "details": "LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56938" }, + { + "type": "WEB", + "url": "https://github.com/nikolas-ch/CVEs/blob/main/LearnDash_v6.7.1/CVE-2024-56938/StoredXSS_MaterialsContent_LearnDash_v6.7.1.PNG" + }, { "type": "WEB", "url": "https://github.com/nikolas-ch/CVEs/tree/main/LearnDash_v6.7.1" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-12T22:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vjxw-jj99-5xw3/GHSA-vjxw-jj99-5xw3.json b/advisories/unreviewed/2025/02/GHSA-vjxw-jj99-5xw3/GHSA-vjxw-jj99-5xw3.json index 5fc9410fb2d..3d84ab6e866 100644 --- a/advisories/unreviewed/2025/02/GHSA-vjxw-jj99-5xw3/GHSA-vjxw-jj99-5xw3.json +++ b/advisories/unreviewed/2025/02/GHSA-vjxw-jj99-5xw3/GHSA-vjxw-jj99-5xw3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vjxw-jj99-5xw3", - "modified": "2025-02-14T00:30:44Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-14T00:30:44Z", "aliases": [ "CVE-2024-37601" ], "details": "An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-x37v-6gqg-j8gj/GHSA-x37v-6gqg-j8gj.json b/advisories/unreviewed/2025/02/GHSA-x37v-6gqg-j8gj/GHSA-x37v-6gqg-j8gj.json index 3f6620b50bb..d7de85d9aab 100644 --- a/advisories/unreviewed/2025/02/GHSA-x37v-6gqg-j8gj/GHSA-x37v-6gqg-j8gj.json +++ b/advisories/unreviewed/2025/02/GHSA-x37v-6gqg-j8gj/GHSA-x37v-6gqg-j8gj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x37v-6gqg-j8gj", - "modified": "2025-02-14T18:30:52Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:52Z", "aliases": [ "CVE-2025-25990" ], "details": "Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-x5h7-6c5j-qhg6/GHSA-x5h7-6c5j-qhg6.json b/advisories/unreviewed/2025/02/GHSA-x5h7-6c5j-qhg6/GHSA-x5h7-6c5j-qhg6.json index 293a9858bd3..53d0ef31534 100644 --- a/advisories/unreviewed/2025/02/GHSA-x5h7-6c5j-qhg6/GHSA-x5h7-6c5j-qhg6.json +++ b/advisories/unreviewed/2025/02/GHSA-x5h7-6c5j-qhg6/GHSA-x5h7-6c5j-qhg6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5h7-6c5j-qhg6", - "modified": "2025-02-13T18:32:34Z", + "modified": "2025-02-14T21:31:04Z", "published": "2025-02-13T18:32:34Z", "aliases": [ "CVE-2025-25355" ], "details": "A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T16:16:49Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xgr2-6f6r-9xqp/GHSA-xgr2-6f6r-9xqp.json b/advisories/unreviewed/2025/02/GHSA-xgr2-6f6r-9xqp/GHSA-xgr2-6f6r-9xqp.json index 5b65b91cbcf..c1a978adf17 100644 --- a/advisories/unreviewed/2025/02/GHSA-xgr2-6f6r-9xqp/GHSA-xgr2-6f6r-9xqp.json +++ b/advisories/unreviewed/2025/02/GHSA-xgr2-6f6r-9xqp/GHSA-xgr2-6f6r-9xqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xgr2-6f6r-9xqp", - "modified": "2025-02-14T18:30:53Z", + "modified": "2025-02-14T21:31:05Z", "published": "2025-02-14T18:30:53Z", "aliases": [ "CVE-2025-26158" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-14T17:15:22Z"