diff --git a/advisories/unreviewed/2022/05/GHSA-p2w9-g2w7-8fw9/GHSA-p2w9-g2w7-8fw9.json b/advisories/unreviewed/2022/05/GHSA-p2w9-g2w7-8fw9/GHSA-p2w9-g2w7-8fw9.json index a1db1553ec2..169d2b4fa0a 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2w9-g2w7-8fw9/GHSA-p2w9-g2w7-8fw9.json +++ b/advisories/unreviewed/2022/05/GHSA-p2w9-g2w7-8fw9/GHSA-p2w9-g2w7-8fw9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p2w9-g2w7-8fw9", - "modified": "2022-08-16T00:00:42Z", + "modified": "2025-02-28T15:30:55Z", "published": "2022-05-24T19:03:15Z", "aliases": [ "CVE-2021-3549" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202208-30" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/08/GHSA-ch7h-w2mm-gm7m/GHSA-ch7h-w2mm-gm7m.json b/advisories/unreviewed/2022/08/GHSA-ch7h-w2mm-gm7m/GHSA-ch7h-w2mm-gm7m.json index 39099fbef7c..c3b5dcd209d 100644 --- a/advisories/unreviewed/2022/08/GHSA-ch7h-w2mm-gm7m/GHSA-ch7h-w2mm-gm7m.json +++ b/advisories/unreviewed/2022/08/GHSA-ch7h-w2mm-gm7m/GHSA-ch7h-w2mm-gm7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ch7h-w2mm-gm7m", - "modified": "2022-09-02T00:01:10Z", + "modified": "2025-02-28T15:30:57Z", "published": "2022-08-27T00:00:45Z", "aliases": [ "CVE-2021-3735" @@ -30,11 +30,16 @@ { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2021-3735" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0009" } ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-667" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json b/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json index a443c3805cf..310f60d3bbc 100644 --- a/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json +++ b/advisories/unreviewed/2022/08/GHSA-h66w-323g-4q62/GHSA-h66w-323g-4q62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h66w-323g-4q62", - "modified": "2022-09-01T00:00:21Z", + "modified": "2025-02-28T15:30:57Z", "published": "2022-08-26T00:03:29Z", "aliases": [ "CVE-2021-3929" @@ -39,9 +39,17 @@ "type": "WEB", "url": "https://gitlab.com/qemu-project/qemu/-/issues/782" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XHNN7QJCEQH7AQG5AQP2GEFAQE6K635I" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json b/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json index 51e85bf97e1..3135d624c1d 100644 --- a/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json +++ b/advisories/unreviewed/2023/06/GHSA-pcw9-xw4x-jgj3/GHSA-pcw9-xw4x-jgj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcw9-xw4x-jgj3", - "modified": "2024-04-04T05:08:38Z", + "modified": "2025-02-28T15:30:58Z", "published": "2023-06-23T21:30:33Z", "aliases": [ "CVE-2023-34188" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://github.com/cesanta/mongoose/compare/7.9...7.10" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json b/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json index 0382b340c04..0a66a78adf0 100644 --- a/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json +++ b/advisories/unreviewed/2024/05/GHSA-x8qh-8j65-v4j9/GHSA-x8qh-8j65-v4j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8qh-8j65-v4j9", - "modified": "2025-02-11T00:31:36Z", + "modified": "2025-02-28T15:30:59Z", "published": "2024-05-14T15:32:52Z", "aliases": [ "CVE-2024-26306" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/esnet/iperf/releases/tag/3.17" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0007" + }, { "type": "WEB", "url": "https://www.insyde.com/security-pledge/SA-2024005" diff --git a/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json b/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json index 9dabadfafa1..50c91c980b5 100644 --- a/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json +++ b/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6c2p-rqx3-w4px", - "modified": "2024-12-24T03:30:46Z", + "modified": "2025-02-28T15:30:59Z", "published": "2024-12-23T18:30:47Z", "aliases": [ "CVE-2024-40896" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/761" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json index ec9ea6d0a9b..660416ed718 100644 --- a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json +++ b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xpw-6594-8f5m", - "modified": "2025-02-04T21:32:26Z", + "modified": "2025-02-28T15:30:59Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2025-0395" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0395" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0006" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32582" diff --git a/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json b/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json index 2f045ad2321..eb2c12c5562 100644 --- a/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json +++ b/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv7p-rjf3-9fr5", - "modified": "2025-01-22T03:30:43Z", + "modified": "2025-02-28T15:30:59Z", "published": "2025-01-22T03:30:43Z", "aliases": [ "CVE-2025-23083" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/january-2025-security-releases" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250228-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json b/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json index 8ce29843633..f64b466f685 100644 --- a/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json +++ b/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-22qr-hr3v-pmr2", - "modified": "2025-02-27T21:32:18Z", + "modified": "2025-02-28T15:31:02Z", "published": "2025-02-27T21:32:18Z", "aliases": [ "CVE-2024-41338" ], "details": "A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to cause a Denial of Service (DoS) via a crafted DHCP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T21:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json b/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json new file mode 100644 index 00000000000..7e1e0b86691 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-46vg-h2w6-gh78/GHSA-46vg-h2w6-gh78.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46vg-h2w6-gh78", + "modified": "2025-02-28T15:31:04Z", + "published": "2025-02-28T15:31:04Z", + "aliases": [ + "CVE-2025-26326" + ], + "details": "A vulnerability in the remote connection complements of the NVDA (Nonvisual Desktop Access) 2024.4.1 and 2024.4.2 was identified, which allows an attacker to obtain total control of the remote system when guessing a weak password. The problem occurs because the complements accept any password typed by the user and do not have an additional authentication or checking mechanism by the computer that will be accessed. Tests indicate that over 1,000 systems use easy to guess passwords, many with less than 4 to 6 characters, including common sequences. This enables brute strength or attempt and error attacks on the part of malicious invaders. Vulnerability can be explored by a remote striker who knows or can guess the password used in the connection. As a result, the invader gets complete access to the affected system and can run commands, modify files and compromise user security.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26326" + }, + { + "type": "WEB", + "url": "https://github.com/azurejoga/CVE-2025-26326" + }, + { + "type": "WEB", + "url": "https://www.nvaccess.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-52xm-jh2q-v993/GHSA-52xm-jh2q-v993.json b/advisories/unreviewed/2025/02/GHSA-52xm-jh2q-v993/GHSA-52xm-jh2q-v993.json new file mode 100644 index 00000000000..07a90372cfd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-52xm-jh2q-v993/GHSA-52xm-jh2q-v993.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52xm-jh2q-v993", + "modified": "2025-02-28T15:31:03Z", + "published": "2025-02-28T15:31:03Z", + "aliases": [ + "CVE-2025-1746" + ], + "details": "Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1746" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cj5h-7hq4-3q37/GHSA-cj5h-7hq4-3q37.json b/advisories/unreviewed/2025/02/GHSA-cj5h-7hq4-3q37/GHSA-cj5h-7hq4-3q37.json new file mode 100644 index 00000000000..9a64fda0f18 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cj5h-7hq4-3q37/GHSA-cj5h-7hq4-3q37.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj5h-7hq4-3q37", + "modified": "2025-02-28T15:31:02Z", + "published": "2025-02-28T15:31:02Z", + "aliases": [ + "CVE-2025-22271" + ], + "details": "The application or its infrastructure allows for IP address spoofing by providing its own value in the \"X-Forwarded-For\" header. Thus, the action logging mechanism in the application loses accountability\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22271" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hqj8-x5h3-q5rg/GHSA-hqj8-x5h3-q5rg.json b/advisories/unreviewed/2025/02/GHSA-hqj8-x5h3-q5rg/GHSA-hqj8-x5h3-q5rg.json new file mode 100644 index 00000000000..8f79741fc82 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hqj8-x5h3-q5rg/GHSA-hqj8-x5h3-q5rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqj8-x5h3-q5rg", + "modified": "2025-02-28T15:31:04Z", + "published": "2025-02-28T15:31:04Z", + "aliases": [ + "CVE-2025-1749" + ], + "details": "HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1749" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j2fg-56xp-h6wh/GHSA-j2fg-56xp-h6wh.json b/advisories/unreviewed/2025/02/GHSA-j2fg-56xp-h6wh/GHSA-j2fg-56xp-h6wh.json new file mode 100644 index 00000000000..716f08497b8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j2fg-56xp-h6wh/GHSA-j2fg-56xp-h6wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2fg-56xp-h6wh", + "modified": "2025-02-28T15:31:04Z", + "published": "2025-02-28T15:31:04Z", + "aliases": [ + "CVE-2025-1776" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in /app-google-custom-search/searchResults. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1776" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-vulnerability-soteshop" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mg9h-3wx4-hhfr/GHSA-mg9h-3wx4-hhfr.json b/advisories/unreviewed/2025/02/GHSA-mg9h-3wx4-hhfr/GHSA-mg9h-3wx4-hhfr.json new file mode 100644 index 00000000000..5a60c7c782f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mg9h-3wx4-hhfr/GHSA-mg9h-3wx4-hhfr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg9h-3wx4-hhfr", + "modified": "2025-02-28T15:31:03Z", + "published": "2025-02-28T15:31:03Z", + "aliases": [ + "CVE-2025-1747" + ], + "details": "HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1747" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pcp6-pxxr-g2vh/GHSA-pcp6-pxxr-g2vh.json b/advisories/unreviewed/2025/02/GHSA-pcp6-pxxr-g2vh/GHSA-pcp6-pxxr-g2vh.json new file mode 100644 index 00000000000..ad1f8a8aec0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pcp6-pxxr-g2vh/GHSA-pcp6-pxxr-g2vh.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcp6-pxxr-g2vh", + "modified": "2025-02-28T15:31:03Z", + "published": "2025-02-28T15:31:02Z", + "aliases": [ + "CVE-2025-22273" + ], + "details": "Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the \"/EPMUI/VfManager.asmx/ChangePassword\" endpoint it is possible to perform a brute force attack on the current password in use.\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22273" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pm77-vj97-hfv8/GHSA-pm77-vj97-hfv8.json b/advisories/unreviewed/2025/02/GHSA-pm77-vj97-hfv8/GHSA-pm77-vj97-hfv8.json new file mode 100644 index 00000000000..2097d54868c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pm77-vj97-hfv8/GHSA-pm77-vj97-hfv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm77-vj97-hfv8", + "modified": "2025-02-28T15:31:03Z", + "published": "2025-02-28T15:31:03Z", + "aliases": [ + "CVE-2025-1748" + ], + "details": "HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1748" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-opencart" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json b/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json new file mode 100644 index 00000000000..38668df0bfd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pqmh-jm9r-hq9j/GHSA-pqmh-jm9r-hq9j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqmh-jm9r-hq9j", + "modified": "2025-02-28T15:31:04Z", + "published": "2025-02-28T15:31:04Z", + "aliases": [ + "CVE-2025-25916" + ], + "details": "wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \\coreframe\\app\\member\\admin\\group.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25916" + }, + { + "type": "WEB", + "url": "https://github.com/wuzhicms/wuzhicms/issues/213" + }, + { + "type": "WEB", + "url": "https://gist.github.com/A7cc/e28b5790d8b40df8d418d1bd15c25d12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json b/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json index 6e14aec6d93..7207489d382 100644 --- a/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json +++ b/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prh5-fm3v-6477", - "modified": "2025-02-27T21:32:16Z", + "modified": "2025-02-28T15:31:01Z", "published": "2025-02-27T21:32:16Z", "aliases": [ "CVE-2024-53408" ], "details": "AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T20:16:01Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pw23-jv8r-492x/GHSA-pw23-jv8r-492x.json b/advisories/unreviewed/2025/02/GHSA-pw23-jv8r-492x/GHSA-pw23-jv8r-492x.json new file mode 100644 index 00000000000..c68cdb50c80 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pw23-jv8r-492x/GHSA-pw23-jv8r-492x.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw23-jv8r-492x", + "modified": "2025-02-28T15:31:03Z", + "published": "2025-02-28T15:31:03Z", + "aliases": [ + "CVE-2025-22272" + ], + "details": "In the \"/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg\" endpoint, it is possible to inject code in the \"modalDlgMsgInternal\" parameter via POST, which is then executed in the browser. The risk of exploiting vulnerability is reduced due to the required additional bypassing the Content-Security-Policy policy\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22272" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json b/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json new file mode 100644 index 00000000000..0de88177179 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwgw-jf68-fjmq", + "modified": "2025-02-28T15:31:02Z", + "published": "2025-02-28T15:31:02Z", + "aliases": [ + "CVE-2025-1319" + ], + "details": "The Site Mailer – SMTP Replacement, Email API Deliverability & Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1319" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3247059" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/site-mailer/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c9fe3574-f338-474c-af78-f843501d422c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rp64-rc76-xrq5/GHSA-rp64-rc76-xrq5.json b/advisories/unreviewed/2025/02/GHSA-rp64-rc76-xrq5/GHSA-rp64-rc76-xrq5.json new file mode 100644 index 00000000000..df15d03080b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rp64-rc76-xrq5/GHSA-rp64-rc76-xrq5.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp64-rc76-xrq5", + "modified": "2025-02-28T15:31:03Z", + "published": "2025-02-28T15:31:03Z", + "aliases": [ + "CVE-2025-22274" + ], + "details": "It is possible to inject HTML code into the page content using the \"content\" field in the \"Application definition\" page.\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22274" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wc94-qmw7-2jp8/GHSA-wc94-qmw7-2jp8.json b/advisories/unreviewed/2025/02/GHSA-wc94-qmw7-2jp8/GHSA-wc94-qmw7-2jp8.json new file mode 100644 index 00000000000..2afe228ed78 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wc94-qmw7-2jp8/GHSA-wc94-qmw7-2jp8.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc94-qmw7-2jp8", + "modified": "2025-02-28T15:31:02Z", + "published": "2025-02-28T15:31:02Z", + "aliases": [ + "CVE-2025-22270" + ], + "details": "An attacker with access to the Administration panel, specifically the \"Role Management\"\ntab, can\ninject code by adding a new role in the \"name\" field. It should be noted, however, that the risk of exploiting vulnerability is reduced due to the\nrequired additional error that allows bypassing the Content-Security-Policy policy, which\nmitigates JS code execution while still allowing HTML injection.\n\n\nThis issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/02/CVE-2025-22270" + }, + { + "type": "WEB", + "url": "https://docs.cyberark.com/epm/24.7.1/en/content/resources/_topnav/cc_home.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-28T13:15:27Z" + } +} \ No newline at end of file