diff --git a/advisories/unreviewed/2025/01/GHSA-23f6-j7x4-jrjh/GHSA-23f6-j7x4-jrjh.json b/advisories/unreviewed/2025/01/GHSA-23f6-j7x4-jrjh/GHSA-23f6-j7x4-jrjh.json new file mode 100644 index 00000000000..dadae5b35ae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-23f6-j7x4-jrjh/GHSA-23f6-j7x4-jrjh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23f6-j7x4-jrjh", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:10Z", + "aliases": [ + "CVE-2024-50694" + ], + "details": "In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50694" + }, + { + "type": "WEB", + "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2j93-2wmq-74fv/GHSA-2j93-2wmq-74fv.json b/advisories/unreviewed/2025/01/GHSA-2j93-2wmq-74fv/GHSA-2j93-2wmq-74fv.json new file mode 100644 index 00000000000..aa34cb1018c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2j93-2wmq-74fv/GHSA-2j93-2wmq-74fv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j93-2wmq-74fv", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:09Z", + "aliases": [ + "CVE-2024-50690" + ], + "details": "SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50690" + }, + { + "type": "WEB", + "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5h9h-53mh-jpcv/GHSA-5h9h-53mh-jpcv.json b/advisories/unreviewed/2025/01/GHSA-5h9h-53mh-jpcv/GHSA-5h9h-53mh-jpcv.json new file mode 100644 index 00000000000..3ec889db610 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5h9h-53mh-jpcv/GHSA-5h9h-53mh-jpcv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h9h-53mh-jpcv", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:10Z", + "aliases": [ + "CVE-2025-21262" + ], + "details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21262" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21262" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-451" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T22:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7g57-82xx-wrwm/GHSA-7g57-82xx-wrwm.json b/advisories/unreviewed/2025/01/GHSA-7g57-82xx-wrwm/GHSA-7g57-82xx-wrwm.json index 30db3f90bda..bcdba673627 100644 --- a/advisories/unreviewed/2025/01/GHSA-7g57-82xx-wrwm/GHSA-7g57-82xx-wrwm.json +++ b/advisories/unreviewed/2025/01/GHSA-7g57-82xx-wrwm/GHSA-7g57-82xx-wrwm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g57-82xx-wrwm", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-25T00:33:09Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-53588" ], "details": "A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \\ProgramData\\iTop VPN\\Downloader\\vpn6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8c2r-6439-8493/GHSA-8c2r-6439-8493.json b/advisories/unreviewed/2025/01/GHSA-8c2r-6439-8493/GHSA-8c2r-6439-8493.json index 47096966ca7..89339679ce1 100644 --- a/advisories/unreviewed/2025/01/GHSA-8c2r-6439-8493/GHSA-8c2r-6439-8493.json +++ b/advisories/unreviewed/2025/01/GHSA-8c2r-6439-8493/GHSA-8c2r-6439-8493.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8c2r-6439-8493", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-25T00:33:09Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-55193" ], "details": "OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8x2p-6xj8-59hx/GHSA-8x2p-6xj8-59hx.json b/advisories/unreviewed/2025/01/GHSA-8x2p-6xj8-59hx/GHSA-8x2p-6xj8-59hx.json index 76347f8b110..31e49298583 100644 --- a/advisories/unreviewed/2025/01/GHSA-8x2p-6xj8-59hx/GHSA-8x2p-6xj8-59hx.json +++ b/advisories/unreviewed/2025/01/GHSA-8x2p-6xj8-59hx/GHSA-8x2p-6xj8-59hx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8x2p-6xj8-59hx", - "modified": "2025-01-24T00:31:47Z", + "modified": "2025-01-25T00:33:09Z", "published": "2025-01-24T00:31:47Z", "aliases": [ "CVE-2024-57386" ], "details": "Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json b/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json new file mode 100644 index 00000000000..8724d3c74f8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gxmw-34m7-64r8/GHSA-gxmw-34m7-64r8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxmw-34m7-64r8", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:10Z", + "aliases": [ + "CVE-2024-50692" + ], + "details": "SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are vulnerable to MitM attacks at the TCP/IP level.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50692" + }, + { + "type": "WEB", + "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jg2r-v58r-q7vh/GHSA-jg2r-v58r-q7vh.json b/advisories/unreviewed/2025/01/GHSA-jg2r-v58r-q7vh/GHSA-jg2r-v58r-q7vh.json new file mode 100644 index 00000000000..78f1190880c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jg2r-v58r-q7vh/GHSA-jg2r-v58r-q7vh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg2r-v58r-q7vh", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:10Z", + "aliases": [ + "CVE-2024-50695" + ], + "details": "SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT messages, due to missing MQTT topic bounds checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50695" + }, + { + "type": "WEB", + "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q97f-8w55-q948/GHSA-q97f-8w55-q948.json b/advisories/unreviewed/2025/01/GHSA-q97f-8w55-q948/GHSA-q97f-8w55-q948.json index 9c244d22171..fa92030b89d 100644 --- a/advisories/unreviewed/2025/01/GHSA-q97f-8w55-q948/GHSA-q97f-8w55-q948.json +++ b/advisories/unreviewed/2025/01/GHSA-q97f-8w55-q948/GHSA-q97f-8w55-q948.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q97f-8w55-q948", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-25T00:33:09Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-57326" ], "details": "A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qcjj-7w9p-r3m9/GHSA-qcjj-7w9p-r3m9.json b/advisories/unreviewed/2025/01/GHSA-qcjj-7w9p-r3m9/GHSA-qcjj-7w9p-r3m9.json index 0bc1334c442..146bc937979 100644 --- a/advisories/unreviewed/2025/01/GHSA-qcjj-7w9p-r3m9/GHSA-qcjj-7w9p-r3m9.json +++ b/advisories/unreviewed/2025/01/GHSA-qcjj-7w9p-r3m9/GHSA-qcjj-7w9p-r3m9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qcjj-7w9p-r3m9", - "modified": "2025-01-24T00:31:47Z", + "modified": "2025-01-25T00:33:09Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-57329" ], "details": "HortusFox v3.9 contains a stored XSS vulnerability in the \"Add Plant\" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rj8h-6rc9-g7qx/GHSA-rj8h-6rc9-g7qx.json b/advisories/unreviewed/2025/01/GHSA-rj8h-6rc9-g7qx/GHSA-rj8h-6rc9-g7qx.json new file mode 100644 index 00000000000..454b21d2d93 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rj8h-6rc9-g7qx/GHSA-rj8h-6rc9-g7qx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj8h-6rc9-g7qx", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:10Z", + "aliases": [ + "CVE-2024-50698" + ], + "details": "SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message content.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50698" + }, + { + "type": "WEB", + "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vg55-9467-jpw8/GHSA-vg55-9467-jpw8.json b/advisories/unreviewed/2025/01/GHSA-vg55-9467-jpw8/GHSA-vg55-9467-jpw8.json new file mode 100644 index 00000000000..edf3701587e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vg55-9467-jpw8/GHSA-vg55-9467-jpw8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg55-9467-jpw8", + "modified": "2025-01-25T00:33:10Z", + "published": "2025-01-25T00:33:10Z", + "aliases": [ + "CVE-2024-50697" + ], + "details": "In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50697" + }, + { + "type": "WEB", + "url": "https://en.sungrowpower.com/security-notice-detail-2/5961" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x4pr-pf8x-7x89/GHSA-x4pr-pf8x-7x89.json b/advisories/unreviewed/2025/01/GHSA-x4pr-pf8x-7x89/GHSA-x4pr-pf8x-7x89.json index 32b858f16b1..c45945a0fbd 100644 --- a/advisories/unreviewed/2025/01/GHSA-x4pr-pf8x-7x89/GHSA-x4pr-pf8x-7x89.json +++ b/advisories/unreviewed/2025/01/GHSA-x4pr-pf8x-7x89/GHSA-x4pr-pf8x-7x89.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x4pr-pf8x-7x89", - "modified": "2025-01-24T00:31:47Z", + "modified": "2025-01-25T00:33:09Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-57328" ], "details": "A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:14Z"