From f63e94108ad40bd8b1b9dfc9fc46eef4cff44ff1 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Thu, 27 Feb 2025 15:33:32 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-4fwr-mh5q-hchh.json | 6 ++-
.../GHSA-phg3-gv66-q38x.json | 6 ++-
.../GHSA-6xff-36r8-rhfg.json | 4 +-
.../GHSA-rjhx-p7x7-qfq6.json | 6 ++-
.../GHSA-3vxf-c798-m86j.json | 4 +-
.../GHSA-5wqc-p6hx-3xmx.json | 4 +-
.../GHSA-637c-qr5f-c3c8.json | 4 +-
.../GHSA-93v4-m245-8mrg.json | 4 +-
.../GHSA-9pvw-c3qw-6hwh.json | 4 +-
.../GHSA-fc9p-94fp-8jcw.json | 4 +-
.../GHSA-mqch-c6jh-g9xj.json | 4 +-
.../GHSA-mw2p-r2fm-9p6g.json | 4 +-
.../GHSA-mw2v-7qj3-3qrq.json | 4 +-
.../GHSA-x75q-8m6m-8c94.json | 4 +-
.../GHSA-25pf-crf2-9cqg.json | 15 +++++--
.../GHSA-2cp7-j8xg-p2m2.json | 15 +++++--
.../GHSA-3jw4-rrq4-7g22.json | 15 +++++--
.../GHSA-3qr9-mgq6-hx96.json | 4 +-
.../GHSA-4cpw-m35q-r38g.json | 6 ++-
.../GHSA-4m6c-v88j-qqxh.json | 15 +++++--
.../GHSA-7mjh-m8r7-cjw8.json | 15 +++++--
.../GHSA-7xpv-78qx-q843.json | 15 +++++--
.../GHSA-8679-mqj6-8992.json | 4 +-
.../GHSA-j2ch-c7pg-phcj.json | 6 ++-
.../GHSA-m7cw-25xq-j5wg.json | 15 +++++--
.../GHSA-p9j3-r5pw-645f.json | 15 +++++--
.../GHSA-vxmc-w576-mqxx.json | 15 +++++--
.../GHSA-x4pp-356g-v2qr.json | 15 +++++--
.../GHSA-rgr9-6xwp-v98f.json | 6 ++-
.../GHSA-wxqq-8jjm-6pjm.json | 6 ++-
.../GHSA-27wv-g8h4-3qr9.json | 36 +++++++++++++++++
.../GHSA-2g33-qx57-xxxh.json | 36 +++++++++++++++++
.../GHSA-43g5-2wr2-q7vj.json | 36 +++++++++++++++++
.../GHSA-5cc9-m24m-vpr3.json | 29 ++++++++++++++
.../GHSA-6mj6-gx42-5596.json | 36 +++++++++++++++++
.../GHSA-6prj-x8h3-vcvh.json | 29 ++++++++++++++
.../GHSA-6rjw-935f-mw9q.json | 36 +++++++++++++++++
.../GHSA-6x53-8wjp-mwv4.json | 6 ++-
.../GHSA-83pp-cpg7-pq36.json | 36 +++++++++++++++++
.../GHSA-86f7-x66f-vfwc.json | 6 ++-
.../GHSA-973h-3x6p-qg37.json | 36 +++++++++++++++++
.../GHSA-9964-v64g-g4c3.json | 10 ++++-
.../GHSA-fp5j-q9fh-m8qx.json | 36 +++++++++++++++++
.../GHSA-g5q8-6vx5-9mpf.json | 36 +++++++++++++++++
.../GHSA-gg4p-8wfq-mx57.json | 36 +++++++++++++++++
.../GHSA-gvv7-wmvp-m3x6.json | 36 +++++++++++++++++
.../GHSA-hjq6-x5xh-mcp3.json | 36 +++++++++++++++++
.../GHSA-hqf8-2r96-c772.json | 36 +++++++++++++++++
.../GHSA-j98h-85cg-gvmj.json | 6 ++-
.../GHSA-jv4w-rfq7-wmcq.json | 36 +++++++++++++++++
.../GHSA-pg54-39x8-3v26.json | 36 +++++++++++++++++
.../GHSA-qc22-v4cr-4rv7.json | 6 ++-
.../GHSA-r95j-4jvf-mrrw.json | 36 +++++++++++++++++
.../GHSA-v6vx-4wqx-25c4.json | 36 +++++++++++++++++
.../GHSA-vgm6-834w-2rfw.json | 36 +++++++++++++++++
.../GHSA-vq63-h845-wgm6.json | 6 ++-
.../GHSA-x24q-xw4j-6gxr.json | 36 +++++++++++++++++
.../GHSA-xcgh-pcrh-mfp2.json | 40 +++++++++++++++++++
58 files changed, 985 insertions(+), 81 deletions(-)
create mode 100644 advisories/unreviewed/2025/02/GHSA-27wv-g8h4-3qr9/GHSA-27wv-g8h4-3qr9.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-2g33-qx57-xxxh/GHSA-2g33-qx57-xxxh.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-43g5-2wr2-q7vj/GHSA-43g5-2wr2-q7vj.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-6mj6-gx42-5596/GHSA-6mj6-gx42-5596.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-6rjw-935f-mw9q/GHSA-6rjw-935f-mw9q.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-83pp-cpg7-pq36/GHSA-83pp-cpg7-pq36.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-973h-3x6p-qg37/GHSA-973h-3x6p-qg37.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-fp5j-q9fh-m8qx/GHSA-fp5j-q9fh-m8qx.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-g5q8-6vx5-9mpf/GHSA-g5q8-6vx5-9mpf.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-gg4p-8wfq-mx57/GHSA-gg4p-8wfq-mx57.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-gvv7-wmvp-m3x6/GHSA-gvv7-wmvp-m3x6.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-hjq6-x5xh-mcp3/GHSA-hjq6-x5xh-mcp3.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-hqf8-2r96-c772/GHSA-hqf8-2r96-c772.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-jv4w-rfq7-wmcq/GHSA-jv4w-rfq7-wmcq.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-pg54-39x8-3v26/GHSA-pg54-39x8-3v26.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-r95j-4jvf-mrrw/GHSA-r95j-4jvf-mrrw.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-v6vx-4wqx-25c4/GHSA-v6vx-4wqx-25c4.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-vgm6-834w-2rfw/GHSA-vgm6-834w-2rfw.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-x24q-xw4j-6gxr/GHSA-x24q-xw4j-6gxr.json
create mode 100644 advisories/unreviewed/2025/02/GHSA-xcgh-pcrh-mfp2/GHSA-xcgh-pcrh-mfp2.json
diff --git a/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json b/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json
index c1d0a26f9c1..1ada49c1dd4 100644
--- a/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json
+++ b/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4fwr-mh5q-hchh",
- "modified": "2025-02-26T21:06:49Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2025-02-26T18:30:39Z",
"aliases": [
"CVE-2025-1634"
@@ -48,6 +48,10 @@
"type": "WEB",
"url": "https://github.com/quarkusio/quarkus/commit/80b8eb41678cdccb46e964dc324d048a5ef00f4b"
},
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2025:1885"
+ },
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-1634"
diff --git a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json
index 8b0bbfe9f2d..eabd814d987 100644
--- a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json
+++ b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phg3-gv66-q38x",
- "modified": "2025-02-13T17:36:19Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2025-02-13T15:31:25Z",
"aliases": [
"CVE-2025-1247"
@@ -67,6 +67,10 @@
"type": "WEB",
"url": "https://github.com/quarkusio/quarkus/commit/02ff9ed45c3928edf2a0f8b906543606fed7cd53"
},
+ {
+ "type": "WEB",
+ "url": "https://access.redhat.com/errata/RHSA-2025:1885"
+ },
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-1247"
diff --git a/advisories/unreviewed/2023/03/GHSA-6xff-36r8-rhfg/GHSA-6xff-36r8-rhfg.json b/advisories/unreviewed/2023/03/GHSA-6xff-36r8-rhfg/GHSA-6xff-36r8-rhfg.json
index a9bb9605e8e..9a0b036ca21 100644
--- a/advisories/unreviewed/2023/03/GHSA-6xff-36r8-rhfg/GHSA-6xff-36r8-rhfg.json
+++ b/advisories/unreviewed/2023/03/GHSA-6xff-36r8-rhfg/GHSA-6xff-36r8-rhfg.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-284"
+ ],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/03/GHSA-rjhx-p7x7-qfq6/GHSA-rjhx-p7x7-qfq6.json b/advisories/unreviewed/2023/03/GHSA-rjhx-p7x7-qfq6/GHSA-rjhx-p7x7-qfq6.json
index 6a7fc04a7c9..14007f1db3b 100644
--- a/advisories/unreviewed/2023/03/GHSA-rjhx-p7x7-qfq6/GHSA-rjhx-p7x7-qfq6.json
+++ b/advisories/unreviewed/2023/03/GHSA-rjhx-p7x7-qfq6/GHSA-rjhx-p7x7-qfq6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjhx-p7x7-qfq6",
- "modified": "2023-03-18T06:30:16Z",
+ "modified": "2025-02-27T15:31:47Z",
"published": "2023-03-15T21:30:26Z",
"aliases": [
"CVE-2023-25344"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-94"
+ ],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json b/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json
index 805d77c9ae5..ec847b9c113 100644
--- a/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json
+++ b/advisories/unreviewed/2024/03/GHSA-3vxf-c798-m86j/GHSA-3vxf-c798-m86j.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vxf-c798-m86j",
- "modified": "2024-03-29T15:30:32Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30510"
],
- "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.\n\n",
+ "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json b/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json
index 27ec9417675..15c9ef40b0e 100644
--- a/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json
+++ b/advisories/unreviewed/2024/03/GHSA-5wqc-p6hx-3xmx/GHSA-5wqc-p6hx-3xmx.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wqc-p6hx-3xmx",
- "modified": "2024-03-29T15:30:32Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30500"
],
- "details": "Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12.\n\n",
+ "details": "Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json b/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json
index 9a3b4a104c4..9fb2c5343e4 100644
--- a/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json
+++ b/advisories/unreviewed/2024/03/GHSA-637c-qr5f-c3c8/GHSA-637c-qr5f-c3c8.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-637c-qr5f-c3c8",
- "modified": "2024-03-29T15:30:31Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30430"
],
- "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.\n\n",
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json b/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json
index 1bbe57f9acb..67725b7f646 100644
--- a/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json
+++ b/advisories/unreviewed/2024/03/GHSA-93v4-m245-8mrg/GHSA-93v4-m245-8mrg.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-93v4-m245-8mrg",
- "modified": "2024-03-29T15:30:31Z",
+ "modified": "2025-02-27T15:31:48Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30427"
],
- "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.\n\n",
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json b/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json
index 8ff41687ab0..db64a858f99 100644
--- a/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json
+++ b/advisories/unreviewed/2024/03/GHSA-9pvw-c3qw-6hwh/GHSA-9pvw-c3qw-6hwh.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pvw-c3qw-6hwh",
- "modified": "2024-03-29T15:30:31Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30478"
],
- "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin – Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin – Bulletin: from n/a through 3.8.5.\n\n",
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin – Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin – Bulletin: from n/a through 3.8.5.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json b/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json
index f6894b5e841..9cf3bd993b3 100644
--- a/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json
+++ b/advisories/unreviewed/2024/03/GHSA-fc9p-94fp-8jcw/GHSA-fc9p-94fp-8jcw.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc9p-94fp-8jcw",
- "modified": "2024-03-29T15:30:32Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30495"
],
- "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faboba Falang multilanguage.This issue affects Falang multilanguage: from n/a through 1.3.47.\n\n",
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faboba Falang multilanguage.This issue affects Falang multilanguage: from n/a through 1.3.47.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json b/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json
index 4c93b3e5d25..9a23daff3f3 100644
--- a/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json
+++ b/advisories/unreviewed/2024/03/GHSA-mqch-c6jh-g9xj/GHSA-mqch-c6jh-g9xj.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqch-c6jh-g9xj",
- "modified": "2024-03-29T15:30:32Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30497"
],
- "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.\n\n",
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json b/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json
index 57a7994785e..53986640879 100644
--- a/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json
+++ b/advisories/unreviewed/2024/03/GHSA-mw2p-r2fm-9p6g/GHSA-mw2p-r2fm-9p6g.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw2p-r2fm-9p6g",
- "modified": "2024-03-29T15:30:32Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-03-29T15:30:32Z",
"aliases": [
"CVE-2024-30501"
],
- "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.\n\n",
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json b/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json
index fa23b798784..c2a70c0843d 100644
--- a/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json
+++ b/advisories/unreviewed/2024/03/GHSA-mw2v-7qj3-3qrq/GHSA-mw2v-7qj3-3qrq.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw2v-7qj3-3qrq",
- "modified": "2024-03-29T15:30:31Z",
+ "modified": "2025-02-27T15:31:48Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30428"
],
- "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery allows Reflected XSS.This issue affects Contest Gallery: from n/a through 21.3.5.\n\n",
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery allows Reflected XSS.This issue affects Contest Gallery: from n/a through 21.3.5.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json b/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json
index f64e51b4800..ef471fd1da3 100644
--- a/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json
+++ b/advisories/unreviewed/2024/03/GHSA-x75q-8m6m-8c94/GHSA-x75q-8m6m-8c94.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x75q-8m6m-8c94",
- "modified": "2024-03-29T15:30:31Z",
+ "modified": "2025-02-27T15:31:48Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30429"
],
- "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2.\n\n",
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json b/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json
index ac22347967d..69bd73a88cd 100644
--- a/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json
+++ b/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25pf-crf2-9cqg",
- "modified": "2024-04-03T15:30:42Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2024-26699"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr\n\n[Why]\nThere is a potential memory access violation while\niterating through array of dcn35 clks.\n\n[How]\nLimit iteration per array size.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:52Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-2cp7-j8xg-p2m2/GHSA-2cp7-j8xg-p2m2.json b/advisories/unreviewed/2024/04/GHSA-2cp7-j8xg-p2m2/GHSA-2cp7-j8xg-p2m2.json
index e918da97f3a..026e764fc71 100644
--- a/advisories/unreviewed/2024/04/GHSA-2cp7-j8xg-p2m2/GHSA-2cp7-j8xg-p2m2.json
+++ b/advisories/unreviewed/2024/04/GHSA-2cp7-j8xg-p2m2/GHSA-2cp7-j8xg-p2m2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cp7-j8xg-p2m2",
- "modified": "2024-04-03T18:30:43Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26774"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid dividing by 0 in mb_update_avg_fragment_size() when block bitmap corrupt\n\nDetermine if bb_fragments is 0 instead of determining bb_free to eliminate\nthe risk of dividing by zero when the block bitmap is corrupted.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-369"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-3jw4-rrq4-7g22/GHSA-3jw4-rrq4-7g22.json b/advisories/unreviewed/2024/04/GHSA-3jw4-rrq4-7g22/GHSA-3jw4-rrq4-7g22.json
index 420f6ae47f7..ab406a9e58e 100644
--- a/advisories/unreviewed/2024/04/GHSA-3jw4-rrq4-7g22/GHSA-3jw4-rrq4-7g22.json
+++ b/advisories/unreviewed/2024/04/GHSA-3jw4-rrq4-7g22/GHSA-3jw4-rrq4-7g22.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jw4-rrq4-7g22",
- "modified": "2024-06-26T00:31:36Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26776"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: hisi-sfc-v3xx: Return IRQ_NONE if no interrupts were detected\n\nReturn IRQ_NONE from the interrupt handler when no interrupt was\ndetected. Because an empty interrupt will cause a null pointer error:\n\n Unable to handle kernel NULL pointer dereference at virtual\n address 0000000000000008\n Call trace:\n complete+0x54/0x100\n hisi_sfc_v3xx_isr+0x2c/0x40 [spi_hisi_sfc_v3xx]\n __handle_irq_event_percpu+0x64/0x1e0\n handle_irq_event+0x7c/0x1cc",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json b/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json
index 14cf37a922d..64de13d6176 100644
--- a/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json
+++ b/advisories/unreviewed/2024/04/GHSA-3qr9-mgq6-hx96/GHSA-3qr9-mgq6-hx96.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json b/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json
index ef01a9ac217..ec8bb334836 100644
--- a/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json
+++ b/advisories/unreviewed/2024/04/GHSA-4cpw-m35q-r38g/GHSA-4cpw-m35q-r38g.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cpw-m35q-r38g",
- "modified": "2024-04-09T21:31:58Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2024-04-09T21:31:57Z",
"aliases": [
"CVE-2024-1424"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json b/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json
index 20244dba10d..34e4ee9d2d8 100644
--- a/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json
+++ b/advisories/unreviewed/2024/04/GHSA-4m6c-v88j-qqxh/GHSA-4m6c-v88j-qqxh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m6c-v88j-qqxh",
- "modified": "2024-06-27T12:30:44Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26778"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: savage: Error out if pixclock equals zero\n\nThe userspace program could pass any values to the driver through\nioctl() interface. If the driver doesn't check the value of pixclock,\nit may cause divide-by-zero error.\n\nAlthough pixclock is checked in savagefb_decode_var(), but it is not\nchecked properly in savagefb_probe(). Fix this by checking whether\npixclock is zero in the function savagefb_check_var() before\ninfo->var.pixclock is used as the divisor.\n\nThis is similar to CVE-2022-3061 in i740fb which was fixed by\ncommit 15cf0b8.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-369"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json b/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json
index 6bdd081c6ca..9c5e8f7f782 100644
--- a/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json
+++ b/advisories/unreviewed/2024/04/GHSA-7mjh-m8r7-cjw8/GHSA-7mjh-m8r7-cjw8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mjh-m8r7-cjw8",
- "modified": "2024-06-27T15:30:38Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26777"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: sis: Error out if pixclock equals zero\n\nThe userspace program could pass any values to the driver through\nioctl() interface. If the driver doesn't check the value of pixclock,\nit may cause divide-by-zero error.\n\nIn sisfb_check_var(), var->pixclock is used as a divisor to caculate\ndrate before it is checked against zero. Fix this by checking it\nat the beginning.\n\nThis is similar to CVE-2022-3061 in i740fb which was fixed by\ncommit 15cf0b8.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-369"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:53Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json b/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json
index 5c8da005f4e..328048c101c 100644
--- a/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json
+++ b/advisories/unreviewed/2024/04/GHSA-7xpv-78qx-q843/GHSA-7xpv-78qx-q843.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xpv-78qx-q843",
- "modified": "2024-06-27T12:30:45Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-04T09:30:36Z",
"aliases": [
"CVE-2024-26805"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: Fix kernel-infoleak-after-free in __skb_datagram_iter\n\nsyzbot reported the following uninit-value access issue [1]:\n\nnetlink_to_full_skb() creates a new `skb` and puts the `skb->data`\npassed as a 1st arg of netlink_to_full_skb() onto new `skb`. The data\nsize is specified as `len` and passed to skb_put_data(). This `len`\nis based on `skb->end` that is not data offset but buffer offset. The\n`skb->end` contains data and tailroom. Since the tailroom is not\ninitialized when the new `skb` created, KMSAN detects uninitialized\nmemory area when copying the data.\n\nThis patch resolved this issue by correct the len from `skb->end` to\n`skb->len`, which is the actual data offset.\n\nBUG: KMSAN: kernel-infoleak-after-free in instrument_copy_to_user include/linux/instrumented.h:114 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in copy_to_user_iter lib/iov_iter.c:24 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_ubuf include/linux/iov_iter.h:29 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in iterate_and_advance include/linux/iov_iter.h:271 [inline]\nBUG: KMSAN: kernel-infoleak-after-free in _copy_to_iter+0x364/0x2520 lib/iov_iter.c:186\n instrument_copy_to_user include/linux/instrumented.h:114 [inline]\n copy_to_user_iter lib/iov_iter.c:24 [inline]\n iterate_ubuf include/linux/iov_iter.h:29 [inline]\n iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\n iterate_and_advance include/linux/iov_iter.h:271 [inline]\n _copy_to_iter+0x364/0x2520 lib/iov_iter.c:186\n copy_to_iter include/linux/uio.h:197 [inline]\n simple_copy_to_iter+0x68/0xa0 net/core/datagram.c:532\n __skb_datagram_iter+0x123/0xdc0 net/core/datagram.c:420\n skb_copy_datagram_iter+0x5c/0x200 net/core/datagram.c:546\n skb_copy_datagram_msg include/linux/skbuff.h:3960 [inline]\n packet_recvmsg+0xd9c/0x2000 net/packet/af_packet.c:3482\n sock_recvmsg_nosec net/socket.c:1044 [inline]\n sock_recvmsg net/socket.c:1066 [inline]\n sock_read_iter+0x467/0x580 net/socket.c:1136\n call_read_iter include/linux/fs.h:2014 [inline]\n new_sync_read fs/read_write.c:389 [inline]\n vfs_read+0x8f6/0xe00 fs/read_write.c:470\n ksys_read+0x20f/0x4c0 fs/read_write.c:613\n __do_sys_read fs/read_write.c:623 [inline]\n __se_sys_read fs/read_write.c:621 [inline]\n __x64_sys_read+0x93/0xd0 fs/read_write.c:621\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was stored to memory at:\n skb_put_data include/linux/skbuff.h:2622 [inline]\n netlink_to_full_skb net/netlink/af_netlink.c:181 [inline]\n __netlink_deliver_tap_skb net/netlink/af_netlink.c:298 [inline]\n __netlink_deliver_tap+0x5be/0xc90 net/netlink/af_netlink.c:325\n netlink_deliver_tap net/netlink/af_netlink.c:338 [inline]\n netlink_deliver_tap_kernel net/netlink/af_netlink.c:347 [inline]\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x10f1/0x1250 net/netlink/af_netlink.c:1368\n netlink_sendmsg+0x1238/0x13d0 net/netlink/af_netlink.c:1910\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n __sys_sendmsg net/socket.c:2667 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2674\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n free_pages_prepare mm/page_alloc.c:1087 [inline]\n free_unref_page_prepare+0xb0/0xa40 mm/page_alloc.c:2347\n free_unref_page_list+0xeb/0x1100 mm/page_alloc.c:2533\n release_pages+0x23d3/0x2410 mm/swap.c:1042\n free_pages_and_swap_cache+0xd9/0xf0 mm/swap_state.c:316\n tlb_batch_pages\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-04T09:15:09Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json b/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json
index 71d6f655e13..668463d964a 100644
--- a/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json
+++ b/advisories/unreviewed/2024/04/GHSA-8679-mqj6-8992/GHSA-8679-mqj6-8992.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8679-mqj6-8992",
- "modified": "2024-04-01T18:30:56Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-01T18:30:56Z",
"aliases": [
"CVE-2024-25574"
],
- "details": "\nSQL injection vulnerability exists in GetDIAE_usListParameters.\n\n",
+ "details": "SQL injection vulnerability exists in GetDIAE_usListParameters.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json b/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json
index 1abda6f545d..5c9be6fecbb 100644
--- a/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json
+++ b/advisories/unreviewed/2024/04/GHSA-j2ch-c7pg-phcj/GHSA-j2ch-c7pg-phcj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2ch-c7pg-phcj",
- "modified": "2024-04-06T09:31:02Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2024-04-06T09:31:02Z",
"aliases": [
"CVE-2024-2458"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json b/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json
index 127352bd3e5..728741b2822 100644
--- a/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json
+++ b/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7cw-25xq-j5wg",
- "modified": "2024-04-03T15:30:43Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T15:30:43Z",
"aliases": [
"CVE-2024-26724"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: DPLL, Fix possible use after free after delayed work timer triggers\n\nI managed to hit following use after free warning recently:\n\n[ 2169.711665] ==================================================================\n[ 2169.714009] BUG: KASAN: slab-use-after-free in __run_timers.part.0+0x179/0x4c0\n[ 2169.716293] Write of size 8 at addr ffff88812b326a70 by task swapper/4/0\n\n[ 2169.719022] CPU: 4 PID: 0 Comm: swapper/4 Not tainted 6.8.0-rc2jiri+ #2\n[ 2169.720974] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 2169.722457] Call Trace:\n[ 2169.722756] \n[ 2169.723024] dump_stack_lvl+0x58/0xb0\n[ 2169.723417] print_report+0xc5/0x630\n[ 2169.723807] ? __virt_addr_valid+0x126/0x2b0\n[ 2169.724268] kasan_report+0xbe/0xf0\n[ 2169.724667] ? __run_timers.part.0+0x179/0x4c0\n[ 2169.725116] ? __run_timers.part.0+0x179/0x4c0\n[ 2169.725570] __run_timers.part.0+0x179/0x4c0\n[ 2169.726003] ? call_timer_fn+0x320/0x320\n[ 2169.726404] ? lock_downgrade+0x3a0/0x3a0\n[ 2169.726820] ? kvm_clock_get_cycles+0x14/0x20\n[ 2169.727257] ? ktime_get+0x92/0x150\n[ 2169.727630] ? lapic_next_deadline+0x35/0x60\n[ 2169.728069] run_timer_softirq+0x40/0x80\n[ 2169.728475] __do_softirq+0x1a1/0x509\n[ 2169.728866] irq_exit_rcu+0x95/0xc0\n[ 2169.729241] sysvec_apic_timer_interrupt+0x6b/0x80\n[ 2169.729718] \n[ 2169.729993] \n[ 2169.730259] asm_sysvec_apic_timer_interrupt+0x16/0x20\n[ 2169.730755] RIP: 0010:default_idle+0x13/0x20\n[ 2169.731190] Code: c0 08 00 00 00 4d 29 c8 4c 01 c7 4c 29 c2 e9 72 ff ff ff cc cc cc cc 8b 05 9a 7f 1f 02 85 c0 7e 07 0f 00 2d cf 69 43 00 fb f4 c3 66 66 2e 0f 1f 84 00 00 00 00 00 65 48 8b 04 25 c0 93 04 00\n[ 2169.732759] RSP: 0018:ffff888100dbfe10 EFLAGS: 00000242\n[ 2169.733264] RAX: 0000000000000001 RBX: ffff888100d9c200 RCX: ffffffff8241bd62\n[ 2169.733925] RDX: ffffed109a848b15 RSI: 0000000000000004 RDI: ffffffff8127ac55\n[ 2169.734566] RBP: 0000000000000004 R08: 0000000000000000 R09: ffffed109a848b14\n[ 2169.735200] R10: ffff8884d42458a3 R11: 000000000000ba7e R12: ffffffff83d7d3a0\n[ 2169.735835] R13: 1ffff110201b7fc6 R14: 0000000000000000 R15: ffff888100d9c200\n[ 2169.736478] ? ct_kernel_exit.constprop.0+0xa2/0xc0\n[ 2169.736954] ? do_idle+0x285/0x290\n[ 2169.737323] default_idle_call+0x63/0x90\n[ 2169.737730] do_idle+0x285/0x290\n[ 2169.738089] ? arch_cpu_idle_exit+0x30/0x30\n[ 2169.738511] ? mark_held_locks+0x1a/0x80\n[ 2169.738917] ? lockdep_hardirqs_on_prepare+0x12e/0x200\n[ 2169.739417] cpu_startup_entry+0x30/0x40\n[ 2169.739825] start_secondary+0x19a/0x1c0\n[ 2169.740229] ? set_cpu_sibling_map+0xbd0/0xbd0\n[ 2169.740673] secondary_startup_64_no_verify+0x15d/0x16b\n[ 2169.741179] \n\n[ 2169.741686] Allocated by task 1098:\n[ 2169.742058] kasan_save_stack+0x1c/0x40\n[ 2169.742456] kasan_save_track+0x10/0x30\n[ 2169.742852] __kasan_kmalloc+0x83/0x90\n[ 2169.743246] mlx5_dpll_probe+0xf5/0x3c0 [mlx5_dpll]\n[ 2169.743730] auxiliary_bus_probe+0x62/0xb0\n[ 2169.744148] really_probe+0x127/0x590\n[ 2169.744534] __driver_probe_device+0xd2/0x200\n[ 2169.744973] device_driver_attach+0x6b/0xf0\n[ 2169.745402] bind_store+0x90/0xe0\n[ 2169.745761] kernfs_fop_write_iter+0x1df/0x2a0\n[ 2169.746210] vfs_write+0x41f/0x790\n[ 2169.746579] ksys_write+0xc7/0x160\n[ 2169.746947] do_syscall_64+0x6f/0x140\n[ 2169.747333] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n\n[ 2169.748049] Freed by task 1220:\n[ 2169.748393] kasan_save_stack+0x1c/0x40\n[ 2169.748789] kasan_save_track+0x10/0x30\n[ 2169.749188] kasan_save_free_info+0x3b/0x50\n[ 2169.749621] poison_slab_object+0x106/0x180\n[ 2169.750044] __kasan_slab_free+0x14/0x50\n[ 2169.750451] kfree+0x118/0x330\n[ 2169.750792] mlx5_dpll_remove+0xf5/0x110 [mlx5_dpll]\n[ 2169.751271] auxiliary_bus_remove+0x2e/0x40\n[ 2169.751694] device_release_driver_internal+0x24b/0x2e0\n[ 2169.752191] unbind_store+0xa6/0xb0\n[ 2169.752563] kernfs_fo\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:54Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json b/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json
index f98d43f6897..d37cb3ac599 100644
--- a/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json
+++ b/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9j3-r5pw-645f",
- "modified": "2024-04-03T15:30:42Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T15:30:42Z",
"aliases": [
"CVE-2024-26691"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix circular locking dependency\n\nThe rule inside kvm enforces that the vcpu->mutex is taken *inside*\nkvm->lock. The rule is violated by the pkvm_create_hyp_vm() which acquires\nthe kvm->lock while already holding the vcpu->mutex lock from\nkvm_vcpu_ioctl(). Avoid the circular locking dependency altogether by\nprotecting the hyp vm handle with the config_lock, much like we already\ndo for other forms of VM-scoped data.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T15:15:52Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json b/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json
index e4d7451be57..a92880c3abf 100644
--- a/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json
+++ b/advisories/unreviewed/2024/04/GHSA-vxmc-w576-mqxx/GHSA-vxmc-w576-mqxx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxmc-w576-mqxx",
- "modified": "2024-04-03T18:30:43Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-03T18:30:43Z",
"aliases": [
"CVE-2024-26767"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fixed integer types and null check locations\n\n[why]:\nissues fixed:\n- comparison with wider integer type in loop condition which can cause\ninfinite loops\n- pointer dereference before null check",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-03T17:15:52Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json b/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json
index 4d766b0355f..7bb4612a64e 100644
--- a/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json
+++ b/advisories/unreviewed/2024/04/GHSA-x4pp-356g-v2qr/GHSA-x4pp-356g-v2qr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x4pp-356g-v2qr",
- "modified": "2024-04-04T09:30:36Z",
+ "modified": "2025-02-27T15:31:49Z",
"published": "2024-04-04T09:30:36Z",
"aliases": [
"CVE-2024-26796"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: perf: ctr_get_width function for legacy is not defined\n\nWith parameters CONFIG_RISCV_PMU_LEGACY=y and CONFIG_RISCV_PMU_SBI=n\nlinux kernel crashes when you try perf record:\n\n$ perf record ls\n[ 46.749286] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[ 46.750199] Oops [#1]\n[ 46.750342] Modules linked in:\n[ 46.750608] CPU: 0 PID: 107 Comm: perf-exec Not tainted 6.6.0 #2\n[ 46.750906] Hardware name: riscv-virtio,qemu (DT)\n[ 46.751184] epc : 0x0\n[ 46.751430] ra : arch_perf_update_userpage+0x54/0x13e\n[ 46.751680] epc : 0000000000000000 ra : ffffffff8072ee52 sp : ff2000000022b8f0\n[ 46.751958] gp : ffffffff81505988 tp : ff6000000290d400 t0 : ff2000000022b9c0\n[ 46.752229] t1 : 0000000000000001 t2 : 0000000000000003 s0 : ff2000000022b930\n[ 46.752451] s1 : ff600000028fb000 a0 : 0000000000000000 a1 : ff600000028fb000\n[ 46.752673] a2 : 0000000ae2751268 a3 : 00000000004fb708 a4 : 0000000000000004\n[ 46.752895] a5 : 0000000000000000 a6 : 000000000017ffe3 a7 : 00000000000000d2\n[ 46.753117] s2 : ff600000028fb000 s3 : 0000000ae2751268 s4 : 0000000000000000\n[ 46.753338] s5 : ffffffff8153e290 s6 : ff600000863b9000 s7 : ff60000002961078\n[ 46.753562] s8 : ff60000002961048 s9 : ff60000002961058 s10: 0000000000000001\n[ 46.753783] s11: 0000000000000018 t3 : ffffffffffffffff t4 : ffffffffffffffff\n[ 46.754005] t5 : ff6000000292270c t6 : ff2000000022bb30\n[ 46.754179] status: 0000000200000100 badaddr: 0000000000000000 cause: 000000000000000c\n[ 46.754653] Code: Unable to access instruction at 0xffffffffffffffec.\n[ 46.754939] ---[ end trace 0000000000000000 ]---\n[ 46.755131] note: perf-exec[107] exited with irqs disabled\n[ 46.755546] note: perf-exec[107] exited with preempt_count 4\n\nThis happens because in the legacy case the ctr_get_width function was not\ndefined, but it is used in arch_perf_update_userpage.\n\nAlso remove extra check in riscv_pmu_ctr_get_width_mask",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-04T09:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rgr9-6xwp-v98f/GHSA-rgr9-6xwp-v98f.json b/advisories/unreviewed/2024/05/GHSA-rgr9-6xwp-v98f/GHSA-rgr9-6xwp-v98f.json
index 39249fafec6..f14b275c92d 100644
--- a/advisories/unreviewed/2024/05/GHSA-rgr9-6xwp-v98f/GHSA-rgr9-6xwp-v98f.json
+++ b/advisories/unreviewed/2024/05/GHSA-rgr9-6xwp-v98f/GHSA-rgr9-6xwp-v98f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rgr9-6xwp-v98f",
- "modified": "2024-06-03T18:56:25Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2024-05-23T15:30:39Z",
"aliases": [
"CVE-2024-5084"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-434"
+ ],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json b/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json
index fa794e17993..60020f3ba5c 100644
--- a/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json
+++ b/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxqq-8jjm-6pjm",
- "modified": "2025-01-02T15:31:57Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2024-11-07T12:30:34Z",
"aliases": [
"CVE-2024-50146"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4dbc1d1a9f39c3711ad2a40addca04d07d9ab5d0"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6fe973c8873c998734a050f366b28facc03d32a"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/db84cb4c8c565e6d4de84b23c2818b63991adfdd"
diff --git a/advisories/unreviewed/2025/02/GHSA-27wv-g8h4-3qr9/GHSA-27wv-g8h4-3qr9.json b/advisories/unreviewed/2025/02/GHSA-27wv-g8h4-3qr9/GHSA-27wv-g8h4-3qr9.json
new file mode 100644
index 00000000000..c3506ddb8c6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-27wv-g8h4-3qr9/GHSA-27wv-g8h4-3qr9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-27wv-g8h4-3qr9",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56811"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56811"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-2g33-qx57-xxxh/GHSA-2g33-qx57-xxxh.json b/advisories/unreviewed/2025/02/GHSA-2g33-qx57-xxxh/GHSA-2g33-qx57-xxxh.json
new file mode 100644
index 00000000000..e2ba0b83efb
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-2g33-qx57-xxxh/GHSA-2g33-qx57-xxxh.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2g33-qx57-xxxh",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2025-1739"
+ ],
+ "details": "An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to \"/en/player/activex_pal.asp\" and successfully authenticating the application.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1739"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-trivision-camera-nc227wf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-288"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T13:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-43g5-2wr2-q7vj/GHSA-43g5-2wr2-q7vj.json b/advisories/unreviewed/2025/02/GHSA-43g5-2wr2-q7vj/GHSA-43g5-2wr2-q7vj.json
new file mode 100644
index 00000000000..22152180f55
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-43g5-2wr2-q7vj/GHSA-43g5-2wr2-q7vj.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-43g5-2wr2-q7vj",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2025-1691"
+ ],
+ "details": "The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input and run obfuscated malicious text. This requires user interaction in the form of the user using ‘tab’ to autocomplete text that is a prefix of the attacker’s prepared autocompletion. This issue affects mongosh versions prior to 2.3.9. \n\n\n\n\nThe vulnerability is exploitable only when mongosh is connected to a cluster that is partially or fully controlled by an attacker.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1691"
+ },
+ {
+ "type": "WEB",
+ "url": "https://jira.mongodb.org/browse/MONGOSH-2024"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T13:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json b/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json
new file mode 100644
index 00000000000..ab249ae31b6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5cc9-m24m-vpr3/GHSA-5cc9-m24m-vpr3.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5cc9-m24m-vpr3",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2025-25760"
+ ],
+ "details": "A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25760"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/147536951/Qianyi-learn/blob/main/SUCMS2.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6mj6-gx42-5596/GHSA-6mj6-gx42-5596.json b/advisories/unreviewed/2025/02/GHSA-6mj6-gx42-5596/GHSA-6mj6-gx42-5596.json
new file mode 100644
index 00000000000..6e0bd0993c6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-6mj6-gx42-5596/GHSA-6mj6-gx42-5596.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6mj6-gx42-5596",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2025-22280"
+ ],
+ "details": "Missing Authorization vulnerability in revmakx DefendWP Firewall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DefendWP Firewall: from n/a through 1.1.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22280"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/defend-wp-firewall/vulnerability/wordpress-defendwp-firewall-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T14:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json b/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json
new file mode 100644
index 00000000000..e471a813385
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-6prj-x8h3-vcvh/GHSA-6prj-x8h3-vcvh.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6prj-x8h3-vcvh",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2025-25759"
+ ],
+ "details": "An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/147536951/Qianyi-learn/blob/main/SUCMS.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6rjw-935f-mw9q/GHSA-6rjw-935f-mw9q.json b/advisories/unreviewed/2025/02/GHSA-6rjw-935f-mw9q/GHSA-6rjw-935f-mw9q.json
new file mode 100644
index 00000000000..d719440051c
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-6rjw-935f-mw9q/GHSA-6rjw-935f-mw9q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6rjw-935f-mw9q",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2025-1738"
+ ],
+ "details": "A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity, exposing this sensitive information to a third party.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1738"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-trivision-camera-nc227wf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-598"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T13:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6x53-8wjp-mwv4/GHSA-6x53-8wjp-mwv4.json b/advisories/unreviewed/2025/02/GHSA-6x53-8wjp-mwv4/GHSA-6x53-8wjp-mwv4.json
index 79f93c9cae3..69bbf205f76 100644
--- a/advisories/unreviewed/2025/02/GHSA-6x53-8wjp-mwv4/GHSA-6x53-8wjp-mwv4.json
+++ b/advisories/unreviewed/2025/02/GHSA-6x53-8wjp-mwv4/GHSA-6x53-8wjp-mwv4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6x53-8wjp-mwv4",
- "modified": "2025-02-27T03:34:02Z",
+ "modified": "2025-02-27T15:31:51Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2025-21721"
@@ -18,6 +18,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/481136234dfe96c7f92770829bec6111c7c5f5dd"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7891ac3b0a5c56f7148af507306308ab841cdc31"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/eddd3176b8c4c83a46ab974574cda7c3dfe09388"
diff --git a/advisories/unreviewed/2025/02/GHSA-83pp-cpg7-pq36/GHSA-83pp-cpg7-pq36.json b/advisories/unreviewed/2025/02/GHSA-83pp-cpg7-pq36/GHSA-83pp-cpg7-pq36.json
new file mode 100644
index 00000000000..d2ce95fbd41
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-83pp-cpg7-pq36/GHSA-83pp-cpg7-pq36.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-83pp-cpg7-pq36",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56812"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56812"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-86f7-x66f-vfwc/GHSA-86f7-x66f-vfwc.json b/advisories/unreviewed/2025/02/GHSA-86f7-x66f-vfwc/GHSA-86f7-x66f-vfwc.json
index ef981d2fa9d..e6eac3cbf5d 100644
--- a/advisories/unreviewed/2025/02/GHSA-86f7-x66f-vfwc/GHSA-86f7-x66f-vfwc.json
+++ b/advisories/unreviewed/2025/02/GHSA-86f7-x66f-vfwc/GHSA-86f7-x66f-vfwc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86f7-x66f-vfwc",
- "modified": "2025-02-27T03:34:02Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2024-52559"
@@ -14,6 +14,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52559"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2b99b2c4621d13bd4374ef384e8f1fc188d0a5df"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/2f1845e46c41ed500789d53dc45b383b7745c96c"
diff --git a/advisories/unreviewed/2025/02/GHSA-973h-3x6p-qg37/GHSA-973h-3x6p-qg37.json b/advisories/unreviewed/2025/02/GHSA-973h-3x6p-qg37/GHSA-973h-3x6p-qg37.json
new file mode 100644
index 00000000000..9904dfde4c1
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-973h-3x6p-qg37/GHSA-973h-3x6p-qg37.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-973h-3x6p-qg37",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2025-1692"
+ ],
+ "details": "The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted text can be used to obfuscate malicious code. This issue affects mongosh versions prior to 2.3.9",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1692"
+ },
+ {
+ "type": "WEB",
+ "url": "https://jira.mongodb.org/browse/MONGOSH-2025"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-150"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T13:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9964-v64g-g4c3/GHSA-9964-v64g-g4c3.json b/advisories/unreviewed/2025/02/GHSA-9964-v64g-g4c3/GHSA-9964-v64g-g4c3.json
index ba1c735899b..de5caa4b0b3 100644
--- a/advisories/unreviewed/2025/02/GHSA-9964-v64g-g4c3/GHSA-9964-v64g-g4c3.json
+++ b/advisories/unreviewed/2025/02/GHSA-9964-v64g-g4c3/GHSA-9964-v64g-g4c3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9964-v64g-g4c3",
- "modified": "2025-02-27T03:34:04Z",
+ "modified": "2025-02-27T15:31:51Z",
"published": "2025-02-27T03:34:04Z",
"aliases": [
"CVE-2025-21746"
@@ -18,9 +18,17 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/08bd5b7c9a2401faabdaa1472d45c7de0755fd7e"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3e179d3f1ada963475395d81bfe91daef4d1a24c"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/87da1ea93ec9f9f0004e5b12e78789bc94e360bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a2cbcd70133dc0d4d4c95ad4cd5412b935354c7c"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2025/02/GHSA-fp5j-q9fh-m8qx/GHSA-fp5j-q9fh-m8qx.json b/advisories/unreviewed/2025/02/GHSA-fp5j-q9fh-m8qx/GHSA-fp5j-q9fh-m8qx.json
new file mode 100644
index 00000000000..346ca16e3c1
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fp5j-q9fh-m8qx/GHSA-fp5j-q9fh-m8qx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fp5j-q9fh-m8qx",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2025-25761"
+ ],
+ "details": "HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25761"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/147536951/Qianyi-learn/blob/main/Hkcms.pdf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-73"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-g5q8-6vx5-9mpf/GHSA-g5q8-6vx5-9mpf.json b/advisories/unreviewed/2025/02/GHSA-g5q8-6vx5-9mpf/GHSA-g5q8-6vx5-9mpf.json
new file mode 100644
index 00000000000..675f17d1b1b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-g5q8-6vx5-9mpf/GHSA-g5q8-6vx5-9mpf.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g5q8-6vx5-9mpf",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2025-0759"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-367"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gg4p-8wfq-mx57/GHSA-gg4p-8wfq-mx57.json b/advisories/unreviewed/2025/02/GHSA-gg4p-8wfq-mx57/GHSA-gg4p-8wfq-mx57.json
new file mode 100644
index 00000000000..96579a0e922
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gg4p-8wfq-mx57/GHSA-gg4p-8wfq-mx57.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gg4p-8wfq-mx57",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56494"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56494"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gvv7-wmvp-m3x6/GHSA-gvv7-wmvp-m3x6.json b/advisories/unreviewed/2025/02/GHSA-gvv7-wmvp-m3x6/GHSA-gvv7-wmvp-m3x6.json
new file mode 100644
index 00000000000..a3940569735
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gvv7-wmvp-m3x6/GHSA-gvv7-wmvp-m3x6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gvv7-wmvp-m3x6",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56810"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56810"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hjq6-x5xh-mcp3/GHSA-hjq6-x5xh-mcp3.json b/advisories/unreviewed/2025/02/GHSA-hjq6-x5xh-mcp3/GHSA-hjq6-x5xh-mcp3.json
new file mode 100644
index 00000000000..6c21abc7b48
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hjq6-x5xh-mcp3/GHSA-hjq6-x5xh-mcp3.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hjq6-x5xh-mcp3",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-54169"
+ ],
+ "details": "IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54169"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hqf8-2r96-c772/GHSA-hqf8-2r96-c772.json b/advisories/unreviewed/2025/02/GHSA-hqf8-2r96-c772/GHSA-hqf8-2r96-c772.json
new file mode 100644
index 00000000000..4de70882815
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hqf8-2r96-c772/GHSA-hqf8-2r96-c772.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hqf8-2r96-c772",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56493"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56493"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json b/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json
index 8cfbd8a8b3f..b8ef8f20b89 100644
--- a/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json
+++ b/advisories/unreviewed/2025/02/GHSA-j98h-85cg-gvmj/GHSA-j98h-85cg-gvmj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j98h-85cg-gvmj",
- "modified": "2025-02-27T03:33:58Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2025-02-27T03:33:58Z",
"aliases": [
"CVE-2024-57977"
@@ -18,6 +18,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/46576834291869457d4772bb7df72d7c2bb3d57f"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/972486d37169fe85035e81b8c5dff21f70df1173"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ade81479c7dda1ce3eedb215c78bc615bbd04f06"
diff --git a/advisories/unreviewed/2025/02/GHSA-jv4w-rfq7-wmcq/GHSA-jv4w-rfq7-wmcq.json b/advisories/unreviewed/2025/02/GHSA-jv4w-rfq7-wmcq/GHSA-jv4w-rfq7-wmcq.json
new file mode 100644
index 00000000000..f8f95d95879
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-jv4w-rfq7-wmcq/GHSA-jv4w-rfq7-wmcq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jv4w-rfq7-wmcq",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56495"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56495"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-pg54-39x8-3v26/GHSA-pg54-39x8-3v26.json b/advisories/unreviewed/2025/02/GHSA-pg54-39x8-3v26/GHSA-pg54-39x8-3v26.json
new file mode 100644
index 00000000000..685901cb12c
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-pg54-39x8-3v26/GHSA-pg54-39x8-3v26.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pg54-39x8-3v26",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2024-13148"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection.This issue affects B2B Login Platform: before 16.01.2025.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13148"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-25-0045"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json b/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json
index 5fcbecb2c21..98ffb24e968 100644
--- a/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json
+++ b/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qc22-v4cr-4rv7",
- "modified": "2025-02-27T03:34:02Z",
+ "modified": "2025-02-27T15:31:51Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2024-58002"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/438bda062b2c40ddd7df23b932e29ffe0a448cac"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4dbaa738c583a0e947803c69e8996e88cf98d971"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9edc7d25f7e49c33a1ce7a5ffadea2222065516c"
diff --git a/advisories/unreviewed/2025/02/GHSA-r95j-4jvf-mrrw/GHSA-r95j-4jvf-mrrw.json b/advisories/unreviewed/2025/02/GHSA-r95j-4jvf-mrrw/GHSA-r95j-4jvf-mrrw.json
new file mode 100644
index 00000000000..5e96bf56abd
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-r95j-4jvf-mrrw/GHSA-r95j-4jvf-mrrw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r95j-4jvf-mrrw",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2025-1693"
+ ],
+ "details": "The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell output. This may result in the display of falsified messages that appear to originate from mongosh or the underlying operating system, potentially misleading users into executing unsafe actions.\n\n\nThe vulnerability is exploitable only when mongosh is connected to a cluster that is partially or fully controlled by an attacker.\n\n\nThis issue affects mongosh versions prior to 2.3.9",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1693"
+ },
+ {
+ "type": "WEB",
+ "url": "https://jira.mongodb.org/browse/MONGOSH-2026"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-150"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T13:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v6vx-4wqx-25c4/GHSA-v6vx-4wqx-25c4.json b/advisories/unreviewed/2025/02/GHSA-v6vx-4wqx-25c4/GHSA-v6vx-4wqx-25c4.json
new file mode 100644
index 00000000000..c3651da9e44
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v6vx-4wqx-25c4/GHSA-v6vx-4wqx-25c4.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v6vx-4wqx-25c4",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2024-9334"
+ ],
+ "details": "Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass.This issue affects Pallium Vehicle Tracking: before 17.10.2024.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9334"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-25-0044"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-798"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T14:15:34Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vgm6-834w-2rfw/GHSA-vgm6-834w-2rfw.json b/advisories/unreviewed/2025/02/GHSA-vgm6-834w-2rfw/GHSA-vgm6-834w-2rfw.json
new file mode 100644
index 00000000000..57fbc451af6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vgm6-834w-2rfw/GHSA-vgm6-834w-2rfw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vgm6-834w-2rfw",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-54170"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consumes excessive CPU cycles.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54170"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1333"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json b/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json
index 3c152b50bd9..3cf0ef500b3 100644
--- a/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json
+++ b/advisories/unreviewed/2025/02/GHSA-vq63-h845-wgm6/GHSA-vq63-h845-wgm6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq63-h845-wgm6",
- "modified": "2025-02-27T03:34:01Z",
+ "modified": "2025-02-27T15:31:50Z",
"published": "2025-02-27T03:34:01Z",
"aliases": [
"CVE-2025-21712"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://git.kernel.org/stable/c/4e9316eee3885bfb311b4759513f2ccf37891c09"
},
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/52848a095b55a302af92f52ca0de5b3112059bb8"
+ },
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8d28d0ddb986f56920ac97ae704cc3340a699a30"
diff --git a/advisories/unreviewed/2025/02/GHSA-x24q-xw4j-6gxr/GHSA-x24q-xw4j-6gxr.json b/advisories/unreviewed/2025/02/GHSA-x24q-xw4j-6gxr/GHSA-x24q-xw4j-6gxr.json
new file mode 100644
index 00000000000..1c183738a5a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-x24q-xw4j-6gxr/GHSA-x24q-xw4j-6gxr.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x24q-xw4j-6gxr",
+ "modified": "2025-02-27T15:31:52Z",
+ "published": "2025-02-27T15:31:52Z",
+ "aliases": [
+ "CVE-2024-56496"
+ ],
+ "details": "IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56496"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7184194"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-209"
+ ],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T15:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-xcgh-pcrh-mfp2/GHSA-xcgh-pcrh-mfp2.json b/advisories/unreviewed/2025/02/GHSA-xcgh-pcrh-mfp2/GHSA-xcgh-pcrh-mfp2.json
new file mode 100644
index 00000000000..ab590f5ee2e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-xcgh-pcrh-mfp2/GHSA-xcgh-pcrh-mfp2.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xcgh-pcrh-mfp2",
+ "modified": "2025-02-27T15:31:51Z",
+ "published": "2025-02-27T15:31:51Z",
+ "aliases": [
+ "CVE-2024-13402"
+ ],
+ "details": "The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13402"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.buddyboss.com/resources/buddyboss-platform-releases/2-8-00"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/42743c2f-053b-4f14-bf11-865f978ec017?source=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T13:15:09Z"
+ }
+}
\ No newline at end of file