diff --git a/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json b/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json index 637ca31b0d8..f62424cb081 100644 --- a/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json +++ b/advisories/unreviewed/2024/02/GHSA-4mwq-x2m3-qxc6/GHSA-4mwq-x2m3-qxc6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json b/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json index eb53bfaca30..37e6f9947c1 100644 --- a/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json +++ b/advisories/unreviewed/2024/02/GHSA-675c-mq76-7jv4/GHSA-675c-mq76-7jv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-675c-mq76-7jv4", - "modified": "2024-02-22T15:30:39Z", + "modified": "2025-03-28T21:30:35Z", "published": "2024-02-22T15:30:39Z", "aliases": [ "CVE-2024-26350" ], "details": "flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-22T14:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json b/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json index 1bc2aff3022..b182252fe1b 100644 --- a/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json +++ b/advisories/unreviewed/2024/02/GHSA-rfw9-hv5h-2w85/GHSA-rfw9-hv5h-2w85.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json index 0044f47f6a2..bb9f5333063 100644 --- a/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json +++ b/advisories/unreviewed/2024/03/GHSA-3x3h-fcc9-p4px/GHSA-3x3h-fcc9-p4px.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3x3h-fcc9-p4px", - "modified": "2024-03-28T15:30:33Z", + "modified": "2025-03-28T21:30:37Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2023-45705" ], - "details": "An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.\n", + "details": "An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json b/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json index 2af4f38240b..753bddfa96a 100644 --- a/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json +++ b/advisories/unreviewed/2024/03/GHSA-62qx-2wp9-mxh3/GHSA-62qx-2wp9-mxh3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9r84-j222-pj3r/GHSA-9r84-j222-pj3r.json b/advisories/unreviewed/2024/03/GHSA-9r84-j222-pj3r/GHSA-9r84-j222-pj3r.json index 6eea2a737c6..5dbb0651e01 100644 --- a/advisories/unreviewed/2024/03/GHSA-9r84-j222-pj3r/GHSA-9r84-j222-pj3r.json +++ b/advisories/unreviewed/2024/03/GHSA-9r84-j222-pj3r/GHSA-9r84-j222-pj3r.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ch5v-h69f-mxc8/GHSA-ch5v-h69f-mxc8.json b/advisories/unreviewed/2024/03/GHSA-ch5v-h69f-mxc8/GHSA-ch5v-h69f-mxc8.json index 6d30a8972f8..df47b25c50d 100644 --- a/advisories/unreviewed/2024/03/GHSA-ch5v-h69f-mxc8/GHSA-ch5v-h69f-mxc8.json +++ b/advisories/unreviewed/2024/03/GHSA-ch5v-h69f-mxc8/GHSA-ch5v-h69f-mxc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ch5v-h69f-mxc8", - "modified": "2024-05-01T21:30:30Z", + "modified": "2025-03-28T21:30:36Z", "published": "2024-03-10T06:30:38Z", "aliases": [ "CVE-2024-28757" ], "details": "libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-776" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-10T05:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json b/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json index 0f1dd7f8b68..5180cef866d 100644 --- a/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json +++ b/advisories/unreviewed/2024/03/GHSA-chrr-r69v-42vf/GHSA-chrr-r69v-42vf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gr8j-pcj7-xr6m/GHSA-gr8j-pcj7-xr6m.json b/advisories/unreviewed/2024/03/GHSA-gr8j-pcj7-xr6m/GHSA-gr8j-pcj7-xr6m.json index ed83ccc10fa..bc5cbd74516 100644 --- a/advisories/unreviewed/2024/03/GHSA-gr8j-pcj7-xr6m/GHSA-gr8j-pcj7-xr6m.json +++ b/advisories/unreviewed/2024/03/GHSA-gr8j-pcj7-xr6m/GHSA-gr8j-pcj7-xr6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gr8j-pcj7-xr6m", - "modified": "2024-03-22T18:30:32Z", + "modified": "2025-03-28T21:30:37Z", "published": "2024-03-22T18:30:32Z", "aliases": [ "CVE-2023-4063" ], "details": "Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-22T18:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-j6ph-cmqv-q28r/GHSA-j6ph-cmqv-q28r.json b/advisories/unreviewed/2024/03/GHSA-j6ph-cmqv-q28r/GHSA-j6ph-cmqv-q28r.json index 17d7c1aa5fa..100c88f53b7 100644 --- a/advisories/unreviewed/2024/03/GHSA-j6ph-cmqv-q28r/GHSA-j6ph-cmqv-q28r.json +++ b/advisories/unreviewed/2024/03/GHSA-j6ph-cmqv-q28r/GHSA-j6ph-cmqv-q28r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j6ph-cmqv-q28r", - "modified": "2024-03-12T18:31:15Z", + "modified": "2025-03-28T21:30:36Z", "published": "2024-03-12T18:31:15Z", "aliases": [ "CVE-2024-1138" ], - "details": "The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.\n\n", + "details": "The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json b/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json index 6a91e8f583c..30968506e9f 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json +++ b/advisories/unreviewed/2024/03/GHSA-mfqh-m928-7c6m/GHSA-mfqh-m928-7c6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mfqh-m928-7c6m", - "modified": "2024-03-04T15:31:07Z", + "modified": "2025-03-28T21:30:35Z", "published": "2024-03-04T15:31:07Z", "aliases": [ "CVE-2024-27668" ], "details": "Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T15:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mv3g-77hg-5wrg/GHSA-mv3g-77hg-5wrg.json b/advisories/unreviewed/2024/03/GHSA-mv3g-77hg-5wrg/GHSA-mv3g-77hg-5wrg.json index 0d86e337bd4..1fa73c9a601 100644 --- a/advisories/unreviewed/2024/03/GHSA-mv3g-77hg-5wrg/GHSA-mv3g-77hg-5wrg.json +++ b/advisories/unreviewed/2024/03/GHSA-mv3g-77hg-5wrg/GHSA-mv3g-77hg-5wrg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mv3g-77hg-5wrg", - "modified": "2024-03-18T21:31:23Z", + "modified": "2025-03-28T21:30:37Z", "published": "2024-03-18T21:31:23Z", "aliases": [ "CVE-2024-0820" ], "details": "The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T19:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json index 864778f8202..45d0595d2e1 100644 --- a/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json +++ b/advisories/unreviewed/2024/03/GHSA-ppgm-9w39-cx97/GHSA-ppgm-9w39-cx97.json @@ -89,7 +89,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json b/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json index 5b692a2b726..c23c0015ca9 100644 --- a/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json +++ b/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wwmq-47hw-c7vw", - "modified": "2024-03-29T00:30:34Z", + "modified": "2025-03-28T21:30:38Z", "published": "2024-03-29T00:30:34Z", "aliases": [ "CVE-2023-33528" ], "details": "halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T23:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json b/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json index 8603254cbce..5bf83c08e9b 100644 --- a/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json +++ b/advisories/unreviewed/2024/04/GHSA-299c-jvhc-gxj8/GHSA-299c-jvhc-gxj8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-299c-jvhc-gxj8", - "modified": "2024-05-03T15:30:36Z", + "modified": "2025-03-28T21:30:39Z", "published": "2024-04-08T15:30:33Z", "aliases": [ "CVE-2024-2511" ], "details": "Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -47,7 +52,7 @@ "cwe_ids": [ "CWE-1325" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T14:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json b/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json index 2b376923f87..0f1e529a729 100644 --- a/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json +++ b/advisories/unreviewed/2024/04/GHSA-2frh-5wq5-r279/GHSA-2frh-5wq5-r279.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json b/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json index 9abb2b3c8e7..052e7e2dfb0 100644 --- a/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json +++ b/advisories/unreviewed/2024/04/GHSA-2gc3-gxvv-r87c/GHSA-2gc3-gxvv-r87c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json index 8b9cbeb9be0..7bda016a1d1 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json +++ b/advisories/unreviewed/2024/04/GHSA-3vhm-v3w9-8mr8/GHSA-3vhm-v3w9-8mr8.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json b/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json index 32172780b94..973ca1230ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json +++ b/advisories/unreviewed/2024/04/GHSA-57fw-fgxq-637j/GHSA-57fw-fgxq-637j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57fw-fgxq-637j", - "modified": "2024-04-01T21:30:46Z", + "modified": "2025-03-28T21:30:38Z", "published": "2024-04-01T21:30:46Z", "aliases": [ "CVE-2023-48906" ], "details": "Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T20:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json index a7b3def5b3a..03122f62d66 100644 --- a/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json +++ b/advisories/unreviewed/2024/04/GHSA-5c83-88f2-q34h/GHSA-5c83-88f2-q34h.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json b/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json index 8ae14e198ee..62e415fe24e 100644 --- a/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json +++ b/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5fg3-793p-9qxp", - "modified": "2024-04-03T15:30:41Z", + "modified": "2025-03-28T21:30:38Z", "published": "2024-04-03T15:30:41Z", "aliases": [ "CVE-2024-30571" ], "details": "An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T13:16:02Z" diff --git a/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json b/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json index 3abd8443e5c..200407b5170 100644 --- a/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json +++ b/advisories/unreviewed/2024/04/GHSA-63p9-g7fv-6cvr/GHSA-63p9-g7fv-6cvr.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-656c-x8x7-w3c6/GHSA-656c-x8x7-w3c6.json b/advisories/unreviewed/2024/04/GHSA-656c-x8x7-w3c6/GHSA-656c-x8x7-w3c6.json index f912b1a5f86..0d5769bdb97 100644 --- a/advisories/unreviewed/2024/04/GHSA-656c-x8x7-w3c6/GHSA-656c-x8x7-w3c6.json +++ b/advisories/unreviewed/2024/04/GHSA-656c-x8x7-w3c6/GHSA-656c-x8x7-w3c6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6658-9vpg-8pq9/GHSA-6658-9vpg-8pq9.json b/advisories/unreviewed/2024/04/GHSA-6658-9vpg-8pq9/GHSA-6658-9vpg-8pq9.json index 08848a311c4..ce3c7aafe52 100644 --- a/advisories/unreviewed/2024/04/GHSA-6658-9vpg-8pq9/GHSA-6658-9vpg-8pq9.json +++ b/advisories/unreviewed/2024/04/GHSA-6658-9vpg-8pq9/GHSA-6658-9vpg-8pq9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json b/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json index 8c9bee1ba2c..588d9aac840 100644 --- a/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json +++ b/advisories/unreviewed/2024/04/GHSA-6hjj-7r3r-92p5/GHSA-6hjj-7r3r-92p5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-345" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json b/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json index e7ea7eabf5a..37a4176eca6 100644 --- a/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json +++ b/advisories/unreviewed/2024/04/GHSA-7c7j-m7mw-3vfh/GHSA-7c7j-m7mw-3vfh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7j-m7mw-3vfh", - "modified": "2024-04-17T18:31:36Z", + "modified": "2025-03-28T21:30:40Z", "published": "2024-04-17T18:31:36Z", "aliases": [ "CVE-2024-30981" ], "details": "SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T17:15:15Z" diff --git a/advisories/unreviewed/2024/04/GHSA-83jp-w434-jv4p/GHSA-83jp-w434-jv4p.json b/advisories/unreviewed/2024/04/GHSA-83jp-w434-jv4p/GHSA-83jp-w434-jv4p.json index b391420bd8f..3e807aea719 100644 --- a/advisories/unreviewed/2024/04/GHSA-83jp-w434-jv4p/GHSA-83jp-w434-jv4p.json +++ b/advisories/unreviewed/2024/04/GHSA-83jp-w434-jv4p/GHSA-83jp-w434-jv4p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-963m-mgxp-cg5w/GHSA-963m-mgxp-cg5w.json b/advisories/unreviewed/2024/04/GHSA-963m-mgxp-cg5w/GHSA-963m-mgxp-cg5w.json index 7701c3edffe..4edc721d781 100644 --- a/advisories/unreviewed/2024/04/GHSA-963m-mgxp-cg5w/GHSA-963m-mgxp-cg5w.json +++ b/advisories/unreviewed/2024/04/GHSA-963m-mgxp-cg5w/GHSA-963m-mgxp-cg5w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-963m-mgxp-cg5w", - "modified": "2024-04-29T18:30:44Z", + "modified": "2025-03-28T21:30:40Z", "published": "2024-04-29T18:30:44Z", "aliases": [ "CVE-2023-46270" ], "details": "MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T16:15:34Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json b/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json index 511ea091d61..7a5b5eee214 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json +++ b/advisories/unreviewed/2024/04/GHSA-c8c6-87mv-3fm9/GHSA-c8c6-87mv-3fm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c8c6-87mv-3fm9", - "modified": "2024-04-05T18:30:35Z", + "modified": "2025-03-28T21:30:39Z", "published": "2024-04-05T18:30:35Z", "aliases": [ "CVE-2024-28065" ], "details": "In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T18:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json b/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json index d5be7dc5a61..df234f0eafc 100644 --- a/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json +++ b/advisories/unreviewed/2024/04/GHSA-g36v-5299-38pr/GHSA-g36v-5299-38pr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g36v-5299-38pr", - "modified": "2024-04-05T18:30:33Z", + "modified": "2025-03-28T21:30:39Z", "published": "2024-04-05T18:30:33Z", "aliases": [ "CVE-2023-48426" ], - "details": "u-boot bug that allows for u-boot shell and interrupt over UART\n", + "details": "u-boot bug that allows for u-boot shell and interrupt over UART", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-g399-gv5f-cqhf/GHSA-g399-gv5f-cqhf.json b/advisories/unreviewed/2024/04/GHSA-g399-gv5f-cqhf/GHSA-g399-gv5f-cqhf.json index 60bb3f46df4..0591b04f58e 100644 --- a/advisories/unreviewed/2024/04/GHSA-g399-gv5f-cqhf/GHSA-g399-gv5f-cqhf.json +++ b/advisories/unreviewed/2024/04/GHSA-g399-gv5f-cqhf/GHSA-g399-gv5f-cqhf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gqfm-c246-rhqp/GHSA-gqfm-c246-rhqp.json b/advisories/unreviewed/2024/04/GHSA-gqfm-c246-rhqp/GHSA-gqfm-c246-rhqp.json index 998cd7318bd..f2aaf5bca6e 100644 --- a/advisories/unreviewed/2024/04/GHSA-gqfm-c246-rhqp/GHSA-gqfm-c246-rhqp.json +++ b/advisories/unreviewed/2024/04/GHSA-gqfm-c246-rhqp/GHSA-gqfm-c246-rhqp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-288" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json b/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json index 5ef1ffda435..720afbf3625 100644 --- a/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json +++ b/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mcj7-3h2r-x449/GHSA-mcj7-3h2r-x449.json b/advisories/unreviewed/2024/04/GHSA-mcj7-3h2r-x449/GHSA-mcj7-3h2r-x449.json index 6488db70858..dd0c58613d3 100644 --- a/advisories/unreviewed/2024/04/GHSA-mcj7-3h2r-x449/GHSA-mcj7-3h2r-x449.json +++ b/advisories/unreviewed/2024/04/GHSA-mcj7-3h2r-x449/GHSA-mcj7-3h2r-x449.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p5cr-h893-2pjv/GHSA-p5cr-h893-2pjv.json b/advisories/unreviewed/2024/04/GHSA-p5cr-h893-2pjv/GHSA-p5cr-h893-2pjv.json index ac8d05308bb..d8b3eaaac66 100644 --- a/advisories/unreviewed/2024/04/GHSA-p5cr-h893-2pjv/GHSA-p5cr-h893-2pjv.json +++ b/advisories/unreviewed/2024/04/GHSA-p5cr-h893-2pjv/GHSA-p5cr-h893-2pjv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json b/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json index df8de843e9a..5fb0b8af18d 100644 --- a/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json +++ b/advisories/unreviewed/2024/04/GHSA-qgf9-6cxx-q2qv/GHSA-qgf9-6cxx-q2qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgf9-6cxx-q2qv", - "modified": "2024-04-04T09:30:34Z", + "modified": "2025-03-28T21:30:39Z", "published": "2024-04-04T09:30:34Z", "aliases": [ "CVE-2024-29375" ], "details": "CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1236" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T07:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json b/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json index 71e9071c7a9..8b6ab457360 100644 --- a/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json +++ b/advisories/unreviewed/2024/04/GHSA-r27r-5fwh-vxqw/GHSA-r27r-5fwh-vxqw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json index 8d550aaa86b..bbe2e4f7ec5 100644 --- a/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json +++ b/advisories/unreviewed/2024/04/GHSA-rgmh-52xq-8wg7/GHSA-rgmh-52xq-8wg7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w3ph-2h93-f367/GHSA-w3ph-2h93-f367.json b/advisories/unreviewed/2024/04/GHSA-w3ph-2h93-f367/GHSA-w3ph-2h93-f367.json index 00fc912c807..88da3b02875 100644 --- a/advisories/unreviewed/2024/04/GHSA-w3ph-2h93-f367/GHSA-w3ph-2h93-f367.json +++ b/advisories/unreviewed/2024/04/GHSA-w3ph-2h93-f367/GHSA-w3ph-2h93-f367.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3ph-2h93-f367", - "modified": "2024-04-01T03:30:40Z", + "modified": "2025-03-28T21:30:38Z", "published": "2024-04-01T03:30:40Z", "aliases": [ "CVE-2024-20045" ], "details": "In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08024748; Issue ID: ALPS08029526.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-01T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json index 3c54786a275..c38a9d360f5 100644 --- a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json +++ b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7x4-hw9x-fprc", - "modified": "2024-04-08T06:31:30Z", + "modified": "2025-03-28T21:30:39Z", "published": "2024-04-08T06:31:30Z", "aliases": [ "CVE-2024-1958" ], "details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T05:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json b/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json index d8c93df8541..545d3e209b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json +++ b/advisories/unreviewed/2024/05/GHSA-36cp-x9pq-r87w/GHSA-36cp-x9pq-r87w.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-758" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-6q28-4fqw-89m2/GHSA-6q28-4fqw-89m2.json b/advisories/unreviewed/2024/05/GHSA-6q28-4fqw-89m2/GHSA-6q28-4fqw-89m2.json index b56e1a56bfd..3e822d2f50d 100644 --- a/advisories/unreviewed/2024/05/GHSA-6q28-4fqw-89m2/GHSA-6q28-4fqw-89m2.json +++ b/advisories/unreviewed/2024/05/GHSA-6q28-4fqw-89m2/GHSA-6q28-4fqw-89m2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json b/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json index d22262b0310..eaa791a655e 100644 --- a/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json +++ b/advisories/unreviewed/2024/05/GHSA-8c9g-w38h-qxj2/GHSA-8c9g-w38h-qxj2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8c9g-w38h-qxj2", - "modified": "2024-05-14T18:30:53Z", + "modified": "2025-03-28T21:30:41Z", "published": "2024-05-14T18:30:53Z", "aliases": [ "CVE-2024-3941" ], "details": "The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:42:36Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json b/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json index 5d8c6874611..dfce0a90882 100644 --- a/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json +++ b/advisories/unreviewed/2024/05/GHSA-c989-6j3h-w4c3/GHSA-c989-6j3h-w4c3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json b/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json index 96c776879f0..cb9199e3e99 100644 --- a/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json +++ b/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-359" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json b/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json index e1b1f1d2abb..b2b5fa56e34 100644 --- a/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json +++ b/advisories/unreviewed/2024/05/GHSA-h2pj-pf6w-85p2/GHSA-h2pj-pf6w-85p2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1021" + "CWE-1021", + "CWE-451" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json b/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json index 5d40e37f0b0..23c25b74a39 100644 --- a/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json +++ b/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-444" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json b/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json index efa8835726b..7e79aa72a32 100644 --- a/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json +++ b/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-295" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-mxqp-c3qj-mg2r/GHSA-mxqp-c3qj-mg2r.json b/advisories/unreviewed/2024/05/GHSA-mxqp-c3qj-mg2r/GHSA-mxqp-c3qj-mg2r.json index 06bdeebc91a..74297773ee5 100644 --- a/advisories/unreviewed/2024/05/GHSA-mxqp-c3qj-mg2r/GHSA-mxqp-c3qj-mg2r.json +++ b/advisories/unreviewed/2024/05/GHSA-mxqp-c3qj-mg2r/GHSA-mxqp-c3qj-mg2r.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json b/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json index 657b953b3c9..af2d26a3c72 100644 --- a/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json +++ b/advisories/unreviewed/2024/05/GHSA-p45m-mr9q-rx4p/GHSA-p45m-mr9q-rx4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p45m-mr9q-rx4p", - "modified": "2024-05-23T06:30:46Z", + "modified": "2025-03-28T21:30:41Z", "published": "2024-05-23T06:30:46Z", "aliases": [ "CVE-2024-3918" ], "details": "The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T06:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p4w9-8j85-2xw6/GHSA-p4w9-8j85-2xw6.json b/advisories/unreviewed/2024/05/GHSA-p4w9-8j85-2xw6/GHSA-p4w9-8j85-2xw6.json index db99df8f066..8e62ff5b0fa 100644 --- a/advisories/unreviewed/2024/05/GHSA-p4w9-8j85-2xw6/GHSA-p4w9-8j85-2xw6.json +++ b/advisories/unreviewed/2024/05/GHSA-p4w9-8j85-2xw6/GHSA-p4w9-8j85-2xw6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-v2jj-6wcp-962x/GHSA-v2jj-6wcp-962x.json b/advisories/unreviewed/2024/05/GHSA-v2jj-6wcp-962x/GHSA-v2jj-6wcp-962x.json index eafa88a09ff..aee567f497f 100644 --- a/advisories/unreviewed/2024/05/GHSA-v2jj-6wcp-962x/GHSA-v2jj-6wcp-962x.json +++ b/advisories/unreviewed/2024/05/GHSA-v2jj-6wcp-962x/GHSA-v2jj-6wcp-962x.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v2jj-6wcp-962x", - "modified": "2024-05-14T18:30:47Z", + "modified": "2025-03-28T21:30:41Z", "published": "2024-05-14T18:30:47Z", "aliases": [ "CVE-2024-32739" ], - "details": "A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the \"query_ptask_verbose\" function within MCUDBHelper.\n", + "details": "A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the \"query_ptask_verbose\" function within MCUDBHelper.", "severity": [ { "type": "CVSS_V3", @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-mhx3-v872-pgp6/GHSA-mhx3-v872-pgp6.json b/advisories/unreviewed/2024/06/GHSA-mhx3-v872-pgp6/GHSA-mhx3-v872-pgp6.json index 3e5fbfd977a..243e94ec48c 100644 --- a/advisories/unreviewed/2024/06/GHSA-mhx3-v872-pgp6/GHSA-mhx3-v872-pgp6.json +++ b/advisories/unreviewed/2024/06/GHSA-mhx3-v872-pgp6/GHSA-mhx3-v872-pgp6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mhx3-v872-pgp6", - "modified": "2024-06-04T06:30:37Z", + "modified": "2025-03-28T21:30:42Z", "published": "2024-06-04T06:30:37Z", "aliases": [ "CVE-2024-4857" ], "details": "The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T06:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xm6m-vgxj-3m5c/GHSA-xm6m-vgxj-3m5c.json b/advisories/unreviewed/2025/01/GHSA-xm6m-vgxj-3m5c/GHSA-xm6m-vgxj-3m5c.json index 992ecf9520b..84f85be9d29 100644 --- a/advisories/unreviewed/2025/01/GHSA-xm6m-vgxj-3m5c/GHSA-xm6m-vgxj-3m5c.json +++ b/advisories/unreviewed/2025/01/GHSA-xm6m-vgxj-3m5c/GHSA-xm6m-vgxj-3m5c.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-327", "CWE-780" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json b/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json index b997aadb254..e6d5ea5528c 100644 --- a/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json +++ b/advisories/unreviewed/2025/02/GHSA-x8vm-v82f-5f3c/GHSA-x8vm-v82f-5f3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8vm-v82f-5f3c", - "modified": "2025-02-12T15:32:02Z", + "modified": "2025-03-28T21:30:43Z", "published": "2025-02-12T15:32:02Z", "aliases": [ "CVE-2024-12251" diff --git a/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json b/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json new file mode 100644 index 00000000000..3e6f9942853 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2fqc-9m76-ppwc/GHSA-2fqc-9m76-ppwc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fqc-9m76-ppwc", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2024-56975" + ], + "details": "InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56975" + }, + { + "type": "WEB", + "url": "https://github.com/InvoicePlane/InvoicePlane/pull/1127" + }, + { + "type": "WEB", + "url": "https://github.com/InvoicePlane/InvoicePlane/pull/1166" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2q39-w2hw-2pjm/GHSA-2q39-w2hw-2pjm.json b/advisories/unreviewed/2025/03/GHSA-2q39-w2hw-2pjm/GHSA-2q39-w2hw-2pjm.json new file mode 100644 index 00000000000..e8228e8f52d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2q39-w2hw-2pjm/GHSA-2q39-w2hw-2pjm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q39-w2hw-2pjm", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2024-6875" + ], + "details": "A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6875" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6875" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2298555" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2x2q-xfv9-3v6p/GHSA-2x2q-xfv9-3v6p.json b/advisories/unreviewed/2025/03/GHSA-2x2q-xfv9-3v6p/GHSA-2x2q-xfv9-3v6p.json index 7e2c2741f8a..9faed7b015e 100644 --- a/advisories/unreviewed/2025/03/GHSA-2x2q-xfv9-3v6p/GHSA-2x2q-xfv9-3v6p.json +++ b/advisories/unreviewed/2025/03/GHSA-2x2q-xfv9-3v6p/GHSA-2x2q-xfv9-3v6p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x2q-xfv9-3v6p", - "modified": "2025-03-15T06:30:33Z", + "modified": "2025-03-28T21:30:45Z", "published": "2025-03-15T06:30:33Z", "aliases": [ "CVE-2025-1669" diff --git a/advisories/unreviewed/2025/03/GHSA-4h4x-4m75-47j4/GHSA-4h4x-4m75-47j4.json b/advisories/unreviewed/2025/03/GHSA-4h4x-4m75-47j4/GHSA-4h4x-4m75-47j4.json new file mode 100644 index 00000000000..704d0363745 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4h4x-4m75-47j4/GHSA-4h4x-4m75-47j4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h4x-4m75-47j4", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2024-38985" + ], + "details": "janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38985" + }, + { + "type": "WEB", + "url": "https://github.com/janryWang/depath/issues/11" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/32c0a48023036e51918f6a098f21953d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-68jj-p8cr-xff6/GHSA-68jj-p8cr-xff6.json b/advisories/unreviewed/2025/03/GHSA-68jj-p8cr-xff6/GHSA-68jj-p8cr-xff6.json new file mode 100644 index 00000000000..b9a7169717b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-68jj-p8cr-xff6/GHSA-68jj-p8cr-xff6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68jj-p8cr-xff6", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2025-2922" + ], + "details": "A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2922" + }, + { + "type": "WEB", + "url": "https://scoozi.substack.com/p/hacking-a-netis-wf-2404-router-with" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301897" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301897" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521039" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T19:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json b/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json new file mode 100644 index 00000000000..a2b2aa3d817 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69xp-rrpm-qmj5/GHSA-69xp-rrpm-qmj5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69xp-rrpm-qmj5", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2025-2926" + ], + "details": "A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2926" + }, + { + "type": "WEB", + "url": "https://github.com/HDFGroup/hdf5/issues/5384" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301901" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301901" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521246" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json b/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json new file mode 100644 index 00000000000..dbe2bc6fc3c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-798j-m949-2j7c/GHSA-798j-m949-2j7c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-798j-m949-2j7c", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2024-24292" + ], + "details": "A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24292" + }, + { + "type": "WEB", + "url": "https://gist.github.com/tariqhawis/a8b2c936622c885558173c37df0a77d9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json b/advisories/unreviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json new file mode 100644 index 00000000000..7578afdba1a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-799q-f2px-wx8c", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2024-38988" + ], + "details": "alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38988" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/4c5dfb66bea377889c44dd6c8af28713" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json b/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json new file mode 100644 index 00000000000..367a88a93a6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8j53-82pv-32wq/GHSA-8j53-82pv-32wq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j53-82pv-32wq", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2025-2925" + ], + "details": "A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2925" + }, + { + "type": "WEB", + "url": "https://github.com/HDFGroup/hdf5/issues/5383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301900" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301900" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9rhg-254w-fh9x/GHSA-9rhg-254w-fh9x.json b/advisories/unreviewed/2025/03/GHSA-9rhg-254w-fh9x/GHSA-9rhg-254w-fh9x.json new file mode 100644 index 00000000000..8cc2ec5303d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9rhg-254w-fh9x/GHSA-9rhg-254w-fh9x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rhg-254w-fh9x", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2024-57083" + ], + "details": "A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57083" + }, + { + "type": "WEB", + "url": "https://github.com/Redocly/redoc/issues/2499" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cpfc-m8w6-m9gf/GHSA-cpfc-m8w6-m9gf.json b/advisories/unreviewed/2025/03/GHSA-cpfc-m8w6-m9gf/GHSA-cpfc-m8w6-m9gf.json index 9050f2ef221..13c8d32cf14 100644 --- a/advisories/unreviewed/2025/03/GHSA-cpfc-m8w6-m9gf/GHSA-cpfc-m8w6-m9gf.json +++ b/advisories/unreviewed/2025/03/GHSA-cpfc-m8w6-m9gf/GHSA-cpfc-m8w6-m9gf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpfc-m8w6-m9gf", - "modified": "2025-03-15T06:30:33Z", + "modified": "2025-03-28T21:30:45Z", "published": "2025-03-15T06:30:33Z", "aliases": [ "CVE-2025-1670" diff --git a/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json b/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json new file mode 100644 index 00000000000..8c99ef75f74 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fqw7-q4hr-f893/GHSA-fqw7-q4hr-f893.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqw7-q4hr-f893", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:46Z", + "aliases": [ + "CVE-2025-2924" + ], + "details": "A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2924" + }, + { + "type": "WEB", + "url": "https://github.com/HDFGroup/hdf5/issues/5382" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301899" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301899" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521170" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json b/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json new file mode 100644 index 00000000000..a300e15f742 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gq5x-xc6w-4j57/GHSA-gq5x-xc6w-4j57.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq5x-xc6w-4j57", + "modified": "2025-03-28T21:30:46Z", + "published": "2025-03-28T21:30:45Z", + "aliases": [ + "CVE-2025-2923" + ], + "details": "A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5F_addr_encode_len of the file src/H5Fint.c. The manipulation of the argument pp leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2923" + }, + { + "type": "WEB", + "url": "https://github.com/HDFGroup/hdf5/issues/5381" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301898" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301898" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T19:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jf6p-4hgv-v6qh/GHSA-jf6p-4hgv-v6qh.json b/advisories/unreviewed/2025/03/GHSA-jf6p-4hgv-v6qh/GHSA-jf6p-4hgv-v6qh.json new file mode 100644 index 00000000000..f6025189c44 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jf6p-4hgv-v6qh/GHSA-jf6p-4hgv-v6qh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf6p-4hgv-v6qh", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2025-28254" + ], + "details": "Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().", + "severity": [], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/Leantime/leantime/security/advisories/GHSA-95j3-435g-vjcp" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28254" + }, + { + "type": "WEB", + "url": "https://github.com/Leantime/leantime/commit/ce1d2073e4601183e1bdd90f4b433d16aee46a50" + }, + { + "type": "WEB", + "url": "https://github.com/Leantime/leantime/blob/0e7ddbbe3d582f657a1dddfef7b3419ae588cbf7/app/Domain/Notifications/Services/Notifications.php#L128" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q2m5-q4jg-g9g2/GHSA-q2m5-q4jg-g9g2.json b/advisories/unreviewed/2025/03/GHSA-q2m5-q4jg-g9g2/GHSA-q2m5-q4jg-g9g2.json index 74470084bfb..e85b68bee31 100644 --- a/advisories/unreviewed/2025/03/GHSA-q2m5-q4jg-g9g2/GHSA-q2m5-q4jg-g9g2.json +++ b/advisories/unreviewed/2025/03/GHSA-q2m5-q4jg-g9g2/GHSA-q2m5-q4jg-g9g2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q2m5-q4jg-g9g2", - "modified": "2025-03-15T06:30:33Z", + "modified": "2025-03-28T21:30:45Z", "published": "2025-03-15T06:30:33Z", "aliases": [ "CVE-2025-1668" diff --git a/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json b/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json new file mode 100644 index 00000000000..ce20113a75f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q87j-52xg-48j5/GHSA-q87j-52xg-48j5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q87j-52xg-48j5", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2025-22953" + ], + "details": "A SQL injection vulnerability exists in the Epicor HCM 2021 1.9, specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22953" + }, + { + "type": "WEB", + "url": "https://tinted-hollyhock-92d.notion.site/EPICOR-HCM-Unauthenticated-Blind-SQL-Injection-CVE-2025-22953-170f1fdee211803988d1c9255a8cb904?pvs=4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json b/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json new file mode 100644 index 00000000000..34acc3c7117 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r5v3-gf6q-fgpm/GHSA-r5v3-gf6q-fgpm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5v3-gf6q-fgpm", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2025-2927" + ], + "details": "A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown function of the file /parameter/getFileTypeList.jsp. The manipulation of the argument typename leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2927" + }, + { + "type": "WEB", + "url": "https://github.com/Rain1er/report/blob/main/CDG/Mg%3D%3D.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301902" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301902" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json b/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json new file mode 100644 index 00000000000..7ed48c42766 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rhpc-22qh-75f4/GHSA-rhpc-22qh-75f4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhpc-22qh-75f4", + "modified": "2025-03-28T21:30:47Z", + "published": "2025-03-28T21:30:47Z", + "aliases": [ + "CVE-2025-28256" + ], + "details": "An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28256" + }, + { + "type": "WEB", + "url": "https://github.com/ZackSecurity/VulnerReport/blob/cve/totolink/A3100R/1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vxrx-37r3-23mw/GHSA-vxrx-37r3-23mw.json b/advisories/unreviewed/2025/03/GHSA-vxrx-37r3-23mw/GHSA-vxrx-37r3-23mw.json index 2033f6246da..3d87b33ce75 100644 --- a/advisories/unreviewed/2025/03/GHSA-vxrx-37r3-23mw/GHSA-vxrx-37r3-23mw.json +++ b/advisories/unreviewed/2025/03/GHSA-vxrx-37r3-23mw/GHSA-vxrx-37r3-23mw.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-79" ], "severity": "MODERATE",