From fe29a0bd2adc3a6a882f0db60c35fa7ed1f7cffc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Mar 2025 21:32:36 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r5gx-c49x-h878.json | 65 +++++++++++++++++++ .../GHSA-5p5j-vwv3-3hm9.json | 4 +- .../GHSA-7rc9-5vxf-3h3m.json | 3 +- .../GHSA-j82c-6hc3-3qc4.json | 4 +- .../GHSA-wj5g-5xxg-2f92.json | 4 +- .../GHSA-x9cj-w6h9-jcrq.json | 2 +- .../GHSA-j2v6-fxfh-8942.json | 2 +- .../GHSA-pj6g-c6r4-xjxf.json | 2 +- .../GHSA-2j99-5q75-3f57.json | 6 +- .../GHSA-2mqv-mwvq-mv8h.json | 36 ++++++++++ .../GHSA-2v39-r86v-x85c.json | 36 ++++++++++ .../GHSA-3373-7xwg-mr2v.json | 36 ++++++++++ .../GHSA-37mm-53pr-gqf6.json | 36 ++++++++++ .../GHSA-38cw-7g54-c3g7.json | 36 ++++++++++ .../GHSA-38p6-9wh4-q95c.json | 52 +++++++++++++++ .../GHSA-38w2-wrgq-24qv.json | 36 ++++++++++ .../GHSA-3gq3-9cq7-288g.json | 36 ++++++++++ .../GHSA-3mw5-7hq7-6p5w.json | 36 ++++++++++ .../GHSA-3q6w-vp42-26vx.json | 36 ++++++++++ .../GHSA-3q87-289f-8v5m.json | 36 ++++++++++ .../GHSA-4595-95wg-87wc.json | 36 ++++++++++ .../GHSA-47m3-gw83-4cqc.json | 36 ++++++++++ .../GHSA-49g7-rpc5-m25r.json | 36 ++++++++++ .../GHSA-4cmc-mjvg-x5mp.json | 36 ++++++++++ .../GHSA-4p9p-c25q-hmp5.json | 36 ++++++++++ .../GHSA-4w7g-22mj-6g5c.json | 15 +++-- .../GHSA-52r6-v45h-gh94.json | 36 ++++++++++ .../GHSA-564r-jgrm-jr8x.json | 52 +++++++++++++++ .../GHSA-57xq-wfw8-mh7x.json | 15 +++-- .../GHSA-5fj2-xqgx-m987.json | 3 +- .../GHSA-5rcp-gqjx-6m49.json | 36 ++++++++++ .../GHSA-5x4g-pq34-vr6w.json | 36 ++++++++++ .../GHSA-5xgg-8whq-9cvp.json | 36 ++++++++++ .../GHSA-5xpm-7q7v-rpvf.json | 33 ++++++++++ .../GHSA-62qj-786m-q427.json | 15 +++-- .../GHSA-68fw-47jh-hgqq.json | 36 ++++++++++ .../GHSA-69jh-579f-grhj.json | 36 ++++++++++ .../GHSA-6pqf-q9v8-mg56.json | 36 ++++++++++ .../GHSA-6w9v-343p-v4qm.json | 36 ++++++++++ .../GHSA-78p3-88v5-4j32.json | 36 ++++++++++ .../GHSA-7j7m-w4qx-7vmf.json | 29 +++++++++ .../GHSA-826x-6xrj-6vg9.json | 36 ++++++++++ .../GHSA-87qg-334x-f2cw.json | 36 ++++++++++ .../GHSA-88hj-hc74-5p58.json | 36 ++++++++++ .../GHSA-8h6g-xc7x-fxv4.json | 36 ++++++++++ .../GHSA-973v-5qg7-x6qq.json | 36 ++++++++++ .../GHSA-98pv-v482-w48q.json | 36 ++++++++++ .../GHSA-9c37-6wgw-96fm.json | 36 ++++++++++ .../GHSA-9g29-43mh-wwf6.json | 36 ++++++++++ .../GHSA-9vmp-4f49-fr63.json | 36 ++++++++++ .../GHSA-9wgm-76rq-7796.json | 36 ++++++++++ .../GHSA-9wv3-p38x-5wqv.json | 11 +++- .../GHSA-9xm2-hxxj-hgq7.json | 29 +++++++++ .../GHSA-c34r-ww43-wqcj.json | 2 +- .../GHSA-c39v-vghw-5cg6.json | 36 ++++++++++ .../GHSA-c67q-hx6m-m5wv.json | 36 ++++++++++ .../GHSA-c72g-6v9g-4gq7.json | 36 ++++++++++ .../GHSA-ch57-3pgj-79wf.json | 15 +++-- .../GHSA-crp6-j9hr-46pc.json | 36 ++++++++++ .../GHSA-f33v-j5fp-77mf.json | 36 ++++++++++ .../GHSA-f95q-7848-gf6g.json | 36 ++++++++++ .../GHSA-f99m-pcvw-8vpj.json | 3 +- .../GHSA-fph4-j8gq-8j6r.json | 36 ++++++++++ .../GHSA-gc4p-wgw2-chm7.json | 36 ++++++++++ .../GHSA-ghmw-x83x-hpmp.json | 36 ++++++++++ .../GHSA-gjqp-22h8-mr74.json | 36 ++++++++++ .../GHSA-grfv-8m4f-679x.json | 36 ++++++++++ .../GHSA-h2p3-j299-jf37.json | 52 +++++++++++++++ .../GHSA-h4q2-fjh5-pc8r.json | 36 ++++++++++ .../GHSA-h8p2-3hf9-pqg4.json | 36 ++++++++++ .../GHSA-hphx-8248-267c.json | 36 ++++++++++ .../GHSA-hxm7-743q-rcrf.json | 36 ++++++++++ .../GHSA-hxrr-rqj9-gv3m.json | 36 ++++++++++ .../GHSA-j62x-7rpr-8cwh.json | 36 ++++++++++ .../GHSA-m2c6-j26g-8x96.json | 36 ++++++++++ .../GHSA-m3jw-9qqr-c9jj.json | 15 +++-- .../GHSA-mcqm-xqr9-mjvr.json | 36 ++++++++++ .../GHSA-mwr9-w823-pvwp.json | 36 ++++++++++ .../GHSA-mx4h-4r93-47mh.json | 29 +++++++++ .../GHSA-p26c-54hm-qqv3.json | 36 ++++++++++ .../GHSA-p2v5-rvqj-c2xc.json | 11 +++- .../GHSA-p62r-6qpp-j89h.json | 36 ++++++++++ .../GHSA-p6xj-35fm-qgmf.json | 36 ++++++++++ .../GHSA-p9r8-xjx7-v86q.json | 11 +++- .../GHSA-pj98-cfvv-rcxg.json | 36 ++++++++++ .../GHSA-pqxq-83px-8phf.json | 15 +++-- .../GHSA-qfwc-5f7q-8w42.json | 36 ++++++++++ .../GHSA-qg74-9qxh-vmv5.json | 36 ++++++++++ .../GHSA-qqpv-m393-pw8r.json | 36 ++++++++++ .../GHSA-qv26-j3vv-r7p7.json | 36 ++++++++++ .../GHSA-qvv5-5865-pfw8.json | 36 ++++++++++ .../GHSA-rgrc-x3v2-4gmm.json | 36 ++++++++++ .../GHSA-rhfm-q4h8-frxp.json | 36 ++++++++++ .../GHSA-rmq3-57w7-fmhx.json | 36 ++++++++++ .../GHSA-rq7j-84m9-32jh.json | 36 ++++++++++ .../GHSA-v35m-rx24-w6pg.json | 36 ++++++++++ .../GHSA-vcxc-vj6w-2ffm.json | 36 ++++++++++ .../GHSA-vfrv-g5j6-mgmv.json | 15 +++-- .../GHSA-vhwr-gfg8-hm5j.json | 36 ++++++++++ .../GHSA-vrc8-hxm5-v8wx.json | 36 ++++++++++ .../GHSA-vxg2-q7pw-5mpg.json | 36 ++++++++++ .../GHSA-w56w-w5xr-q52m.json | 15 +++-- .../GHSA-w6jf-6fg2-jpjx.json | 36 ++++++++++ .../GHSA-w8xg-2rhp-v8c4.json | 36 ++++++++++ .../GHSA-wc6w-q8v8-w3c7.json | 36 ++++++++++ .../GHSA-wfr6-fwjh-5jx6.json | 36 ++++++++++ .../GHSA-wh9x-w9vv-rjf9.json | 36 ++++++++++ .../GHSA-wq5j-wjp2-4f74.json | 36 ++++++++++ .../GHSA-x53r-mfrq-c435.json | 2 +- .../GHSA-xcpx-xw8r-x8rf.json | 36 ++++++++++ .../GHSA-xgx2-r4f9-h8w3.json | 36 ++++++++++ .../GHSA-xpq2-2hq8-6f42.json | 36 ++++++++++ .../GHSA-xwx7-4rrg-r95g.json | 36 ++++++++++ 113 files changed, 3430 insertions(+), 53 deletions(-) create mode 100644 advisories/github-reviewed/2025/03/GHSA-r5gx-c49x-h878/GHSA-r5gx-c49x-h878.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2mqv-mwvq-mv8h/GHSA-2mqv-mwvq-mv8h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2v39-r86v-x85c/GHSA-2v39-r86v-x85c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3373-7xwg-mr2v/GHSA-3373-7xwg-mr2v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-37mm-53pr-gqf6/GHSA-37mm-53pr-gqf6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38cw-7g54-c3g7/GHSA-38cw-7g54-c3g7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38p6-9wh4-q95c/GHSA-38p6-9wh4-q95c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38w2-wrgq-24qv/GHSA-38w2-wrgq-24qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3gq3-9cq7-288g/GHSA-3gq3-9cq7-288g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3mw5-7hq7-6p5w/GHSA-3mw5-7hq7-6p5w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3q6w-vp42-26vx/GHSA-3q6w-vp42-26vx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3q87-289f-8v5m/GHSA-3q87-289f-8v5m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4595-95wg-87wc/GHSA-4595-95wg-87wc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-47m3-gw83-4cqc/GHSA-47m3-gw83-4cqc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-49g7-rpc5-m25r/GHSA-49g7-rpc5-m25r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cmc-mjvg-x5mp/GHSA-4cmc-mjvg-x5mp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4p9p-c25q-hmp5/GHSA-4p9p-c25q-hmp5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-52r6-v45h-gh94/GHSA-52r6-v45h-gh94.json create mode 100644 advisories/unreviewed/2025/03/GHSA-564r-jgrm-jr8x/GHSA-564r-jgrm-jr8x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5rcp-gqjx-6m49/GHSA-5rcp-gqjx-6m49.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5x4g-pq34-vr6w/GHSA-5x4g-pq34-vr6w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5xgg-8whq-9cvp/GHSA-5xgg-8whq-9cvp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-68fw-47jh-hgqq/GHSA-68fw-47jh-hgqq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-69jh-579f-grhj/GHSA-69jh-579f-grhj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6pqf-q9v8-mg56/GHSA-6pqf-q9v8-mg56.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w9v-343p-v4qm/GHSA-6w9v-343p-v4qm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-78p3-88v5-4j32/GHSA-78p3-88v5-4j32.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-826x-6xrj-6vg9/GHSA-826x-6xrj-6vg9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-87qg-334x-f2cw/GHSA-87qg-334x-f2cw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-88hj-hc74-5p58/GHSA-88hj-hc74-5p58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8h6g-xc7x-fxv4/GHSA-8h6g-xc7x-fxv4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-973v-5qg7-x6qq/GHSA-973v-5qg7-x6qq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-98pv-v482-w48q/GHSA-98pv-v482-w48q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9c37-6wgw-96fm/GHSA-9c37-6wgw-96fm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9g29-43mh-wwf6/GHSA-9g29-43mh-wwf6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vmp-4f49-fr63/GHSA-9vmp-4f49-fr63.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9wgm-76rq-7796/GHSA-9wgm-76rq-7796.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c39v-vghw-5cg6/GHSA-c39v-vghw-5cg6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c67q-hx6m-m5wv/GHSA-c67q-hx6m-m5wv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c72g-6v9g-4gq7/GHSA-c72g-6v9g-4gq7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-crp6-j9hr-46pc/GHSA-crp6-j9hr-46pc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f33v-j5fp-77mf/GHSA-f33v-j5fp-77mf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f95q-7848-gf6g/GHSA-f95q-7848-gf6g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fph4-j8gq-8j6r/GHSA-fph4-j8gq-8j6r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gc4p-wgw2-chm7/GHSA-gc4p-wgw2-chm7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ghmw-x83x-hpmp/GHSA-ghmw-x83x-hpmp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gjqp-22h8-mr74/GHSA-gjqp-22h8-mr74.json create mode 100644 advisories/unreviewed/2025/03/GHSA-grfv-8m4f-679x/GHSA-grfv-8m4f-679x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h2p3-j299-jf37/GHSA-h2p3-j299-jf37.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4q2-fjh5-pc8r/GHSA-h4q2-fjh5-pc8r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h8p2-3hf9-pqg4/GHSA-h8p2-3hf9-pqg4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hphx-8248-267c/GHSA-hphx-8248-267c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hxm7-743q-rcrf/GHSA-hxm7-743q-rcrf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hxrr-rqj9-gv3m/GHSA-hxrr-rqj9-gv3m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j62x-7rpr-8cwh/GHSA-j62x-7rpr-8cwh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2c6-j26g-8x96/GHSA-m2c6-j26g-8x96.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mcqm-xqr9-mjvr/GHSA-mcqm-xqr9-mjvr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mwr9-w823-pvwp/GHSA-mwr9-w823-pvwp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p26c-54hm-qqv3/GHSA-p26c-54hm-qqv3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p62r-6qpp-j89h/GHSA-p62r-6qpp-j89h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p6xj-35fm-qgmf/GHSA-p6xj-35fm-qgmf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pj98-cfvv-rcxg/GHSA-pj98-cfvv-rcxg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qfwc-5f7q-8w42/GHSA-qfwc-5f7q-8w42.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qg74-9qxh-vmv5/GHSA-qg74-9qxh-vmv5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qqpv-m393-pw8r/GHSA-qqpv-m393-pw8r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qv26-j3vv-r7p7/GHSA-qv26-j3vv-r7p7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qvv5-5865-pfw8/GHSA-qvv5-5865-pfw8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rgrc-x3v2-4gmm/GHSA-rgrc-x3v2-4gmm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rhfm-q4h8-frxp/GHSA-rhfm-q4h8-frxp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rmq3-57w7-fmhx/GHSA-rmq3-57w7-fmhx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rq7j-84m9-32jh/GHSA-rq7j-84m9-32jh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v35m-rx24-w6pg/GHSA-v35m-rx24-w6pg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vcxc-vj6w-2ffm/GHSA-vcxc-vj6w-2ffm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vhwr-gfg8-hm5j/GHSA-vhwr-gfg8-hm5j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vrc8-hxm5-v8wx/GHSA-vrc8-hxm5-v8wx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vxg2-q7pw-5mpg/GHSA-vxg2-q7pw-5mpg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6jf-6fg2-jpjx/GHSA-w6jf-6fg2-jpjx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w8xg-2rhp-v8c4/GHSA-w8xg-2rhp-v8c4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wc6w-q8v8-w3c7/GHSA-wc6w-q8v8-w3c7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wfr6-fwjh-5jx6/GHSA-wfr6-fwjh-5jx6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wh9x-w9vv-rjf9/GHSA-wh9x-w9vv-rjf9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wq5j-wjp2-4f74/GHSA-wq5j-wjp2-4f74.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xcpx-xw8r-x8rf/GHSA-xcpx-xw8r-x8rf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xgx2-r4f9-h8w3/GHSA-xgx2-r4f9-h8w3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xpq2-2hq8-6f42/GHSA-xpq2-2hq8-6f42.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xwx7-4rrg-r95g/GHSA-xwx7-4rrg-r95g.json diff --git a/advisories/github-reviewed/2025/03/GHSA-r5gx-c49x-h878/GHSA-r5gx-c49x-h878.json b/advisories/github-reviewed/2025/03/GHSA-r5gx-c49x-h878/GHSA-r5gx-c49x-h878.json new file mode 100644 index 00000000000..12de55a107d --- /dev/null +++ b/advisories/github-reviewed/2025/03/GHSA-r5gx-c49x-h878/GHSA-r5gx-c49x-h878.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5gx-c49x-h878", + "modified": "2025-03-11T21:31:02Z", + "published": "2025-03-11T21:31:01Z", + "aliases": [ + "CVE-2025-25301" + ], + "summary": "Rembg allows SSRF via /api/remove", + "details": "Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "rembg" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.57" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25301" + }, + { + "type": "PACKAGE", + "url": "https://github.com/danielgatis/rembg" + }, + { + "type": "ADVISORY", + "url": "https://securitylab.github.com/advisories/GHSL-2024-161_GHSL-2024-162_rembg" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-03-11T21:31:01Z", + "nvd_published_at": "2025-03-03T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/02/GHSA-5p5j-vwv3-3hm9/GHSA-5p5j-vwv3-3hm9.json b/advisories/unreviewed/2023/02/GHSA-5p5j-vwv3-3hm9/GHSA-5p5j-vwv3-3hm9.json index f14d53f57d4..596f5c61cb5 100644 --- a/advisories/unreviewed/2023/02/GHSA-5p5j-vwv3-3hm9/GHSA-5p5j-vwv3-3hm9.json +++ b/advisories/unreviewed/2023/02/GHSA-5p5j-vwv3-3hm9/GHSA-5p5j-vwv3-3hm9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-7rc9-5vxf-3h3m/GHSA-7rc9-5vxf-3h3m.json b/advisories/unreviewed/2023/02/GHSA-7rc9-5vxf-3h3m/GHSA-7rc9-5vxf-3h3m.json index d75e191864f..e5d078d368e 100644 --- a/advisories/unreviewed/2023/02/GHSA-7rc9-5vxf-3h3m/GHSA-7rc9-5vxf-3h3m.json +++ b/advisories/unreviewed/2023/02/GHSA-7rc9-5vxf-3h3m/GHSA-7rc9-5vxf-3h3m.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-476" + "CWE-476", + "CWE-617" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-j82c-6hc3-3qc4/GHSA-j82c-6hc3-3qc4.json b/advisories/unreviewed/2023/02/GHSA-j82c-6hc3-3qc4/GHSA-j82c-6hc3-3qc4.json index dc59f92e2b9..de31b690ea3 100644 --- a/advisories/unreviewed/2023/02/GHSA-j82c-6hc3-3qc4/GHSA-j82c-6hc3-3qc4.json +++ b/advisories/unreviewed/2023/02/GHSA-j82c-6hc3-3qc4/GHSA-j82c-6hc3-3qc4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-wj5g-5xxg-2f92/GHSA-wj5g-5xxg-2f92.json b/advisories/unreviewed/2023/02/GHSA-wj5g-5xxg-2f92/GHSA-wj5g-5xxg-2f92.json index 4147ca3f511..a989480dd4b 100644 --- a/advisories/unreviewed/2023/02/GHSA-wj5g-5xxg-2f92/GHSA-wj5g-5xxg-2f92.json +++ b/advisories/unreviewed/2023/02/GHSA-wj5g-5xxg-2f92/GHSA-wj5g-5xxg-2f92.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-664" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-x9cj-w6h9-jcrq/GHSA-x9cj-w6h9-jcrq.json b/advisories/unreviewed/2023/02/GHSA-x9cj-w6h9-jcrq/GHSA-x9cj-w6h9-jcrq.json index 93c11af65fa..78ba7078a7d 100644 --- a/advisories/unreviewed/2023/02/GHSA-x9cj-w6h9-jcrq/GHSA-x9cj-w6h9-jcrq.json +++ b/advisories/unreviewed/2023/02/GHSA-x9cj-w6h9-jcrq/GHSA-x9cj-w6h9-jcrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9cj-w6h9-jcrq", - "modified": "2023-03-03T15:30:24Z", + "modified": "2025-03-11T21:30:27Z", "published": "2023-02-22T03:30:16Z", "aliases": [ "CVE-2022-2883" diff --git a/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json b/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json index c5597bb343f..838a1c8c250 100644 --- a/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json +++ b/advisories/unreviewed/2025/02/GHSA-j2v6-fxfh-8942/GHSA-j2v6-fxfh-8942.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2v6-fxfh-8942", - "modified": "2025-02-12T15:31:58Z", + "modified": "2025-03-11T21:30:30Z", "published": "2025-02-12T12:30:47Z", "aliases": [ "CVE-2024-13473" diff --git a/advisories/unreviewed/2025/02/GHSA-pj6g-c6r4-xjxf/GHSA-pj6g-c6r4-xjxf.json b/advisories/unreviewed/2025/02/GHSA-pj6g-c6r4-xjxf/GHSA-pj6g-c6r4-xjxf.json index c2049c7bcb2..8bb1ebfe9bb 100644 --- a/advisories/unreviewed/2025/02/GHSA-pj6g-c6r4-xjxf/GHSA-pj6g-c6r4-xjxf.json +++ b/advisories/unreviewed/2025/02/GHSA-pj6g-c6r4-xjxf/GHSA-pj6g-c6r4-xjxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pj6g-c6r4-xjxf", - "modified": "2025-02-27T06:30:53Z", + "modified": "2025-03-11T21:30:30Z", "published": "2025-02-27T06:30:53Z", "aliases": [ "CVE-2025-0469" diff --git a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json index 164c9a70a70..baa7f5b85d5 100644 --- a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json +++ b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j99-5q75-3f57", - "modified": "2025-03-11T18:32:20Z", + "modified": "2025-03-11T21:30:34Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2025-24201" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://support.apple.com/en-us/122284" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122285" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-2mqv-mwvq-mv8h/GHSA-2mqv-mwvq-mv8h.json b/advisories/unreviewed/2025/03/GHSA-2mqv-mwvq-mv8h/GHSA-2mqv-mwvq-mv8h.json new file mode 100644 index 00000000000..9dddd18bb06 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2mqv-mwvq-mv8h/GHSA-2mqv-mwvq-mv8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mqv-mwvq-mv8h", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28891" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc allows Stored XSS. This issue affects price-calc: from n/a through 0.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28891" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/price-calc/vulnerability/wordpress-price-calc-plugin-0-6-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2v39-r86v-x85c/GHSA-2v39-r86v-x85c.json b/advisories/unreviewed/2025/03/GHSA-2v39-r86v-x85c/GHSA-2v39-r86v-x85c.json new file mode 100644 index 00000000000..844584537b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2v39-r86v-x85c/GHSA-2v39-r86v-x85c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v39-r86v-x85c", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28906" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thiago S.F. Skitter Slideshow allows Stored XSS. This issue affects Skitter Slideshow: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28906" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-skitter-slideshow/vulnerability/wordpress-skitter-slideshow-plugin-2-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3373-7xwg-mr2v/GHSA-3373-7xwg-mr2v.json b/advisories/unreviewed/2025/03/GHSA-3373-7xwg-mr2v/GHSA-3373-7xwg-mr2v.json new file mode 100644 index 00000000000..c430f49fb5a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3373-7xwg-mr2v/GHSA-3373-7xwg-mr2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3373-7xwg-mr2v", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28872" + ], + "details": "Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28872" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/block-spam-by-math-reloaded/vulnerability/wordpress-block-spam-by-math-reloaded-plugin-2-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-37mm-53pr-gqf6/GHSA-37mm-53pr-gqf6.json b/advisories/unreviewed/2025/03/GHSA-37mm-53pr-gqf6/GHSA-37mm-53pr-gqf6.json new file mode 100644 index 00000000000..0b8ceedec62 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-37mm-53pr-gqf6/GHSA-37mm-53pr-gqf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37mm-53pr-gqf6", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28918" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones Featured Image Thumbnail Grid allows Stored XSS. This issue affects Featured Image Thumbnail Grid: from n/a through 6.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28918" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/thumbnail-grid/vulnerability/wordpress-featured-image-thumbnail-grid-plugin-6-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38cw-7g54-c3g7/GHSA-38cw-7g54-c3g7.json b/advisories/unreviewed/2025/03/GHSA-38cw-7g54-c3g7/GHSA-38cw-7g54-c3g7.json new file mode 100644 index 00000000000..5f10ce5ee7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38cw-7g54-c3g7/GHSA-38cw-7g54-c3g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38cw-7g54-c3g7", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28871" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jwpegram Block Spam By Math Reloaded allows Stored XSS. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/block-spam-by-math-reloaded/vulnerability/wordpress-block-spam-by-math-reloaded-plugin-2-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38p6-9wh4-q95c/GHSA-38p6-9wh4-q95c.json b/advisories/unreviewed/2025/03/GHSA-38p6-9wh4-q95c/GHSA-38p6-9wh4-q95c.json new file mode 100644 index 00000000000..5d358a93282 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38p6-9wh4-q95c/GHSA-38p6-9wh4-q95c.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38p6-9wh4-q95c", + "modified": "2025-03-11T21:30:37Z", + "published": "2025-03-11T21:30:37Z", + "aliases": [ + "CVE-2025-2207" + ], + "details": "A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unknown code of the file /sys/dept. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2207" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/spring-manage.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511737" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38w2-wrgq-24qv/GHSA-38w2-wrgq-24qv.json b/advisories/unreviewed/2025/03/GHSA-38w2-wrgq-24qv/GHSA-38w2-wrgq-24qv.json new file mode 100644 index 00000000000..5fbe2b87578 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38w2-wrgq-24qv/GHSA-38w2-wrgq-24qv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38w2-wrgq-24qv", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28866" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger allows Cross Site Request Forgery. This issue affects Login Logger: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-logger/vulnerability/wordpress-login-logger-plugin-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3gq3-9cq7-288g/GHSA-3gq3-9cq7-288g.json b/advisories/unreviewed/2025/03/GHSA-3gq3-9cq7-288g/GHSA-3gq3-9cq7-288g.json new file mode 100644 index 00000000000..6232b33c67e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3gq3-9cq7-288g/GHSA-3gq3-9cq7-288g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gq3-9cq7-288g", + "modified": "2025-03-11T21:30:37Z", + "published": "2025-03-11T21:30:37Z", + "aliases": [ + "CVE-2025-21170" + ], + "details": "Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21170" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3mw5-7hq7-6p5w/GHSA-3mw5-7hq7-6p5w.json b/advisories/unreviewed/2025/03/GHSA-3mw5-7hq7-6p5w/GHSA-3mw5-7hq7-6p5w.json new file mode 100644 index 00000000000..47f423c4601 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3mw5-7hq7-6p5w/GHSA-3mw5-7hq7-6p5w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mw5-7hq7-6p5w", + "modified": "2025-03-11T21:30:35Z", + "published": "2025-03-11T21:30:35Z", + "aliases": [ + "CVE-2025-23360" + ], + "details": "NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23360" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3q6w-vp42-26vx/GHSA-3q6w-vp42-26vx.json b/advisories/unreviewed/2025/03/GHSA-3q6w-vp42-26vx/GHSA-3q6w-vp42-26vx.json new file mode 100644 index 00000000000..c1debe1c814 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3q6w-vp42-26vx/GHSA-3q6w-vp42-26vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q6w-vp42-26vx", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28914" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28914" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-show-login-form/vulnerability/wordpress-wordpress-login-form-to-anywhere-plugin-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3q87-289f-8v5m/GHSA-3q87-289f-8v5m.json b/advisories/unreviewed/2025/03/GHSA-3q87-289f-8v5m/GHSA-3q87-289f-8v5m.json new file mode 100644 index 00000000000..b22cc6cf84c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3q87-289f-8v5m/GHSA-3q87-289f-8v5m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q87-289f-8v5m", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28929" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget allows Stored XSS. This issue affects Tabbed Login Widget: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28929" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tabbed-login/vulnerability/wordpress-tabbed-login-widget-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4595-95wg-87wc/GHSA-4595-95wg-87wc.json b/advisories/unreviewed/2025/03/GHSA-4595-95wg-87wc/GHSA-4595-95wg-87wc.json new file mode 100644 index 00000000000..64cb000cc55 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4595-95wg-87wc/GHSA-4595-95wg-87wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4595-95wg-87wc", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28868" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe allows Cross Site Request Forgery. This issue affects ZipList Recipe: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28868" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ziplist-recipe-plugin/vulnerability/wordpress-ziplist-recipe-plugin-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-47m3-gw83-4cqc/GHSA-47m3-gw83-4cqc.json b/advisories/unreviewed/2025/03/GHSA-47m3-gw83-4cqc/GHSA-47m3-gw83-4cqc.json new file mode 100644 index 00000000000..806a09ba21b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-47m3-gw83-4cqc/GHSA-47m3-gw83-4cqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47m3-gw83-4cqc", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2020" + ], + "details": "Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25254.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2020" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-124" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-49g7-rpc5-m25r/GHSA-49g7-rpc5-m25r.json b/advisories/unreviewed/2025/03/GHSA-49g7-rpc5-m25r/GHSA-49g7-rpc5-m25r.json new file mode 100644 index 00000000000..236ddba190d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-49g7-rpc5-m25r/GHSA-49g7-rpc5-m25r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49g7-rpc5-m25r", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28926" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in popeating Post Read Time allows Stored XSS. This issue affects Post Read Time: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-read-time/vulnerability/wordpress-post-read-time-plugin-1-2-6-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cmc-mjvg-x5mp/GHSA-4cmc-mjvg-x5mp.json b/advisories/unreviewed/2025/03/GHSA-4cmc-mjvg-x5mp/GHSA-4cmc-mjvg-x5mp.json new file mode 100644 index 00000000000..72404d051d5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cmc-mjvg-x5mp/GHSA-4cmc-mjvg-x5mp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cmc-mjvg-x5mp", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-27173" + ], + "details": "Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27173" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4p9p-c25q-hmp5/GHSA-4p9p-c25q-hmp5.json b/advisories/unreviewed/2025/03/GHSA-4p9p-c25q-hmp5/GHSA-4p9p-c25q-hmp5.json new file mode 100644 index 00000000000..f6edab92144 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4p9p-c25q-hmp5/GHSA-4p9p-c25q-hmp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p9p-c25q-hmp5", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2013" + ], + "details": "Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of CO files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25186.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2013" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-120" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4w7g-22mj-6g5c/GHSA-4w7g-22mj-6g5c.json b/advisories/unreviewed/2025/03/GHSA-4w7g-22mj-6g5c/GHSA-4w7g-22mj-6g5c.json index 449d26d6e8d..ac1cbd572fa 100644 --- a/advisories/unreviewed/2025/03/GHSA-4w7g-22mj-6g5c/GHSA-4w7g-22mj-6g5c.json +++ b/advisories/unreviewed/2025/03/GHSA-4w7g-22mj-6g5c/GHSA-4w7g-22mj-6g5c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4w7g-22mj-6g5c", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T21:30:33Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-56185" ], "details": "In ProtocolUnsolOnSSAdapter::GetServiceClass() of protocolcalladapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-52r6-v45h-gh94/GHSA-52r6-v45h-gh94.json b/advisories/unreviewed/2025/03/GHSA-52r6-v45h-gh94/GHSA-52r6-v45h-gh94.json new file mode 100644 index 00000000000..765dfb503ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-52r6-v45h-gh94/GHSA-52r6-v45h-gh94.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52r6-v45h-gh94", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28937" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search allows Stored XSS. This issue affects Lava Ajax Search: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lava-ajax-search/vulnerability/wordpress-lava-ajax-search-plugin-1-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-564r-jgrm-jr8x/GHSA-564r-jgrm-jr8x.json b/advisories/unreviewed/2025/03/GHSA-564r-jgrm-jr8x/GHSA-564r-jgrm-jr8x.json new file mode 100644 index 00000000000..b19065cf1ce --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-564r-jgrm-jr8x/GHSA-564r-jgrm-jr8x.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564r-jgrm-jr8x", + "modified": "2025-03-11T21:30:42Z", + "published": "2025-03-11T21:30:42Z", + "aliases": [ + "CVE-2025-2208" + ], + "details": "A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue affects some unknown processing of the file /sysFiles/upload of the component Filename Handler. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2208" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/spring-manage.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511738" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57xq-wfw8-mh7x/GHSA-57xq-wfw8-mh7x.json b/advisories/unreviewed/2025/03/GHSA-57xq-wfw8-mh7x/GHSA-57xq-wfw8-mh7x.json index dce91bc100a..3ed653022d5 100644 --- a/advisories/unreviewed/2025/03/GHSA-57xq-wfw8-mh7x/GHSA-57xq-wfw8-mh7x.json +++ b/advisories/unreviewed/2025/03/GHSA-57xq-wfw8-mh7x/GHSA-57xq-wfw8-mh7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57xq-wfw8-mh7x", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T21:30:33Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-56184" ], "details": "In static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:38Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5fj2-xqgx-m987/GHSA-5fj2-xqgx-m987.json b/advisories/unreviewed/2025/03/GHSA-5fj2-xqgx-m987/GHSA-5fj2-xqgx-m987.json index 2d33696250b..8381129c4b6 100644 --- a/advisories/unreviewed/2025/03/GHSA-5fj2-xqgx-m987/GHSA-5fj2-xqgx-m987.json +++ b/advisories/unreviewed/2025/03/GHSA-5fj2-xqgx-m987/GHSA-5fj2-xqgx-m987.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-5rcp-gqjx-6m49/GHSA-5rcp-gqjx-6m49.json b/advisories/unreviewed/2025/03/GHSA-5rcp-gqjx-6m49/GHSA-5rcp-gqjx-6m49.json new file mode 100644 index 00000000000..a571a84a824 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5rcp-gqjx-6m49/GHSA-5rcp-gqjx-6m49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rcp-gqjx-6m49", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28932" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BCS Website Solutions Insert Code allows Stored XSS. This issue affects Insert Code: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/insert-code/vulnerability/wordpress-insert-code-plugin-2-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5x4g-pq34-vr6w/GHSA-5x4g-pq34-vr6w.json b/advisories/unreviewed/2025/03/GHSA-5x4g-pq34-vr6w/GHSA-5x4g-pq34-vr6w.json new file mode 100644 index 00000000000..f7d21f2091a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5x4g-pq34-vr6w/GHSA-5x4g-pq34-vr6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x4g-pq34-vr6w", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28861" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker allows Stored XSS. This issue affects WP jQuery Persian Datepicker: from n/a through 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28861" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpjqp-datepicker/vulnerability/wordpress-wp-jquery-persian-datepicker-plugin-0-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5xgg-8whq-9cvp/GHSA-5xgg-8whq-9cvp.json b/advisories/unreviewed/2025/03/GHSA-5xgg-8whq-9cvp/GHSA-5xgg-8whq-9cvp.json new file mode 100644 index 00000000000..fb464854262 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5xgg-8whq-9cvp/GHSA-5xgg-8whq-9cvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xgg-8whq-9cvp", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28925" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hieu Nguyen WATI Chat and Notification allows Stored XSS. This issue affects WATI Chat and Notification: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wati-chat-and-notification/vulnerability/wordpress-wati-chat-and-notification-plugin-1-1-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json b/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json new file mode 100644 index 00000000000..384d0ff2f3b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5xpm-7q7v-rpvf/GHSA-5xpm-7q7v-rpvf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xpm-7q7v-rpvf", + "modified": "2025-03-11T21:30:35Z", + "published": "2025-03-11T21:30:35Z", + "aliases": [ + "CVE-2025-25925" + ], + "details": "A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25925" + }, + { + "type": "WEB", + "url": "https://github.com/johnchd/CVEs/blob/main/OpenMRS/CVE-2025-25925%20-%20P-XSS.md" + }, + { + "type": "WEB", + "url": "http://openmrs.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json b/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json index 767a173c8f4..4e26e8ae107 100644 --- a/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json +++ b/advisories/unreviewed/2025/03/GHSA-62qj-786m-q427/GHSA-62qj-786m-q427.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62qj-786m-q427", - "modified": "2025-03-11T15:31:01Z", + "modified": "2025-03-11T21:30:34Z", "published": "2025-03-11T15:31:01Z", "aliases": [ "CVE-2024-51320" ], "details": "Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T15:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-68fw-47jh-hgqq/GHSA-68fw-47jh-hgqq.json b/advisories/unreviewed/2025/03/GHSA-68fw-47jh-hgqq/GHSA-68fw-47jh-hgqq.json new file mode 100644 index 00000000000..9c32c51bb25 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-68fw-47jh-hgqq/GHSA-68fw-47jh-hgqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68fw-47jh-hgqq", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28878" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will Brubaker Awesome Surveys allows Stored XSS. This issue affects Awesome Surveys: from n/a through 2.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28878" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-surveys/vulnerability/wordpress-awesome-surveys-plugin-2-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69jh-579f-grhj/GHSA-69jh-579f-grhj.json b/advisories/unreviewed/2025/03/GHSA-69jh-579f-grhj/GHSA-69jh-579f-grhj.json new file mode 100644 index 00000000000..ab00496d4f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69jh-579f-grhj/GHSA-69jh-579f-grhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69jh-579f-grhj", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28859" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice allows Cross Site Request Forgery. This issue affects Maintenance Notice: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28859" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/maintenance-notice/vulnerability/wordpress-maintenance-notice-plugin-1-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6pqf-q9v8-mg56/GHSA-6pqf-q9v8-mg56.json b/advisories/unreviewed/2025/03/GHSA-6pqf-q9v8-mg56/GHSA-6pqf-q9v8-mg56.json new file mode 100644 index 00000000000..f7d695f944d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6pqf-q9v8-mg56/GHSA-6pqf-q9v8-mg56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pqf-q9v8-mg56", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28919" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shellbot Easy Image Display allows Stored XSS. This issue affects Easy Image Display: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28919" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-image-display/vulnerability/wordpress-easy-image-display-plugin-1-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6w9v-343p-v4qm/GHSA-6w9v-343p-v4qm.json b/advisories/unreviewed/2025/03/GHSA-6w9v-343p-v4qm/GHSA-6w9v-343p-v4qm.json new file mode 100644 index 00000000000..92acdac9f0c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6w9v-343p-v4qm/GHSA-6w9v-343p-v4qm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w9v-343p-v4qm", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28884" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Kumar WP Bulk Post Duplicator allows Cross Site Request Forgery. This issue affects WP Bulk Post Duplicator: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28884" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-bulk-post-duplicator/vulnerability/wordpress-wp-bulk-post-duplicator-plugin-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-78p3-88v5-4j32/GHSA-78p3-88v5-4j32.json b/advisories/unreviewed/2025/03/GHSA-78p3-88v5-4j32/GHSA-78p3-88v5-4j32.json new file mode 100644 index 00000000000..5ebd87ebfec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78p3-88v5-4j32/GHSA-78p3-88v5-4j32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78p3-88v5-4j32", + "modified": "2025-03-11T21:30:42Z", + "published": "2025-03-11T21:30:42Z", + "aliases": [ + "CVE-2025-2023" + ], + "details": "Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of LI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25348.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2023" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json b/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json new file mode 100644 index 00000000000..6e7bf8427f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7j7m-w4qx-7vmf/GHSA-7j7m-w4qx-7vmf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j7m-w4qx-7vmf", + "modified": "2025-03-11T21:30:36Z", + "published": "2025-03-11T21:30:36Z", + "aliases": [ + "CVE-2025-25928" + ], + "details": "A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25928" + }, + { + "type": "WEB", + "url": "https://github.com/johnchd/CVEs/blob/main/OpenMRS/CVE-2025-25928%20-%20CSRF%20PrivEsc.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-826x-6xrj-6vg9/GHSA-826x-6xrj-6vg9.json b/advisories/unreviewed/2025/03/GHSA-826x-6xrj-6vg9/GHSA-826x-6xrj-6vg9.json new file mode 100644 index 00000000000..4ff1ad25329 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-826x-6xrj-6vg9/GHSA-826x-6xrj-6vg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-826x-6xrj-6vg9", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2014" + ], + "details": "Ashlar-Vellum Cobalt VS File Parsing Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VS files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25235.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2014" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-87qg-334x-f2cw/GHSA-87qg-334x-f2cw.json b/advisories/unreviewed/2025/03/GHSA-87qg-334x-f2cw/GHSA-87qg-334x-f2cw.json new file mode 100644 index 00000000000..ec14d1d8d78 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-87qg-334x-f2cw/GHSA-87qg-334x-f2cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87qg-334x-f2cw", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28905" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaser324 Featured Posts Grid allows Stored XSS. This issue affects Featured Posts Grid: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28905" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/featured-posts-grid/vulnerability/wordpress-featured-posts-grid-plugin-1-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-88hj-hc74-5p58/GHSA-88hj-hc74-5p58.json b/advisories/unreviewed/2025/03/GHSA-88hj-hc74-5p58/GHSA-88hj-hc74-5p58.json new file mode 100644 index 00000000000..379021a5a71 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-88hj-hc74-5p58/GHSA-88hj-hc74-5p58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88hj-hc74-5p58", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2018" + ], + "details": "Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25245.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2018" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8h6g-xc7x-fxv4/GHSA-8h6g-xc7x-fxv4.json b/advisories/unreviewed/2025/03/GHSA-8h6g-xc7x-fxv4/GHSA-8h6g-xc7x-fxv4.json new file mode 100644 index 00000000000..30548de9caf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8h6g-xc7x-fxv4/GHSA-8h6g-xc7x-fxv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h6g-xc7x-fxv4", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2015" + ], + "details": "Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25236.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2015" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-116" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-973v-5qg7-x6qq/GHSA-973v-5qg7-x6qq.json b/advisories/unreviewed/2025/03/GHSA-973v-5qg7-x6qq/GHSA-973v-5qg7-x6qq.json new file mode 100644 index 00000000000..ad6ef0aa8e2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-973v-5qg7-x6qq/GHSA-973v-5qg7-x6qq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-973v-5qg7-x6qq", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28927" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in A. Chappard Display Template Name allows Cross Site Request Forgery. This issue affects Display Template Name: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/display-template-name/vulnerability/wordpress-display-template-name-plugin-1-7-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-98pv-v482-w48q/GHSA-98pv-v482-w48q.json b/advisories/unreviewed/2025/03/GHSA-98pv-v482-w48q/GHSA-98pv-v482-w48q.json new file mode 100644 index 00000000000..e1b49955ce0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-98pv-v482-w48q/GHSA-98pv-v482-w48q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98pv-v482-w48q", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28883" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables allows Stored XSS. This issue affects WP Compare Tables: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28883" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-compare-tables/vulnerability/wordpress-wp-compare-tables-plugin-1-0-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9c37-6wgw-96fm/GHSA-9c37-6wgw-96fm.json b/advisories/unreviewed/2025/03/GHSA-9c37-6wgw-96fm/GHSA-9c37-6wgw-96fm.json new file mode 100644 index 00000000000..e5c637a1efc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9c37-6wgw-96fm/GHSA-9c37-6wgw-96fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c37-6wgw-96fm", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28863" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image allows Cross Site Request Forgery. This issue affects Delete Original Image: from n/a through 0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28863" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/delete-original-image/vulnerability/wordpress-delete-original-image-plugin-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9g29-43mh-wwf6/GHSA-9g29-43mh-wwf6.json b/advisories/unreviewed/2025/03/GHSA-9g29-43mh-wwf6/GHSA-9g29-43mh-wwf6.json new file mode 100644 index 00000000000..b01744ec582 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9g29-43mh-wwf6/GHSA-9g29-43mh-wwf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g29-43mh-wwf6", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28908" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pipdig pipDisqus allows Stored XSS. This issue affects pipDisqus: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28908" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pipdisqus/vulnerability/wordpress-pipdisqus-plugin-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vmp-4f49-fr63/GHSA-9vmp-4f49-fr63.json b/advisories/unreviewed/2025/03/GHSA-9vmp-4f49-fr63/GHSA-9vmp-4f49-fr63.json new file mode 100644 index 00000000000..43dd6081742 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9vmp-4f49-fr63/GHSA-9vmp-4f49-fr63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vmp-4f49-fr63", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28870" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in amocrm amoCRM WebForm allows DOM-Based XSS. This issue affects amoCRM WebForm: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/amocrm-webform/vulnerability/wordpress-amocrm-webform-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9wgm-76rq-7796/GHSA-9wgm-76rq-7796.json b/advisories/unreviewed/2025/03/GHSA-9wgm-76rq-7796/GHSA-9wgm-76rq-7796.json new file mode 100644 index 00000000000..742c6eb6edf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9wgm-76rq-7796/GHSA-9wgm-76rq-7796.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wgm-76rq-7796", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28897" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme allows Stored XSS. This issue affects Domain Theme: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28897" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/domain-theme/vulnerability/wordpress-domain-theme-plugin-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json b/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json index 31d46759fbd..7e23812ee92 100644 --- a/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json +++ b/advisories/unreviewed/2025/03/GHSA-9wv3-p38x-5wqv/GHSA-9wv3-p38x-5wqv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9wv3-p38x-5wqv", - "modified": "2025-03-09T06:31:42Z", + "modified": "2025-03-11T21:30:31Z", "published": "2025-03-09T06:31:42Z", "aliases": [ "CVE-2025-1362" ], "details": "The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-09T06:15:10Z" diff --git a/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json b/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json new file mode 100644 index 00000000000..36386350788 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9xm2-hxxj-hgq7/GHSA-9xm2-hxxj-hgq7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xm2-hxxj-hgq7", + "modified": "2025-03-11T21:30:36Z", + "published": "2025-03-11T21:30:36Z", + "aliases": [ + "CVE-2025-25929" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the reportType parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25929" + }, + { + "type": "WEB", + "url": "https://github.com/johnchd/CVEs/blob/main/OpenMRS/CVE-2025-25929%20-%20R-XSS.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c34r-ww43-wqcj/GHSA-c34r-ww43-wqcj.json b/advisories/unreviewed/2025/03/GHSA-c34r-ww43-wqcj/GHSA-c34r-ww43-wqcj.json index bba8070b46f..3813c266790 100644 --- a/advisories/unreviewed/2025/03/GHSA-c34r-ww43-wqcj/GHSA-c34r-ww43-wqcj.json +++ b/advisories/unreviewed/2025/03/GHSA-c34r-ww43-wqcj/GHSA-c34r-ww43-wqcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c34r-ww43-wqcj", - "modified": "2025-03-08T12:30:31Z", + "modified": "2025-03-11T21:30:31Z", "published": "2025-03-08T12:30:31Z", "aliases": [ "CVE-2024-13675" diff --git a/advisories/unreviewed/2025/03/GHSA-c39v-vghw-5cg6/GHSA-c39v-vghw-5cg6.json b/advisories/unreviewed/2025/03/GHSA-c39v-vghw-5cg6/GHSA-c39v-vghw-5cg6.json new file mode 100644 index 00000000000..592650f1049 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c39v-vghw-5cg6/GHSA-c39v-vghw-5cg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c39v-vghw-5cg6", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28864" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Planet Studio Builder for Contact Form 7 by Webconstruct allows Cross Site Request Forgery. This issue affects Builder for Contact Form 7 by Webconstruct: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28864" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-builder/vulnerability/wordpress-builder-for-contact-form-7-by-webconstruct-plugin-1-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c67q-hx6m-m5wv/GHSA-c67q-hx6m-m5wv.json b/advisories/unreviewed/2025/03/GHSA-c67q-hx6m-m5wv/GHSA-c67q-hx6m-m5wv.json new file mode 100644 index 00000000000..67f5d13ab17 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c67q-hx6m-m5wv/GHSA-c67q-hx6m-m5wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c67q-hx6m-m5wv", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2012" + ], + "details": "Ashlar-Vellum Cobalt VS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25185.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2012" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c72g-6v9g-4gq7/GHSA-c72g-6v9g-4gq7.json b/advisories/unreviewed/2025/03/GHSA-c72g-6v9g-4gq7/GHSA-c72g-6v9g-4gq7.json new file mode 100644 index 00000000000..8dbe3903886 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c72g-6v9g-4gq7/GHSA-c72g-6v9g-4gq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c72g-6v9g-4gq7", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28881" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mg12 Mobile Themes allows Cross Site Request Forgery. This issue affects Mobile Themes: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28881" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mobile-themes/vulnerability/wordpress-mobile-themes-plugin-1-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json b/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json index 4844e5c3200..e75eaa44fd5 100644 --- a/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json +++ b/advisories/unreviewed/2025/03/GHSA-ch57-3pgj-79wf/GHSA-ch57-3pgj-79wf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ch57-3pgj-79wf", - "modified": "2025-03-11T15:31:02Z", + "modified": "2025-03-11T21:30:34Z", "published": "2025-03-11T15:31:02Z", "aliases": [ "CVE-2024-51322" ], "details": "Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-11T15:15:42Z" diff --git a/advisories/unreviewed/2025/03/GHSA-crp6-j9hr-46pc/GHSA-crp6-j9hr-46pc.json b/advisories/unreviewed/2025/03/GHSA-crp6-j9hr-46pc/GHSA-crp6-j9hr-46pc.json new file mode 100644 index 00000000000..5a397522190 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-crp6-j9hr-46pc/GHSA-crp6-j9hr-46pc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crp6-j9hr-46pc", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28860" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator allows Stored XSS. This issue affects Google News Editors Picks Feed Generator: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28860" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-news-editors-picks-news-feeds/vulnerability/wordpress-google-news-editors-picks-feed-generator-plugin-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f33v-j5fp-77mf/GHSA-f33v-j5fp-77mf.json b/advisories/unreviewed/2025/03/GHSA-f33v-j5fp-77mf/GHSA-f33v-j5fp-77mf.json new file mode 100644 index 00000000000..e01c3d8e5eb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f33v-j5fp-77mf/GHSA-f33v-j5fp-77mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f33v-j5fp-77mf", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28923" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in philippe No Disposable Email allows Stored XSS. This issue affects No Disposable Email: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/no-disposable-email/vulnerability/wordpress-no-disposable-email-plugin-2-5-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f95q-7848-gf6g/GHSA-f95q-7848-gf6g.json b/advisories/unreviewed/2025/03/GHSA-f95q-7848-gf6g/GHSA-f95q-7848-gf6g.json new file mode 100644 index 00000000000..bbc51a686ca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f95q-7848-gf6g/GHSA-f95q-7848-gf6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f95q-7848-gf6g", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28922" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Terence D. Go To Top allows Stored XSS. This issue affects Go To Top: from n/a through 0.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28922" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/go-to-top/vulnerability/wordpress-go-to-top-plugin-0-0-8-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f99m-pcvw-8vpj/GHSA-f99m-pcvw-8vpj.json b/advisories/unreviewed/2025/03/GHSA-f99m-pcvw-8vpj/GHSA-f99m-pcvw-8vpj.json index 6952465c380..4a1137562bc 100644 --- a/advisories/unreviewed/2025/03/GHSA-f99m-pcvw-8vpj/GHSA-f99m-pcvw-8vpj.json +++ b/advisories/unreviewed/2025/03/GHSA-f99m-pcvw-8vpj/GHSA-f99m-pcvw-8vpj.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-fph4-j8gq-8j6r/GHSA-fph4-j8gq-8j6r.json b/advisories/unreviewed/2025/03/GHSA-fph4-j8gq-8j6r/GHSA-fph4-j8gq-8j6r.json new file mode 100644 index 00000000000..f9989e3f5a8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fph4-j8gq-8j6r/GHSA-fph4-j8gq-8j6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fph4-j8gq-8j6r", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28910" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ravinder Khurana WP Hide Admin Bar allows Cross Site Request Forgery. This issue affects WP Hide Admin Bar: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28910" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-hide-admin-bar/vulnerability/wordpress-wp-hide-admin-bar-plugin-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gc4p-wgw2-chm7/GHSA-gc4p-wgw2-chm7.json b/advisories/unreviewed/2025/03/GHSA-gc4p-wgw2-chm7/GHSA-gc4p-wgw2-chm7.json new file mode 100644 index 00000000000..53b7bc988ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gc4p-wgw2-chm7/GHSA-gc4p-wgw2-chm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc4p-wgw2-chm7", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28941" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ohtan Spam Byebye allows Cross Site Request Forgery. This issue affects Spam Byebye: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28941" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spam-byebye/vulnerability/wordpress-spam-bybye-plugin-2-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ghmw-x83x-hpmp/GHSA-ghmw-x83x-hpmp.json b/advisories/unreviewed/2025/03/GHSA-ghmw-x83x-hpmp/GHSA-ghmw-x83x-hpmp.json new file mode 100644 index 00000000000..2fddbe55876 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ghmw-x83x-hpmp/GHSA-ghmw-x83x-hpmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghmw-x83x-hpmp", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28915" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit allows Upload a Web Shell to a Web Server. This issue affects ThemeEgg ToolKit: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28915" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themeegg-toolkit/vulnerability/wordpress-themeegg-toolkit-plugin-1-2-9-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gjqp-22h8-mr74/GHSA-gjqp-22h8-mr74.json b/advisories/unreviewed/2025/03/GHSA-gjqp-22h8-mr74/GHSA-gjqp-22h8-mr74.json new file mode 100644 index 00000000000..3e6be268fa5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gjqp-22h8-mr74/GHSA-gjqp-22h8-mr74.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjqp-22h8-mr74", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28938" + ], + "details": "Missing Authorization vulnerability in Bjoern WP Performance Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Performance Pack: from n/a through 2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28938" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-performance-pack/vulnerability/wordpress-wp-performance-pack-plugin-2-5-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-grfv-8m4f-679x/GHSA-grfv-8m4f-679x.json b/advisories/unreviewed/2025/03/GHSA-grfv-8m4f-679x/GHSA-grfv-8m4f-679x.json new file mode 100644 index 00000000000..864a448dd4d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-grfv-8m4f-679x/GHSA-grfv-8m4f-679x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grfv-8m4f-679x", + "modified": "2025-03-11T21:30:42Z", + "published": "2025-03-11T21:30:42Z", + "aliases": [ + "CVE-2025-2022" + ], + "details": "Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25276.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2022" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-126" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h2p3-j299-jf37/GHSA-h2p3-j299-jf37.json b/advisories/unreviewed/2025/03/GHSA-h2p3-j299-jf37/GHSA-h2p3-j299-jf37.json new file mode 100644 index 00000000000..0c7b1989946 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h2p3-j299-jf37/GHSA-h2p3-j299-jf37.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2p3-j299-jf37", + "modified": "2025-03-11T21:30:37Z", + "published": "2025-03-11T21:30:37Z", + "aliases": [ + "CVE-2025-2206" + ], + "details": "A vulnerability classified as problematic has been found in aitangbao springboot-manager 3.0. This affects an unknown part of the file /sys/permission. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2206" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/spring-manage.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511736" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h4q2-fjh5-pc8r/GHSA-h4q2-fjh5-pc8r.json b/advisories/unreviewed/2025/03/GHSA-h4q2-fjh5-pc8r/GHSA-h4q2-fjh5-pc8r.json new file mode 100644 index 00000000000..5a767dcf730 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h4q2-fjh5-pc8r/GHSA-h4q2-fjh5-pc8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4q2-fjh5-pc8r", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28930" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rodolphe MOULIN List Mixcloud allows Stored XSS. This issue affects List Mixcloud: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/list-mixcloud/vulnerability/wordpress-list-mixcloud-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h8p2-3hf9-pqg4/GHSA-h8p2-3hf9-pqg4.json b/advisories/unreviewed/2025/03/GHSA-h8p2-3hf9-pqg4/GHSA-h8p2-3hf9-pqg4.json new file mode 100644 index 00000000000..88f43337815 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h8p2-3hf9-pqg4/GHSA-h8p2-3hf9-pqg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8p2-3hf9-pqg4", + "modified": "2025-03-11T21:30:35Z", + "published": "2025-03-11T21:30:35Z", + "aliases": [ + "CVE-2025-23242" + ], + "details": "NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23242" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5625" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hphx-8248-267c/GHSA-hphx-8248-267c.json b/advisories/unreviewed/2025/03/GHSA-hphx-8248-267c/GHSA-hphx-8248-267c.json new file mode 100644 index 00000000000..487bae4a70e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hphx-8248-267c/GHSA-hphx-8248-267c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hphx-8248-267c", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28857" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration allows Stored XSS. This issue affects Rankchecker.io Integration: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28857" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rankchecker-io-integration/vulnerability/wordpress-rankchecker-io-integration-plugin-1-0-9-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hxm7-743q-rcrf/GHSA-hxm7-743q-rcrf.json b/advisories/unreviewed/2025/03/GHSA-hxm7-743q-rcrf/GHSA-hxm7-743q-rcrf.json new file mode 100644 index 00000000000..0d36927c851 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hxm7-743q-rcrf/GHSA-hxm7-743q-rcrf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxm7-743q-rcrf", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28879" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aumsrini Bee Layer Slider allows Stored XSS. This issue affects Bee Layer Slider: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bee-layer-slider/vulnerability/wordpress-bee-layer-slider-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hxrr-rqj9-gv3m/GHSA-hxrr-rqj9-gv3m.json b/advisories/unreviewed/2025/03/GHSA-hxrr-rqj9-gv3m/GHSA-hxrr-rqj9-gv3m.json new file mode 100644 index 00000000000..f9aee1148fc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hxrr-rqj9-gv3m/GHSA-hxrr-rqj9-gv3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxrr-rqj9-gv3m", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28856" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats allows Cross Site Request Forgery. This issue affects W3Counter Free Real-Time Web Stats: from n/a through 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28856" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blog-stats-by-w3counter/vulnerability/wordpress-w3counter-free-real-time-web-stats-plugin-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j62x-7rpr-8cwh/GHSA-j62x-7rpr-8cwh.json b/advisories/unreviewed/2025/03/GHSA-j62x-7rpr-8cwh/GHSA-j62x-7rpr-8cwh.json new file mode 100644 index 00000000000..b80350d8f5e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j62x-7rpr-8cwh/GHSA-j62x-7rpr-8cwh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j62x-7rpr-8cwh", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28876" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official allows Cross Site Request Forgery. This issue affects Skrill Official: from n/a through 1.0.65.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28876" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/official-skrill-woocommerce/vulnerability/wordpress-skrill-official-plugin-1-0-65-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2c6-j26g-8x96/GHSA-m2c6-j26g-8x96.json b/advisories/unreviewed/2025/03/GHSA-m2c6-j26g-8x96/GHSA-m2c6-j26g-8x96.json new file mode 100644 index 00000000000..1ea53b2ea0f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m2c6-j26g-8x96/GHSA-m2c6-j26g-8x96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2c6-j26g-8x96", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28875" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates allows Stored XSS. This issue affects BP Email Assign Templates: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28875" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bp-email-assign-templates/vulnerability/wordpress-bp-email-assign-templates-by-shanebp-plugin-1-6-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m3jw-9qqr-c9jj/GHSA-m3jw-9qqr-c9jj.json b/advisories/unreviewed/2025/03/GHSA-m3jw-9qqr-c9jj/GHSA-m3jw-9qqr-c9jj.json index a0812756e11..59d873f248d 100644 --- a/advisories/unreviewed/2025/03/GHSA-m3jw-9qqr-c9jj/GHSA-m3jw-9qqr-c9jj.json +++ b/advisories/unreviewed/2025/03/GHSA-m3jw-9qqr-c9jj/GHSA-m3jw-9qqr-c9jj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m3jw-9qqr-c9jj", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T21:30:33Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-56187" ], "details": "In ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-mcqm-xqr9-mjvr/GHSA-mcqm-xqr9-mjvr.json b/advisories/unreviewed/2025/03/GHSA-mcqm-xqr9-mjvr/GHSA-mcqm-xqr9-mjvr.json new file mode 100644 index 00000000000..d3f04397cb5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mcqm-xqr9-mjvr/GHSA-mcqm-xqr9-mjvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcqm-xqr9-mjvr", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28913" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aftab Ali Muni WP Add Active Class To Menu Item allows Cross Site Request Forgery. This issue affects WP Add Active Class To Menu Item: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-add-active-class-to-menu-item/vulnerability/wordpress-wp-add-active-class-to-menu-item-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mwr9-w823-pvwp/GHSA-mwr9-w823-pvwp.json b/advisories/unreviewed/2025/03/GHSA-mwr9-w823-pvwp/GHSA-mwr9-w823-pvwp.json new file mode 100644 index 00000000000..c3dd8679153 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mwr9-w823-pvwp/GHSA-mwr9-w823-pvwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwr9-w823-pvwp", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28901" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users allows Stored XSS. This issue affects Members page only for logged in users: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28901" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/members-page-only-for-logged-in-users/vulnerability/wordpress-members-page-only-for-logged-in-users-plugin-1-4-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json b/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json new file mode 100644 index 00000000000..b2e5920614b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mx4h-4r93-47mh/GHSA-mx4h-4r93-47mh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx4h-4r93-47mh", + "modified": "2025-03-11T21:30:36Z", + "published": "2025-03-11T21:30:36Z", + "aliases": [ + "CVE-2025-25927" + ], + "details": "A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25927" + }, + { + "type": "WEB", + "url": "https://github.com/johnchd/CVEs/blob/main/OpenMRS/CVE-2025-25927%20-%20CSRF%20via%20GET.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p26c-54hm-qqv3/GHSA-p26c-54hm-qqv3.json b/advisories/unreviewed/2025/03/GHSA-p26c-54hm-qqv3/GHSA-p26c-54hm-qqv3.json new file mode 100644 index 00000000000..135b6fd531f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p26c-54hm-qqv3/GHSA-p26c-54hm-qqv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p26c-54hm-qqv3", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28907" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rahul Arora WP Last Modified allows Stored XSS. This issue affects WP Last Modified: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28907" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-last-modified/vulnerability/wordpress-wp-last-modified-plugin-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json b/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json index b25f1c1f7ae..56ae26aa20f 100644 --- a/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json +++ b/advisories/unreviewed/2025/03/GHSA-p2v5-rvqj-c2xc/GHSA-p2v5-rvqj-c2xc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2v5-rvqj-c2xc", - "modified": "2025-03-09T06:31:42Z", + "modified": "2025-03-11T21:30:32Z", "published": "2025-03-09T06:31:42Z", "aliases": [ "CVE-2025-1363" ], "details": "The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-09T06:15:11Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p62r-6qpp-j89h/GHSA-p62r-6qpp-j89h.json b/advisories/unreviewed/2025/03/GHSA-p62r-6qpp-j89h/GHSA-p62r-6qpp-j89h.json new file mode 100644 index 00000000000..f892790ad8c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p62r-6qpp-j89h/GHSA-p62r-6qpp-j89h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p62r-6qpp-j89h", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-27181" + ], + "details": "Substance3D - Modeler versions 1.15.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27181" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p6xj-35fm-qgmf/GHSA-p6xj-35fm-qgmf.json b/advisories/unreviewed/2025/03/GHSA-p6xj-35fm-qgmf/GHSA-p6xj-35fm-qgmf.json new file mode 100644 index 00000000000..c5323f78ee4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p6xj-35fm-qgmf/GHSA-p6xj-35fm-qgmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6xj-35fm-qgmf", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28874" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BP Email Assign Templates: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28874" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bp-email-assign-templates/vulnerability/wordpress-bp-email-assign-templates-by-shanebp-plugin-1-6-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p9r8-xjx7-v86q/GHSA-p9r8-xjx7-v86q.json b/advisories/unreviewed/2025/03/GHSA-p9r8-xjx7-v86q/GHSA-p9r8-xjx7-v86q.json index 00fe978bd56..e6a5ee6b7a1 100644 --- a/advisories/unreviewed/2025/03/GHSA-p9r8-xjx7-v86q/GHSA-p9r8-xjx7-v86q.json +++ b/advisories/unreviewed/2025/03/GHSA-p9r8-xjx7-v86q/GHSA-p9r8-xjx7-v86q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p9r8-xjx7-v86q", - "modified": "2025-03-10T15:30:48Z", + "modified": "2025-03-11T21:30:33Z", "published": "2025-03-10T15:30:48Z", "aliases": [ "CVE-2025-26865" ], "details": "Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: from 18.12.17 before 18.12.18.  \n\nIt's a regression between 18.12.17 and 18.12.18.\nIn case you use something like that, which is not recommended!\nFor security, only official releases should be used.\n\nIn other words, if you use 18.12.17 you are still safe.\nThe version 18.12.17 is not a affected.\nBut something between 18.12.17 and 18.12.18 is.\n\nIn that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-1336" ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T14:15:25Z" diff --git a/advisories/unreviewed/2025/03/GHSA-pj98-cfvv-rcxg/GHSA-pj98-cfvv-rcxg.json b/advisories/unreviewed/2025/03/GHSA-pj98-cfvv-rcxg/GHSA-pj98-cfvv-rcxg.json new file mode 100644 index 00000000000..0a06ec74d80 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pj98-cfvv-rcxg/GHSA-pj98-cfvv-rcxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj98-cfvv-rcxg", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28902" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Benjamin Pick Contact Form 7 Select Box Editor Button allows Cross Site Request Forgery. This issue affects Contact Form 7 Select Box Editor Button: from n/a through 0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28902" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-select-box-editor-button/vulnerability/wordpress-contact-form-7-select-box-editor-button-plugin-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pqxq-83px-8phf/GHSA-pqxq-83px-8phf.json b/advisories/unreviewed/2025/03/GHSA-pqxq-83px-8phf/GHSA-pqxq-83px-8phf.json index 6e744c3da78..7eb4a9c7d83 100644 --- a/advisories/unreviewed/2025/03/GHSA-pqxq-83px-8phf/GHSA-pqxq-83px-8phf.json +++ b/advisories/unreviewed/2025/03/GHSA-pqxq-83px-8phf/GHSA-pqxq-83px-8phf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pqxq-83px-8phf", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T21:30:33Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-56186" ], "details": "In closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qfwc-5f7q-8w42/GHSA-qfwc-5f7q-8w42.json b/advisories/unreviewed/2025/03/GHSA-qfwc-5f7q-8w42/GHSA-qfwc-5f7q-8w42.json new file mode 100644 index 00000000000..25a0ef31a7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qfwc-5f7q-8w42/GHSA-qfwc-5f7q-8w42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfwc-5f7q-8w42", + "modified": "2025-03-11T21:30:37Z", + "published": "2025-03-11T21:30:37Z", + "aliases": [ + "CVE-2025-0900" + ], + "details": "PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25368.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0900" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-086" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qg74-9qxh-vmv5/GHSA-qg74-9qxh-vmv5.json b/advisories/unreviewed/2025/03/GHSA-qg74-9qxh-vmv5/GHSA-qg74-9qxh-vmv5.json new file mode 100644 index 00000000000..a105ea105e5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qg74-9qxh-vmv5/GHSA-qg74-9qxh-vmv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg74-9qxh-vmv5", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-27180" + ], + "details": "Substance3D - Modeler versions 1.15.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27180" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qqpv-m393-pw8r/GHSA-qqpv-m393-pw8r.json b/advisories/unreviewed/2025/03/GHSA-qqpv-m393-pw8r/GHSA-qqpv-m393-pw8r.json new file mode 100644 index 00000000000..d1ea1a40d76 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qqpv-m393-pw8r/GHSA-qqpv-m393-pw8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqpv-m393-pw8r", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28912" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Muntasir Rahman Custom Dashboard Page allows Cross Site Request Forgery. This issue affects Custom Dashboard Page: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-dashboard-page/vulnerability/wordpress-custom-dashboard-page-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qv26-j3vv-r7p7/GHSA-qv26-j3vv-r7p7.json b/advisories/unreviewed/2025/03/GHSA-qv26-j3vv-r7p7/GHSA-qv26-j3vv-r7p7.json new file mode 100644 index 00000000000..5f50728e380 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qv26-j3vv-r7p7/GHSA-qv26-j3vv-r7p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv26-j3vv-r7p7", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2016" + ], + "details": "Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25238.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2016" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-117" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qvv5-5865-pfw8/GHSA-qvv5-5865-pfw8.json b/advisories/unreviewed/2025/03/GHSA-qvv5-5865-pfw8/GHSA-qvv5-5865-pfw8.json new file mode 100644 index 00000000000..7acb5c44e7b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvv5-5865-pfw8/GHSA-qvv5-5865-pfw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvv5-5865-pfw8", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28867" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter allows Cross Site Request Forgery. This issue affects Frontpage category filter: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28867" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/frontpage-category-filter/vulnerability/wordpress-frontpage-category-filter-plugin-1-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rgrc-x3v2-4gmm/GHSA-rgrc-x3v2-4gmm.json b/advisories/unreviewed/2025/03/GHSA-rgrc-x3v2-4gmm/GHSA-rgrc-x3v2-4gmm.json new file mode 100644 index 00000000000..b988623feae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rgrc-x3v2-4gmm/GHSA-rgrc-x3v2-4gmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgrc-x3v2-4gmm", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28892" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync allows Stored XSS. This issue affects FTP Sync: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28892" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ftp-sync/vulnerability/wordpress-ftp-sync-plugin-1-1-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rhfm-q4h8-frxp/GHSA-rhfm-q4h8-frxp.json b/advisories/unreviewed/2025/03/GHSA-rhfm-q4h8-frxp/GHSA-rhfm-q4h8-frxp.json new file mode 100644 index 00000000000..f0be0e8b9dd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rhfm-q4h8-frxp/GHSA-rhfm-q4h8-frxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhfm-q4h8-frxp", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28886" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram allows Cross Site Request Forgery. This issue affects REST API TO MiniProgram: from n/a through 4.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28886" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rest-api-to-miniprogram/vulnerability/wordpress-rest-api-to-miniprogram-plugin-4-7-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmq3-57w7-fmhx/GHSA-rmq3-57w7-fmhx.json b/advisories/unreviewed/2025/03/GHSA-rmq3-57w7-fmhx/GHSA-rmq3-57w7-fmhx.json new file mode 100644 index 00000000000..3d06af9624e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmq3-57w7-fmhx/GHSA-rmq3-57w7-fmhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmq3-57w7-fmhx", + "modified": "2025-03-11T21:30:38Z", + "published": "2025-03-11T21:30:38Z", + "aliases": [ + "CVE-2025-28862" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover allows Cross Site Request Forgery. This issue affects Comment Date and Gravatar remover: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28862" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/remove-date-and-gravatar-under-comment/vulnerability/wordpress-comment-date-and-gravatar-remover-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rq7j-84m9-32jh/GHSA-rq7j-84m9-32jh.json b/advisories/unreviewed/2025/03/GHSA-rq7j-84m9-32jh/GHSA-rq7j-84m9-32jh.json new file mode 100644 index 00000000000..c29a1795ba3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rq7j-84m9-32jh/GHSA-rq7j-84m9-32jh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq7j-84m9-32jh", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28936" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sakurapixel Lunar allows Stored XSS. This issue affects Lunar: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28936" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lunar-sell-photos-online/vulnerability/wordpress-lunar-plugin-1-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v35m-rx24-w6pg/GHSA-v35m-rx24-w6pg.json b/advisories/unreviewed/2025/03/GHSA-v35m-rx24-w6pg/GHSA-v35m-rx24-w6pg.json new file mode 100644 index 00000000000..c320ea654c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v35m-rx24-w6pg/GHSA-v35m-rx24-w6pg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v35m-rx24-w6pg", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28887" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column allows Cross Site Request Forgery. This issue affects Plugins Last Updated Column: from n/a through 0.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/plugins-last-updated-column/vulnerability/wordpress-plugins-last-updated-column-plugin-0-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vcxc-vj6w-2ffm/GHSA-vcxc-vj6w-2ffm.json b/advisories/unreviewed/2025/03/GHSA-vcxc-vj6w-2ffm/GHSA-vcxc-vj6w-2ffm.json new file mode 100644 index 00000000000..ac479cdcfd8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vcxc-vj6w-2ffm/GHSA-vcxc-vj6w-2ffm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcxc-vj6w-2ffm", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28909" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in edwardw WP No-Bot Question allows Cross Site Request Forgery. This issue affects WP No-Bot Question: from n/a through 0.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28909" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-no-bot-question/vulnerability/wordpress-wp-no-bot-question-plugin-0-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vfrv-g5j6-mgmv/GHSA-vfrv-g5j6-mgmv.json b/advisories/unreviewed/2025/03/GHSA-vfrv-g5j6-mgmv/GHSA-vfrv-g5j6-mgmv.json index 53293cb8f1e..994bfc6d743 100644 --- a/advisories/unreviewed/2025/03/GHSA-vfrv-g5j6-mgmv/GHSA-vfrv-g5j6-mgmv.json +++ b/advisories/unreviewed/2025/03/GHSA-vfrv-g5j6-mgmv/GHSA-vfrv-g5j6-mgmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vfrv-g5j6-mgmv", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T21:30:34Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2024-56188" ], "details": "there is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:39Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vhwr-gfg8-hm5j/GHSA-vhwr-gfg8-hm5j.json b/advisories/unreviewed/2025/03/GHSA-vhwr-gfg8-hm5j/GHSA-vhwr-gfg8-hm5j.json new file mode 100644 index 00000000000..d7f2596b128 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vhwr-gfg8-hm5j/GHSA-vhwr-gfg8-hm5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhwr-gfg8-hm5j", + "modified": "2025-03-11T21:30:42Z", + "published": "2025-03-11T21:30:42Z", + "aliases": [ + "CVE-2025-2021" + ], + "details": "Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25264.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2021" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-125" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vrc8-hxm5-v8wx/GHSA-vrc8-hxm5-v8wx.json b/advisories/unreviewed/2025/03/GHSA-vrc8-hxm5-v8wx/GHSA-vrc8-hxm5-v8wx.json new file mode 100644 index 00000000000..0625b2bfa1d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vrc8-hxm5-v8wx/GHSA-vrc8-hxm5-v8wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrc8-hxm5-v8wx", + "modified": "2025-03-11T21:30:42Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2019" + ], + "details": "Ashlar-Vellum Cobalt VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25252.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2019" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-123" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vxg2-q7pw-5mpg/GHSA-vxg2-q7pw-5mpg.json b/advisories/unreviewed/2025/03/GHSA-vxg2-q7pw-5mpg/GHSA-vxg2-q7pw-5mpg.json new file mode 100644 index 00000000000..aa531e42753 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vxg2-q7pw-5mpg/GHSA-vxg2-q7pw-5mpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxg2-q7pw-5mpg", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28931" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DevriX Hashtags allows Stored XSS. This issue affects Hashtags: from n/a through 0.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-hashtags/vulnerability/wordpress-wordpress-hashtags-plugin-0-3-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w56w-w5xr-q52m/GHSA-w56w-w5xr-q52m.json b/advisories/unreviewed/2025/03/GHSA-w56w-w5xr-q52m/GHSA-w56w-w5xr-q52m.json index e09fcf05195..0c64f09d1bc 100644 --- a/advisories/unreviewed/2025/03/GHSA-w56w-w5xr-q52m/GHSA-w56w-w5xr-q52m.json +++ b/advisories/unreviewed/2025/03/GHSA-w56w-w5xr-q52m/GHSA-w56w-w5xr-q52m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w56w-w5xr-q52m", - "modified": "2025-03-10T21:31:12Z", + "modified": "2025-03-11T21:30:34Z", "published": "2025-03-10T21:31:12Z", "aliases": [ "CVE-2025-26696" ], "details": "Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-10T19:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w6jf-6fg2-jpjx/GHSA-w6jf-6fg2-jpjx.json b/advisories/unreviewed/2025/03/GHSA-w6jf-6fg2-jpjx/GHSA-w6jf-6fg2-jpjx.json new file mode 100644 index 00000000000..a3b1ff01dbe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w6jf-6fg2-jpjx/GHSA-w6jf-6fg2-jpjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6jf-6fg2-jpjx", + "modified": "2025-03-11T21:30:42Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-2017" + ], + "details": "Ashlar-Vellum Cobalt CO File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25240.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2017" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w8xg-2rhp-v8c4/GHSA-w8xg-2rhp-v8c4.json b/advisories/unreviewed/2025/03/GHSA-w8xg-2rhp-v8c4/GHSA-w8xg-2rhp-v8c4.json new file mode 100644 index 00000000000..47ce6d9d20c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w8xg-2rhp-v8c4/GHSA-w8xg-2rhp-v8c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8xg-2rhp-v8c4", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28943" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mylo2h2s DP ALTerminator - Missing ALT manager allows Stored XSS. This issue affects DP ALTerminator - Missing ALT manager: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28943" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dp-alterminator-missing-alt-manager/vulnerability/wordpress-dp-alterminator-missing-alt-manager-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wc6w-q8v8-w3c7/GHSA-wc6w-q8v8-w3c7.json b/advisories/unreviewed/2025/03/GHSA-wc6w-q8v8-w3c7/GHSA-wc6w-q8v8-w3c7.json new file mode 100644 index 00000000000..dfcf37df316 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wc6w-q8v8-w3c7/GHSA-wc6w-q8v8-w3c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc6w-q8v8-w3c7", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28900" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in webgarb TabGarb Pro allows Stored XSS. This issue affects TabGarb Pro: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28900" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tabgarb/vulnerability/wordpress-tabgarb-pro-plugin-2-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wfr6-fwjh-5jx6/GHSA-wfr6-fwjh-5jx6.json b/advisories/unreviewed/2025/03/GHSA-wfr6-fwjh-5jx6/GHSA-wfr6-fwjh-5jx6.json new file mode 100644 index 00000000000..9afa01cd182 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wfr6-fwjh-5jx6/GHSA-wfr6-fwjh-5jx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfr6-fwjh-5jx6", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28920" + ], + "details": "Missing Authorization vulnerability in Jogesh Responsive Google Map allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Responsive Google Map: from n/a through 3.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28920" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsive-google-map/vulnerability/wordpress-responsive-google-map-plugin-3-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wh9x-w9vv-rjf9/GHSA-wh9x-w9vv-rjf9.json b/advisories/unreviewed/2025/03/GHSA-wh9x-w9vv-rjf9/GHSA-wh9x-w9vv-rjf9.json new file mode 100644 index 00000000000..d30bc90fb38 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wh9x-w9vv-rjf9/GHSA-wh9x-w9vv-rjf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh9x-w9vv-rjf9", + "modified": "2025-03-11T21:30:35Z", + "published": "2025-03-11T21:30:35Z", + "aliases": [ + "CVE-2025-23243" + ], + "details": "NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23243" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5625" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T20:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wq5j-wjp2-4f74/GHSA-wq5j-wjp2-4f74.json b/advisories/unreviewed/2025/03/GHSA-wq5j-wjp2-4f74/GHSA-wq5j-wjp2-4f74.json new file mode 100644 index 00000000000..5a162d5879d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wq5j-wjp2-4f74/GHSA-wq5j-wjp2-4f74.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq5j-wjp2-4f74", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28896" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akshar Soft Solutions AS English Admin allows Phishing. This issue affects AS English Admin: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28896" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/as-english-admin/vulnerability/wordpress-as-english-admin-plugin-1-0-0-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x53r-mfrq-c435/GHSA-x53r-mfrq-c435.json b/advisories/unreviewed/2025/03/GHSA-x53r-mfrq-c435/GHSA-x53r-mfrq-c435.json index 7c2d9005a68..f60054be676 100644 --- a/advisories/unreviewed/2025/03/GHSA-x53r-mfrq-c435/GHSA-x53r-mfrq-c435.json +++ b/advisories/unreviewed/2025/03/GHSA-x53r-mfrq-c435/GHSA-x53r-mfrq-c435.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x53r-mfrq-c435", - "modified": "2025-03-08T12:30:31Z", + "modified": "2025-03-11T21:30:31Z", "published": "2025-03-08T12:30:31Z", "aliases": [ "CVE-2025-1664" diff --git a/advisories/unreviewed/2025/03/GHSA-xcpx-xw8r-x8rf/GHSA-xcpx-xw8r-x8rf.json b/advisories/unreviewed/2025/03/GHSA-xcpx-xw8r-x8rf/GHSA-xcpx-xw8r-x8rf.json new file mode 100644 index 00000000000..1c86238cd34 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xcpx-xw8r-x8rf/GHSA-xcpx-xw8r-x8rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcpx-xw8r-x8rf", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28894" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in frucomerci List of Posts from each Category plugin for WordPress allows Stored XSS. This issue affects List of Posts from each Category plugin for WordPress: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28894" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/list-posts-by-category/vulnerability/wordpress-list-of-posts-from-each-category-plugin-for-wordpress-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xgx2-r4f9-h8w3/GHSA-xgx2-r4f9-h8w3.json b/advisories/unreviewed/2025/03/GHSA-xgx2-r4f9-h8w3/GHSA-xgx2-r4f9-h8w3.json new file mode 100644 index 00000000000..6f82bcbc53d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xgx2-r4f9-h8w3/GHSA-xgx2-r4f9-h8w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgx2-r4f9-h8w3", + "modified": "2025-03-11T21:30:40Z", + "published": "2025-03-11T21:30:40Z", + "aliases": [ + "CVE-2025-28933" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B allows Stored XSS. This issue affects MaxA/B: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28933" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/maxab/vulnerability/wordpress-maxa-b-plugin-2-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xpq2-2hq8-6f42/GHSA-xpq2-2hq8-6f42.json b/advisories/unreviewed/2025/03/GHSA-xpq2-2hq8-6f42/GHSA-xpq2-2hq8-6f42.json new file mode 100644 index 00000000000..50907dec691 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xpq2-2hq8-6f42/GHSA-xpq2-2hq8-6f42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpq2-2hq8-6f42", + "modified": "2025-03-11T21:30:39Z", + "published": "2025-03-11T21:30:39Z", + "aliases": [ + "CVE-2025-28895" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumanbiswas013 Custom top bar allows Stored XSS. This issue affects Custom top bar: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28895" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-top-bar/vulnerability/wordpress-custom-top-bar-plugin-2-0-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xwx7-4rrg-r95g/GHSA-xwx7-4rrg-r95g.json b/advisories/unreviewed/2025/03/GHSA-xwx7-4rrg-r95g/GHSA-xwx7-4rrg-r95g.json new file mode 100644 index 00000000000..4333ef4b796 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xwx7-4rrg-r95g/GHSA-xwx7-4rrg-r95g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwx7-4rrg-r95g", + "modified": "2025-03-11T21:30:41Z", + "published": "2025-03-11T21:30:41Z", + "aliases": [ + "CVE-2025-28940" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in arkapravamajumder Back To Top allows Cross Site Request Forgery. This issue affects Back To Top: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28940" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/backtotop/vulnerability/wordpress-back-to-top-plugin-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-11T21:15:51Z" + } +} \ No newline at end of file