diff --git a/advisories/unreviewed/2023/03/GHSA-2qrx-mpvp-j33p/GHSA-2qrx-mpvp-j33p.json b/advisories/unreviewed/2023/03/GHSA-2qrx-mpvp-j33p/GHSA-2qrx-mpvp-j33p.json index 789ce565f44..c5fa888463a 100644 --- a/advisories/unreviewed/2023/03/GHSA-2qrx-mpvp-j33p/GHSA-2qrx-mpvp-j33p.json +++ b/advisories/unreviewed/2023/03/GHSA-2qrx-mpvp-j33p/GHSA-2qrx-mpvp-j33p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-77f3-6546-6rj7/GHSA-77f3-6546-6rj7.json b/advisories/unreviewed/2023/03/GHSA-77f3-6546-6rj7/GHSA-77f3-6546-6rj7.json index 7e7f5df436a..2ecb96e8ce4 100644 --- a/advisories/unreviewed/2023/03/GHSA-77f3-6546-6rj7/GHSA-77f3-6546-6rj7.json +++ b/advisories/unreviewed/2023/03/GHSA-77f3-6546-6rj7/GHSA-77f3-6546-6rj7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77f3-6546-6rj7", - "modified": "2023-04-04T18:30:23Z", + "modified": "2025-02-18T21:32:06Z", "published": "2023-03-28T15:30:16Z", "aliases": [ "CVE-2023-0465" diff --git a/advisories/unreviewed/2023/03/GHSA-8jh9-5v73-5hrf/GHSA-8jh9-5v73-5hrf.json b/advisories/unreviewed/2023/03/GHSA-8jh9-5v73-5hrf/GHSA-8jh9-5v73-5hrf.json index b9301ca3573..b2d19a4dae8 100644 --- a/advisories/unreviewed/2023/03/GHSA-8jh9-5v73-5hrf/GHSA-8jh9-5v73-5hrf.json +++ b/advisories/unreviewed/2023/03/GHSA-8jh9-5v73-5hrf/GHSA-8jh9-5v73-5hrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8jh9-5v73-5hrf", - "modified": "2023-04-03T18:32:07Z", + "modified": "2025-02-18T21:32:06Z", "published": "2023-03-28T15:30:16Z", "aliases": [ "CVE-2023-27008" diff --git a/advisories/unreviewed/2023/03/GHSA-9vhh-53xv-f4c4/GHSA-9vhh-53xv-f4c4.json b/advisories/unreviewed/2023/03/GHSA-9vhh-53xv-f4c4/GHSA-9vhh-53xv-f4c4.json index e8e69a3e09d..163e4291a61 100644 --- a/advisories/unreviewed/2023/03/GHSA-9vhh-53xv-f4c4/GHSA-9vhh-53xv-f4c4.json +++ b/advisories/unreviewed/2023/03/GHSA-9vhh-53xv-f4c4/GHSA-9vhh-53xv-f4c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vhh-53xv-f4c4", - "modified": "2023-04-01T03:30:16Z", + "modified": "2025-02-18T21:32:04Z", "published": "2023-03-28T03:30:18Z", "aliases": [ "CVE-2023-23330" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23330" }, + { + "type": "WEB", + "url": "https://medium.com/%40saleh.py/amano-xparc-local-file-inclusion-cve-2023-23330-672ae8fbfd1e" + }, { "type": "WEB", "url": "https://medium.com/@saleh.py/amano-xparc-local-file-inclusion-cve-2023-23330-672ae8fbfd1e" diff --git a/advisories/unreviewed/2023/03/GHSA-hmjw-7429-p2vc/GHSA-hmjw-7429-p2vc.json b/advisories/unreviewed/2023/03/GHSA-hmjw-7429-p2vc/GHSA-hmjw-7429-p2vc.json index 6b98d057d34..8f643a53e85 100644 --- a/advisories/unreviewed/2023/03/GHSA-hmjw-7429-p2vc/GHSA-hmjw-7429-p2vc.json +++ b/advisories/unreviewed/2023/03/GHSA-hmjw-7429-p2vc/GHSA-hmjw-7429-p2vc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-250" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json b/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json index 5c76d7b8e8b..ed00c9ff7ab 100644 --- a/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json +++ b/advisories/unreviewed/2023/03/GHSA-m46g-8pc6-m8q7/GHSA-m46g-8pc6-m8q7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json b/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json index a3cfb7a40b5..ff74c995047 100644 --- a/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json +++ b/advisories/unreviewed/2023/03/GHSA-m79g-73hm-2964/GHSA-m79g-73hm-2964.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m79g-73hm-2964", - "modified": "2023-04-05T00:30:38Z", + "modified": "2025-02-18T21:32:06Z", "published": "2023-03-28T21:30:16Z", "aliases": [ "CVE-2023-24304" diff --git a/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json b/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json index 7c04fbee70f..a4132c888a7 100644 --- a/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json +++ b/advisories/unreviewed/2023/03/GHSA-mvgg-p48p-h9jc/GHSA-mvgg-p48p-h9jc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvgg-p48p-h9jc", - "modified": "2023-04-08T03:30:28Z", + "modified": "2025-02-18T21:32:06Z", "published": "2023-03-29T21:30:16Z", "aliases": [ "CVE-2023-0664" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://gitlab.com/qemu-project/qemu/-/commit/88288c2a51faa7c795f053fc8b31b1c16ff804c5" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MURWGXDIF2WTDXV36T6HFJDBL632AO7R" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEOC7SRJWLZSXCND2ADFW6C76ZMTZLE4" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MURWGXDIF2WTDXV36T6HFJDBL632AO7R" diff --git a/advisories/unreviewed/2024/05/GHSA-969g-hr92-7wvc/GHSA-969g-hr92-7wvc.json b/advisories/unreviewed/2024/05/GHSA-969g-hr92-7wvc/GHSA-969g-hr92-7wvc.json index a139bbe2920..5e1bff86447 100644 --- a/advisories/unreviewed/2024/05/GHSA-969g-hr92-7wvc/GHSA-969g-hr92-7wvc.json +++ b/advisories/unreviewed/2024/05/GHSA-969g-hr92-7wvc/GHSA-969g-hr92-7wvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-969g-hr92-7wvc", - "modified": "2024-05-16T12:30:21Z", + "modified": "2025-02-18T21:32:07Z", "published": "2024-05-16T12:30:21Z", "aliases": [ "CVE-2024-4974" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-f6jx-gr5x-vh48/GHSA-f6jx-gr5x-vh48.json b/advisories/unreviewed/2024/05/GHSA-f6jx-gr5x-vh48/GHSA-f6jx-gr5x-vh48.json index 482793d1ad9..fb5fed1f087 100644 --- a/advisories/unreviewed/2024/05/GHSA-f6jx-gr5x-vh48/GHSA-f6jx-gr5x-vh48.json +++ b/advisories/unreviewed/2024/05/GHSA-f6jx-gr5x-vh48/GHSA-f6jx-gr5x-vh48.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6jx-gr5x-vh48", - "modified": "2024-05-16T09:33:09Z", + "modified": "2025-02-18T21:32:07Z", "published": "2024-05-16T09:33:09Z", "aliases": [ "CVE-2024-4972" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-m9c5-g98x-fwhm/GHSA-m9c5-g98x-fwhm.json b/advisories/unreviewed/2024/05/GHSA-m9c5-g98x-fwhm/GHSA-m9c5-g98x-fwhm.json index 8ec15713861..d07910eea08 100644 --- a/advisories/unreviewed/2024/05/GHSA-m9c5-g98x-fwhm/GHSA-m9c5-g98x-fwhm.json +++ b/advisories/unreviewed/2024/05/GHSA-m9c5-g98x-fwhm/GHSA-m9c5-g98x-fwhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9c5-g98x-fwhm", - "modified": "2024-05-16T12:30:21Z", + "modified": "2025-02-18T21:32:07Z", "published": "2024-05-16T12:30:21Z", "aliases": [ "CVE-2024-4973" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-xrc9-xx3q-8c6x/GHSA-xrc9-xx3q-8c6x.json b/advisories/unreviewed/2024/05/GHSA-xrc9-xx3q-8c6x/GHSA-xrc9-xx3q-8c6x.json index 4a37724c5e1..a5af099550e 100644 --- a/advisories/unreviewed/2024/05/GHSA-xrc9-xx3q-8c6x/GHSA-xrc9-xx3q-8c6x.json +++ b/advisories/unreviewed/2024/05/GHSA-xrc9-xx3q-8c6x/GHSA-xrc9-xx3q-8c6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xrc9-xx3q-8c6x", - "modified": "2024-05-16T12:30:22Z", + "modified": "2025-02-18T21:32:07Z", "published": "2024-05-16T12:30:21Z", "aliases": [ "CVE-2024-4975" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json b/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json index cde81db90f9..9231cd59b73 100644 --- a/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json +++ b/advisories/unreviewed/2024/09/GHSA-8xf3-x93c-2ch6/GHSA-8xf3-x93c-2ch6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xf3-x93c-2ch6", - "modified": "2024-09-27T18:32:26Z", + "modified": "2025-02-18T21:32:08Z", "published": "2024-09-27T18:32:25Z", "aliases": [ "CVE-2024-45744" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://www.topquadrant.com/release-note/7-3" + }, + { + "type": "WEB", + "url": "https://www.topquadrant.com/wp-content/uploads/2025/02/changes-8.3.0.txt" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-25x4-r7rm-rcw2/GHSA-25x4-r7rm-rcw2.json b/advisories/unreviewed/2024/12/GHSA-25x4-r7rm-rcw2/GHSA-25x4-r7rm-rcw2.json index 5921391bd96..1b69c4abc1a 100644 --- a/advisories/unreviewed/2024/12/GHSA-25x4-r7rm-rcw2/GHSA-25x4-r7rm-rcw2.json +++ b/advisories/unreviewed/2024/12/GHSA-25x4-r7rm-rcw2/GHSA-25x4-r7rm-rcw2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json b/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json index d5b27d9f7c1..73ffdd17f14 100644 --- a/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json +++ b/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-cc4m-2w6w-v644/GHSA-cc4m-2w6w-v644.json b/advisories/unreviewed/2024/12/GHSA-cc4m-2w6w-v644/GHSA-cc4m-2w6w-v644.json index b8d07bf2670..938fda3f1c9 100644 --- a/advisories/unreviewed/2024/12/GHSA-cc4m-2w6w-v644/GHSA-cc4m-2w6w-v644.json +++ b/advisories/unreviewed/2024/12/GHSA-cc4m-2w6w-v644/GHSA-cc4m-2w6w-v644.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-f7jm-w7p3-2p64/GHSA-f7jm-w7p3-2p64.json b/advisories/unreviewed/2024/12/GHSA-f7jm-w7p3-2p64/GHSA-f7jm-w7p3-2p64.json index 5479b2f8fd8..a60c67a7f71 100644 --- a/advisories/unreviewed/2024/12/GHSA-f7jm-w7p3-2p64/GHSA-f7jm-w7p3-2p64.json +++ b/advisories/unreviewed/2024/12/GHSA-f7jm-w7p3-2p64/GHSA-f7jm-w7p3-2p64.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json b/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json index 904614f7b7c..0d49089c8bd 100644 --- a/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json +++ b/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-mwc8-m5w9-fmf3/GHSA-mwc8-m5w9-fmf3.json b/advisories/unreviewed/2024/12/GHSA-mwc8-m5w9-fmf3/GHSA-mwc8-m5w9-fmf3.json index 8708f87523e..39e622398db 100644 --- a/advisories/unreviewed/2024/12/GHSA-mwc8-m5w9-fmf3/GHSA-mwc8-m5w9-fmf3.json +++ b/advisories/unreviewed/2024/12/GHSA-mwc8-m5w9-fmf3/GHSA-mwc8-m5w9-fmf3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-p7p8-8m5p-c79x/GHSA-p7p8-8m5p-c79x.json b/advisories/unreviewed/2024/12/GHSA-p7p8-8m5p-c79x/GHSA-p7p8-8m5p-c79x.json index 6f429500dad..d5d00e3da74 100644 --- a/advisories/unreviewed/2024/12/GHSA-p7p8-8m5p-c79x/GHSA-p7p8-8m5p-c79x.json +++ b/advisories/unreviewed/2024/12/GHSA-p7p8-8m5p-c79x/GHSA-p7p8-8m5p-c79x.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json b/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json index ca574ee390d..ede039094c5 100644 --- a/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json +++ b/advisories/unreviewed/2025/01/GHSA-chv5-gcx2-vw99/GHSA-chv5-gcx2-vw99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chv5-gcx2-vw99", - "modified": "2025-01-28T18:31:25Z", + "modified": "2025-02-18T21:32:29Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54475" diff --git a/advisories/unreviewed/2025/01/GHSA-g997-2wcf-j63g/GHSA-g997-2wcf-j63g.json b/advisories/unreviewed/2025/01/GHSA-g997-2wcf-j63g/GHSA-g997-2wcf-j63g.json new file mode 100644 index 00000000000..de26e379306 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g997-2wcf-j63g/GHSA-g997-2wcf-j63g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g997-2wcf-j63g", + "modified": "2025-02-18T21:32:35Z", + "published": "2025-01-31T15:30:44Z", + "aliases": [ + "CVE-2025-24827" + ], + "details": "Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39378.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24827" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-7841" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gw2x-wpmj-6qcq/GHSA-gw2x-wpmj-6qcq.json b/advisories/unreviewed/2025/01/GHSA-gw2x-wpmj-6qcq/GHSA-gw2x-wpmj-6qcq.json index 3440add3194..c6f46ff3468 100644 --- a/advisories/unreviewed/2025/01/GHSA-gw2x-wpmj-6qcq/GHSA-gw2x-wpmj-6qcq.json +++ b/advisories/unreviewed/2025/01/GHSA-gw2x-wpmj-6qcq/GHSA-gw2x-wpmj-6qcq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json index 3bc3710a62b..65dcab5dd92 100644 --- a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json +++ b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mx5v-hjgf-32j4", - "modified": "2025-01-28T15:31:56Z", + "modified": "2025-02-18T21:32:29Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24102" diff --git a/advisories/unreviewed/2025/01/GHSA-wgmv-5488-h5p5/GHSA-wgmv-5488-h5p5.json b/advisories/unreviewed/2025/01/GHSA-wgmv-5488-h5p5/GHSA-wgmv-5488-h5p5.json index e9dc64b4e76..4a66187c493 100644 --- a/advisories/unreviewed/2025/01/GHSA-wgmv-5488-h5p5/GHSA-wgmv-5488-h5p5.json +++ b/advisories/unreviewed/2025/01/GHSA-wgmv-5488-h5p5/GHSA-wgmv-5488-h5p5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgmv-5488-h5p5", - "modified": "2025-01-31T18:31:06Z", + "modified": "2025-02-18T21:32:35Z", "published": "2025-01-31T12:33:02Z", "aliases": [ "CVE-2024-12267" diff --git a/advisories/unreviewed/2025/02/GHSA-2rg6-xxcc-pvj5/GHSA-2rg6-xxcc-pvj5.json b/advisories/unreviewed/2025/02/GHSA-2rg6-xxcc-pvj5/GHSA-2rg6-xxcc-pvj5.json index 89d4f09119c..4c2ad5bbe0b 100644 --- a/advisories/unreviewed/2025/02/GHSA-2rg6-xxcc-pvj5/GHSA-2rg6-xxcc-pvj5.json +++ b/advisories/unreviewed/2025/02/GHSA-2rg6-xxcc-pvj5/GHSA-2rg6-xxcc-pvj5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json new file mode 100644 index 00000000000..5726800647a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xfx-cg6v-cwqv", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2024-45781" + ], + "details": "A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issues and eventually allowing an attacker to circumvent secure boot protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45781" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45781" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345857" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3888-hq29-rm5x/GHSA-3888-hq29-rm5x.json b/advisories/unreviewed/2025/02/GHSA-3888-hq29-rm5x/GHSA-3888-hq29-rm5x.json new file mode 100644 index 00000000000..f4613d55a64 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3888-hq29-rm5x/GHSA-3888-hq29-rm5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3888-hq29-rm5x", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2025-22654" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified allows Using Malicious Files. This issue affects Simplified: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22654" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simplified/vulnerability/wordpress-simplified-plugin-plugin-1-0-6-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3gfg-2v89-c3pm/GHSA-3gfg-2v89-c3pm.json b/advisories/unreviewed/2025/02/GHSA-3gfg-2v89-c3pm/GHSA-3gfg-2v89-c3pm.json index f44e12cfded..77bfd3d28f7 100644 --- a/advisories/unreviewed/2025/02/GHSA-3gfg-2v89-c3pm/GHSA-3gfg-2v89-c3pm.json +++ b/advisories/unreviewed/2025/02/GHSA-3gfg-2v89-c3pm/GHSA-3gfg-2v89-c3pm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gfg-2v89-c3pm", - "modified": "2025-02-18T18:33:21Z", + "modified": "2025-02-18T21:32:50Z", "published": "2025-02-18T18:33:21Z", "aliases": [ "CVE-2024-49589" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49589" }, + { + "type": "WEB", + "url": "https://palantir.safebase.us/?tcuUid=ad6b08b1-2f79-4e32-b125-406dd2b9b1c3" + }, { "type": "WEB", "url": "https://palantir.safebase.us/?tcuUid=b60db1ee-4b1a-475d-848e-c5a670a0da16" @@ -26,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-3gr4-8q4g-6f4q/GHSA-3gr4-8q4g-6f4q.json b/advisories/unreviewed/2025/02/GHSA-3gr4-8q4g-6f4q/GHSA-3gr4-8q4g-6f4q.json new file mode 100644 index 00000000000..a2b1a2e4418 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3gr4-8q4g-6f4q/GHSA-3gr4-8q4g-6f4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gr4-8q4g-6f4q", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2025-22639" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Distance Rate Shipping for WooCommerce allows Blind SQL Injection. This issue affects Distance Rate Shipping for WooCommerce: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/distance-rate-shipping-for-woocommerce-pro/vulnerability/wordpress-distance-rate-shipping-for-woocommerce-plugin-1-3-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-44f2-jwph-6ghp/GHSA-44f2-jwph-6ghp.json b/advisories/unreviewed/2025/02/GHSA-44f2-jwph-6ghp/GHSA-44f2-jwph-6ghp.json new file mode 100644 index 00000000000..db41260438b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-44f2-jwph-6ghp/GHSA-44f2-jwph-6ghp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44f2-jwph-6ghp", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2025-22650" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget allows Stored XSS. This issue affects Smartarget: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22650" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smartarget-contact-us/vulnerability/wordpress-smartarget-online-integration-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json b/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json new file mode 100644 index 00000000000..ca9c609f88a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4wxw-3vrc-3hmh/GHSA-4wxw-3vrc-3hmh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wxw-3vrc-3hmh", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2024-45783" + ], + "details": "A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue may lead to a NULL pointer access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45783" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45783" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345863" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-911" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5w9j-4347-x66c/GHSA-5w9j-4347-x66c.json b/advisories/unreviewed/2025/02/GHSA-5w9j-4347-x66c/GHSA-5w9j-4347-x66c.json new file mode 100644 index 00000000000..b81213d300f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5w9j-4347-x66c/GHSA-5w9j-4347-x66c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w9j-4347-x66c", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:52Z", + "aliases": [ + "CVE-2025-22657" + ], + "details": "Missing Authorization vulnerability in Vito Peleg Atarim allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Atarim: from n/a through 4.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22657" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atarim-visual-collaboration/vulnerability/wordpress-atarim-plugin-4-0-9-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json b/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json index 53397a72daf..3791a224bdc 100644 --- a/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json +++ b/advisories/unreviewed/2025/02/GHSA-67x3-pf53-7724/GHSA-67x3-pf53-7724.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-67x3-pf53-7724", - "modified": "2025-02-15T06:30:51Z", + "modified": "2025-02-18T21:32:46Z", "published": "2025-02-15T06:30:51Z", "aliases": [ "CVE-2024-13208" ], "details": "The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-15T06:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json b/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json index 34fdbb781dd..49dcdc791dd 100644 --- a/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json +++ b/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6j8j-86h8-528v", - "modified": "2025-02-15T09:30:29Z", + "modified": "2025-02-18T21:32:46Z", "published": "2025-02-15T09:30:29Z", "aliases": [ "CVE-2025-22208" ], "details": "A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-15T09:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6xff-6366-vrm2/GHSA-6xff-6366-vrm2.json b/advisories/unreviewed/2025/02/GHSA-6xff-6366-vrm2/GHSA-6xff-6366-vrm2.json new file mode 100644 index 00000000000..362cca7ad27 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6xff-6366-vrm2/GHSA-6xff-6366-vrm2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xff-6366-vrm2", + "modified": "2025-02-18T21:32:46Z", + "published": "2025-02-06T15:32:53Z", + "aliases": [ + "CVE-2023-5878" + ], + "details": "Honeywell OneWireless \n\nWireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to \n\n R322.3, R330.2 or the most recent version of this product2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5878" + }, + { + "type": "WEB", + "url": "https://process.honeywell.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-766r-hgq9-v6vx/GHSA-766r-hgq9-v6vx.json b/advisories/unreviewed/2025/02/GHSA-766r-hgq9-v6vx/GHSA-766r-hgq9-v6vx.json new file mode 100644 index 00000000000..74775afd6e5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-766r-hgq9-v6vx/GHSA-766r-hgq9-v6vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-766r-hgq9-v6vx", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2024-56000" + ], + "details": "Incorrect Privilege Assignment vulnerability in NotFound K Elements allows Privilege Escalation. This issue affects K Elements: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/k-elements/vulnerability/wordpress-k-elements-plugin-5-2-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json b/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json new file mode 100644 index 00000000000..c83322d3e6c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8852-57vj-5pjq/GHSA-8852-57vj-5pjq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8852-57vj-5pjq", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2024-45776" + ], + "details": "When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes. This flaw allows an attacker to leak sensitive data or overwrite critical data, possibly circumventing secure boot protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45776" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45776" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8rf3-52xm-w6jc/GHSA-8rf3-52xm-w6jc.json b/advisories/unreviewed/2025/02/GHSA-8rf3-52xm-w6jc/GHSA-8rf3-52xm-w6jc.json new file mode 100644 index 00000000000..ce6252c3925 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8rf3-52xm-w6jc/GHSA-8rf3-52xm-w6jc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rf3-52xm-w6jc", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2025-22645" + ], + "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/real-estate-manager/vulnerability/wordpress-real-estate-manager-property-listing-and-agent-management-plugin-7-3-captcha-bypass-vulnerability-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json b/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json index a188952b339..e699f0c839f 100644 --- a/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json +++ b/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9v7f-8fcp-rxqx", - "modified": "2025-02-15T09:30:29Z", + "modified": "2025-02-18T21:32:46Z", "published": "2025-02-15T09:30:29Z", "aliases": [ "CVE-2025-22209" ], "details": "A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-15T09:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-chxc-45g7-vr66/GHSA-chxc-45g7-vr66.json b/advisories/unreviewed/2025/02/GHSA-chxc-45g7-vr66/GHSA-chxc-45g7-vr66.json new file mode 100644 index 00000000000..a6e26f0b7c4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-chxc-45g7-vr66/GHSA-chxc-45g7-vr66.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chxc-45g7-vr66", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2024-57056" + ], + "details": "Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to impersonate an existing user session.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57056" + }, + { + "type": "WEB", + "url": "https://www.wombatdialer.com/blog/blog/2025/02/18/CVE" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json b/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json new file mode 100644 index 00000000000..e8f5158b8c0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f5v2-rhg6-jmg7/GHSA-f5v2-rhg6-jmg7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5v2-rhg6-jmg7", + "modified": "2025-02-18T21:32:50Z", + "published": "2025-02-18T21:32:50Z", + "aliases": [ + "CVE-2024-45774" + ], + "details": "A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive information to bypass secure boot protections is not discarded.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45774" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45774" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2337461" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gf79-frwr-2v77/GHSA-gf79-frwr-2v77.json b/advisories/unreviewed/2025/02/GHSA-gf79-frwr-2v77/GHSA-gf79-frwr-2v77.json index 005c7b4a3fd..aa5ad30c3c2 100644 --- a/advisories/unreviewed/2025/02/GHSA-gf79-frwr-2v77/GHSA-gf79-frwr-2v77.json +++ b/advisories/unreviewed/2025/02/GHSA-gf79-frwr-2v77/GHSA-gf79-frwr-2v77.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-61" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-gx24-9fw3-rrqp/GHSA-gx24-9fw3-rrqp.json b/advisories/unreviewed/2025/02/GHSA-gx24-9fw3-rrqp/GHSA-gx24-9fw3-rrqp.json new file mode 100644 index 00000000000..be1bcb86319 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gx24-9fw3-rrqp/GHSA-gx24-9fw3-rrqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx24-9fw3-rrqp", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:52Z", + "aliases": [ + "CVE-2025-22663" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site allows Path Traversal. This issue affects Paid Videochat Turnkey Site: from n/a through 7.2.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22663" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ppv-live-webcams/vulnerability/wordpress-paid-videochat-turnkey-site-plugin-7-2-12-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json b/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json index 04427d84278..3eb912680f9 100644 --- a/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json +++ b/advisories/unreviewed/2025/02/GHSA-j27x-pp9j-vhj8/GHSA-j27x-pp9j-vhj8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j27x-pp9j-vhj8", - "modified": "2025-02-15T06:30:51Z", + "modified": "2025-02-18T21:32:46Z", "published": "2025-02-15T06:30:51Z", "aliases": [ "CVE-2024-13306" ], "details": "The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-15T06:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jrwv-mv4h-7rrq/GHSA-jrwv-mv4h-7rrq.json b/advisories/unreviewed/2025/02/GHSA-jrwv-mv4h-7rrq/GHSA-jrwv-mv4h-7rrq.json new file mode 100644 index 00000000000..82b9136826a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jrwv-mv4h-7rrq/GHSA-jrwv-mv4h-7rrq.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrwv-mv4h-7rrq", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2025-26465" + ], + "details": "A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26465" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-26465" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2344780" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T19:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jv46-gr4p-7xp9/GHSA-jv46-gr4p-7xp9.json b/advisories/unreviewed/2025/02/GHSA-jv46-gr4p-7xp9/GHSA-jv46-gr4p-7xp9.json index bdee48cca34..105ac1a9f72 100644 --- a/advisories/unreviewed/2025/02/GHSA-jv46-gr4p-7xp9/GHSA-jv46-gr4p-7xp9.json +++ b/advisories/unreviewed/2025/02/GHSA-jv46-gr4p-7xp9/GHSA-jv46-gr4p-7xp9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-mp4p-vfgp-m87p/GHSA-mp4p-vfgp-m87p.json b/advisories/unreviewed/2025/02/GHSA-mp4p-vfgp-m87p/GHSA-mp4p-vfgp-m87p.json index 1b5e24fbc24..9d7a054f6d7 100644 --- a/advisories/unreviewed/2025/02/GHSA-mp4p-vfgp-m87p/GHSA-mp4p-vfgp-m87p.json +++ b/advisories/unreviewed/2025/02/GHSA-mp4p-vfgp-m87p/GHSA-mp4p-vfgp-m87p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mp4p-vfgp-m87p", - "modified": "2025-02-10T18:30:47Z", + "modified": "2025-02-18T21:32:46Z", "published": "2025-02-10T18:30:47Z", "aliases": [ "CVE-2024-48170" ], "details": "PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T18:15:26Z" diff --git a/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json b/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json index 743a9c20fda..64d88e0c9df 100644 --- a/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json +++ b/advisories/unreviewed/2025/02/GHSA-p5jc-239c-pvvf/GHSA-p5jc-239c-pvvf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5jc-239c-pvvf", - "modified": "2025-02-18T15:31:07Z", + "modified": "2025-02-18T21:32:49Z", "published": "2025-02-18T15:31:07Z", "aliases": [ "CVE-2025-1414" ], "details": "Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-18T14:15:28Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json b/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json new file mode 100644 index 00000000000..42bf9c450a8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pf8f-3pq9-mrv7/GHSA-pf8f-3pq9-mrv7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf8f-3pq9-mrv7", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2024-45775" + ], + "details": "A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation fails, a NULL point will be processed by the parse_option() function, leading grub to crash or, in some rare scenarios, corrupt the IVT data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45775" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45775" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2337481" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-252" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r7rh-c7wm-cc7x/GHSA-r7rh-c7wm-cc7x.json b/advisories/unreviewed/2025/02/GHSA-r7rh-c7wm-cc7x/GHSA-r7rh-c7wm-cc7x.json new file mode 100644 index 00000000000..49470e720d0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r7rh-c7wm-cc7x/GHSA-r7rh-c7wm-cc7x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7rh-c7wm-cc7x", + "modified": "2025-02-18T21:32:50Z", + "published": "2025-02-18T21:32:50Z", + "aliases": [ + "CVE-2024-57055" + ], + "details": "Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57055" + }, + { + "type": "WEB", + "url": "https://www.wombatdialer.com/blog/blog/2025/02/18/CVE" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rj3h-7vjp-p2xf/GHSA-rj3h-7vjp-p2xf.json b/advisories/unreviewed/2025/02/GHSA-rj3h-7vjp-p2xf/GHSA-rj3h-7vjp-p2xf.json new file mode 100644 index 00000000000..3a800a3b86d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rj3h-7vjp-p2xf/GHSA-rj3h-7vjp-p2xf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj3h-7vjp-p2xf", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:52Z", + "aliases": [ + "CVE-2025-27016" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite – Google Drive Plugin allows Stored XSS. This issue affects Drivr Lite – Google Drive Plugin: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27016" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/drivr-google-drive-file-picker/vulnerability/wordpress-drivr-lite-google-drive-plugin-plugin-1-0-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v935-x4wr-fq98/GHSA-v935-x4wr-fq98.json b/advisories/unreviewed/2025/02/GHSA-v935-x4wr-fq98/GHSA-v935-x4wr-fq98.json new file mode 100644 index 00000000000..5e0b12825e7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v935-x4wr-fq98/GHSA-v935-x4wr-fq98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v935-x4wr-fq98", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:52Z", + "aliases": [ + "CVE-2025-27013" + ], + "details": "Missing Authorization vulnerability in EPC MediCenter - Health Medical Clinic WordPress Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MediCenter - Health Medical Clinic WordPress Theme: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27013" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/medicenter/vulnerability/wordpress-medicenter-theme-14-7-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json b/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json new file mode 100644 index 00000000000..184f8dbb10e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vjmw-pmxv-8c6w/GHSA-vjmw-pmxv-8c6w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjmw-pmxv-8c6w", + "modified": "2025-02-18T21:32:52Z", + "published": "2025-02-18T21:32:52Z", + "aliases": [ + "CVE-2025-0622" + ], + "details": "A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading to a use-after-free vulnerability. If correctly exploited, this vulnerability may result in arbitrary code execution, eventually allowing the attacker to bypass secure boot protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0622" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0622" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345865" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xf58-m74g-2gmf/GHSA-xf58-m74g-2gmf.json b/advisories/unreviewed/2025/02/GHSA-xf58-m74g-2gmf/GHSA-xf58-m74g-2gmf.json new file mode 100644 index 00000000000..f4dda46efcb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xf58-m74g-2gmf/GHSA-xf58-m74g-2gmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf58-m74g-2gmf", + "modified": "2025-02-18T21:32:51Z", + "published": "2025-02-18T21:32:51Z", + "aliases": [ + "CVE-2025-22656" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster allows PHP Local File Inclusion. This issue affects Cookie Monster: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22656" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cookie-monster/vulnerability/wordpress-cookie-monster-plugin-1-2-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-18T20:15:27Z" + } +} \ No newline at end of file