Skip to content

Commit 8a993f4

Browse files
Advisory Database Sync
1 parent ab9ebd0 commit 8a993f4

42 files changed

Lines changed: 1172 additions & 35 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/unreviewed/2024/03/GHSA-3wjc-g785-xjp8/GHSA-3wjc-g785-xjp8.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-3wjc-g785-xjp8",
4-
"modified": "2024-03-25T06:30:24Z",
4+
"modified": "2026-01-13T15:36:47Z",
55
"published": "2024-03-25T06:30:24Z",
66
"aliases": [
77
"CVE-2023-37885"
88
],
9-
"details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.\n\n",
9+
"details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.",
1010
"severity": [
1111
{
1212
"type": "CVSS_V3",

advisories/unreviewed/2024/03/GHSA-858p-q38q-g87r/GHSA-858p-q38q-g87r.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,9 @@
3333
}
3434
],
3535
"database_specific": {
36-
"cwe_ids": [],
36+
"cwe_ids": [
37+
"CWE-670"
38+
],
3739
"severity": "MODERATE",
3840
"github_reviewed": false,
3941
"github_reviewed_at": null,

advisories/unreviewed/2024/03/GHSA-h3h4-5vcv-376h/GHSA-h3h4-5vcv-376h.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-h3h4-5vcv-376h",
4-
"modified": "2024-03-15T15:30:43Z",
4+
"modified": "2026-01-13T15:36:46Z",
55
"published": "2024-03-15T15:30:43Z",
66
"aliases": [
77
"CVE-2024-27189"
88
],
9-
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget allows Stored XSS.This issue affects WP Social Widget: from n/a through 2.2.5.\n\n",
9+
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget allows Stored XSS.This issue affects WP Social Widget: from n/a through 2.2.5.",
1010
"severity": [
1111
{
1212
"type": "CVSS_V3",

advisories/unreviewed/2024/03/GHSA-rqhc-7mvg-jchq/GHSA-rqhc-7mvg-jchq.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-rqhc-7mvg-jchq",
4-
"modified": "2024-03-25T06:30:24Z",
4+
"modified": "2026-01-13T15:36:47Z",
55
"published": "2024-03-25T06:30:24Z",
66
"aliases": [
77
"CVE-2023-37886"
88
],
9-
"details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.\n\n",
9+
"details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.",
1010
"severity": [
1111
{
1212
"type": "CVSS_V3",

advisories/unreviewed/2025/12/GHSA-wqgj-c38v-hpmm/GHSA-wqgj-c38v-hpmm.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-wqgj-c38v-hpmm",
4-
"modified": "2025-12-10T21:31:30Z",
4+
"modified": "2026-01-13T15:36:47Z",
55
"published": "2025-12-09T18:30:35Z",
66
"aliases": [
77
"CVE-2025-14327"
@@ -30,6 +30,10 @@
3030
{
3131
"type": "WEB",
3232
"url": "https://www.mozilla.org/security/advisories/mfsa2025-95"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://www.mozilla.org/security/advisories/mfsa2026-03"
3337
}
3438
],
3539
"database_specific": {

advisories/unreviewed/2026/01/GHSA-27xq-wwxh-hrf6/GHSA-27xq-wwxh-hrf6.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-27xq-wwxh-hrf6",
4-
"modified": "2026-01-06T18:31:36Z",
4+
"modified": "2026-01-13T15:36:48Z",
55
"published": "2026-01-06T18:31:36Z",
66
"aliases": [
77
"CVE-2025-69359"
88
],
99
"details": "Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-862"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2026-01-06T17:15:48Z"

advisories/unreviewed/2026/01/GHSA-283f-7499-gpcp/GHSA-283f-7499-gpcp.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-283f-7499-gpcp",
4-
"modified": "2026-01-06T18:31:36Z",
4+
"modified": "2026-01-13T15:36:48Z",
55
"published": "2026-01-06T18:31:36Z",
66
"aliases": [
77
"CVE-2025-69355"
88
],
99
"details": "Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.4.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-862"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2026-01-06T17:15:48Z"

advisories/unreviewed/2026/01/GHSA-2934-gw32-fqg4/GHSA-2934-gw32-fqg4.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2934-gw32-fqg4",
4-
"modified": "2026-01-06T18:31:36Z",
4+
"modified": "2026-01-13T15:36:48Z",
55
"published": "2026-01-06T18:31:36Z",
66
"aliases": [
77
"CVE-2025-69356"
88
],
99
"details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.0.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-98"
2530
],
26-
"severity": null,
31+
"severity": "HIGH",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2026-01-06T17:15:48Z"
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3m78-88vj-q2rf",
4+
"modified": "2026-01-13T15:37:04Z",
5+
"published": "2026-01-13T15:37:04Z",
6+
"aliases": [
7+
"CVE-2026-0892"
8+
],
9+
"details": "Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0892"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1986912%2C1996718%2C1999633%2C2001081%2C2004443"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://www.mozilla.org/security/advisories/mfsa2026-01"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-119"
34+
],
35+
"severity": "CRITICAL",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-01-13T14:16:39Z"
39+
}
40+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-484x-228c-ffm5",
4+
"modified": "2026-01-13T15:37:05Z",
5+
"published": "2026-01-13T15:37:04Z",
6+
"aliases": [
7+
"CVE-2026-0890"
8+
],
9+
"details": "Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0890"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2005081"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://www.mozilla.org/security/advisories/mfsa2026-01"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://www.mozilla.org/security/advisories/mfsa2026-03"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-01-13T14:16:39Z"
36+
}
37+
}

0 commit comments

Comments
 (0)