From 0da2233b9ada0fe53e4747468c307928ed229cbf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 9 May 2025 21:32:19 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-46r4-f8gj-xg56.json | 6 +- .../GHSA-qxp5-gwg8-xv66.json | 6 +- .../GHSA-7w53-225r-6vxv.json | 18 +++++- .../GHSA-pjrj-fmxp-cmc4.json | 6 +- .../GHSA-wjcr-wjqx-g6rq.json | 6 +- .../GHSA-3r9v-jg25-4p3p.json | 6 +- .../GHSA-m2cq-w2fq-677j.json | 2 +- .../GHSA-wr4w-95gx-6cfr.json | 6 +- .../GHSA-c472-r2q4-4qpm.json | 15 ++++- .../GHSA-j82p-r65h-xx77.json | 6 +- .../GHSA-9cv8-8vgq-fg45.json | 6 +- .../GHSA-274g-94c9-xmph.json | 15 +++-- .../GHSA-3244-vj38-xw85.json | 3 +- .../GHSA-75cj-hgmm-jp24.json | 3 +- .../GHSA-7m2c-3c5m-7433.json | 3 +- .../GHSA-7m42-95vx-wx7q.json | 3 +- .../GHSA-jfqq-89vx-39m4.json | 3 +- .../GHSA-2x3v-hc5x-cgrg.json | 4 +- .../GHSA-346m-8227-pf2q.json | 56 +++++++++++++++++++ .../GHSA-4qhg-xgv5-f524.json | 1 + .../GHSA-5587-5jwr-xc28.json | 1 + .../GHSA-5fqp-63w2-x62m.json | 56 +++++++++++++++++++ .../GHSA-5p7v-9wpg-4p6w.json | 4 +- .../GHSA-75wp-8x35-464m.json | 1 + .../GHSA-853r-m9wx-cf9f.json | 56 +++++++++++++++++++ .../GHSA-8vrp-7fg6-82g7.json | 3 +- .../GHSA-c98f-fq4v-v6r3.json | 1 + .../GHSA-cmv3-46wg-pxvm.json | 3 +- .../GHSA-f2w6-r722-5fr8.json | 6 +- .../GHSA-f3h8-83qp-x347.json | 56 +++++++++++++++++++ .../GHSA-fwvc-979w-wh96.json | 1 + .../GHSA-fxgw-v59w-42pv.json | 3 +- .../GHSA-ghfm-pj4r-3hw7.json | 1 + .../GHSA-gp65-8mx5-x88c.json | 3 +- .../GHSA-h6x3-9vpp-c52f.json | 56 +++++++++++++++++++ .../GHSA-hg75-2frp-v4c6.json | 3 +- .../GHSA-hm66-jfx6-28m9.json | 56 +++++++++++++++++++ .../GHSA-jcfm-3qg5-q269.json | 3 +- .../GHSA-pv78-q37w-r4jp.json | 3 +- .../GHSA-rv96-2r7c-vcr8.json | 56 +++++++++++++++++++ .../GHSA-v5fc-cqrv-w647.json | 3 +- .../GHSA-v7h8-cxrw-qc24.json | 56 +++++++++++++++++++ .../GHSA-w3rx-344f-qxwh.json | 1 + .../GHSA-wmvg-c6fc-33c8.json | 40 +++++++++++++ .../GHSA-x87v-x434-mx3g.json | 3 +- 45 files changed, 617 insertions(+), 32 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-346m-8227-pf2q/GHSA-346m-8227-pf2q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5fqp-63w2-x62m/GHSA-5fqp-63w2-x62m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-853r-m9wx-cf9f/GHSA-853r-m9wx-cf9f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f3h8-83qp-x347/GHSA-f3h8-83qp-x347.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h6x3-9vpp-c52f/GHSA-h6x3-9vpp-c52f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hm66-jfx6-28m9/GHSA-hm66-jfx6-28m9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rv96-2r7c-vcr8/GHSA-rv96-2r7c-vcr8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v7h8-cxrw-qc24/GHSA-v7h8-cxrw-qc24.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wmvg-c6fc-33c8/GHSA-wmvg-c6fc-33c8.json diff --git a/advisories/github-reviewed/2025/03/GHSA-46r4-f8gj-xg56/GHSA-46r4-f8gj-xg56.json b/advisories/github-reviewed/2025/03/GHSA-46r4-f8gj-xg56/GHSA-46r4-f8gj-xg56.json index 88c55b50b1e..e013bb319d9 100644 --- a/advisories/github-reviewed/2025/03/GHSA-46r4-f8gj-xg56/GHSA-46r4-f8gj-xg56.json +++ b/advisories/github-reviewed/2025/03/GHSA-46r4-f8gj-xg56/GHSA-46r4-f8gj-xg56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46r4-f8gj-xg56", - "modified": "2025-03-12T14:09:49Z", + "modified": "2025-05-09T21:31:08Z", "published": "2025-03-11T19:23:22Z", "aliases": [ "CVE-2025-27773" @@ -106,6 +106,10 @@ { "type": "WEB", "url": "https://github.com/simplesamlphp/saml2/blob/9545abd0d9d48388f2fa00469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php#L178-L217" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00013.html" } ], "database_specific": { diff --git a/advisories/github-reviewed/2025/03/GHSA-qxp5-gwg8-xv66/GHSA-qxp5-gwg8-xv66.json b/advisories/github-reviewed/2025/03/GHSA-qxp5-gwg8-xv66/GHSA-qxp5-gwg8-xv66.json index 57b51a1357f..65f517b3ad7 100644 --- a/advisories/github-reviewed/2025/03/GHSA-qxp5-gwg8-xv66/GHSA-qxp5-gwg8-xv66.json +++ b/advisories/github-reviewed/2025/03/GHSA-qxp5-gwg8-xv66/GHSA-qxp5-gwg8-xv66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxp5-gwg8-xv66", - "modified": "2025-03-19T15:36:20Z", + "modified": "2025-05-09T21:31:08Z", "published": "2025-03-12T22:06:40Z", "aliases": [ "CVE-2025-22870" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2025-3503" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0007" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/03/07/2" diff --git a/advisories/unreviewed/2022/05/GHSA-7w53-225r-6vxv/GHSA-7w53-225r-6vxv.json b/advisories/unreviewed/2022/05/GHSA-7w53-225r-6vxv/GHSA-7w53-225r-6vxv.json index b446bc4dd3c..3994bc1ca64 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w53-225r-6vxv/GHSA-7w53-225r-6vxv.json +++ b/advisories/unreviewed/2022/05/GHSA-7w53-225r-6vxv/GHSA-7w53-225r-6vxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w53-225r-6vxv", - "modified": "2022-05-24T17:44:57Z", + "modified": "2025-05-09T21:31:06Z", "published": "2022-05-24T17:44:57Z", "aliases": [ "CVE-2021-28831" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2021/04/msg00001.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UDQGJRECXFS5EZVDH2OI45FMO436AC4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7ZIFKPRR32ZYA3WAA2NXFA3QHHOU6FJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZASBW7QRRLY5V2R44MQ4QQM4CZIDHM2U" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UDQGJRECXFS5EZVDH2OI45FMO436AC4" @@ -42,6 +54,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202105-09" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-pjrj-fmxp-cmc4/GHSA-pjrj-fmxp-cmc4.json b/advisories/unreviewed/2022/05/GHSA-pjrj-fmxp-cmc4/GHSA-pjrj-fmxp-cmc4.json index be4d58be46e..fd81df17463 100644 --- a/advisories/unreviewed/2022/05/GHSA-pjrj-fmxp-cmc4/GHSA-pjrj-fmxp-cmc4.json +++ b/advisories/unreviewed/2022/05/GHSA-pjrj-fmxp-cmc4/GHSA-pjrj-fmxp-cmc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjrj-fmxp-cmc4", - "modified": "2024-04-04T03:04:32Z", + "modified": "2025-05-09T21:31:06Z", "published": "2022-05-24T17:41:39Z", "aliases": [ "CVE-2021-26937" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202105-11" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0004" + }, { "type": "WEB", "url": "https://www.debian.org/security/2021/dsa-4861" diff --git a/advisories/unreviewed/2022/05/GHSA-wjcr-wjqx-g6rq/GHSA-wjcr-wjqx-g6rq.json b/advisories/unreviewed/2022/05/GHSA-wjcr-wjqx-g6rq/GHSA-wjcr-wjqx-g6rq.json index c7f06d20782..07f135023e1 100644 --- a/advisories/unreviewed/2022/05/GHSA-wjcr-wjqx-g6rq/GHSA-wjcr-wjqx-g6rq.json +++ b/advisories/unreviewed/2022/05/GHSA-wjcr-wjqx-g6rq/GHSA-wjcr-wjqx-g6rq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wjcr-wjqx-g6rq", - "modified": "2025-04-12T12:45:39Z", + "modified": "2025-05-09T21:31:06Z", "published": "2022-05-14T01:08:48Z", "aliases": [ "CVE-2015-0240" @@ -34,6 +34,10 @@ "type": "WEB", "url": "https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0001" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1191325" diff --git a/advisories/unreviewed/2022/10/GHSA-3r9v-jg25-4p3p/GHSA-3r9v-jg25-4p3p.json b/advisories/unreviewed/2022/10/GHSA-3r9v-jg25-4p3p/GHSA-3r9v-jg25-4p3p.json index 568da89797e..1c01e2a8cc2 100644 --- a/advisories/unreviewed/2022/10/GHSA-3r9v-jg25-4p3p/GHSA-3r9v-jg25-4p3p.json +++ b/advisories/unreviewed/2022/10/GHSA-3r9v-jg25-4p3p/GHSA-3r9v-jg25-4p3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r9v-jg25-4p3p", - "modified": "2022-11-01T19:00:31Z", + "modified": "2025-05-09T21:31:06Z", "published": "2022-10-27T19:00:28Z", "aliases": [ "CVE-2022-3725" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://gitlab.com/wireshark/wireshark/-/issues/18378" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OIEIFFZ27YKCTK5C2VT4OEQSHPQDBNSF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OIEIFFZ27YKCTK5C2VT4OEQSHPQDBNSF" diff --git a/advisories/unreviewed/2022/10/GHSA-m2cq-w2fq-677j/GHSA-m2cq-w2fq-677j.json b/advisories/unreviewed/2022/10/GHSA-m2cq-w2fq-677j/GHSA-m2cq-w2fq-677j.json index d9ddf2513ca..b516def6aa7 100644 --- a/advisories/unreviewed/2022/10/GHSA-m2cq-w2fq-677j/GHSA-m2cq-w2fq-677j.json +++ b/advisories/unreviewed/2022/10/GHSA-m2cq-w2fq-677j/GHSA-m2cq-w2fq-677j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m2cq-w2fq-677j", - "modified": "2022-10-28T19:00:42Z", + "modified": "2025-05-09T21:31:06Z", "published": "2022-10-26T12:00:31Z", "aliases": [ "CVE-2022-33185" diff --git a/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json b/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json index 6f883b3ce9a..841fa02141d 100644 --- a/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json +++ b/advisories/unreviewed/2023/04/GHSA-wr4w-95gx-6cfr/GHSA-wr4w-95gx-6cfr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wr4w-95gx-6cfr", - "modified": "2023-04-14T18:30:19Z", + "modified": "2025-05-09T21:31:07Z", "published": "2023-04-08T06:30:24Z", "aliases": [ "CVE-2023-24626" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://savannah.gnu.org/bugs/?63195" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0003" + }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/51252" diff --git a/advisories/unreviewed/2024/03/GHSA-c472-r2q4-4qpm/GHSA-c472-r2q4-4qpm.json b/advisories/unreviewed/2024/03/GHSA-c472-r2q4-4qpm/GHSA-c472-r2q4-4qpm.json index fd2cec6aeb4..8cdc8960514 100644 --- a/advisories/unreviewed/2024/03/GHSA-c472-r2q4-4qpm/GHSA-c472-r2q4-4qpm.json +++ b/advisories/unreviewed/2024/03/GHSA-c472-r2q4-4qpm/GHSA-c472-r2q4-4qpm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c472-r2q4-4qpm", - "modified": "2024-08-01T15:31:32Z", + "modified": "2025-05-09T21:31:07Z", "published": "2024-03-14T03:31:15Z", "aliases": [ "CVE-2024-25652" @@ -19,6 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25652" }, + { + "type": "WEB", + "url": "https://docs.delinea.com/online-help/secret-server/admin/unlimited-administration-mode/index.htm?Highlight=unlimited%20admin" + }, + { + "type": "WEB", + "url": "https://docs.delinea.com/online-help/secret-server/release-notes/ssc-rn-2024-02-10.htm" + }, + { + "type": "WEB", + "url": "https://trust.delinea.com" + }, { "type": "WEB", "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25652" @@ -26,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/05/GHSA-j82p-r65h-xx77/GHSA-j82p-r65h-xx77.json b/advisories/unreviewed/2024/05/GHSA-j82p-r65h-xx77/GHSA-j82p-r65h-xx77.json index f677a4a24b2..2810580572f 100644 --- a/advisories/unreviewed/2024/05/GHSA-j82p-r65h-xx77/GHSA-j82p-r65h-xx77.json +++ b/advisories/unreviewed/2024/05/GHSA-j82p-r65h-xx77/GHSA-j82p-r65h-xx77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j82p-r65h-xx77", - "modified": "2024-05-19T09:34:47Z", + "modified": "2025-05-09T21:31:07Z", "published": "2024-05-19T09:34:47Z", "aliases": [ "CVE-2024-35890" @@ -33,6 +33,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-9cv8-8vgq-fg45/GHSA-9cv8-8vgq-fg45.json b/advisories/unreviewed/2024/11/GHSA-9cv8-8vgq-fg45/GHSA-9cv8-8vgq-fg45.json index ab2ea8296b4..d976c4a1f57 100644 --- a/advisories/unreviewed/2024/11/GHSA-9cv8-8vgq-fg45/GHSA-9cv8-8vgq-fg45.json +++ b/advisories/unreviewed/2024/11/GHSA-9cv8-8vgq-fg45/GHSA-9cv8-8vgq-fg45.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cv8-8vgq-fg45", - "modified": "2024-11-14T15:32:15Z", + "modified": "2025-05-09T21:31:08Z", "published": "2024-11-14T15:32:15Z", "aliases": [ "CVE-2024-10976" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10976" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250509-0010" + }, { "type": "WEB", "url": "https://www.postgresql.org/support/security/CVE-2024-10976" diff --git a/advisories/unreviewed/2025/04/GHSA-274g-94c9-xmph/GHSA-274g-94c9-xmph.json b/advisories/unreviewed/2025/04/GHSA-274g-94c9-xmph/GHSA-274g-94c9-xmph.json index e7ecc1f3b94..42c01d96f95 100644 --- a/advisories/unreviewed/2025/04/GHSA-274g-94c9-xmph/GHSA-274g-94c9-xmph.json +++ b/advisories/unreviewed/2025/04/GHSA-274g-94c9-xmph/GHSA-274g-94c9-xmph.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-274g-94c9-xmph", - "modified": "2025-04-29T12:30:21Z", + "modified": "2025-05-09T21:31:08Z", "published": "2025-04-29T12:30:21Z", "aliases": [ "CVE-2024-58099" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame\n\nAndrew and Nikolay reported connectivity issues with Cilium's service\nload-balancing in case of vmxnet3.\n\nIf a BPF program for native XDP adds an encapsulation header such as\nIPIP and transmits the packet out the same interface, then in case\nof vmxnet3 a corrupted packet is being sent and subsequently dropped\non the path.\n\nvmxnet3_xdp_xmit_frame() which is called e.g. via vmxnet3_run_xdp()\nthrough vmxnet3_xdp_xmit_back() calculates an incorrect DMA address:\n\n page = virt_to_page(xdpf->data);\n tbi->dma_addr = page_pool_get_dma_addr(page) +\n VMXNET3_XDP_HEADROOM;\n dma_sync_single_for_device(&adapter->pdev->dev,\n tbi->dma_addr, buf_size,\n DMA_TO_DEVICE);\n\nThe above assumes a fixed offset (VMXNET3_XDP_HEADROOM), but the XDP\nBPF program could have moved xdp->data. While the passed buf_size is\ncorrect (xdpf->len), the dma_addr needs to have a dynamic offset which\ncan be calculated as xdpf->data - (void *)xdpf, that is, xdp->data -\nxdp->data_hard_start.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-29T12:15:31Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3244-vj38-xw85/GHSA-3244-vj38-xw85.json b/advisories/unreviewed/2025/04/GHSA-3244-vj38-xw85/GHSA-3244-vj38-xw85.json index 30347560923..1af06109223 100644 --- a/advisories/unreviewed/2025/04/GHSA-3244-vj38-xw85/GHSA-3244-vj38-xw85.json +++ b/advisories/unreviewed/2025/04/GHSA-3244-vj38-xw85/GHSA-3244-vj38-xw85.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-75cj-hgmm-jp24/GHSA-75cj-hgmm-jp24.json b/advisories/unreviewed/2025/04/GHSA-75cj-hgmm-jp24/GHSA-75cj-hgmm-jp24.json index f288ec06af9..27672639ea0 100644 --- a/advisories/unreviewed/2025/04/GHSA-75cj-hgmm-jp24/GHSA-75cj-hgmm-jp24.json +++ b/advisories/unreviewed/2025/04/GHSA-75cj-hgmm-jp24/GHSA-75cj-hgmm-jp24.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-7m2c-3c5m-7433/GHSA-7m2c-3c5m-7433.json b/advisories/unreviewed/2025/04/GHSA-7m2c-3c5m-7433/GHSA-7m2c-3c5m-7433.json index 15102191787..3a09baffef0 100644 --- a/advisories/unreviewed/2025/04/GHSA-7m2c-3c5m-7433/GHSA-7m2c-3c5m-7433.json +++ b/advisories/unreviewed/2025/04/GHSA-7m2c-3c5m-7433/GHSA-7m2c-3c5m-7433.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-7m42-95vx-wx7q/GHSA-7m42-95vx-wx7q.json b/advisories/unreviewed/2025/04/GHSA-7m42-95vx-wx7q/GHSA-7m42-95vx-wx7q.json index 3df4521cc8b..193865b67f8 100644 --- a/advisories/unreviewed/2025/04/GHSA-7m42-95vx-wx7q/GHSA-7m42-95vx-wx7q.json +++ b/advisories/unreviewed/2025/04/GHSA-7m42-95vx-wx7q/GHSA-7m42-95vx-wx7q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jfqq-89vx-39m4/GHSA-jfqq-89vx-39m4.json b/advisories/unreviewed/2025/04/GHSA-jfqq-89vx-39m4/GHSA-jfqq-89vx-39m4.json index b98ecab4c0d..3931b7b3ac6 100644 --- a/advisories/unreviewed/2025/04/GHSA-jfqq-89vx-39m4/GHSA-jfqq-89vx-39m4.json +++ b/advisories/unreviewed/2025/04/GHSA-jfqq-89vx-39m4/GHSA-jfqq-89vx-39m4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2x3v-hc5x-cgrg/GHSA-2x3v-hc5x-cgrg.json b/advisories/unreviewed/2025/05/GHSA-2x3v-hc5x-cgrg/GHSA-2x3v-hc5x-cgrg.json index 8a09584412f..4e29520a0e3 100644 --- a/advisories/unreviewed/2025/05/GHSA-2x3v-hc5x-cgrg/GHSA-2x3v-hc5x-cgrg.json +++ b/advisories/unreviewed/2025/05/GHSA-2x3v-hc5x-cgrg/GHSA-2x3v-hc5x-cgrg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-346m-8227-pf2q/GHSA-346m-8227-pf2q.json b/advisories/unreviewed/2025/05/GHSA-346m-8227-pf2q/GHSA-346m-8227-pf2q.json new file mode 100644 index 00000000000..e2afedd7911 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-346m-8227-pf2q/GHSA-346m-8227-pf2q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-346m-8227-pf2q", + "modified": "2025-05-09T21:31:20Z", + "published": "2025-05-09T21:31:20Z", + "aliases": [ + "CVE-2025-4491" + ], + "details": "A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4491" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308206" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308206" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566786" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4qhg-xgv5-f524/GHSA-4qhg-xgv5-f524.json b/advisories/unreviewed/2025/05/GHSA-4qhg-xgv5-f524/GHSA-4qhg-xgv5-f524.json index 519e7e44f36..b29bcaf44a8 100644 --- a/advisories/unreviewed/2025/05/GHSA-4qhg-xgv5-f524/GHSA-4qhg-xgv5-f524.json +++ b/advisories/unreviewed/2025/05/GHSA-4qhg-xgv5-f524/GHSA-4qhg-xgv5-f524.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-823" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-5587-5jwr-xc28/GHSA-5587-5jwr-xc28.json b/advisories/unreviewed/2025/05/GHSA-5587-5jwr-xc28/GHSA-5587-5jwr-xc28.json index 748c336db4c..5602d1bd73c 100644 --- a/advisories/unreviewed/2025/05/GHSA-5587-5jwr-xc28/GHSA-5587-5jwr-xc28.json +++ b/advisories/unreviewed/2025/05/GHSA-5587-5jwr-xc28/GHSA-5587-5jwr-xc28.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-5fqp-63w2-x62m/GHSA-5fqp-63w2-x62m.json b/advisories/unreviewed/2025/05/GHSA-5fqp-63w2-x62m/GHSA-5fqp-63w2-x62m.json new file mode 100644 index 00000000000..0b96e21585a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fqp-63w2-x62m/GHSA-5fqp-63w2-x62m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fqp-63w2-x62m", + "modified": "2025-05-09T21:31:19Z", + "published": "2025-05-09T21:31:19Z", + "aliases": [ + "CVE-2025-4485" + ], + "details": "A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=delete_trainer. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4485" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308200" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308200" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566780" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T19:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5p7v-9wpg-4p6w/GHSA-5p7v-9wpg-4p6w.json b/advisories/unreviewed/2025/05/GHSA-5p7v-9wpg-4p6w/GHSA-5p7v-9wpg-4p6w.json index affa555e7e3..2897ea17824 100644 --- a/advisories/unreviewed/2025/05/GHSA-5p7v-9wpg-4p6w/GHSA-5p7v-9wpg-4p6w.json +++ b/advisories/unreviewed/2025/05/GHSA-5p7v-9wpg-4p6w/GHSA-5p7v-9wpg-4p6w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-75wp-8x35-464m/GHSA-75wp-8x35-464m.json b/advisories/unreviewed/2025/05/GHSA-75wp-8x35-464m/GHSA-75wp-8x35-464m.json index 56203351bfe..7371113ede0 100644 --- a/advisories/unreviewed/2025/05/GHSA-75wp-8x35-464m/GHSA-75wp-8x35-464m.json +++ b/advisories/unreviewed/2025/05/GHSA-75wp-8x35-464m/GHSA-75wp-8x35-464m.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-200" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-853r-m9wx-cf9f/GHSA-853r-m9wx-cf9f.json b/advisories/unreviewed/2025/05/GHSA-853r-m9wx-cf9f/GHSA-853r-m9wx-cf9f.json new file mode 100644 index 00000000000..3ddd6a038ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-853r-m9wx-cf9f/GHSA-853r-m9wx-cf9f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-853r-m9wx-cf9f", + "modified": "2025-05-09T21:31:19Z", + "published": "2025-05-09T21:31:19Z", + "aliases": [ + "CVE-2025-4484" + ], + "details": "A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4484" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308199" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308199" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566779" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T19:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8vrp-7fg6-82g7/GHSA-8vrp-7fg6-82g7.json b/advisories/unreviewed/2025/05/GHSA-8vrp-7fg6-82g7/GHSA-8vrp-7fg6-82g7.json index 22a584dbf88..f76203bcdfa 100644 --- a/advisories/unreviewed/2025/05/GHSA-8vrp-7fg6-82g7/GHSA-8vrp-7fg6-82g7.json +++ b/advisories/unreviewed/2025/05/GHSA-8vrp-7fg6-82g7/GHSA-8vrp-7fg6-82g7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-c98f-fq4v-v6r3/GHSA-c98f-fq4v-v6r3.json b/advisories/unreviewed/2025/05/GHSA-c98f-fq4v-v6r3/GHSA-c98f-fq4v-v6r3.json index 1103f440ba6..a3a94f48e5e 100644 --- a/advisories/unreviewed/2025/05/GHSA-c98f-fq4v-v6r3/GHSA-c98f-fq4v-v6r3.json +++ b/advisories/unreviewed/2025/05/GHSA-c98f-fq4v-v6r3/GHSA-c98f-fq4v-v6r3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-cmv3-46wg-pxvm/GHSA-cmv3-46wg-pxvm.json b/advisories/unreviewed/2025/05/GHSA-cmv3-46wg-pxvm/GHSA-cmv3-46wg-pxvm.json index 6c262eb1ea7..1d49f00c49f 100644 --- a/advisories/unreviewed/2025/05/GHSA-cmv3-46wg-pxvm/GHSA-cmv3-46wg-pxvm.json +++ b/advisories/unreviewed/2025/05/GHSA-cmv3-46wg-pxvm/GHSA-cmv3-46wg-pxvm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json index f23c7044426..a3178b1fc5c 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json +++ b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2w6-r722-5fr8", - "modified": "2025-05-07T18:30:50Z", + "modified": "2025-05-09T21:31:19Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-47203" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://github.com/mkj/dropbear/blob/master/src/cli-main.c" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/09/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-f3h8-83qp-x347/GHSA-f3h8-83qp-x347.json b/advisories/unreviewed/2025/05/GHSA-f3h8-83qp-x347/GHSA-f3h8-83qp-x347.json new file mode 100644 index 00000000000..49c337de123 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f3h8-83qp-x347/GHSA-f3h8-83qp-x347.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3h8-83qp-x347", + "modified": "2025-05-09T21:31:20Z", + "published": "2025-05-09T21:31:19Z", + "aliases": [ + "CVE-2025-4488" + ], + "details": "A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_package. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4488" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308203" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566783" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fwvc-979w-wh96/GHSA-fwvc-979w-wh96.json b/advisories/unreviewed/2025/05/GHSA-fwvc-979w-wh96/GHSA-fwvc-979w-wh96.json index 73d3e7ebd3b..6f795db3704 100644 --- a/advisories/unreviewed/2025/05/GHSA-fwvc-979w-wh96/GHSA-fwvc-979w-wh96.json +++ b/advisories/unreviewed/2025/05/GHSA-fwvc-979w-wh96/GHSA-fwvc-979w-wh96.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-fxgw-v59w-42pv/GHSA-fxgw-v59w-42pv.json b/advisories/unreviewed/2025/05/GHSA-fxgw-v59w-42pv/GHSA-fxgw-v59w-42pv.json index bf71a2a1c79..52fcbfe7926 100644 --- a/advisories/unreviewed/2025/05/GHSA-fxgw-v59w-42pv/GHSA-fxgw-v59w-42pv.json +++ b/advisories/unreviewed/2025/05/GHSA-fxgw-v59w-42pv/GHSA-fxgw-v59w-42pv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-ghfm-pj4r-3hw7/GHSA-ghfm-pj4r-3hw7.json b/advisories/unreviewed/2025/05/GHSA-ghfm-pj4r-3hw7/GHSA-ghfm-pj4r-3hw7.json index 6266d1038c3..f893f6afd3b 100644 --- a/advisories/unreviewed/2025/05/GHSA-ghfm-pj4r-3hw7/GHSA-ghfm-pj4r-3hw7.json +++ b/advisories/unreviewed/2025/05/GHSA-ghfm-pj4r-3hw7/GHSA-ghfm-pj4r-3hw7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-gp65-8mx5-x88c/GHSA-gp65-8mx5-x88c.json b/advisories/unreviewed/2025/05/GHSA-gp65-8mx5-x88c/GHSA-gp65-8mx5-x88c.json index c6bbd6c8c3a..bde88c1930a 100644 --- a/advisories/unreviewed/2025/05/GHSA-gp65-8mx5-x88c/GHSA-gp65-8mx5-x88c.json +++ b/advisories/unreviewed/2025/05/GHSA-gp65-8mx5-x88c/GHSA-gp65-8mx5-x88c.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-280" + "CWE-280", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h6x3-9vpp-c52f/GHSA-h6x3-9vpp-c52f.json b/advisories/unreviewed/2025/05/GHSA-h6x3-9vpp-c52f/GHSA-h6x3-9vpp-c52f.json new file mode 100644 index 00000000000..db9c7132ccc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h6x3-9vpp-c52f/GHSA-h6x3-9vpp-c52f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6x3-9vpp-c52f", + "modified": "2025-05-09T21:31:19Z", + "published": "2025-05-09T21:31:19Z", + "aliases": [ + "CVE-2025-4486" + ], + "details": "A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_plan. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4486" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308201" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308201" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566781" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hg75-2frp-v4c6/GHSA-hg75-2frp-v4c6.json b/advisories/unreviewed/2025/05/GHSA-hg75-2frp-v4c6/GHSA-hg75-2frp-v4c6.json index e59c989fd93..da03396bbfd 100644 --- a/advisories/unreviewed/2025/05/GHSA-hg75-2frp-v4c6/GHSA-hg75-2frp-v4c6.json +++ b/advisories/unreviewed/2025/05/GHSA-hg75-2frp-v4c6/GHSA-hg75-2frp-v4c6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hm66-jfx6-28m9/GHSA-hm66-jfx6-28m9.json b/advisories/unreviewed/2025/05/GHSA-hm66-jfx6-28m9/GHSA-hm66-jfx6-28m9.json new file mode 100644 index 00000000000..662cfed514d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hm66-jfx6-28m9/GHSA-hm66-jfx6-28m9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm66-jfx6-28m9", + "modified": "2025-05-09T21:31:20Z", + "published": "2025-05-09T21:31:20Z", + "aliases": [ + "CVE-2025-4489" + ], + "details": "A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /routers/user-router.php. The manipulation of the argument t1_verified leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4489" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308204" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308204" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566784" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jcfm-3qg5-q269/GHSA-jcfm-3qg5-q269.json b/advisories/unreviewed/2025/05/GHSA-jcfm-3qg5-q269/GHSA-jcfm-3qg5-q269.json index e8a61f4c343..4f268b171bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-jcfm-3qg5-q269/GHSA-jcfm-3qg5-q269.json +++ b/advisories/unreviewed/2025/05/GHSA-jcfm-3qg5-q269/GHSA-jcfm-3qg5-q269.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pv78-q37w-r4jp/GHSA-pv78-q37w-r4jp.json b/advisories/unreviewed/2025/05/GHSA-pv78-q37w-r4jp/GHSA-pv78-q37w-r4jp.json index ea63399dcf0..ac431a470c6 100644 --- a/advisories/unreviewed/2025/05/GHSA-pv78-q37w-r4jp/GHSA-pv78-q37w-r4jp.json +++ b/advisories/unreviewed/2025/05/GHSA-pv78-q37w-r4jp/GHSA-pv78-q37w-r4jp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-390" + "CWE-390", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rv96-2r7c-vcr8/GHSA-rv96-2r7c-vcr8.json b/advisories/unreviewed/2025/05/GHSA-rv96-2r7c-vcr8/GHSA-rv96-2r7c-vcr8.json new file mode 100644 index 00000000000..ecfc876ca20 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rv96-2r7c-vcr8/GHSA-rv96-2r7c-vcr8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv96-2r7c-vcr8", + "modified": "2025-05-09T21:31:20Z", + "published": "2025-05-09T21:31:19Z", + "aliases": [ + "CVE-2025-4487" + ], + "details": "A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4487" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308202" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308202" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566782" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v5fc-cqrv-w647/GHSA-v5fc-cqrv-w647.json b/advisories/unreviewed/2025/05/GHSA-v5fc-cqrv-w647/GHSA-v5fc-cqrv-w647.json index 3d6e1e5df0f..ef925041e48 100644 --- a/advisories/unreviewed/2025/05/GHSA-v5fc-cqrv-w647/GHSA-v5fc-cqrv-w647.json +++ b/advisories/unreviewed/2025/05/GHSA-v5fc-cqrv-w647/GHSA-v5fc-cqrv-w647.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v7h8-cxrw-qc24/GHSA-v7h8-cxrw-qc24.json b/advisories/unreviewed/2025/05/GHSA-v7h8-cxrw-qc24/GHSA-v7h8-cxrw-qc24.json new file mode 100644 index 00000000000..cfeded8a50c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7h8-cxrw-qc24/GHSA-v7h8-cxrw-qc24.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7h8-cxrw-qc24", + "modified": "2025-05-09T21:31:20Z", + "published": "2025-05-09T21:31:20Z", + "aliases": [ + "CVE-2025-4490" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /view-ticket-admin.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4490" + }, + { + "type": "WEB", + "url": "https://github.com/wyl091256/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308205" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308205" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.566785" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3rx-344f-qxwh/GHSA-w3rx-344f-qxwh.json b/advisories/unreviewed/2025/05/GHSA-w3rx-344f-qxwh/GHSA-w3rx-344f-qxwh.json index bd458d49ad2..be50ee51bf2 100644 --- a/advisories/unreviewed/2025/05/GHSA-w3rx-344f-qxwh/GHSA-w3rx-344f-qxwh.json +++ b/advisories/unreviewed/2025/05/GHSA-w3rx-344f-qxwh/GHSA-w3rx-344f-qxwh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-wmvg-c6fc-33c8/GHSA-wmvg-c6fc-33c8.json b/advisories/unreviewed/2025/05/GHSA-wmvg-c6fc-33c8/GHSA-wmvg-c6fc-33c8.json new file mode 100644 index 00000000000..cb835c0076e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmvg-c6fc-33c8/GHSA-wmvg-c6fc-33c8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmvg-c6fc-33c8", + "modified": "2025-05-09T21:31:19Z", + "published": "2025-05-09T21:31:19Z", + "aliases": [ + "CVE-2025-4447" + ], + "details": "In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4447" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-openj9/openj9/pull/21762" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/61" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-09T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x87v-x434-mx3g/GHSA-x87v-x434-mx3g.json b/advisories/unreviewed/2025/05/GHSA-x87v-x434-mx3g/GHSA-x87v-x434-mx3g.json index 089167e9ad0..99d75cbd8ad 100644 --- a/advisories/unreviewed/2025/05/GHSA-x87v-x434-mx3g/GHSA-x87v-x434-mx3g.json +++ b/advisories/unreviewed/2025/05/GHSA-x87v-x434-mx3g/GHSA-x87v-x434-mx3g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false,