From 18fd2a5a92b154545237fc70b7b3c35e0caae8ea Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 May 2025 15:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4487-mjx5-9v4r.json | 3 +- .../GHSA-hr5h-qhmp-927q.json | 6 +- .../GHSA-mc87-5qgf-5qvj.json | 3 +- .../GHSA-5222-7chv-655h.json | 4 +- .../GHSA-p479-f9r2-wpp2.json | 3 +- .../GHSA-xc6g-7c6r-9wxc.json | 3 +- .../GHSA-2r24-5j8r-cf83.json | 15 +++-- .../GHSA-2687-xwfr-5fx9.json | 36 ++++++++++++ .../GHSA-6329-hg8m-7q29.json | 36 ++++++++++++ .../GHSA-6678-8j3c-rghf.json | 36 ++++++++++++ .../GHSA-6pf2-52g7-p22m.json | 36 ++++++++++++ .../GHSA-7f2q-g84r-xq9f.json | 11 +++- .../GHSA-7hj5-5w8q-cjrp.json | 56 +++++++++++++++++++ .../GHSA-7hrm-65gw-c87h.json | 56 +++++++++++++++++++ .../GHSA-8hm3-3px2-4xp9.json | 36 ++++++++++++ .../GHSA-942h-7wq8-4623.json | 11 +++- .../GHSA-gw62-7pm8-x49v.json | 11 +++- .../GHSA-h272-rm32-wwcr.json | 33 +++++++++++ .../GHSA-h593-cg7r-4hp4.json | 36 ++++++++++++ .../GHSA-jfjv-vw9w-9w8v.json | 36 ++++++++++++ .../GHSA-jgch-gjvp-j2r8.json | 11 +++- .../GHSA-mfvj-g4mp-wqx2.json | 11 +++- .../GHSA-mqh3-r83q-28jh.json | 33 +++++++++++ .../GHSA-p6mr-8qh7-926h.json | 33 +++++++++++ .../GHSA-pcjq-4m2m-9fw8.json | 11 +++- .../GHSA-r438-m7jx-83x3.json | 25 +++++++++ .../GHSA-rcp3-h3cv-rfv7.json | 11 +++- .../GHSA-v7fp-w3f5-7445.json | 11 +++- .../GHSA-vqfj-4mcp-7qx6.json | 36 ++++++++++++ .../GHSA-wg96-rrcf-j3mh.json | 36 ++++++++++++ .../GHSA-x4gc-7rpm-6497.json | 56 +++++++++++++++++++ 31 files changed, 707 insertions(+), 34 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2687-xwfr-5fx9/GHSA-2687-xwfr-5fx9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6329-hg8m-7q29/GHSA-6329-hg8m-7q29.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6678-8j3c-rghf/GHSA-6678-8j3c-rghf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6pf2-52g7-p22m/GHSA-6pf2-52g7-p22m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7hj5-5w8q-cjrp/GHSA-7hj5-5w8q-cjrp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7hrm-65gw-c87h/GHSA-7hrm-65gw-c87h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8hm3-3px2-4xp9/GHSA-8hm3-3px2-4xp9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h272-rm32-wwcr/GHSA-h272-rm32-wwcr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h593-cg7r-4hp4/GHSA-h593-cg7r-4hp4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jfjv-vw9w-9w8v/GHSA-jfjv-vw9w-9w8v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mqh3-r83q-28jh/GHSA-mqh3-r83q-28jh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p6mr-8qh7-926h/GHSA-p6mr-8qh7-926h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r438-m7jx-83x3/GHSA-r438-m7jx-83x3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vqfj-4mcp-7qx6/GHSA-vqfj-4mcp-7qx6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wg96-rrcf-j3mh/GHSA-wg96-rrcf-j3mh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x4gc-7rpm-6497/GHSA-x4gc-7rpm-6497.json diff --git a/advisories/unreviewed/2022/10/GHSA-4487-mjx5-9v4r/GHSA-4487-mjx5-9v4r.json b/advisories/unreviewed/2022/10/GHSA-4487-mjx5-9v4r/GHSA-4487-mjx5-9v4r.json index 9a146d64e6b..2a9dd313997 100644 --- a/advisories/unreviewed/2022/10/GHSA-4487-mjx5-9v4r/GHSA-4487-mjx5-9v4r.json +++ b/advisories/unreviewed/2022/10/GHSA-4487-mjx5-9v4r/GHSA-4487-mjx5-9v4r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-425" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-hr5h-qhmp-927q/GHSA-hr5h-qhmp-927q.json b/advisories/unreviewed/2022/10/GHSA-hr5h-qhmp-927q/GHSA-hr5h-qhmp-927q.json index 2e458893e9c..666a62e2219 100644 --- a/advisories/unreviewed/2022/10/GHSA-hr5h-qhmp-927q/GHSA-hr5h-qhmp-927q.json +++ b/advisories/unreviewed/2022/10/GHSA-hr5h-qhmp-927q/GHSA-hr5h-qhmp-927q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr5h-qhmp-927q", - "modified": "2022-10-08T00:00:18Z", + "modified": "2025-05-20T15:30:32Z", "published": "2022-10-07T18:16:01Z", "aliases": [ "CVE-2022-40872" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/xtxxueyan/bug_report/blob/main/vendors/onetnom23/Simple%20E-Learning%20System/SQLi-1.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php-simple-e-learning-system-source-code" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-mc87-5qgf-5qvj/GHSA-mc87-5qgf-5qvj.json b/advisories/unreviewed/2022/10/GHSA-mc87-5qgf-5qvj/GHSA-mc87-5qgf-5qvj.json index 1fb0725d964..31902b76b4d 100644 --- a/advisories/unreviewed/2022/10/GHSA-mc87-5qgf-5qvj/GHSA-mc87-5qgf-5qvj.json +++ b/advisories/unreviewed/2022/10/GHSA-mc87-5qgf-5qvj/GHSA-mc87-5qgf-5qvj.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5222-7chv-655h/GHSA-5222-7chv-655h.json b/advisories/unreviewed/2024/03/GHSA-5222-7chv-655h/GHSA-5222-7chv-655h.json index b26bde4c817..f54734d7f7a 100644 --- a/advisories/unreviewed/2024/03/GHSA-5222-7chv-655h/GHSA-5222-7chv-655h.json +++ b/advisories/unreviewed/2024/03/GHSA-5222-7chv-655h/GHSA-5222-7chv-655h.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p479-f9r2-wpp2/GHSA-p479-f9r2-wpp2.json b/advisories/unreviewed/2024/05/GHSA-p479-f9r2-wpp2/GHSA-p479-f9r2-wpp2.json index 5cc6bbaef5e..781ff4a247d 100644 --- a/advisories/unreviewed/2024/05/GHSA-p479-f9r2-wpp2/GHSA-p479-f9r2-wpp2.json +++ b/advisories/unreviewed/2024/05/GHSA-p479-f9r2-wpp2/GHSA-p479-f9r2-wpp2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-xc6g-7c6r-9wxc/GHSA-xc6g-7c6r-9wxc.json b/advisories/unreviewed/2024/05/GHSA-xc6g-7c6r-9wxc/GHSA-xc6g-7c6r-9wxc.json index 8326c691863..ce26becbe01 100644 --- a/advisories/unreviewed/2024/05/GHSA-xc6g-7c6r-9wxc/GHSA-xc6g-7c6r-9wxc.json +++ b/advisories/unreviewed/2024/05/GHSA-xc6g-7c6r-9wxc/GHSA-xc6g-7c6r-9wxc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-2r24-5j8r-cf83/GHSA-2r24-5j8r-cf83.json b/advisories/unreviewed/2024/06/GHSA-2r24-5j8r-cf83/GHSA-2r24-5j8r-cf83.json index 965b38de36b..427c2fe7e88 100644 --- a/advisories/unreviewed/2024/06/GHSA-2r24-5j8r-cf83/GHSA-2r24-5j8r-cf83.json +++ b/advisories/unreviewed/2024/06/GHSA-2r24-5j8r-cf83/GHSA-2r24-5j8r-cf83.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r24-5j8r-cf83", - "modified": "2024-06-03T09:30:48Z", + "modified": "2025-05-20T15:30:36Z", "published": "2024-06-03T09:30:48Z", "aliases": [ "CVE-2024-36963" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracefs: Reset permissions on remount if permissions are options\n\nThere's an inconsistency with the way permissions are handled in tracefs.\nBecause the permissions are generated when accessed, they default to the\nroot inode's permission if they were never set by the user. If the user\nsets the permissions, then a flag is set and the permissions are saved via\nthe inode (for tracefs files) or an internal attribute field (for\neventfs).\n\nBut if a remount happens that specify the permissions, all the files that\nwere not changed by the user gets updated, but the ones that were are not.\nIf the user were to remount the file system with a given permission, then\nall files and directories within that file system should be updated.\n\nThis can cause security issues if a file's permission was updated but the\nadmin forgot about it. They could incorrectly think that remounting with\npermissions set would update all files, but miss some.\n\nFor example:\n\n # cd /sys/kernel/tracing\n # chgrp 1002 current_tracer\n # ls -l\n[..]\n -rw-r----- 1 root root 0 May 1 21:25 buffer_size_kb\n -rw-r----- 1 root root 0 May 1 21:25 buffer_subbuf_size_kb\n -r--r----- 1 root root 0 May 1 21:25 buffer_total_size_kb\n -rw-r----- 1 root lkp 0 May 1 21:25 current_tracer\n -rw-r----- 1 root root 0 May 1 21:25 dynamic_events\n -r--r----- 1 root root 0 May 1 21:25 dyn_ftrace_total_info\n -r--r----- 1 root root 0 May 1 21:25 enabled_functions\n\nWhere current_tracer now has group \"lkp\".\n\n # mount -o remount,gid=1001 .\n # ls -l\n -rw-r----- 1 root tracing 0 May 1 21:25 buffer_size_kb\n -rw-r----- 1 root tracing 0 May 1 21:25 buffer_subbuf_size_kb\n -r--r----- 1 root tracing 0 May 1 21:25 buffer_total_size_kb\n -rw-r----- 1 root lkp 0 May 1 21:25 current_tracer\n -rw-r----- 1 root tracing 0 May 1 21:25 dynamic_events\n -r--r----- 1 root tracing 0 May 1 21:25 dyn_ftrace_total_info\n -r--r----- 1 root tracing 0 May 1 21:25 enabled_functions\n\nEverything changed but the \"current_tracer\".\n\nAdd a new link list that keeps track of all the tracefs_inodes which has\nthe permission flags that tell if the file/dir should use the root inode's\npermission or not. Then on remount, clear all the flags so that the\ndefault behavior of using the root inode's permission is done for all\nfiles and directories.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T08:15:09Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2687-xwfr-5fx9/GHSA-2687-xwfr-5fx9.json b/advisories/unreviewed/2025/05/GHSA-2687-xwfr-5fx9/GHSA-2687-xwfr-5fx9.json new file mode 100644 index 00000000000..87325e2a8bd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2687-xwfr-5fx9/GHSA-2687-xwfr-5fx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2687-xwfr-5fx9", + "modified": "2025-05-20T15:30:41Z", + "published": "2025-05-20T15:30:40Z", + "aliases": [ + "CVE-2025-41225" + ], + "details": "The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41225" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6329-hg8m-7q29/GHSA-6329-hg8m-7q29.json b/advisories/unreviewed/2025/05/GHSA-6329-hg8m-7q29/GHSA-6329-hg8m-7q29.json new file mode 100644 index 00000000000..01848c2d5e1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6329-hg8m-7q29/GHSA-6329-hg8m-7q29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6329-hg8m-7q29", + "modified": "2025-05-20T15:30:39Z", + "published": "2025-05-20T15:30:39Z", + "aliases": [ + "CVE-2025-40635" + ], + "details": "SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘uidActivity’, ‘codCompany’ and ‘uidInstance’ parameters of the ‘/comerzzia/login’ endpoint.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40635" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-comerzzia" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6678-8j3c-rghf/GHSA-6678-8j3c-rghf.json b/advisories/unreviewed/2025/05/GHSA-6678-8j3c-rghf/GHSA-6678-8j3c-rghf.json new file mode 100644 index 00000000000..d67aa9c5b50 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6678-8j3c-rghf/GHSA-6678-8j3c-rghf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6678-8j3c-rghf", + "modified": "2025-05-20T15:30:39Z", + "published": "2025-05-20T15:30:39Z", + "aliases": [ + "CVE-2025-41229" + ], + "details": "VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41229" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6pf2-52g7-p22m/GHSA-6pf2-52g7-p22m.json b/advisories/unreviewed/2025/05/GHSA-6pf2-52g7-p22m/GHSA-6pf2-52g7-p22m.json new file mode 100644 index 00000000000..71c82878d22 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6pf2-52g7-p22m/GHSA-6pf2-52g7-p22m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pf2-52g7-p22m", + "modified": "2025-05-20T15:30:39Z", + "published": "2025-05-20T15:30:39Z", + "aliases": [ + "CVE-2025-41231" + ], + "details": "VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41231" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json b/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json index da786aa77a3..c70d752c6fd 100644 --- a/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json +++ b/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7f2q-g84r-xq9f", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7174" ], "details": "The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7hj5-5w8q-cjrp/GHSA-7hj5-5w8q-cjrp.json b/advisories/unreviewed/2025/05/GHSA-7hj5-5w8q-cjrp/GHSA-7hj5-5w8q-cjrp.json new file mode 100644 index 00000000000..e4b6fcaef7a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7hj5-5w8q-cjrp/GHSA-7hj5-5w8q-cjrp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hj5-5w8q-cjrp", + "modified": "2025-05-20T15:30:40Z", + "published": "2025-05-20T15:30:40Z", + "aliases": [ + "CVE-2025-4980" + ], + "details": "A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vulnerability affects unknown code of the file /currentsetting.htm of the component mini_http. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4980" + }, + { + "type": "WEB", + "url": "https://github.com/at0de/my_vulns/blob/main/Netgear/DGND3700v2/currentsetting.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309640" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309640" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.564714" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7hrm-65gw-c87h/GHSA-7hrm-65gw-c87h.json b/advisories/unreviewed/2025/05/GHSA-7hrm-65gw-c87h/GHSA-7hrm-65gw-c87h.json new file mode 100644 index 00000000000..0bc78788e82 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7hrm-65gw-c87h/GHSA-7hrm-65gw-c87h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hrm-65gw-c87h", + "modified": "2025-05-20T15:30:39Z", + "published": "2025-05-20T15:30:39Z", + "aliases": [ + "CVE-2025-4977" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Netgear DGND3700 1.1.00.15_1.00.15NA. Affected by this issue is some unknown functionality of the file /BRS_top.html. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4977" + }, + { + "type": "WEB", + "url": "https://github.com/at0de/my_vulns/blob/main/Netgear/DGND3700v2/BRS_top.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309638" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309638" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.564711" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8hm3-3px2-4xp9/GHSA-8hm3-3px2-4xp9.json b/advisories/unreviewed/2025/05/GHSA-8hm3-3px2-4xp9/GHSA-8hm3-3px2-4xp9.json new file mode 100644 index 00000000000..104ca2e4543 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8hm3-3px2-4xp9/GHSA-8hm3-3px2-4xp9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hm3-3px2-4xp9", + "modified": "2025-05-20T15:30:39Z", + "published": "2025-05-20T15:30:39Z", + "aliases": [ + "CVE-2025-41230" + ], + "details": "VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to gain access to sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41230" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json b/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json index 6326125a766..148f3e78a2c 100644 --- a/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json +++ b/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-942h-7wq8-4623", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7196" ], "details": "The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json b/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json index 8148118fef1..67758c0a32e 100644 --- a/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json +++ b/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gw62-7pm8-x49v", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-2643" ], "details": "The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h272-rm32-wwcr/GHSA-h272-rm32-wwcr.json b/advisories/unreviewed/2025/05/GHSA-h272-rm32-wwcr/GHSA-h272-rm32-wwcr.json new file mode 100644 index 00000000000..6b1bbd56c8c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h272-rm32-wwcr/GHSA-h272-rm32-wwcr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h272-rm32-wwcr", + "modified": "2025-05-20T15:30:40Z", + "published": "2025-05-20T15:30:40Z", + "aliases": [ + "CVE-2024-53359" + ], + "details": "An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53359" + }, + { + "type": "WEB", + "url": "https://github.com/crysalix4/CVE/tree/main/CVE-2024-53359" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/in/le-anh-truong" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h593-cg7r-4hp4/GHSA-h593-cg7r-4hp4.json b/advisories/unreviewed/2025/05/GHSA-h593-cg7r-4hp4/GHSA-h593-cg7r-4hp4.json new file mode 100644 index 00000000000..cf951933631 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h593-cg7r-4hp4/GHSA-h593-cg7r-4hp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h593-cg7r-4hp4", + "modified": "2025-05-20T15:30:41Z", + "published": "2025-05-20T15:30:41Z", + "aliases": [ + "CVE-2025-41227" + ], + "details": "VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41227" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfjv-vw9w-9w8v/GHSA-jfjv-vw9w-9w8v.json b/advisories/unreviewed/2025/05/GHSA-jfjv-vw9w-9w8v/GHSA-jfjv-vw9w-9w8v.json new file mode 100644 index 00000000000..a10377afbf2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfjv-vw9w-9w8v/GHSA-jfjv-vw9w-9w8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfjv-vw9w-9w8v", + "modified": "2025-05-20T15:30:41Z", + "published": "2025-05-20T15:30:41Z", + "aliases": [ + "CVE-2025-41226" + ], + "details": "VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41226" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgch-gjvp-j2r8/GHSA-jgch-gjvp-j2r8.json b/advisories/unreviewed/2025/05/GHSA-jgch-gjvp-j2r8/GHSA-jgch-gjvp-j2r8.json index 7bcc7632119..0dd6e0976fd 100644 --- a/advisories/unreviewed/2025/05/GHSA-jgch-gjvp-j2r8/GHSA-jgch-gjvp-j2r8.json +++ b/advisories/unreviewed/2025/05/GHSA-jgch-gjvp-j2r8/GHSA-jgch-gjvp-j2r8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jgch-gjvp-j2r8", - "modified": "2025-05-20T06:32:18Z", + "modified": "2025-05-20T15:30:39Z", "published": "2025-05-20T06:32:18Z", "aliases": [ "CVE-2025-2929" ], "details": "The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-20T06:15:38Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json b/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json index bac73e919a8..e76f6e247c0 100644 --- a/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json +++ b/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mfvj-g4mp-wqx2", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7197" ], "details": "The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mqh3-r83q-28jh/GHSA-mqh3-r83q-28jh.json b/advisories/unreviewed/2025/05/GHSA-mqh3-r83q-28jh/GHSA-mqh3-r83q-28jh.json new file mode 100644 index 00000000000..430a1ab972f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mqh3-r83q-28jh/GHSA-mqh3-r83q-28jh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqh3-r83q-28jh", + "modified": "2025-05-20T15:30:40Z", + "published": "2025-05-20T15:30:40Z", + "aliases": [ + "CVE-2025-45862" + ], + "details": "TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45862" + }, + { + "type": "WEB", + "url": "https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/7/overflow.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p6mr-8qh7-926h/GHSA-p6mr-8qh7-926h.json b/advisories/unreviewed/2025/05/GHSA-p6mr-8qh7-926h/GHSA-p6mr-8qh7-926h.json new file mode 100644 index 00000000000..6016498fa98 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p6mr-8qh7-926h/GHSA-p6mr-8qh7-926h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6mr-8qh7-926h", + "modified": "2025-05-20T15:30:40Z", + "published": "2025-05-20T15:30:40Z", + "aliases": [ + "CVE-2025-26086" + ], + "details": "An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26086" + }, + { + "type": "WEB", + "url": "https://seclists.org/fulldisclosure/2025/May/21" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/May/21" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json b/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json index bd8e7f5fd5a..cd8a2dba6aa 100644 --- a/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json +++ b/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pcjq-4m2m-9fw8", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7168" ], "details": "The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r438-m7jx-83x3/GHSA-r438-m7jx-83x3.json b/advisories/unreviewed/2025/05/GHSA-r438-m7jx-83x3/GHSA-r438-m7jx-83x3.json new file mode 100644 index 00000000000..c28df9ed1d8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r438-m7jx-83x3/GHSA-r438-m7jx-83x3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r438-m7jx-83x3", + "modified": "2025-05-20T15:30:37Z", + "published": "2025-05-20T15:30:37Z", + "aliases": [ + "CVE-2022-49056" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49056" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json b/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json index 55313d5fe7f..3bb7d152c64 100644 --- a/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json +++ b/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcp3-h3cv-rfv7", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7195" ], "details": "The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json b/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json index 3a60e5fb80d..6e0aa4a64c9 100644 --- a/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json +++ b/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7fp-w3f5-7445", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T15:30:38Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-1663" ], "details": "The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:41Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vqfj-4mcp-7qx6/GHSA-vqfj-4mcp-7qx6.json b/advisories/unreviewed/2025/05/GHSA-vqfj-4mcp-7qx6/GHSA-vqfj-4mcp-7qx6.json new file mode 100644 index 00000000000..da346120022 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vqfj-4mcp-7qx6/GHSA-vqfj-4mcp-7qx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqfj-4mcp-7qx6", + "modified": "2025-05-20T15:30:41Z", + "published": "2025-05-20T15:30:41Z", + "aliases": [ + "CVE-2025-41228" + ], + "details": "VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41228" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wg96-rrcf-j3mh/GHSA-wg96-rrcf-j3mh.json b/advisories/unreviewed/2025/05/GHSA-wg96-rrcf-j3mh/GHSA-wg96-rrcf-j3mh.json new file mode 100644 index 00000000000..e1117b1f7b8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wg96-rrcf-j3mh/GHSA-wg96-rrcf-j3mh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg96-rrcf-j3mh", + "modified": "2025-05-20T15:30:41Z", + "published": "2025-05-20T15:30:41Z", + "aliases": [ + "CVE-2023-33861" + ], + "details": "IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33861" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233972" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x4gc-7rpm-6497/GHSA-x4gc-7rpm-6497.json b/advisories/unreviewed/2025/05/GHSA-x4gc-7rpm-6497/GHSA-x4gc-7rpm-6497.json new file mode 100644 index 00000000000..82edf865cc2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x4gc-7rpm-6497/GHSA-x4gc-7rpm-6497.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4gc-7rpm-6497", + "modified": "2025-05-20T15:30:40Z", + "published": "2025-05-20T15:30:40Z", + "aliases": [ + "CVE-2025-4978" + ], + "details": "A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4978" + }, + { + "type": "WEB", + "url": "https://github.com/at0de/my_vulns/blob/main/Netgear/DGND3700v2/backdoor.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309639" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309639" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.564712" + }, + { + "type": "WEB", + "url": "https://www.netgear.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T13:15:48Z" + } +} \ No newline at end of file