diff --git a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json index e761396899b..022048a8be8 100644 --- a/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json +++ b/advisories/unreviewed/2025/02/GHSA-gghq-qp34-gqg8/GHSA-gghq-qp34-gqg8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gghq-qp34-gqg8", - "modified": "2025-03-01T21:30:40Z", + "modified": "2025-03-03T03:31:17Z", "published": "2025-02-12T15:32:02Z", "aliases": [ "CVE-2025-1244" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1917" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1961" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1963" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1964" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-1244" diff --git a/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json b/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json new file mode 100644 index 00000000000..8069f8fd431 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-22cf-67wm-xj29/GHSA-22cf-67wm-xj29.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22cf-67wm-xj29", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-25951" + ], + "details": "An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25951" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89638" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json b/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json new file mode 100644 index 00000000000..8b23894847b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-27hr-9v6h-xmx3/GHSA-27hr-9v6h-xmx3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27hr-9v6h-xmx3", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-25952" + ], + "details": "An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted API request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25952" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89639" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json b/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json new file mode 100644 index 00000000000..3c6767f17b1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2f98-4x2w-23pw/GHSA-2f98-4x2w-23pw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f98-4x2w-23pw", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-1845" + ], + "details": "A vulnerability has been found in ESAFENET DSM 3.1.2 and classified as critical. Affected by this vulnerability is the function examExportPDF of the file /admin/plan/examExportPDF. The manipulation of the argument s leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1845" + }, + { + "type": "WEB", + "url": "https://github.com/666lail/report/blob/main/tmp/2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298111" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.505009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json b/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json new file mode 100644 index 00000000000..8d6b7939805 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3j27-47wq-ghmh/GHSA-3j27-47wq-ghmh.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j27-47wq-ghmh", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20646" + ], + "details": "In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389074; Issue ID: MSV-1803.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20646" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json b/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json new file mode 100644 index 00000000000..1f13672a23b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3wj6-xwvq-325w/GHSA-3wj6-xwvq-325w.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wj6-xwvq-325w", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20645" + ], + "details": "In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20645" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json b/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json new file mode 100644 index 00000000000..bfcce945f5a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3xm4-5347-4q37/GHSA-3xm4-5347-4q37.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xm4-5347-4q37", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20649" + ], + "details": "In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20649" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json b/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json new file mode 100644 index 00000000000..49e640290b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-44rm-j4gx-rrg2/GHSA-44rm-j4gx-rrg2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44rm-j4gx-rrg2", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-25950" + ], + "details": "Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25950" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89637" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json b/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json new file mode 100644 index 00000000000..201095a52f5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-44vc-9wvw-r372/GHSA-44vc-9wvw-r372.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44vc-9wvw-r372", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20653" + ], + "details": "In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291064; Issue ID: MSV-2046.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20653" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json b/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json new file mode 100644 index 00000000000..15ef3ff3da7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-472p-7734-hxc8/GHSA-472p-7734-hxc8.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-472p-7734-hxc8", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20648" + ], + "details": "In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20648" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json b/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json new file mode 100644 index 00000000000..f553024590f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-634g-m7q6-xphf/GHSA-634g-m7q6-xphf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-634g-m7q6-xphf", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-25953" + ], + "details": "Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25953" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89640" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json b/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json new file mode 100644 index 00000000000..2303f8c6345 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-73jf-w7j4-5h24/GHSA-73jf-w7j4-5h24.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73jf-w7j4-5h24", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-27584" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name parameter at /rest/staffResource/update.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27584" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89636" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json b/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json new file mode 100644 index 00000000000..5766e349cf2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9926-q228-4mpp/GHSA-9926-q228-4mpp.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9926-q228-4mpp", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20650" + ], + "details": "In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2061.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20650" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json b/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json new file mode 100644 index 00000000000..a2b9fae154f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c3p2-xw2j-qrf4/GHSA-c3p2-xw2j-qrf4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3p2-xw2j-qrf4", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20644" + ], + "details": "In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01525673; Issue ID: MSV-2747.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20644" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json b/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json new file mode 100644 index 00000000000..c237362dacc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f56w-wc87-frcc/GHSA-f56w-wc87-frcc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f56w-wc87-frcc", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20651" + ], + "details": "In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20651" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fggg-72p3-wj6v/GHSA-fggg-72p3-wj6v.json b/advisories/unreviewed/2025/03/GHSA-fggg-72p3-wj6v/GHSA-fggg-72p3-wj6v.json new file mode 100644 index 00000000000..7a11b5edc79 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fggg-72p3-wj6v/GHSA-fggg-72p3-wj6v.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fggg-72p3-wj6v", + "modified": "2025-03-03T03:31:17Z", + "published": "2025-03-03T03:31:17Z", + "aliases": [ + "CVE-2025-1843" + ], + "details": "A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20250211. This issue affects the function select of the file com/xq/tmall/dao/ProductMapper.java. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1843" + }, + { + "type": "WEB", + "url": "https://github.com/qkdjksfkeg/cve_article/blob/main/Tmall_demo/SQL%20injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298109" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.504958" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json b/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json new file mode 100644 index 00000000000..3ce03962d03 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g93r-3jrg-24gc/GHSA-g93r-3jrg-24gc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g93r-3jrg-24gc", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-27585" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Print Name parameter at /rest/staffResource/update.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27585" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89636" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gxpv-gj6w-5742/GHSA-gxpv-gj6w-5742.json b/advisories/unreviewed/2025/03/GHSA-gxpv-gj6w-5742/GHSA-gxpv-gj6w-5742.json new file mode 100644 index 00000000000..cb1364e1319 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gxpv-gj6w-5742/GHSA-gxpv-gj6w-5742.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxpv-gj6w-5742", + "modified": "2025-03-03T03:31:17Z", + "published": "2025-03-03T03:31:17Z", + "aliases": [ + "CVE-2025-1842" + ], + "details": "A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1842" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.504603" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json b/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json new file mode 100644 index 00000000000..565aa42a81e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m8x3-4xx7-hm4v/GHSA-m8x3-4xx7-hm4v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8x3-4xx7-hm4v", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:17Z", + "aliases": [ + "CVE-2025-25949" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25949" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-89636" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mphv-4vx5-5cr8/GHSA-mphv-4vx5-5cr8.json b/advisories/unreviewed/2025/03/GHSA-mphv-4vx5-5cr8/GHSA-mphv-4vx5-5cr8.json new file mode 100644 index 00000000000..329a8ae9e94 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mphv-4vx5-5cr8/GHSA-mphv-4vx5-5cr8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mphv-4vx5-5cr8", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-27583" + ], + "details": "Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27583" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-53637" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json b/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json new file mode 100644 index 00000000000..6b69cb081e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q269-fjx3-x255/GHSA-q269-fjx3-x255.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q269-fjx3-x255", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-25948" + ], + "details": "Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25948" + }, + { + "type": "WEB", + "url": "https://github.com/VvV1per/Vulnerability-Research-CVEs/tree/main/CVE-2024-53637" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r8x4-pq89-gfpq/GHSA-r8x4-pq89-gfpq.json b/advisories/unreviewed/2025/03/GHSA-r8x4-pq89-gfpq/GHSA-r8x4-pq89-gfpq.json new file mode 100644 index 00000000000..7940bc76591 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r8x4-pq89-gfpq/GHSA-r8x4-pq89-gfpq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8x4-pq89-gfpq", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-1847" + ], + "details": "A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1847" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/zz/ZZ_2024_8%E5%9E%82%E7%9B%B4%E8%B6%8A%E6%9D%83.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298115" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298115" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.505303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w3m2-g7pm-8c3r/GHSA-w3m2-g7pm-8c3r.json b/advisories/unreviewed/2025/03/GHSA-w3m2-g7pm-8c3r/GHSA-w3m2-g7pm-8c3r.json new file mode 100644 index 00000000000..74949ff9760 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w3m2-g7pm-8c3r/GHSA-w3m2-g7pm-8c3r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3m2-g7pm-8c3r", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-1846" + ], + "details": "A vulnerability was found in zj1983 zz up to 2024-8. It has been declared as problematic. This vulnerability affects the function deleteLocalFile of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.java of the component File Handler. The manipulation of the argument zids leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1846" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/zz/zz_2024_8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%88%A0%E9%99%A4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298114" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298114" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.505097" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json b/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json new file mode 100644 index 00000000000..d4105b8e06a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w9wx-xm8x-jhqq/GHSA-w9wx-xm8x-jhqq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9wx-xm8x-jhqq", + "modified": "2025-03-03T03:31:18Z", + "published": "2025-03-03T03:31:18Z", + "aliases": [ + "CVE-2025-1844" + ], + "details": "A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. Affected is an unknown function of the file /CDGServer3/logManagement/backupLogDetail.jsp. The manipulation of the argument logTaskId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1844" + }, + { + "type": "WEB", + "url": "https://github.com/666lail/report/blob/main/tmp/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298110" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.505008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T02:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json b/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json new file mode 100644 index 00000000000..bebb53353c4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqcw-wh9g-67rg", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20647" + ], + "details": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00791311 / MOLY01067019; Issue ID: MSV-2721.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20647" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json b/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json new file mode 100644 index 00000000000..4913e56ef85 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xx4g-62m6-v2w7/GHSA-xx4g-62m6-v2w7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx4g-62m6-v2w7", + "modified": "2025-03-03T03:31:19Z", + "published": "2025-03-03T03:31:19Z", + "aliases": [ + "CVE-2025-20652" + ], + "details": "In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20652" + }, + { + "type": "WEB", + "url": "https://corp.mediatek.com/product-security-bulletin/March-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T03:15:10Z" + } +} \ No newline at end of file