diff --git a/advisories/unreviewed/2023/03/GHSA-rrh8-crj8-rjwr/GHSA-rrh8-crj8-rjwr.json b/advisories/unreviewed/2023/03/GHSA-rrh8-crj8-rjwr/GHSA-rrh8-crj8-rjwr.json index 726a62b1269..4ac5e9c9ad8 100644 --- a/advisories/unreviewed/2023/03/GHSA-rrh8-crj8-rjwr/GHSA-rrh8-crj8-rjwr.json +++ b/advisories/unreviewed/2023/03/GHSA-rrh8-crj8-rjwr/GHSA-rrh8-crj8-rjwr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rrh8-crj8-rjwr", - "modified": "2023-03-13T18:30:42Z", + "modified": "2025-03-07T00:31:55Z", "published": "2023-03-07T00:30:25Z", "aliases": [ "CVE-2023-24217" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-98" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json b/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json index 4cef0848000..902a0233e58 100644 --- a/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json +++ b/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53x3-6ggr-2vp5", - "modified": "2025-02-28T18:31:04Z", + "modified": "2025-03-07T00:31:55Z", "published": "2025-02-28T18:31:04Z", "aliases": [ "CVE-2025-26263" ], "details": "GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-28T16:15:40Z" diff --git a/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json b/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json index 4587bb53eab..2774b2e8734 100644 --- a/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json +++ b/advisories/unreviewed/2025/03/GHSA-2h2j-468c-9fxc/GHSA-2h2j-468c-9fxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2h2j-468c-9fxc", - "modified": "2025-03-05T21:32:13Z", + "modified": "2025-03-07T00:31:55Z", "published": "2025-03-05T21:32:13Z", "aliases": [ "CVE-2025-25634" ], "details": "A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T21:15:19Z" diff --git a/advisories/unreviewed/2025/03/GHSA-5w2w-xv87-387r/GHSA-5w2w-xv87-387r.json b/advisories/unreviewed/2025/03/GHSA-5w2w-xv87-387r/GHSA-5w2w-xv87-387r.json new file mode 100644 index 00000000000..e85b3eddc6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5w2w-xv87-387r/GHSA-5w2w-xv87-387r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w2w-xv87-387r", + "modified": "2025-03-07T00:31:55Z", + "published": "2025-03-07T00:31:55Z", + "aliases": [ + "CVE-2025-2049" + ], + "details": "A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file AB+.php. The manipulation of the argument Bloodname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2049" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/ABC-YOLO/cve/blob/main/xss45.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298800" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298800" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7p56-992f-276f/GHSA-7p56-992f-276f.json b/advisories/unreviewed/2025/03/GHSA-7p56-992f-276f/GHSA-7p56-992f-276f.json new file mode 100644 index 00000000000..b5c3bdbe508 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7p56-992f-276f/GHSA-7p56-992f-276f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p56-992f-276f", + "modified": "2025-03-07T00:31:55Z", + "published": "2025-03-07T00:31:55Z", + "aliases": [ + "CVE-2025-2046" + ], + "details": "A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2046" + }, + { + "type": "WEB", + "url": "https://github.com/Hefei-Coffee/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298796" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298796" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.513971" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T22:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9p6p-jg3p-f8mv/GHSA-9p6p-jg3p-f8mv.json b/advisories/unreviewed/2025/03/GHSA-9p6p-jg3p-f8mv/GHSA-9p6p-jg3p-f8mv.json new file mode 100644 index 00000000000..2f6336ecf6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9p6p-jg3p-f8mv/GHSA-9p6p-jg3p-f8mv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p6p-jg3p-f8mv", + "modified": "2025-03-07T00:31:55Z", + "published": "2025-03-07T00:31:55Z", + "aliases": [ + "CVE-2025-1121" + ], + "details": "Test CVE description", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1121" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/b/336153054" + }, + { + "type": "WEB", + "url": "https://issuetracker.google.com/issues/336153054" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T00:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hpc3-qphc-hp5q/GHSA-hpc3-qphc-hp5q.json b/advisories/unreviewed/2025/03/GHSA-hpc3-qphc-hp5q/GHSA-hpc3-qphc-hp5q.json new file mode 100644 index 00000000000..9368da9c492 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hpc3-qphc-hp5q/GHSA-hpc3-qphc-hp5q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpc3-qphc-hp5q", + "modified": "2025-03-07T00:31:55Z", + "published": "2025-03-07T00:31:55Z", + "aliases": [ + "CVE-2025-2047" + ], + "details": "A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2047" + }, + { + "type": "WEB", + "url": "https://github.com/chenyihao-cyber/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298797" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298797" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json b/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json index 5f59f23d01e..71cf0bfc009 100644 --- a/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json +++ b/advisories/unreviewed/2025/03/GHSA-mfqx-wfm8-g2h8/GHSA-mfqx-wfm8-g2h8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mfqx-wfm8-g2h8", - "modified": "2025-03-05T21:32:13Z", + "modified": "2025-03-07T00:31:55Z", "published": "2025-03-05T21:32:13Z", "aliases": [ "CVE-2024-57174" ], "details": "A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and point its wildcard DNS entry to an attacker-controlled IP address, making it possible to access sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-05T21:15:19Z" diff --git a/advisories/unreviewed/2025/03/GHSA-w647-j7mf-2p33/GHSA-w647-j7mf-2p33.json b/advisories/unreviewed/2025/03/GHSA-w647-j7mf-2p33/GHSA-w647-j7mf-2p33.json new file mode 100644 index 00000000000..cc6f198c6c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w647-j7mf-2p33/GHSA-w647-j7mf-2p33.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w647-j7mf-2p33", + "modified": "2025-03-07T00:31:56Z", + "published": "2025-03-07T00:31:55Z", + "aliases": [ + "CVE-2025-2044" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_bloodGroup.php. The manipulation of the argument blood_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2044" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/SQL5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298789" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298789" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.513653" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json b/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json new file mode 100644 index 00000000000..4e9f0c0e7cc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wjw9-vpcj-v7j3/GHSA-wjw9-vpcj-v7j3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjw9-vpcj-v7j3", + "modified": "2025-03-07T00:31:56Z", + "published": "2025-03-07T00:31:56Z", + "aliases": [ + "CVE-2025-2050" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2050" + }, + { + "type": "WEB", + "url": "https://github.com/guttlefish/vul/issues/8" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298801" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298801" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-07T00:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wqwm-2jpv-828c/GHSA-wqwm-2jpv-828c.json b/advisories/unreviewed/2025/03/GHSA-wqwm-2jpv-828c/GHSA-wqwm-2jpv-828c.json new file mode 100644 index 00000000000..7a1ccf8a524 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wqwm-2jpv-828c/GHSA-wqwm-2jpv-828c.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqwm-2jpv-828c", + "modified": "2025-03-07T00:31:55Z", + "published": "2025-03-07T00:31:55Z", + "aliases": [ + "CVE-2025-2043" + ], + "details": "A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2043" + }, + { + "type": "WEB", + "url": "https://github.com/Jingyi-u/Pb-cms2/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298787" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298787" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.513243" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-06T22:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json b/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json index b5cb4c38b9f..0311593c93e 100644 --- a/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json +++ b/advisories/unreviewed/2025/03/GHSA-xfr2-g2r2-vf88/GHSA-xfr2-g2r2-vf88.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xfr2-g2r2-vf88", - "modified": "2025-03-06T21:31:27Z", + "modified": "2025-03-07T00:31:55Z", "published": "2025-03-06T21:31:27Z", "aliases": [ "CVE-2024-57972" ], "details": "A vulnerability in the pairing request method in Microsoft HoloLens 1 and 2 - Windows Holographic 10.0.17763.3046 through 10.0.22621.1244 allows remote attackers to cause a Denial of Service via the Device Portal framework.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-06T21:15:14Z"