From 212bb8cd161f0d5dffd96d5f1b718e3c387ad0e8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 21 Apr 2025 15:32:29 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-grmv-gp4f-w59q.json | 10 +++- .../GHSA-2cww-m3rc-2vgr.json | 10 +++- .../GHSA-356q-44f6-58cf.json | 3 +- .../GHSA-3gcg-chcp-rq42.json | 4 +- .../GHSA-3mmq-4r29-8xqf.json | 4 +- .../GHSA-3p9p-h6x6-85gg.json | 4 +- .../GHSA-4cm7-7r9p-hq66.json | 7 ++- .../GHSA-5jxc-4vwp-66q7.json | 4 +- .../GHSA-6mq6-fpvp-rmfg.json | 4 +- .../GHSA-6vrj-5r6c-cp4f.json | 1 + .../GHSA-7668-cr6w-9f3m.json | 4 +- .../GHSA-8p26-v8p8-whm6.json | 3 +- .../GHSA-9cph-hcr9-fvgm.json | 10 +++- .../GHSA-g583-4mg8-hq84.json | 1 + .../GHSA-gg8p-2j6g-g8mc.json | 4 +- .../GHSA-hm5v-5ww3-9m4f.json | 6 +- .../GHSA-j5ff-q8rv-qm43.json | 4 +- .../GHSA-j5gx-4346-5ffr.json | 1 + .../GHSA-j8wj-77mv-262g.json | 1 + .../GHSA-jxvj-5mm5-3cx5.json | 10 +++- .../GHSA-m6vx-pgv7-3f4w.json | 6 +- .../GHSA-mgf9-v7f6-c7w7.json | 4 +- .../GHSA-mjj5-7gmf-mfjx.json | 3 +- .../GHSA-mv7w-74c6-4w37.json | 4 +- .../GHSA-pjwj-r3p9-jjrq.json | 11 +++- .../GHSA-qjg8-52hj-5hj8.json | 6 +- .../GHSA-v86p-p58r-p852.json | 6 +- .../GHSA-w2pw-66cr-j3j9.json | 4 +- .../GHSA-w65h-fh24-25gr.json | 3 +- .../GHSA-w6g9-7v5h-xv4x.json | 3 +- .../GHSA-xc3v-8w4w-w63x.json | 4 +- .../GHSA-xfwv-95wj-h3jj.json | 4 +- .../GHSA-3975-4fwf-j526.json | 10 +++- .../GHSA-h6c3-73mq-5cp9.json | 2 +- .../GHSA-2vw6-5f85-h22m.json | 36 ++++++++++++ .../GHSA-3922-2r6r-r4fv.json | 44 +++++++++++++++ .../GHSA-3ph3-5vg6-324h.json | 36 ++++++++++++ .../GHSA-69cv-j485-xjf7.json | 29 ++++++++++ .../GHSA-7m3w-m5g3-cc88.json | 44 +++++++++++++++ .../GHSA-7rh8-vj62-qfcg.json | 36 ++++++++++++ .../GHSA-847x-x4jg-6gf4.json | 29 ++++++++++ .../GHSA-8c8c-3855-2gv4.json | 36 ++++++++++++ .../GHSA-8fp6-f772-8g6x.json | 15 +++-- .../GHSA-c2rf-m726-rrr8.json | 11 +++- .../GHSA-c57h-rx24-vf52.json | 10 +++- .../GHSA-chrr-x92m-658x.json | 40 +++++++++++++ .../GHSA-chx3-h6vh-h2pv.json | 29 ++++++++++ .../GHSA-fg69-m383-f979.json | 56 +++++++++++++++++++ .../GHSA-g2wh-gmwq-2gmc.json | 36 ++++++++++++ .../GHSA-gj89-4h85-hv53.json | 15 +++-- .../GHSA-h75c-f2xx-9vxv.json | 29 ++++++++++ .../GHSA-j2pm-rwgr-r5gf.json | 15 +++-- .../GHSA-jhcm-4gfm-2q7g.json | 29 ++++++++++ .../GHSA-jrxv-vv4v-jrrh.json | 15 +++-- .../GHSA-m8p9-q552-5h79.json | 15 +++-- .../GHSA-p688-g48x-vg8h.json | 29 ++++++++++ .../GHSA-q9qg-fj9x-mqhg.json | 15 +++-- .../GHSA-rcpj-p3qg-rwwh.json | 40 +++++++++++++ .../GHSA-rfmx-5227-mw6r.json | 40 +++++++++++++ .../GHSA-v3cw-79rq-fhpq.json | 36 ++++++++++++ .../GHSA-vhqp-wr72-mxv8.json | 40 +++++++++++++ .../GHSA-wm23-hcgv-w4x3.json | 29 ++++++++++ .../GHSA-wq8j-qvfr-hj44.json | 52 +++++++++++++++++ .../GHSA-x9ph-h9wh-vcm2.json | 36 ++++++++++++ 64 files changed, 1027 insertions(+), 60 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2vw6-5f85-h22m/GHSA-2vw6-5f85-h22m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3922-2r6r-r4fv/GHSA-3922-2r6r-r4fv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7m3w-m5g3-cc88/GHSA-7m3w-m5g3-cc88.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7rh8-vj62-qfcg/GHSA-7rh8-vj62-qfcg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-847x-x4jg-6gf4/GHSA-847x-x4jg-6gf4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8c8c-3855-2gv4/GHSA-8c8c-3855-2gv4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-chrr-x92m-658x/GHSA-chrr-x92m-658x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fg69-m383-f979/GHSA-fg69-m383-f979.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g2wh-gmwq-2gmc/GHSA-g2wh-gmwq-2gmc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h75c-f2xx-9vxv/GHSA-h75c-f2xx-9vxv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rcpj-p3qg-rwwh/GHSA-rcpj-p3qg-rwwh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rfmx-5227-mw6r/GHSA-rfmx-5227-mw6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v3cw-79rq-fhpq/GHSA-v3cw-79rq-fhpq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhqp-wr72-mxv8/GHSA-vhqp-wr72-mxv8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wq8j-qvfr-hj44/GHSA-wq8j-qvfr-hj44.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x9ph-h9wh-vcm2/GHSA-x9ph-h9wh-vcm2.json diff --git a/advisories/unreviewed/2022/04/GHSA-grmv-gp4f-w59q/GHSA-grmv-gp4f-w59q.json b/advisories/unreviewed/2022/04/GHSA-grmv-gp4f-w59q/GHSA-grmv-gp4f-w59q.json index 34e6ad152a5..06670db13de 100644 --- a/advisories/unreviewed/2022/04/GHSA-grmv-gp4f-w59q/GHSA-grmv-gp4f-w59q.json +++ b/advisories/unreviewed/2022/04/GHSA-grmv-gp4f-w59q/GHSA-grmv-gp4f-w59q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-grmv-gp4f-w59q", - "modified": "2022-05-06T00:01:15Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-04-26T00:00:39Z", "aliases": [ "CVE-2021-25094" @@ -23,10 +23,18 @@ "type": "WEB", "url": "https://darkpills.com/wordpress-tatsu-builder-preauth-rce-cve-2021-25094" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190566" + }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/fb0097a0-5d7b-4e5b-97de-aacafa8fffcd" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52260" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/167190/WordPress-Tatsu-Builder-Remote-Code-Execution.html" diff --git a/advisories/unreviewed/2022/12/GHSA-2cww-m3rc-2vgr/GHSA-2cww-m3rc-2vgr.json b/advisories/unreviewed/2022/12/GHSA-2cww-m3rc-2vgr/GHSA-2cww-m3rc-2vgr.json index 96f644b29d4..eaad8f1d654 100644 --- a/advisories/unreviewed/2022/12/GHSA-2cww-m3rc-2vgr/GHSA-2cww-m3rc-2vgr.json +++ b/advisories/unreviewed/2022/12/GHSA-2cww-m3rc-2vgr/GHSA-2cww-m3rc-2vgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cww-m3rc-2vgr", - "modified": "2022-12-21T15:30:18Z", + "modified": "2025-04-21T15:31:11Z", "published": "2022-12-16T00:30:44Z", "aliases": [ "CVE-2022-46392" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://github.com/Mbed-TLS/mbedtls/releases/tag/v3.3.0" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BR7ZCVKLPGCOEEALUHZMFHXQHR6S4QL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XMKJ5IMJEPXYAHHU56Z4P2FSYIEAESB" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BR7ZCVKLPGCOEEALUHZMFHXQHR6S4QL" diff --git a/advisories/unreviewed/2022/12/GHSA-356q-44f6-58cf/GHSA-356q-44f6-58cf.json b/advisories/unreviewed/2022/12/GHSA-356q-44f6-58cf/GHSA-356q-44f6-58cf.json index 1eb6b3255d6..65510373ca9 100644 --- a/advisories/unreviewed/2022/12/GHSA-356q-44f6-58cf/GHSA-356q-44f6-58cf.json +++ b/advisories/unreviewed/2022/12/GHSA-356q-44f6-58cf/GHSA-356q-44f6-58cf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-3gcg-chcp-rq42/GHSA-3gcg-chcp-rq42.json b/advisories/unreviewed/2022/12/GHSA-3gcg-chcp-rq42/GHSA-3gcg-chcp-rq42.json index 197931835b2..0f46ada465f 100644 --- a/advisories/unreviewed/2022/12/GHSA-3gcg-chcp-rq42/GHSA-3gcg-chcp-rq42.json +++ b/advisories/unreviewed/2022/12/GHSA-3gcg-chcp-rq42/GHSA-3gcg-chcp-rq42.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json b/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json index 9011173303b..28fc5eb2de9 100644 --- a/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json +++ b/advisories/unreviewed/2022/12/GHSA-3mmq-4r29-8xqf/GHSA-3mmq-4r29-8xqf.json @@ -69,7 +69,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json b/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json index 7890aa48058..7a1efdd3764 100644 --- a/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json +++ b/advisories/unreviewed/2022/12/GHSA-3p9p-h6x6-85gg/GHSA-3p9p-h6x6-85gg.json @@ -73,7 +73,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4cm7-7r9p-hq66/GHSA-4cm7-7r9p-hq66.json b/advisories/unreviewed/2022/12/GHSA-4cm7-7r9p-hq66/GHSA-4cm7-7r9p-hq66.json index 2f0ee060674..35087ef7bb7 100644 --- a/advisories/unreviewed/2022/12/GHSA-4cm7-7r9p-hq66/GHSA-4cm7-7r9p-hq66.json +++ b/advisories/unreviewed/2022/12/GHSA-4cm7-7r9p-hq66/GHSA-4cm7-7r9p-hq66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4cm7-7r9p-hq66", - "modified": "2022-12-19T21:30:27Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-12-15T21:30:30Z", "aliases": [ "CVE-2022-42849" @@ -38,10 +38,15 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-5jxc-4vwp-66q7/GHSA-5jxc-4vwp-66q7.json b/advisories/unreviewed/2022/12/GHSA-5jxc-4vwp-66q7/GHSA-5jxc-4vwp-66q7.json index 0a77a79cefa..d5e0c4ef933 100644 --- a/advisories/unreviewed/2022/12/GHSA-5jxc-4vwp-66q7/GHSA-5jxc-4vwp-66q7.json +++ b/advisories/unreviewed/2022/12/GHSA-5jxc-4vwp-66q7/GHSA-5jxc-4vwp-66q7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6mq6-fpvp-rmfg/GHSA-6mq6-fpvp-rmfg.json b/advisories/unreviewed/2022/12/GHSA-6mq6-fpvp-rmfg/GHSA-6mq6-fpvp-rmfg.json index 1e23efa3c25..120f1a20faf 100644 --- a/advisories/unreviewed/2022/12/GHSA-6mq6-fpvp-rmfg/GHSA-6mq6-fpvp-rmfg.json +++ b/advisories/unreviewed/2022/12/GHSA-6mq6-fpvp-rmfg/GHSA-6mq6-fpvp-rmfg.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-6vrj-5r6c-cp4f/GHSA-6vrj-5r6c-cp4f.json b/advisories/unreviewed/2022/12/GHSA-6vrj-5r6c-cp4f/GHSA-6vrj-5r6c-cp4f.json index 7b1a2c4c837..3a7d1c190a7 100644 --- a/advisories/unreviewed/2022/12/GHSA-6vrj-5r6c-cp4f/GHSA-6vrj-5r6c-cp4f.json +++ b/advisories/unreviewed/2022/12/GHSA-6vrj-5r6c-cp4f/GHSA-6vrj-5r6c-cp4f.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-209", "CWE-668" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/12/GHSA-7668-cr6w-9f3m/GHSA-7668-cr6w-9f3m.json b/advisories/unreviewed/2022/12/GHSA-7668-cr6w-9f3m/GHSA-7668-cr6w-9f3m.json index e94a2143edd..fb0e5aac00e 100644 --- a/advisories/unreviewed/2022/12/GHSA-7668-cr6w-9f3m/GHSA-7668-cr6w-9f3m.json +++ b/advisories/unreviewed/2022/12/GHSA-7668-cr6w-9f3m/GHSA-7668-cr6w-9f3m.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-8p26-v8p8-whm6/GHSA-8p26-v8p8-whm6.json b/advisories/unreviewed/2022/12/GHSA-8p26-v8p8-whm6/GHSA-8p26-v8p8-whm6.json index 4ad5c25883d..069747109d1 100644 --- a/advisories/unreviewed/2022/12/GHSA-8p26-v8p8-whm6/GHSA-8p26-v8p8-whm6.json +++ b/advisories/unreviewed/2022/12/GHSA-8p26-v8p8-whm6/GHSA-8p26-v8p8-whm6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-9cph-hcr9-fvgm/GHSA-9cph-hcr9-fvgm.json b/advisories/unreviewed/2022/12/GHSA-9cph-hcr9-fvgm/GHSA-9cph-hcr9-fvgm.json index 8cd32717300..5a5ffe5165c 100644 --- a/advisories/unreviewed/2022/12/GHSA-9cph-hcr9-fvgm/GHSA-9cph-hcr9-fvgm.json +++ b/advisories/unreviewed/2022/12/GHSA-9cph-hcr9-fvgm/GHSA-9cph-hcr9-fvgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cph-hcr9-fvgm", - "modified": "2022-12-20T03:30:28Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-12-15T21:30:30Z", "aliases": [ "CVE-2022-42845" @@ -62,10 +62,16 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-g583-4mg8-hq84/GHSA-g583-4mg8-hq84.json b/advisories/unreviewed/2022/12/GHSA-g583-4mg8-hq84/GHSA-g583-4mg8-hq84.json index 4b71f202704..950025825ea 100644 --- a/advisories/unreviewed/2022/12/GHSA-g583-4mg8-hq84/GHSA-g583-4mg8-hq84.json +++ b/advisories/unreviewed/2022/12/GHSA-g583-4mg8-hq84/GHSA-g583-4mg8-hq84.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-327" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json b/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json index 0720587a82e..76c45688692 100644 --- a/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json +++ b/advisories/unreviewed/2022/12/GHSA-gg8p-2j6g-g8mc/GHSA-gg8p-2j6g-g8mc.json @@ -73,7 +73,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-345" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-hm5v-5ww3-9m4f/GHSA-hm5v-5ww3-9m4f.json b/advisories/unreviewed/2022/12/GHSA-hm5v-5ww3-9m4f/GHSA-hm5v-5ww3-9m4f.json index 1b8f54f5b33..79e3e9f3c41 100644 --- a/advisories/unreviewed/2022/12/GHSA-hm5v-5ww3-9m4f/GHSA-hm5v-5ww3-9m4f.json +++ b/advisories/unreviewed/2022/12/GHSA-hm5v-5ww3-9m4f/GHSA-hm5v-5ww3-9m4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm5v-5ww3-9m4f", - "modified": "2022-12-20T15:30:37Z", + "modified": "2025-04-21T15:31:11Z", "published": "2022-12-15T21:30:31Z", "aliases": [ "CVE-2022-46695" @@ -54,6 +54,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-j5ff-q8rv-qm43/GHSA-j5ff-q8rv-qm43.json b/advisories/unreviewed/2022/12/GHSA-j5ff-q8rv-qm43/GHSA-j5ff-q8rv-qm43.json index 4cdc147a5b5..72c11080718 100644 --- a/advisories/unreviewed/2022/12/GHSA-j5ff-q8rv-qm43/GHSA-j5ff-q8rv-qm43.json +++ b/advisories/unreviewed/2022/12/GHSA-j5ff-q8rv-qm43/GHSA-j5ff-q8rv-qm43.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-j5gx-4346-5ffr/GHSA-j5gx-4346-5ffr.json b/advisories/unreviewed/2022/12/GHSA-j5gx-4346-5ffr/GHSA-j5gx-4346-5ffr.json index 97b91a684c3..f7288d985e1 100644 --- a/advisories/unreviewed/2022/12/GHSA-j5gx-4346-5ffr/GHSA-j5gx-4346-5ffr.json +++ b/advisories/unreviewed/2022/12/GHSA-j5gx-4346-5ffr/GHSA-j5gx-4346-5ffr.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/12/GHSA-j8wj-77mv-262g/GHSA-j8wj-77mv-262g.json b/advisories/unreviewed/2022/12/GHSA-j8wj-77mv-262g/GHSA-j8wj-77mv-262g.json index 5f05d67ad13..0a71c107277 100644 --- a/advisories/unreviewed/2022/12/GHSA-j8wj-77mv-262g/GHSA-j8wj-77mv-262g.json +++ b/advisories/unreviewed/2022/12/GHSA-j8wj-77mv-262g/GHSA-j8wj-77mv-262g.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-345", "CWE-639" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-jxvj-5mm5-3cx5/GHSA-jxvj-5mm5-3cx5.json b/advisories/unreviewed/2022/12/GHSA-jxvj-5mm5-3cx5/GHSA-jxvj-5mm5-3cx5.json index 83de1f90c2f..301cbb35f70 100644 --- a/advisories/unreviewed/2022/12/GHSA-jxvj-5mm5-3cx5/GHSA-jxvj-5mm5-3cx5.json +++ b/advisories/unreviewed/2022/12/GHSA-jxvj-5mm5-3cx5/GHSA-jxvj-5mm5-3cx5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxvj-5mm5-3cx5", - "modified": "2022-12-20T18:30:20Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-12-15T21:30:30Z", "aliases": [ "CVE-2022-42859" @@ -38,10 +38,16 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/23" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-m6vx-pgv7-3f4w/GHSA-m6vx-pgv7-3f4w.json b/advisories/unreviewed/2022/12/GHSA-m6vx-pgv7-3f4w/GHSA-m6vx-pgv7-3f4w.json index 653ef558149..3d7ad8dd337 100644 --- a/advisories/unreviewed/2022/12/GHSA-m6vx-pgv7-3f4w/GHSA-m6vx-pgv7-3f4w.json +++ b/advisories/unreviewed/2022/12/GHSA-m6vx-pgv7-3f4w/GHSA-m6vx-pgv7-3f4w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6vx-pgv7-3f4w", - "modified": "2022-12-20T15:30:37Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-12-15T21:30:31Z", "aliases": [ "CVE-2022-46694" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-mgf9-v7f6-c7w7/GHSA-mgf9-v7f6-c7w7.json b/advisories/unreviewed/2022/12/GHSA-mgf9-v7f6-c7w7/GHSA-mgf9-v7f6-c7w7.json index ce68ca06c9f..06c82120fd2 100644 --- a/advisories/unreviewed/2022/12/GHSA-mgf9-v7f6-c7w7/GHSA-mgf9-v7f6-c7w7.json +++ b/advisories/unreviewed/2022/12/GHSA-mgf9-v7f6-c7w7/GHSA-mgf9-v7f6-c7w7.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-mjj5-7gmf-mfjx/GHSA-mjj5-7gmf-mfjx.json b/advisories/unreviewed/2022/12/GHSA-mjj5-7gmf-mfjx/GHSA-mjj5-7gmf-mfjx.json index 3db2f242ef8..56a5f368be9 100644 --- a/advisories/unreviewed/2022/12/GHSA-mjj5-7gmf-mfjx/GHSA-mjj5-7gmf-mfjx.json +++ b/advisories/unreviewed/2022/12/GHSA-mjj5-7gmf-mfjx/GHSA-mjj5-7gmf-mfjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjj5-7gmf-mfjx", - "modified": "2022-12-20T15:30:37Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-12-14T09:30:23Z", "aliases": [ "CVE-2022-3590" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-367", "CWE-918" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-mv7w-74c6-4w37/GHSA-mv7w-74c6-4w37.json b/advisories/unreviewed/2022/12/GHSA-mv7w-74c6-4w37/GHSA-mv7w-74c6-4w37.json index 4ed596c370b..716fe16ff73 100644 --- a/advisories/unreviewed/2022/12/GHSA-mv7w-74c6-4w37/GHSA-mv7w-74c6-4w37.json +++ b/advisories/unreviewed/2022/12/GHSA-mv7w-74c6-4w37/GHSA-mv7w-74c6-4w37.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-pjwj-r3p9-jjrq/GHSA-pjwj-r3p9-jjrq.json b/advisories/unreviewed/2022/12/GHSA-pjwj-r3p9-jjrq/GHSA-pjwj-r3p9-jjrq.json index 0c73599e6fe..3de13dc3a47 100644 --- a/advisories/unreviewed/2022/12/GHSA-pjwj-r3p9-jjrq/GHSA-pjwj-r3p9-jjrq.json +++ b/advisories/unreviewed/2022/12/GHSA-pjwj-r3p9-jjrq/GHSA-pjwj-r3p9-jjrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjwj-r3p9-jjrq", - "modified": "2022-12-20T21:30:19Z", + "modified": "2025-04-21T15:31:11Z", "published": "2022-12-16T00:30:44Z", "aliases": [ "CVE-2022-46393" @@ -27,6 +27,14 @@ "type": "WEB", "url": "https://github.com/Mbed-TLS/mbedtls/releases/tag/v3.3.0" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BR7ZCVKLPGCOEEALUHZMFHXQHR6S4QL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XMKJ5IMJEPXYAHHU56Z4P2FSYIEAESB" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BR7ZCVKLPGCOEEALUHZMFHXQHR6S4QL" @@ -42,6 +50,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/12/GHSA-qjg8-52hj-5hj8/GHSA-qjg8-52hj-5hj8.json b/advisories/unreviewed/2022/12/GHSA-qjg8-52hj-5hj8/GHSA-qjg8-52hj-5hj8.json index c988a4251a5..319fb00f2ed 100644 --- a/advisories/unreviewed/2022/12/GHSA-qjg8-52hj-5hj8/GHSA-qjg8-52hj-5hj8.json +++ b/advisories/unreviewed/2022/12/GHSA-qjg8-52hj-5hj8/GHSA-qjg8-52hj-5hj8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjg8-52hj-5hj8", - "modified": "2022-12-20T18:30:20Z", + "modified": "2025-04-21T15:31:11Z", "published": "2022-12-15T21:30:31Z", "aliases": [ "CVE-2022-46693" @@ -50,6 +50,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-v86p-p58r-p852/GHSA-v86p-p58r-p852.json b/advisories/unreviewed/2022/12/GHSA-v86p-p58r-p852/GHSA-v86p-p58r-p852.json index 0ca6c858c17..ade6879b656 100644 --- a/advisories/unreviewed/2022/12/GHSA-v86p-p58r-p852/GHSA-v86p-p58r-p852.json +++ b/advisories/unreviewed/2022/12/GHSA-v86p-p58r-p852/GHSA-v86p-p58r-p852.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v86p-p58r-p852", - "modified": "2022-12-20T18:30:20Z", + "modified": "2025-04-21T15:31:10Z", "published": "2022-12-15T21:30:30Z", "aliases": [ "CVE-2022-46690" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/12/GHSA-w2pw-66cr-j3j9/GHSA-w2pw-66cr-j3j9.json b/advisories/unreviewed/2022/12/GHSA-w2pw-66cr-j3j9/GHSA-w2pw-66cr-j3j9.json index 20a5ebf19ab..87d8ede61c9 100644 --- a/advisories/unreviewed/2022/12/GHSA-w2pw-66cr-j3j9/GHSA-w2pw-66cr-j3j9.json +++ b/advisories/unreviewed/2022/12/GHSA-w2pw-66cr-j3j9/GHSA-w2pw-66cr-j3j9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-w65h-fh24-25gr/GHSA-w65h-fh24-25gr.json b/advisories/unreviewed/2022/12/GHSA-w65h-fh24-25gr/GHSA-w65h-fh24-25gr.json index 40f5fd115ef..d91e2b40ed3 100644 --- a/advisories/unreviewed/2022/12/GHSA-w65h-fh24-25gr/GHSA-w65h-fh24-25gr.json +++ b/advisories/unreviewed/2022/12/GHSA-w65h-fh24-25gr/GHSA-w65h-fh24-25gr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-w6g9-7v5h-xv4x/GHSA-w6g9-7v5h-xv4x.json b/advisories/unreviewed/2022/12/GHSA-w6g9-7v5h-xv4x/GHSA-w6g9-7v5h-xv4x.json index 45a3ffdc232..bb552c4fcb0 100644 --- a/advisories/unreviewed/2022/12/GHSA-w6g9-7v5h-xv4x/GHSA-w6g9-7v5h-xv4x.json +++ b/advisories/unreviewed/2022/12/GHSA-w6g9-7v5h-xv4x/GHSA-w6g9-7v5h-xv4x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-693" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-xc3v-8w4w-w63x/GHSA-xc3v-8w4w-w63x.json b/advisories/unreviewed/2022/12/GHSA-xc3v-8w4w-w63x/GHSA-xc3v-8w4w-w63x.json index 08de979320a..1063ba4ee6e 100644 --- a/advisories/unreviewed/2022/12/GHSA-xc3v-8w4w-w63x/GHSA-xc3v-8w4w-w63x.json +++ b/advisories/unreviewed/2022/12/GHSA-xc3v-8w4w-w63x/GHSA-xc3v-8w4w-w63x.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-xfwv-95wj-h3jj/GHSA-xfwv-95wj-h3jj.json b/advisories/unreviewed/2022/12/GHSA-xfwv-95wj-h3jj/GHSA-xfwv-95wj-h3jj.json index 6db072287b1..40d4f7e3391 100644 --- a/advisories/unreviewed/2022/12/GHSA-xfwv-95wj-h3jj/GHSA-xfwv-95wj-h3jj.json +++ b/advisories/unreviewed/2022/12/GHSA-xfwv-95wj-h3jj/GHSA-xfwv-95wj-h3jj.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-3975-4fwf-j526/GHSA-3975-4fwf-j526.json b/advisories/unreviewed/2024/01/GHSA-3975-4fwf-j526/GHSA-3975-4fwf-j526.json index c988694772d..e9a4bc68dc6 100644 --- a/advisories/unreviewed/2024/01/GHSA-3975-4fwf-j526/GHSA-3975-4fwf-j526.json +++ b/advisories/unreviewed/2024/01/GHSA-3975-4fwf-j526/GHSA-3975-4fwf-j526.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3975-4fwf-j526", - "modified": "2024-01-15T06:30:28Z", + "modified": "2025-04-21T15:31:14Z", "published": "2024-01-15T06:30:28Z", "aliases": [ "CVE-2024-0545" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -26,6 +30,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.250714" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.266974" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json b/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json index 7c8269dbebb..7afc6611faf 100644 --- a/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json +++ b/advisories/unreviewed/2024/11/GHSA-h6c3-73mq-5cp9/GHSA-h6c3-73mq-5cp9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6c3-73mq-5cp9", - "modified": "2024-11-26T15:31:03Z", + "modified": "2025-04-21T15:31:15Z", "published": "2024-11-26T15:31:03Z", "aliases": [ "CVE-2024-8236" diff --git a/advisories/unreviewed/2025/04/GHSA-2vw6-5f85-h22m/GHSA-2vw6-5f85-h22m.json b/advisories/unreviewed/2025/04/GHSA-2vw6-5f85-h22m/GHSA-2vw6-5f85-h22m.json new file mode 100644 index 00000000000..e44d883228d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2vw6-5f85-h22m/GHSA-2vw6-5f85-h22m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vw6-5f85-h22m", + "modified": "2025-04-21T15:31:26Z", + "published": "2025-04-21T15:31:26Z", + "aliases": [ + "CVE-2025-2517" + ], + "details": "Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2517" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000040103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-672" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3922-2r6r-r4fv/GHSA-3922-2r6r-r4fv.json b/advisories/unreviewed/2025/04/GHSA-3922-2r6r-r4fv/GHSA-3922-2r6r-r4fv.json new file mode 100644 index 00000000000..2a0fca22188 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3922-2r6r-r4fv/GHSA-3922-2r6r-r4fv.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3922-2r6r-r4fv", + "modified": "2025-04-21T15:31:25Z", + "published": "2025-04-21T15:31:25Z", + "aliases": [ + "CVE-2025-29287" + ], + "details": "An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29287" + }, + { + "type": "WEB", + "url": "https://gist.github.com/erdan111/38dcb5150b523436fe01249b2542f02f#file-cve-2025-29287" + }, + { + "type": "WEB", + "url": "https://gitee.com/mingSoft/MCMS/issues/IBOOTX" + }, + { + "type": "WEB", + "url": "http://cms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json b/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json new file mode 100644 index 00000000000..210bea02a3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ph3-5vg6-324h", + "modified": "2025-04-21T15:31:23Z", + "published": "2025-04-21T15:31:23Z", + "aliases": [ + "CVE-2025-32408" + ], + "details": "In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32408" + }, + { + "type": "WEB", + "url": "https://bookstack.soffid.com/books/security-advisories/page/cve-2024-39669" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json b/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json new file mode 100644 index 00000000000..4d8db250d37 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-69cv-j485-xjf7/GHSA-69cv-j485-xjf7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69cv-j485-xjf7", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-28230" + ], + "details": "Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28230" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28230" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7m3w-m5g3-cc88/GHSA-7m3w-m5g3-cc88.json b/advisories/unreviewed/2025/04/GHSA-7m3w-m5g3-cc88/GHSA-7m3w-m5g3-cc88.json new file mode 100644 index 00000000000..4b731809996 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7m3w-m5g3-cc88/GHSA-7m3w-m5g3-cc88.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m3w-m5g3-cc88", + "modified": "2025-04-21T15:31:23Z", + "published": "2025-04-21T15:31:23Z", + "aliases": [ + "CVE-2024-41446" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41446" + }, + { + "type": "WEB", + "url": "https://github.com/Sidd545-cr/CVE/blob/main/CVE-2024-41446%20-%20Stored%20XSS%20in%20image%20copyright%20attribute.pdf" + }, + { + "type": "WEB", + "url": "http://alkacon.com" + }, + { + "type": "WEB", + "url": "http://opencms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rh8-vj62-qfcg/GHSA-7rh8-vj62-qfcg.json b/advisories/unreviewed/2025/04/GHSA-7rh8-vj62-qfcg/GHSA-7rh8-vj62-qfcg.json new file mode 100644 index 00000000000..bbd8fed0723 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rh8-vj62-qfcg/GHSA-7rh8-vj62-qfcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rh8-vj62-qfcg", + "modified": "2025-04-21T15:31:26Z", + "published": "2025-04-21T15:31:26Z", + "aliases": [ + "CVE-2025-2298" + ], + "details": "An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the system has access to, including system files and files stored in remote locations such as S3, Azure Blob Storage, and local filesystems. This vulnerability exists due to insufficient access controls on an API endpoint, enabling any authenticated user to specify and delete files outside their intended scope. Exploiting this flaw could lead to data loss, denial of service (DoS), and potential escalation of impact depending on the deleted files.\n\nAffected versions:\n * Any version of Dremio below 24.0.0\n\n\n * Dremio 24.3.0 - 24.3.16\n\n\n * Dremio 25.0.0 - 25.0.14\n\n\n * Dremio 25.1.0 - 25.1.7\n\n\n * Dremio 25.2.0 - 25.2.4\n\n\n\n\n\nFixed in version: \n * Dremio 24.3.17 and above\n\n\n * Dremio 25.0.15 and above\n\n\n * Dremio 25.1.8 and above\n\n\n * Dremio 25.2.5 and above\n\n\n * Dremio 26.0.0 and above", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2298" + }, + { + "type": "WEB", + "url": "https://docs.dremio.com/current/reference/bulletins/2025-04-21-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-847x-x4jg-6gf4/GHSA-847x-x4jg-6gf4.json b/advisories/unreviewed/2025/04/GHSA-847x-x4jg-6gf4/GHSA-847x-x4jg-6gf4.json new file mode 100644 index 00000000000..cd25610892d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-847x-x4jg-6gf4/GHSA-847x-x4jg-6gf4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-847x-x4jg-6gf4", + "modified": "2025-04-21T15:31:18Z", + "published": "2025-04-21T15:31:18Z", + "aliases": [ + "CVE-2024-29643" + ], + "details": "An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29643" + }, + { + "type": "WEB", + "url": "https://medium.com/@christbowel6/cve-2024-29643-host-header-injection-in-croogo-v3-0-2-0aded525f574" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8c8c-3855-2gv4/GHSA-8c8c-3855-2gv4.json b/advisories/unreviewed/2025/04/GHSA-8c8c-3855-2gv4/GHSA-8c8c-3855-2gv4.json new file mode 100644 index 00000000000..990315dffff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8c8c-3855-2gv4/GHSA-8c8c-3855-2gv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c8c-3855-2gv4", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-2950" + ], + "details": "IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2950" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231320" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json b/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json index e2fb7975b0b..026a499d499 100644 --- a/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json +++ b/advisories/unreviewed/2025/04/GHSA-8fp6-f772-8g6x/GHSA-8fp6-f772-8g6x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8fp6-f772-8g6x", - "modified": "2025-04-16T15:34:44Z", + "modified": "2025-04-21T15:31:16Z", "published": "2025-04-16T15:34:44Z", "aliases": [ "CVE-2025-22088" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Prevent use-after-free in erdma_accept_newconn()\n\nAfter the erdma_cep_put(new_cep) being called, new_cep will be freed,\nand the following dereference will cause a UAF problem. Fix this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:16:03Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c2rf-m726-rrr8/GHSA-c2rf-m726-rrr8.json b/advisories/unreviewed/2025/04/GHSA-c2rf-m726-rrr8/GHSA-c2rf-m726-rrr8.json index 1b3391f3751..f97ae056fad 100644 --- a/advisories/unreviewed/2025/04/GHSA-c2rf-m726-rrr8/GHSA-c2rf-m726-rrr8.json +++ b/advisories/unreviewed/2025/04/GHSA-c2rf-m726-rrr8/GHSA-c2rf-m726-rrr8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c2rf-m726-rrr8", - "modified": "2025-04-18T03:31:22Z", + "modified": "2025-04-21T15:31:17Z", "published": "2025-04-18T03:31:22Z", "aliases": [ "CVE-2025-0467" ], "details": "Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-823" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T01:15:32Z" diff --git a/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json b/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json index 7422fc2f10e..f9427288f77 100644 --- a/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json +++ b/advisories/unreviewed/2025/04/GHSA-c57h-rx24-vf52/GHSA-c57h-rx24-vf52.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c57h-rx24-vf52", - "modified": "2025-04-05T21:30:22Z", + "modified": "2025-04-21T15:31:16Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2025-31161" @@ -46,6 +46,14 @@ { "type": "WEB", "url": "https://www.infosecurity-magazine.com/news/crushftp-flaw-exploited-disclosure" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-31161-detect-crushftp-vulnerability" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cve-2025-31161-mitigate-crushftp-vulnerability" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-chrr-x92m-658x/GHSA-chrr-x92m-658x.json b/advisories/unreviewed/2025/04/GHSA-chrr-x92m-658x/GHSA-chrr-x92m-658x.json new file mode 100644 index 00000000000..7ec2c366dbc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chrr-x92m-658x/GHSA-chrr-x92m-658x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chrr-x92m-658x", + "modified": "2025-04-21T15:31:26Z", + "published": "2025-04-21T15:31:25Z", + "aliases": [ + "CVE-2025-29660" + ], + "details": "A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29660" + }, + { + "type": "WEB", + "url": "https://github.com/Yasha-ops/RCE-YiIOT" + }, + { + "type": "WEB", + "url": "https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-29660" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json b/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json new file mode 100644 index 00000000000..e8de42c00d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chx3-h6vh-h2pv/GHSA-chx3-h6vh-h2pv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chx3-h6vh-h2pv", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-28232" + ], + "details": "Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28232" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28232" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fg69-m383-f979/GHSA-fg69-m383-f979.json b/advisories/unreviewed/2025/04/GHSA-fg69-m383-f979/GHSA-fg69-m383-f979.json new file mode 100644 index 00000000000..ade8f809462 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fg69-m383-f979/GHSA-fg69-m383-f979.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg69-m383-f979", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-3791" + ], + "details": "A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3791" + }, + { + "type": "WEB", + "url": "https://github.com/symisc/unqlite/issues/173" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/19652580/unqlite-reproduce-heap-overflow.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305614" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305614" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554574" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g2wh-gmwq-2gmc/GHSA-g2wh-gmwq-2gmc.json b/advisories/unreviewed/2025/04/GHSA-g2wh-gmwq-2gmc/GHSA-g2wh-gmwq-2gmc.json new file mode 100644 index 00000000000..d8f37d08f62 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g2wh-gmwq-2gmc/GHSA-g2wh-gmwq-2gmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2wh-gmwq-2gmc", + "modified": "2025-04-21T15:31:24Z", + "published": "2025-04-21T15:31:24Z", + "aliases": [ + "CVE-2025-43916" + ], + "details": "Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC 6819 section 5.2.3.5. An authorization code may be sent to an attacker-controlled destination. This might have further implications in conjunction with \"Decompiling the app revealed a hardcoded secret.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43916" + }, + { + "type": "WEB", + "url": "https://github.com/larlarua/vulnerability-reports/blob/main/CVE-2025-43916/detail.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-647" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json b/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json index 3c2c5e3adb4..4c5f6a53a97 100644 --- a/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json +++ b/advisories/unreviewed/2025/04/GHSA-gj89-4h85-hv53/GHSA-gj89-4h85-hv53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gj89-4h85-hv53", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-21T15:31:16Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22041" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in ksmbd_sessions_deregister()\n\nIn multichannel mode, UAF issue can occur in session_deregister\nwhen the second channel sets up a session through the connection of\nthe first channel. session that is freed through the global session\ntable can be accessed again through ->sessions of connection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:56Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h75c-f2xx-9vxv/GHSA-h75c-f2xx-9vxv.json b/advisories/unreviewed/2025/04/GHSA-h75c-f2xx-9vxv/GHSA-h75c-f2xx-9vxv.json new file mode 100644 index 00000000000..eb21316de85 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h75c-f2xx-9vxv/GHSA-h75c-f2xx-9vxv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h75c-f2xx-9vxv", + "modified": "2025-04-21T15:31:25Z", + "published": "2025-04-21T15:31:25Z", + "aliases": [ + "CVE-2024-42699" + ], + "details": "Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42699" + }, + { + "type": "WEB", + "url": "https://github.com/Sidd545-cr/CVE/blob/main/CVE-2024-42699%20-%20Stored%20XSS%20in%20image%20title.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json b/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json index de5885a4db8..267c8c9cd1f 100644 --- a/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json +++ b/advisories/unreviewed/2025/04/GHSA-j2pm-rwgr-r5gf/GHSA-j2pm-rwgr-r5gf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j2pm-rwgr-r5gf", - "modified": "2025-04-16T15:34:43Z", + "modified": "2025-04-21T15:31:16Z", "published": "2025-04-16T15:34:43Z", "aliases": [ "CVE-2025-22085" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix use-after-free when rename device name\n\nSyzbot reported a slab-use-after-free with the following call trace:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in nla_put+0xd3/0x150 lib/nlattr.c:1099\nRead of size 5 at addr ffff888140ea1c60 by task syz.0.988/10025\n\nCPU: 0 UID: 0 PID: 10025 Comm: syz.0.988\nNot tainted 6.14.0-rc4-syzkaller-00859-gf77f12010f67 #0\nHardware name: Google Compute Engine, BIOS Google 02/12/2025\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:408 [inline]\n print_report+0x16e/0x5b0 mm/kasan/report.c:521\n kasan_report+0x143/0x180 mm/kasan/report.c:634\n kasan_check_range+0x282/0x290 mm/kasan/generic.c:189\n __asan_memcpy+0x29/0x70 mm/kasan/shadow.c:105\n nla_put+0xd3/0x150 lib/nlattr.c:1099\n nla_put_string include/net/netlink.h:1621 [inline]\n fill_nldev_handle+0x16e/0x200 drivers/infiniband/core/nldev.c:265\n rdma_nl_notify_event+0x561/0xef0 drivers/infiniband/core/nldev.c:2857\n ib_device_notify_register+0x22/0x230 drivers/infiniband/core/device.c:1344\n ib_register_device+0x1292/0x1460 drivers/infiniband/core/device.c:1460\n rxe_register_device+0x233/0x350 drivers/infiniband/sw/rxe/rxe_verbs.c:1540\n rxe_net_add+0x74/0xf0 drivers/infiniband/sw/rxe/rxe_net.c:550\n rxe_newlink+0xde/0x1a0 drivers/infiniband/sw/rxe/rxe.c:212\n nldev_newlink+0x5ea/0x680 drivers/infiniband/core/nldev.c:1795\n rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]\n rdma_nl_rcv+0x6dd/0x9e0 drivers/infiniband/core/netlink.c:259\n netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1339\n netlink_sendmsg+0x8de/0xcb0 net/netlink/af_netlink.c:1883\n sock_sendmsg_nosec net/socket.c:709 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:724\n ____sys_sendmsg+0x53a/0x860 net/socket.c:2564\n ___sys_sendmsg net/socket.c:2618 [inline]\n __sys_sendmsg+0x269/0x350 net/socket.c:2650\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f42d1b8d169\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 ...\nRSP: 002b:00007f42d2960038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f42d1da6320 RCX: 00007f42d1b8d169\nRDX: 0000000000000000 RSI: 00004000000002c0 RDI: 000000000000000c\nRBP: 00007f42d1c0e2a0 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f42d1da6320 R15: 00007ffe399344a8\n \n\nAllocated by task 10025:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4294 [inline]\n __kmalloc_node_track_caller_noprof+0x28b/0x4c0 mm/slub.c:4313\n __kmemdup_nul mm/util.c:61 [inline]\n kstrdup+0x42/0x100 mm/util.c:81\n kobject_set_name_vargs+0x61/0x120 lib/kobject.c:274\n dev_set_name+0xd5/0x120 drivers/base/core.c:3468\n assign_name drivers/infiniband/core/device.c:1202 [inline]\n ib_register_device+0x178/0x1460 drivers/infiniband/core/device.c:1384\n rxe_register_device+0x233/0x350 drivers/infiniband/sw/rxe/rxe_verbs.c:1540\n rxe_net_add+0x74/0xf0 drivers/infiniband/sw/rxe/rxe_net.c:550\n rxe_newlink+0xde/0x1a0 drivers/infiniband/sw/rxe/rxe.c:212\n nldev_newlink+0x5ea/0x680 drivers/infiniband/core/nldev.c:1795\n rdma_nl_rcv_skb drivers/infiniband/core/netlink.c:239 [inline]\n rdma_nl_rcv+0x6dd/0x9e0 drivers/infiniband/core/netlink.c:259\n netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1339\n netlink_sendmsg+0x8de/0xcb0 net\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:16:02Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json b/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json new file mode 100644 index 00000000000..4e6c3d01442 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jhcm-4gfm-2q7g/GHSA-jhcm-4gfm-2q7g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhcm-4gfm-2q7g", + "modified": "2025-04-21T15:31:19Z", + "published": "2025-04-21T15:31:19Z", + "aliases": [ + "CVE-2025-28229" + ], + "details": "Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28229" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28229" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json b/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json index ace58fd261f..14290fad182 100644 --- a/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json +++ b/advisories/unreviewed/2025/04/GHSA-jrxv-vv4v-jrrh/GHSA-jrxv-vv4v-jrrh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jrxv-vv4v-jrrh", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-21T15:31:16Z", "published": "2025-04-16T15:34:39Z", "aliases": [ "CVE-2025-22035" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix use-after-free in print_graph_function_flags during tracer switching\n\nKairui reported a UAF issue in print_graph_function_flags() during\nftrace stress testing [1]. This issue can be reproduced if puting a\n'mdelay(10)' after 'mutex_unlock(&trace_types_lock)' in s_start(),\nand executing the following script:\n\n $ echo function_graph > current_tracer\n $ cat trace > /dev/null &\n $ sleep 5 # Ensure the 'cat' reaches the 'mdelay(10)' point\n $ echo timerlat > current_tracer\n\nThe root cause lies in the two calls to print_graph_function_flags\nwithin print_trace_line during each s_show():\n\n * One through 'iter->trace->print_line()';\n * Another through 'event->funcs->trace()', which is hidden in\n print_trace_fmt() before print_trace_line returns.\n\nTracer switching only updates the former, while the latter continues\nto use the print_line function of the old tracer, which in the script\nabove is print_graph_function_flags.\n\nMoreover, when switching from the 'function_graph' tracer to the\n'timerlat' tracer, s_start only calls graph_trace_close of the\n'function_graph' tracer to free 'iter->private', but does not set\nit to NULL. This provides an opportunity for 'event->funcs->trace()'\nto use an invalid 'iter->private'.\n\nTo fix this issue, set 'iter->private' to NULL immediately after\nfreeing it in graph_trace_close(), ensuring that an invalid pointer\nis not passed to other tracers. Additionally, clean up the unnecessary\n'iter->private = NULL' during each 'cat trace' when using wakeup and\nirqsoff tracers.\n\n [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:56Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m8p9-q552-5h79/GHSA-m8p9-q552-5h79.json b/advisories/unreviewed/2025/04/GHSA-m8p9-q552-5h79/GHSA-m8p9-q552-5h79.json index 03544ff8085..79e89ceefcc 100644 --- a/advisories/unreviewed/2025/04/GHSA-m8p9-q552-5h79/GHSA-m8p9-q552-5h79.json +++ b/advisories/unreviewed/2025/04/GHSA-m8p9-q552-5h79/GHSA-m8p9-q552-5h79.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8p9-q552-5h79", - "modified": "2025-04-20T09:30:33Z", + "modified": "2025-04-21T15:31:21Z", "published": "2025-04-20T09:30:33Z", "aliases": [ "CVE-2025-37838" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition\n\nIn the ssi_protocol_probe() function, &ssi->work is bound with\nssip_xmit_work(), In ssip_pn_setup(), the ssip_pn_xmit() function\nwithin the ssip_pn_ops structure is capable of starting the\nwork.\n\nIf we remove the module which will call ssi_protocol_remove()\nto make a cleanup, it will free ssi through kfree(ssi),\nwhile the work mentioned above will be used. The sequence\nof operations that may lead to a UAF bug is as follows:\n\nCPU0 CPU1\n\n | ssip_xmit_work\nssi_protocol_remove |\nkfree(ssi); |\n | struct hsi_client *cl = ssi->cl;\n | // use ssi\n\nFix it by ensuring that the work is canceled before proceeding\nwith the cleanup in ssi_protocol_remove().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-18T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json b/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json new file mode 100644 index 00000000000..24f242bbf8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p688-g48x-vg8h/GHSA-p688-g48x-vg8h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p688-g48x-vg8h", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-29209" + ], + "details": "TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29209" + }, + { + "type": "WEB", + "url": "https://github.com/LZY0522/CVE/blob/main/X18-sub_41105c.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json b/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json index bc6e66e91c7..c8dbcae23af 100644 --- a/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json +++ b/advisories/unreviewed/2025/04/GHSA-q9qg-fj9x-mqhg/GHSA-q9qg-fj9x-mqhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q9qg-fj9x-mqhg", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-21T15:31:16Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22040" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix session use-after-free in multichannel connection\n\nThere is a race condition between session setup and\nksmbd_sessions_deregister. The session can be freed before the connection\nis added to channel list of session.\nThis patch check reference count of session before freeing it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:56Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rcpj-p3qg-rwwh/GHSA-rcpj-p3qg-rwwh.json b/advisories/unreviewed/2025/04/GHSA-rcpj-p3qg-rwwh/GHSA-rcpj-p3qg-rwwh.json new file mode 100644 index 00000000000..47d0ff95be8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rcpj-p3qg-rwwh/GHSA-rcpj-p3qg-rwwh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcpj-p3qg-rwwh", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-29625" + ], + "details": "A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29625" + }, + { + "type": "WEB", + "url": "https://github.com/CruiserOne/Astrolog/issues/25" + }, + { + "type": "WEB", + "url": "https://blog.reodus.com/posts/cve-2025-29625" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfmx-5227-mw6r/GHSA-rfmx-5227-mw6r.json b/advisories/unreviewed/2025/04/GHSA-rfmx-5227-mw6r/GHSA-rfmx-5227-mw6r.json new file mode 100644 index 00000000000..1d6480979d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfmx-5227-mw6r/GHSA-rfmx-5227-mw6r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfmx-5227-mw6r", + "modified": "2025-04-21T15:31:25Z", + "published": "2025-04-21T15:31:25Z", + "aliases": [ + "CVE-2025-29659" + ], + "details": "Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the \"cmd_listen\" function located in the \"cmd\" binary.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29659" + }, + { + "type": "WEB", + "url": "https://github.com/Yasha-ops/RCE-YiIOT" + }, + { + "type": "WEB", + "url": "https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-29659" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v3cw-79rq-fhpq/GHSA-v3cw-79rq-fhpq.json b/advisories/unreviewed/2025/04/GHSA-v3cw-79rq-fhpq/GHSA-v3cw-79rq-fhpq.json new file mode 100644 index 00000000000..05daf93b8fb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v3cw-79rq-fhpq/GHSA-v3cw-79rq-fhpq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3cw-79rq-fhpq", + "modified": "2025-04-21T15:31:24Z", + "published": "2025-04-21T15:31:24Z", + "aliases": [ + "CVE-2024-12862" + ], + "details": "Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to remove external collaborators.This issue affects Content Server: 20.2-24.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12862" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0839115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhqp-wr72-mxv8/GHSA-vhqp-wr72-mxv8.json b/advisories/unreviewed/2025/04/GHSA-vhqp-wr72-mxv8/GHSA-vhqp-wr72-mxv8.json new file mode 100644 index 00000000000..2d5fbe3c4ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhqp-wr72-mxv8/GHSA-vhqp-wr72-mxv8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhqp-wr72-mxv8", + "modified": "2025-04-21T15:31:25Z", + "published": "2025-04-21T15:31:25Z", + "aliases": [ + "CVE-2025-28121" + ], + "details": "code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the \"q\" parameter allowing remote attackers to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28121" + }, + { + "type": "WEB", + "url": "https://code-projects.org/online-exam-mastering-system-php" + }, + { + "type": "WEB", + "url": "https://github.com/pruthuraut/CVE-2025-28121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json b/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json new file mode 100644 index 00000000000..f99f93767b6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wm23-hcgv-w4x3/GHSA-wm23-hcgv-w4x3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm23-hcgv-w4x3", + "modified": "2025-04-21T15:31:19Z", + "published": "2025-04-21T15:31:19Z", + "aliases": [ + "CVE-2025-28228" + ], + "details": "A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28228" + }, + { + "type": "WEB", + "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-28228" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wq8j-qvfr-hj44/GHSA-wq8j-qvfr-hj44.json b/advisories/unreviewed/2025/04/GHSA-wq8j-qvfr-hj44/GHSA-wq8j-qvfr-hj44.json new file mode 100644 index 00000000000..9820d871457 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wq8j-qvfr-hj44/GHSA-wq8j-qvfr-hj44.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq8j-qvfr-hj44", + "modified": "2025-04-21T15:31:21Z", + "published": "2025-04-21T15:31:21Z", + "aliases": [ + "CVE-2025-3792" + ], + "details": "A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3792" + }, + { + "type": "WEB", + "url": "https://github.com/FSRM1/CVE/blob/main/seacms_sql%E6%B3%A8%E5%85%A5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.305615" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.305615" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.554592" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-18T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x9ph-h9wh-vcm2/GHSA-x9ph-h9wh-vcm2.json b/advisories/unreviewed/2025/04/GHSA-x9ph-h9wh-vcm2/GHSA-x9ph-h9wh-vcm2.json new file mode 100644 index 00000000000..5c2927a67b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x9ph-h9wh-vcm2/GHSA-x9ph-h9wh-vcm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9ph-h9wh-vcm2", + "modified": "2025-04-21T15:31:25Z", + "published": "2025-04-21T15:31:25Z", + "aliases": [ + "CVE-2024-12863" + ], + "details": "Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12863" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0839121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T15:15:58Z" + } +} \ No newline at end of file